<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1687073.xsl"?>
<?xml-stylesheet type="text/css" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1686935.css"?>
<cvrf:cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle VM Server for x86 Bulletin - July 2016 - Oracle CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle VM Server for x86 Bulletin Advisory</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>OVMBulletinJul2016</ID>
      </Identification>
      <Status>Final</Status>
      <Version>3.0</Version>
      <RevisionHistory>
         <Revision>
            <Number>1.0</Number>
            <Date>2016-07-19T13:00:00-07:00</Date>
            <Description>Initial Distribution</Description>
         </Revision>
         <Revision>
            <Number>2.0</Number>
            <Date>2016-08-19T13:00:00-07:00</Date>
            <Description>New CVEs added.</Description>
         </Revision>
         <Revision>
            <Number>3.0</Number>
            <Date>2016-09-19T13:00:00-07:00</Date>
            <Description>New CVEs added.</Description>
         </Revision>
      </RevisionHistory>
   </DocumentTracking>
   <DocumentNotes>
      <Note Audience="All" Ordinal="1" Title="Summary" Type="Summary" xml:lang="en">This document contains descriptions of Oracle VM Server for x86 security vulnerabilities which have had fixes released for all supported versions and platforms.</Note>
   </DocumentNotes>
   <DocumentReferences>
      <Reference Type="External">
         <URL>http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Name="Oracle" Type="Vendor">
         <Branch Name="Oracle VM Server for x86" Type="Product Family">
            <Branch Name="Oracle VM Server for x86" Type="Product Name">
               <Branch Name="3.2" Type="Product Version">
                  <FullProductName ProductID="P-4455V-3.2">Oracle VM Server for x86 3.2</FullProductName>
               </Branch>
               <Branch Name="3.3" Type="Product Version">
                  <FullProductName ProductID="P-4455V-3.3">Oracle VM Server for x86 3.3</FullProductName>
               </Branch>
               <Branch Name="3.4" Type="Product Version">
                  <FullProductName ProductID="P-4455V-3.4">Oracle VM Server for x86 3.4</FullProductName>
               </Branch>
            </Branch>
         </Branch>
     </Branch>
  </ProductTree>
<Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-7154</Title>
         <Notes>
               <Note Audience="All" Ordinal="1" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 8.3 CVSS V2 Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-7154</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.3</BaseScore>
               <Vector>AV:A/AC:L/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0102.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-6435</Title>
         <Notes>
               <Note Audience="All" Ordinal="2" Title="Details" Type="Details">This is a vulnerability in  rpm  in Oracle VM Server for x86. It was found that RPM wrote file contents to the target installation directory under a temporary name, and verified its cryptographic signature only after the temporary file has been written completely. Under certain conditions, the system interprets the unverified temporary file contents and extracts commands from it. This could allow an attacker to modify signed RPM files in such a way that they would execute code chosen by the attacker during package installation. CVSS Base Score: 7.6 CVSS V2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-6435</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.6</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0077.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8550</Title>
         <Notes>
               <Note Audience="All" Ordinal="3" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. Xen, when used on a system providing PV backends, allows local guestOS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability. CVSS Base Score: 7.4 CVSS V2 Vector: AV:A/AC:M/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8550</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.4</BaseScore>
               <Vector>AV:A/AC:M/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0089.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4470</Title>
         <Notes>
               <Note Audience="All" Ordinal="4" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The key_reject_and_link function in security/keys/key.c in the Linuxkernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command. CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4470</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0094.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4470</Title>
         <Notes>
               <Note Audience="All" Ordinal="5" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The key_reject_and_link function in security/keys/key.c in the Linuxkernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command. CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4470</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0095.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-0292</Title>
         <Notes>
               <Note Audience="All" Ordinal="6" Title="Details" Type="Details">This is a vulnerability in  dbus-glib  in Oracle VM Server for x86. The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal. CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-0292</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0057.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4565</Title>
         <Notes>
               <Note Audience="All" Ordinal="7" Title="Details" Type="Details">This is a vulnerability in  kernel-uek   in Oracle VM Server for x86. The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface. CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4565</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0060.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="8" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4565</Title>
         <Notes>
               <Note Audience="All" Ordinal="8" Title="Details" Type="Details">This is a vulnerability in  kernel-uek  in Oracle VM Server for x86. The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface. CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4565</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0083.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="9" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4565</Title>
         <Notes>
               <Note Audience="All" Ordinal="9" Title="Details" Type="Details">This is a vulnerability in  kernel-uek  in Oracle VM Server for x86. The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface. CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4565</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0084.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="10" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-2174</Title>
         <Notes>
               <Note Audience="All" Ordinal="10" Title="Details" Type="Details">This is a vulnerability in  curl  in Oracle VM Server for x86. Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string ending in a % (percent) character. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-2174</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0056.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="11" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7554</Title>
         <Notes>
               <Note Audience="All" Ordinal="11" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle VM Server for x86. The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allowsattackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via crafted field data in an extension tag in a TIFF image. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7554</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0093.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="12" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8784</Title>
         <Notes>
               <Note Audience="All" Ordinal="12" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle VM Server for x86. The NeXTDecode function in tif_next.c in LibTIFF allows remoteattackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image, as demonstrated by libtiff5.tif. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8784</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0093.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="13" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3632</Title>
         <Notes>
               <Note Audience="All" Ordinal="13" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3632</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0093.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="14" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3945</Title>
         <Notes>
               <Note Audience="All" Ordinal="14" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3945</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0093.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="15" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3990</Title>
         <Notes>
               <Note Audience="All" Ordinal="15" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3990</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0093.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="16" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3991</Title>
         <Notes>
               <Note Audience="All" Ordinal="16" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3991</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0093.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="17" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-5320</Title>
         <Notes>
               <Note Audience="All" Ordinal="17" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-5320</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0093.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="18" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1834</Title>
         <Notes>
               <Note Audience="All" Ordinal="18" Title="Details" Type="Details">This is a vulnerability in  libxml2  in Oracle VM Server for x86. libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOSbefore 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2016-1833, CVE-2016-1836, CVE-2016-1837, CVE-2016-1838, CVE-2016-1839, and CVE-2016-1840. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1834</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0087.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="19" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-5605</Title>
         <Notes>
               <Note Audience="All" Ordinal="19" Title="Details" Type="Details">This is a vulnerability in  nspr  in Oracle VM Server for x86. Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid handshake packets. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-5605</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0065.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="20" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-1544</Title>
         <Notes>
               <Note Audience="All" Ordinal="20" Title="Details" Type="Details">This is a vulnerability in  nspr  in Oracle VM Server for x86. A race condition was found in the way NSS verified certain certificates. A remote attacker could use this flaw to crash an application using NSS or, possibly, execute arbitrary code with the privileges of the user running that application. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-1544</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0065.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="21" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7181</Title>
         <Notes>
               <Note Audience="All" Ordinal="21" Title="Details" Type="Details">This is a vulnerability in  nspr  in Oracle VM Server for x86. The sec_asn1d_parse_leaf function in Mozilla Network Security Services(NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data, related to a use-after-poison issue.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7181</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0065.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="22" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7182</Title>
         <Notes>
               <Note Audience="All" Ordinal="22" Title="Details" Type="Details">This is a vulnerability in  nspr  in Oracle VM Server for x86. Heap-based buffer overflow in the ASN.1 decoder in Mozilla NetworkSecurity Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7182</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0065.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="23" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7183</Title>
         <Notes>
               <Note Audience="All" Ordinal="23" Title="Details" Type="Details">This is a vulnerability in  nspr  in Oracle VM Server for x86. Integer overflow in the PL_ARENA_ALLOCATE implementation in NetscapePortable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7183</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0065.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="24" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-5605</Title>
         <Notes>
               <Note Audience="All" Ordinal="24" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid handshake packets. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-5605</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="25" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-1544</Title>
         <Notes>
               <Note Audience="All" Ordinal="25" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. A race condition was found in the way NSS verified certain certificates. A remote attacker could use this flaw to crash an application using NSS or, possibly, execute arbitrary code with the privileges of the user running that application. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-1544</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="26" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7181</Title>
         <Notes>
               <Note Audience="All" Ordinal="26" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. The sec_asn1d_parse_leaf function in Mozilla Network Security Services(NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data, related to a use-after-poison issue.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7181</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="27" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7182</Title>
         <Notes>
               <Note Audience="All" Ordinal="27" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. Heap-based buffer overflow in the ASN.1 decoder in Mozilla NetworkSecurity Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7182</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="28" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7183</Title>
         <Notes>
               <Note Audience="All" Ordinal="28" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. Integer overflow in the PL_ARENA_ALLOCATE implementation in NetscapePortable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7183</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="29" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1950</Title>
         <Notes>
               <Note Audience="All" Ordinal="29" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. Heap-based buffer overflow in Mozilla Network Security Services (NSS)before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1950</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="30" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2012-0060</Title>
         <Notes>
               <Note Audience="All" Ordinal="30" Title="Details" Type="Details">This is a vulnerability in  rpm  in Oracle VM Server for x86. RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an invalid region tag in a package header to the (1) headerLoad, (2) rpmReadSignature, or (3) headerVerify function. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2012-0060</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0077.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="31" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2012-0061</Title>
         <Notes>
               <Note Audience="All" Ordinal="31" Title="Details" Type="Details">This is a vulnerability in  rpm  in Oracle VM Server for x86. The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large region size in a package header. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2012-0061</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0077.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="32" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2012-0815</Title>
         <Notes>
               <Note Audience="All" Ordinal="32" Title="Details" Type="Details">This is a vulnerability in  rpm  in Oracle VM Server for x86. The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2012-0815</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0077.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="33" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-0106</Title>
         <Notes>
               <Note Audience="All" Ordinal="33" Title="Details" Type="Details">This is a vulnerability in  sudo  in Oracle VM Server for x86. Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable. CVSS Base Score: 6.6 CVSS V2 Vector: AV:L/AC:M/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-0106</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.6</BaseScore>
               <Vector>AV:L/AC:M/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0079.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="34" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7504</Title>
         <Notes>
               <Note Audience="All" Ordinal="34" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.5 CVSS V2 Vector: AV:A/AC:H/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7504</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>AV:A/AC:H/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0081.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="35" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8554</Title>
         <Notes>
               <Note Audience="All" Ordinal="35" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. Buffer overflow in hw/pt-msi.c in Xen 4.6.x and earlier, when usingthe qemu-xen-traditional (aka qemu-dm) device model, allows local x86 HVM guest administrators to gain privileges by leveraging a system with access to a passed-through MSI-X capable physical PCI device and MSI-X table entries, related to a write CVSS Base Score: 6.5 CVSS V2 Vector: AV:A/AC:H/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8554</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>AV:A/AC:H/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0081.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="36" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3710</Title>
         <Notes>
               <Note Audience="All" Ordinal="36" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The VGA module in QEMU improperly performs bounds checking on bankedaccess to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the Dark CVSS Base Score: 6.5 CVSS V2 Vector: AV:A/AC:H/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3710</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>AV:A/AC:H/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0081.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="37" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3710</Title>
         <Notes>
               <Note Audience="All" Ordinal="37" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The VGA module in QEMU improperly performs bounds checking on bankedaccess to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the Dark CVSS Base Score: 6.5 CVSS V2 Vector: AV:A/AC:H/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3710</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>AV:A/AC:H/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0088.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="38" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3710</Title>
         <Notes>
               <Note Audience="All" Ordinal="38" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The VGA module in QEMU improperly performs bounds checking on bankedaccess to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the Dark CVSS Base Score: 6.5 CVSS V2 Vector: AV:A/AC:H/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3710</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>AV:A/AC:H/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0089.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="39" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8660</Title>
         <Notes>
               <Note Audience="All" Ordinal="39" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernelthrough 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application. CVSS Base Score: 6 CVSS V2 Vector: AV:L/AC:H/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8660</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6</BaseScore>
               <Vector>AV:L/AC:H/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0094.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="40" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4962</Title>
         <Notes>
               <Note Audience="All" Ordinal="40" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The libxl device-handling in Xen 4.6.x and earlier allows local OSguest administrators to cause a denial of service (resource consumption or management facility confusion) or gain host OS privileges by manipulating information in guest controlled areas of xenstore. CVSS Base Score: 6 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4962</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0088.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="41" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4962</Title>
         <Notes>
               <Note Audience="All" Ordinal="41" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The libxl device-handling in Xen 4.6.x and earlier allows local OSguest administrators to cause a denial of service (resource consumption or management facility confusion) or gain host OS privileges by manipulating information in guest controlled areas of xenstore. CVSS Base Score: 6 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4962</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0089.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="42" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-6258</Title>
         <Notes>
               <Note Audience="All" Ordinal="42" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allowslocal 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries. CVSS Base Score: 6 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-6258</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0088.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="43" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-6258</Title>
         <Notes>
               <Note Audience="All" Ordinal="43" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allowslocal 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries. CVSS Base Score: 6 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-6258</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0089.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="44" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-6258</Title>
         <Notes>
               <Note Audience="All" Ordinal="44" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allowslocal 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries. CVSS Base Score: 6 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-6258</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0090.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="45" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-5696</Title>
         <Notes>
               <Note Audience="All" Ordinal="45" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properlydetermine the rate of challenge ACK segments, which makes it easier for man-in-the-middle attackers to hijack TCP sessions via a blind in-window attack. CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-5696</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0097.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="46" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-5696</Title>
         <Notes>
               <Note Audience="All" Ordinal="46" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle VM Server for x86. net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properlydetermine the rate of challenge ACK segments, which makes it easier for man-in-the-middle attackers to hijack TCP sessions via a blind in-window attack. CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-5696</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0098.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="47" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-9655</Title>
         <Notes>
               <Note Audience="All" Ordinal="47" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle VM Server for x86. The (1) putcontig8bitYCbCr21tile function in tif_getimage.c or (2)NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff-cvs-1.tif and libtiff-cvs-2.tif. CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-9655</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0093.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="48" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-1547</Title>
         <Notes>
               <Note Audience="All" Ordinal="48" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle VM Server for x86. The NeXTDecode function in tif_next.c in LibTIFF allows remoteattackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff5.tif. CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-1547</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0093.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="49" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-1568</Title>
         <Notes>
               <Note Audience="All" Ordinal="49" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. A flaw was found in the way NSS parsed ASN.1 (Abstract Syntax Notation One) input from certain RSA signatures. A remote attacker could use this flaw to forge RSA certificates by providing a specially crafted signature to an application using NSS. CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-1568</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="50" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-3197</Title>
         <Notes>
               <Note Audience="All" Ordinal="50" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2fdoes not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions. CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-3197</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0071.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="51" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0800</Title>
         <Notes>
               <Note Audience="All" Ordinal="51" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain plaintext RSA data, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a DROWN attack. CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0800</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0071.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="52" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3960</Title>
         <Notes>
               <Note Audience="All" Ordinal="52" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. Integer overflow in the x86 shadow pagetable code in Xen allows localguest OS users to cause a denial of service (host crash) or possibly gain privileges by shadowing a superpage mapping. CVSS Base Score: 5.8 CVSS V2 Vector: AV:A/AC:M/Au:S/C:N/I:P/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3960</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:A/AC:M/Au:S/C:N/I:P/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0088.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="53" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3960</Title>
         <Notes>
               <Note Audience="All" Ordinal="53" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. Integer overflow in the x86 shadow pagetable code in Xen allows localguest OS users to cause a denial of service (host crash) or possibly gain privileges by shadowing a superpage mapping. CVSS Base Score: 5.8 CVSS V2 Vector: AV:A/AC:M/Au:S/C:N/I:P/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3960</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:A/AC:M/Au:S/C:N/I:P/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0089.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="54" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3960</Title>
         <Notes>
               <Note Audience="All" Ordinal="54" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. Integer overflow in the x86 shadow pagetable code in Xen allows localguest OS users to cause a denial of service (host crash) or possibly gain privileges by shadowing a superpage mapping. CVSS Base Score: 5.8 CVSS V2 Vector: AV:A/AC:M/Au:S/C:N/I:P/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3960</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:A/AC:M/Au:S/C:N/I:P/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0090.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="55" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2012-3440</Title>
         <Notes>
               <Note Audience="All" Ordinal="55" Title="Details" Type="Details">This is a vulnerability in  sudo  in Oracle VM Server for x86. A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on the /var/tmp/nsswitch.conf.bak temporary file. CVSS Base Score: 5.6 CVSS V2 Vector: AV:L/AC:H/Au:N/C:N/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2012-3440</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.6</BaseScore>
               <Vector>AV:L/AC:H/Au:N/C:N/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0079.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="56" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-3672</Title>
         <Notes>
               <Note Audience="All" Ordinal="56" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The qemu implementation in libvirt before 1.3.0 and Xen allows localguest OS users to cause a denial of service (host disk consumption) by writing to stdout or stderr. CVSS Base Score: 5.2 CVSS V2 Vector: AV:A/AC:M/Au:S/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-3672</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.2</BaseScore>
               <Vector>AV:A/AC:M/Au:S/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0088.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="57" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-3672</Title>
         <Notes>
               <Note Audience="All" Ordinal="57" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The qemu implementation in libvirt before 1.3.0 and Xen allows localguest OS users to cause a denial of service (host disk consumption) by writing to stdout or stderr. CVSS Base Score: 5.2 CVSS V2 Vector: AV:A/AC:M/Au:S/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-3672</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.2</BaseScore>
               <Vector>AV:A/AC:M/Au:S/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0089.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="58" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-3672</Title>
         <Notes>
               <Note Audience="All" Ordinal="58" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The qemu implementation in libvirt before 1.3.0 and Xen allows localguest OS users to cause a denial of service (host disk consumption) by writing to stdout or stderr. CVSS Base Score: 5.2 CVSS V2 Vector: AV:A/AC:M/Au:S/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-3672</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.2</BaseScore>
               <Vector>AV:A/AC:M/Au:S/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0090.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="59" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-5307</Title>
         <Notes>
               <Note Audience="All" Ordinal="59" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.xthrough 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c. CVSS Base Score: 5.2 CVSS V2 Vector: AV:A/AC:M/Au:S/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-5307</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.2</BaseScore>
               <Vector>AV:A/AC:M/Au:S/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0081.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="60" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8104</Title>
         <Notes>
               <Note Audience="All" Ordinal="60" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.xthrough 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c. CVSS Base Score: 5.2 CVSS V2 Vector: AV:A/AC:M/Au:S/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8104</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.2</BaseScore>
               <Vector>AV:A/AC:M/Au:S/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0081.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="61" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2270</Title>
         <Notes>
               <Note Audience="All" Ordinal="61" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. Xen 4.6.x and earlier allows local guest administrators to cause adenial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings. CVSS Base Score: 5.2 CVSS V2 Vector: AV:A/AC:M/Au:S/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2270</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.2</BaseScore>
               <Vector>AV:A/AC:M/Au:S/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0081.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="62" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2270</Title>
         <Notes>
               <Note Audience="All" Ordinal="62" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. Xen 4.6.x and earlier allows local guest administrators to cause adenial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings. CVSS Base Score: 5.2 CVSS V2 Vector: AV:A/AC:M/Au:S/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2270</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.2</BaseScore>
               <Vector>AV:A/AC:M/Au:S/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0088.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="63" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1840</Title>
         <Notes>
               <Note Audience="All" Ordinal="63" Title="Details" Type="Details">This is a vulnerability in  libxml2  in Oracle VM Server for x86. libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOSbefore 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2016-1833, CVE-2016-1834, CVE-2016-1836, CVE-2016-1837, CVE-2016-1838, and CVE-2016-1839. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1840</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0087.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="64" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4448</Title>
         <Notes>
               <Note Audience="All" Ordinal="64" Title="Details" Type="Details">This is a vulnerability in  libxml2  in Oracle VM Server for x86. Format string vulnerability in libxml2 before 2.9.4 allows attackersto have unspecified impact via format string specifiers in unknown vectors. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4448</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0087.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="65" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-1620</Title>
         <Notes>
               <Note Audience="All" Ordinal="65" Title="Details" Type="Details">This is a vulnerability in  nspr  in Oracle VM Server for x86. The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-1620</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0065.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="66" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1978</Title>
         <Notes>
               <Note Audience="All" Ordinal="66" Title="Details" Type="Details">This is a vulnerability in  nspr  in Oracle VM Server for x86. Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchangefunction in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1978</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0065.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="67" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1979</Title>
         <Notes>
               <Note Audience="All" Ordinal="67" Title="Details" Type="Details">This is a vulnerability in  nspr  in Oracle VM Server for x86. Use-after-free vulnerability in thePK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1979</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0065.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="68" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-1620</Title>
         <Notes>
               <Note Audience="All" Ordinal="68" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-1620</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="69" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-1490</Title>
         <Notes>
               <Note Audience="All" Ordinal="69" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. A race condition was found in the way NSS implemented session ticket handling as specified by RFC 5077. An attacker could use this flaw to crash an application using NSS or, in rare cases, execute arbitrary code with the privileges of the user running that application. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-1490</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="70" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-1545</Title>
         <Notes>
               <Note Audience="All" Ordinal="70" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. An out-of-bounds write flaw was found in NSPR. A remote attacker could potentially use this flaw to crash an application using NSPR or, possibly, execute arbitrary code with the privileges of the user running that application. This NSPR flaw was not exposed to web content in any shipped version of Firefox. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-1545</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="71" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-2721</Title>
         <Notes>
               <Note Audience="All" Ordinal="71" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. It was found that NSS permitted skipping of the ServerKeyExchange packet during a handshake involving ECDHE (Elliptic Curve Diffie-Hellman key Exchange). A remote attacker could use this flaw to bypass the forward-secrecy of a TLS/SSL connection. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-2721</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="72" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1978</Title>
         <Notes>
               <Note Audience="All" Ordinal="72" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchangefunction in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1978</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="73" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1979</Title>
         <Notes>
               <Note Audience="All" Ordinal="73" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. Use-after-free vulnerability in thePK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1979</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="74" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2105</Title>
         <Notes>
               <Note Audience="All" Ordinal="74" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. Integer overflow in the EVP_EncodeUpdate function incrypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2105</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0086.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="75" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2106</Title>
         <Notes>
               <Note Audience="All" Ordinal="75" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. Integer overflow in the EVP_EncryptUpdate function incrypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of data. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2106</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0086.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="76" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2012-5195</Title>
         <Notes>
               <Note Audience="All" Ordinal="76" Title="Details" Type="Details">This is a vulnerability in  perl  in Oracle VM Server for x86. Heap-based buffer overflow in the Perl_repeatcpy function in util.c in Perl 5.12.x before 5.12.5, 5.14.x before 5.14.3, and 5.15.x before 15.15.5 allows context-dependent attackers to cause a denial of service (memory consumption and crash) or possibly execute arbitrary code via the 'x' string repeat operator. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2012-5195</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0076.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="77" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2012-6329</Title>
         <Notes>
               <Note Audience="All" Ordinal="77" Title="Details" Type="Details">This is a vulnerability in  perl  in Oracle VM Server for x86. The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and fully qualified method names during compilation of bracket notation, which allows context-dependent attackers to execute arbitrary commands via crafted input to an application that accepts translation strings from users, as demonstrated by the TWiki application before 5.1.3, and the Foswiki application 1.0.x through 1.0.10 and 1.1.x through 1.1.6. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2012-6329</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0076.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="78" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2012-5166</Title>
         <Notes>
               <Note Audience="All" Ordinal="78" Title="Details" Type="Details">This is a vulnerability in  bind  in Oracle VM Server for x86. ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records. CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2012-5166</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0055.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="79" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-8500</Title>
         <Notes>
               <Note Audience="All" Ordinal="79" Title="Details" Type="Details">This is a vulnerability in  bind  in Oracle VM Server for x86. A denial of service flaw was found in the way BIND followed DNS delegations. A remote attacker could use a specially crafted zone containing a large number of referrals which, when looked up and processed, would cause named to use excessive amounts of memory or crash. CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-8500</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0055.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="80" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-5477</Title>
         <Notes>
               <Note Audience="All" Ordinal="80" Title="Details" Type="Details">This is a vulnerability in  bind  in Oracle VM Server for x86. A flaw was found in the way BIND handled requests for TKEY DNS resource records. A remote attacker could use this flaw to make named (functioning as an authoritative DNS server or a DNS resolver) exit unexpectedly with an assertion failure via a specially crafted DNS request packet. CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-5477</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0055.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="81" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-5722</Title>
         <Notes>
               <Note Audience="All" Ordinal="81" Title="Details" Type="Details">This is a vulnerability in  bind  in Oracle VM Server for x86. A denial of service flaw was found in the way BIND parsed certain malformed DNSSEC keys. A remote attacker could use this flaw to send a specially crafted DNS query (for example, a query requiring a response from a zone containing a deliberately malformed key) that would cause named functioning as a validating resolver to crash. CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-5722</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0055.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="82" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1285</Title>
         <Notes>
               <Note Audience="All" Ordinal="82" Title="Details" Type="Details">This is a vulnerability in  bind  in Oracle VM Server for x86. named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c. CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1285</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0055.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="83" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1286</Title>
         <Notes>
               <Note Audience="All" Ordinal="83" Title="Details" Type="Details">This is a vulnerability in  bind  in Oracle VM Server for x86. named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c. CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1286</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0055.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="84" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-6908</Title>
         <Notes>
               <Note Audience="All" Ordinal="84" Title="Details" Type="Details">This is a vulnerability in  openldap  in Oracle VM Server for x86. A flaw was found in the way the OpenLDAP server daemon (slapd) parsed certain BER data. A remote attacker could exploit this flaw by using a specially crafted packet to crash the OpenLDAP server (denial of service). The server could be crashed even when running in daemon mode. CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-6908</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0069.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="85" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-1667</Title>
         <Notes>
               <Note Audience="All" Ordinal="85" Title="Details" Type="Details">This is a vulnerability in  perl  in Oracle VM Server for x86. The rehash mechanism in Perl 5.8.2 through 5.16.x allows context-dependent attackers to cause a denial of service (memory consumption and crash) via a crafted hash key. CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-1667</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0076.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="86" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1000110</Title>
         <Notes>
               <Note Audience="All" Ordinal="86" Title="Details" Type="Details">This is a vulnerability in  python  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1000110</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0099.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="87" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3115</Title>
         <Notes>
               <Note Audience="All" Ordinal="87" Title="Details" Type="Details">This is a vulnerability in  openssh  in Oracle VM Server for x86. Multiple CRLF injection vulnerabilities in session.c in sshd inOpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) do_authenticated1 and (2) session_x11_req functions. CVSS Base Score: 4.9 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3115</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0070.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="88" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2011-4339</Title>
         <Notes>
               <Note Audience="All" Ordinal="88" Title="Details" Type="Details">This is a vulnerability in  OpenIPMI  in Oracle VM Server for x86. ipmievd (aka the IPMI event daemon) in OpenIPMI, as used in the ipmitool package 1.8.11 in Red Hat Enterprise Linux (RHEL) 6, Debian GNU/Linux, Fedora 16, and other products uses 0666 permissions for its ipmievd.pid PID file, which allows local users to kill arbitrary processes by writing to this file. CVSS Base Score: 4.7 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2011-4339</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.7</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0068.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="89" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-6197</Title>
         <Notes>
               <Note Audience="All" Ordinal="89" Title="Details" Type="Details">This is a vulnerability in  kernel-uek  in Oracle VM Server for x86. fs/overlayfs/dir.c in the OverlayFS filesystem implementation in theLinux kernel before 4.6 does not properly verify the upper dentry before proceeding with unlink and rename system-call processing, which allows local users to cause a denial of service (system crash) via a rename system call that specifies a self-hardlink. CVSS Base Score: 4.7 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-6197</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.7</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0091.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="90" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-6198</Title>
         <Notes>
               <Note Audience="All" Ordinal="90" Title="Details" Type="Details">This is a vulnerability in  kernel-uek  in Oracle VM Server for x86. The filesystem layer in the Linux kernel before 4.5.5 proceeds withpost-rename operations after an OverlayFS file is renamed to a self-hardlink, which allows local users to cause a denial of service (system crash) via a rename system call, related to fs/namei.c and fs/open.c. CVSS Base Score: 4.7 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-6198</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.7</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0091.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="91" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8000</Title>
         <Notes>
               <Note Audience="All" Ordinal="91" Title="Details" Type="Details">This is a vulnerability in  bind  in Oracle VM Server for x86. db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a malformed class attribute.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8000</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0055.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="92" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-1944</Title>
         <Notes>
               <Note Audience="All" Ordinal="92" Title="Details" Type="Details">This is a vulnerability in  curl  in Oracle VM Server for x86. The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-1944</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0056.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="93" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-9330</Title>
         <Notes>
               <Note Audience="All" Ordinal="93" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle VM Server for x86. Integer overflow in tif_packbits.c in bmp2tif in libtiff 4.0.3 allowsremote attackers to cause a denial of service (crash) via crafted BMP image, related to dimensions, which triggers an out-of-bounds read. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-9330</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0093.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="94" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8665</Title>
         <Notes>
               <Note Audience="All" Ordinal="94" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle VM Server for x86. tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause adenial of service (out-of-bounds read) via the SamplesPerPixel tag in a TIFF image. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8665</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0093.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="95" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8668</Title>
         <Notes>
               <Note Audience="All" Ordinal="95" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle VM Server for x86. Heap-based buffer overflow in the PackBitsPreEncode function intif_packbits.c in bmp2tiff in libtiff 4.0.6 and earlier allows remote attackers to execute arbitrary code or cause a denial of service via a large width field in a BMP image. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8668</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0093.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="96" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8683</Title>
         <Notes>
               <Note Audience="All" Ordinal="96" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle VM Server for x86. The putcontig8bitCIELab function in tif_getimage.c in LibTIFF 4.0.6allows remote attackers to cause a denial of service (out-of-bounds read) via a packed TIFF image. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8683</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0093.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="97" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8781</Title>
         <Notes>
               <Note Audience="All" Ordinal="97" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle VM Server for x86. tif_luv.c in libtiff allows attackers to cause a denial of service(out-of-bounds write) via an invalid number of samples per pixel in a LogL compressed TIFF image, a different vulnerability than CVE-2015-8782. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8781</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0093.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="98" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8782</Title>
         <Notes>
               <Note Audience="All" Ordinal="98" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle VM Server for x86. tif_luv.c in libtiff allows attackers to cause a denial of service(out-of-bounds writes) via a crafted TIFF image, a different vulnerability than CVE-2015-8781. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8782</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0093.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="99" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8783</Title>
         <Notes>
               <Note Audience="All" Ordinal="99" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle VM Server for x86. tif_luv.c in libtiff allows attackers to cause a denial of service(out-of-bounds reads) via a crafted TIFF image. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8783</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0093.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="100" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-3660</Title>
         <Notes>
               <Note Audience="All" Ordinal="100" Title="Details" Type="Details">This is a vulnerability in  libxml2  in Oracle VM Server for x86. A denial of service flaw was found in libxml2, a library providing support to read, modify and write XML and HTML files. A remote attacker could provide a specially crafted XML file that, when processed by an application using libxml2, would lead to excessive CPU consumption (denial of service) based on excessive entity substitutions, even if entity substitution was disabled, which is the parser default behavior. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-3660</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0063.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="101" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1762</Title>
         <Notes>
               <Note Audience="All" Ordinal="101" Title="Details" Type="Details">This is a vulnerability in  libxml2  in Oracle VM Server for x86. libxml2 in Apple iOS before 9.3, OS X before 10.11.4, Safari before9.1, tvOS before 9.2, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1762</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0087.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="102" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1833</Title>
         <Notes>
               <Note Audience="All" Ordinal="102" Title="Details" Type="Details">This is a vulnerability in  libxml2  in Oracle VM Server for x86. libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOSbefore 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2016-1834, CVE-2016-1836, CVE-2016-1837, CVE-2016-1838, CVE-2016-1839, and CVE-2016-1840. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1833</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0087.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="103" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1835</Title>
         <Notes>
               <Note Audience="All" Ordinal="103" Title="Details" Type="Details">This is a vulnerability in  libxml2  in Oracle VM Server for x86. libxml2, as used in Apple iOS before 9.3.2 and OS X before 10.11.5,allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1835</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0087.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="104" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1836</Title>
         <Notes>
               <Note Audience="All" Ordinal="104" Title="Details" Type="Details">This is a vulnerability in  libxml2  in Oracle VM Server for x86. libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOSbefore 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2016-1833, CVE-2016-1834, CVE-2016-1837, CVE-2016-1838, CVE-2016-1839, and CVE-2016-1840. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1836</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0087.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="105" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1837</Title>
         <Notes>
               <Note Audience="All" Ordinal="105" Title="Details" Type="Details">This is a vulnerability in  libxml2  in Oracle VM Server for x86. libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOSbefore 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2016-1833, CVE-2016-1834, CVE-2016-1836, CVE-2016-1838, CVE-2016-1839, and CVE-2016-1840. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1837</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0087.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="106" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1838</Title>
         <Notes>
               <Note Audience="All" Ordinal="106" Title="Details" Type="Details">This is a vulnerability in  libxml2  in Oracle VM Server for x86. libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOSbefore 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2016-1833, CVE-2016-1834, CVE-2016-1836, CVE-2016-1837, CVE-2016-1839, and CVE-2016-1840. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1838</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0087.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="107" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1839</Title>
         <Notes>
               <Note Audience="All" Ordinal="107" Title="Details" Type="Details">This is a vulnerability in  libxml2  in Oracle VM Server for x86. libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOSbefore 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2016-1833, CVE-2016-1834, CVE-2016-1836, CVE-2016-1837, CVE-2016-1838, and CVE-2016-1840. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1839</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0087.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="108" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3627</Title>
         <Notes>
               <Note Audience="All" Ordinal="108" Title="Details" Type="Details">This is a vulnerability in  libxml2  in Oracle VM Server for x86. The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 andearlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML document. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3627</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0087.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="109" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3705</Title>
         <Notes>
               <Note Audience="All" Ordinal="109" Title="Details" Type="Details">This is a vulnerability in  libxml2  in Oracle VM Server for x86. The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functionsin parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3705</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0087.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="110" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4447</Title>
         <Notes>
               <Note Audience="All" Ordinal="110" Title="Details" Type="Details">This is a vulnerability in  libxml2  in Oracle VM Server for x86. The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4447</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0087.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="111" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4449</Title>
         <Notes>
               <Note Audience="All" Ordinal="111" Title="Details" Type="Details">This is a vulnerability in  libxml2  in Oracle VM Server for x86. XML external entity (XXE) vulnerability in thexmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4449</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0087.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="112" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2012-0441</Title>
         <Notes>
               <Note Audience="All" Ordinal="112" Title="Details" Type="Details">This is a vulnerability in  nspr  in Oracle VM Server for x86. The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10, allows remote attackers to cause a denial of service (application crash) via a zero-length item, as demonstrated by (1) a zero-length basic constraint or (2) a zero-length field in an OCSP response. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2012-0441</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0065.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="113" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-0791</Title>
         <Notes>
               <Note Audience="All" Ordinal="113" Title="Details" Type="Details">This is a vulnerability in  nspr  in Oracle VM Server for x86. The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted certificate. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-0791</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0065.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="114" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-1739</Title>
         <Notes>
               <Note Audience="All" Ordinal="114" Title="Details" Type="Details">This is a vulnerability in  nspr  in Oracle VM Server for x86. Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-1739</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0065.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="115" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-1741</Title>
         <Notes>
               <Note Audience="All" Ordinal="115" Title="Details" Type="Details">This is a vulnerability in  nspr  in Oracle VM Server for x86. Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large size value. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-1741</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0065.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="116" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-5606</Title>
         <Notes>
               <Note Audience="All" Ordinal="116" Title="Details" Type="Details">This is a vulnerability in  nspr  in Oracle VM Server for x86. The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-5606</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0065.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="117" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-5607</Title>
         <Notes>
               <Note Audience="All" Ordinal="117" Title="Details" Type="Details">This is a vulnerability in  nspr  in Oracle VM Server for x86. Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-5607</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0065.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="118" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2012-0441</Title>
         <Notes>
               <Note Audience="All" Ordinal="118" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10, allows remote attackers to cause a denial of service (application crash) via a zero-length item, as demonstrated by (1) a zero-length basic constraint or (2) a zero-length field in an OCSP response. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2012-0441</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="119" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-0791</Title>
         <Notes>
               <Note Audience="All" Ordinal="119" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted certificate. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-0791</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="120" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-1739</Title>
         <Notes>
               <Note Audience="All" Ordinal="120" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-1739</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="121" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-1740</Title>
         <Notes>
               <Note Audience="All" Ordinal="121" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. A flaw was found in the way TLS False Start was implemented in NSS. An attacker could use this flaw to potentially return unencrypted information from the server. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-1740</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="122" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-1741</Title>
         <Notes>
               <Note Audience="All" Ordinal="122" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large size value. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-1741</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="123" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-5606</Title>
         <Notes>
               <Note Audience="All" Ordinal="123" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-5606</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="124" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-5607</Title>
         <Notes>
               <Note Audience="All" Ordinal="124" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-5607</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="125" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-1491</Title>
         <Notes>
               <Note Audience="All" Ordinal="125" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. It was found that NSS accepted weak Diffie-Hellman Key exchange (DHKE) parameters. This could possibly lead to weak encryption being used in communication between the client and the server. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-1491</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="126" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-2730</Title>
         <Notes>
               <Note Audience="All" Ordinal="126" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. A flaw was found in the way NSS verified certain ECDSA (Elliptic Curve Digital Signature Algorithm) signatures. Under certain conditions, an attacker could use this flaw to conduct signature forgery attacks. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-2730</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="127" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-4449</Title>
         <Notes>
               <Note Audience="All" Ordinal="127" Title="Details" Type="Details">This is a vulnerability in  openldap  in Oracle VM Server for x86. The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which triggers rwm_conn_destroy to free the session context while it is being used by rwm_op_search. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-4449</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0069.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="128" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-5600</Title>
         <Notes>
               <Note Audience="All" Ordinal="128" Title="Details" Type="Details">This is a vulnerability in  openssh  in Oracle VM Server for x86. The kbdint_next_device function in auth2-chall.c in sshd in OpenSSHthrough 6.9 does not properly restrict the processing of keyboard-interactive devices within a single connection, which makes it easier for remote attackers to conduct brute-force attacks or cause a denial of service (CPU consumption) via a long and duplicative list in the ssh -oKbdInteractiveDevices option, as demonstrated by a modified client that provides a different password for each pam element on this list. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-5600</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0070.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="129" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-3195</Title>
         <Notes>
               <Note Audience="All" Ordinal="129" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c inOpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-3195</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0071.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="130" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0797</Title>
         <Notes>
               <Note Audience="All" Ordinal="130" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2before 1.0.2g allow remote attackers to cause a denial of service (heap memory corruption or NULL pointer dereference) or possibly have unspecified other impact via a long digit string that is mishandled by the (1) BN_dec2bn or (2) BN_hex2bn function, related to crypto/bn/bn.h and crypto/bn/bn_print.c. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0797</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0071.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="131" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4480</Title>
         <Notes>
               <Note Audience="All" Ordinal="131" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory. CVSS Base Score: 4.3 CVSS V2 Vector: AV:A/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4480</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:A/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0088.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="132" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4480</Title>
         <Notes>
               <Note Audience="All" Ordinal="132" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory. CVSS Base Score: 4.3 CVSS V2 Vector: AV:A/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4480</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:A/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0089.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="133" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4480</Title>
         <Notes>
               <Note Audience="All" Ordinal="133" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory. CVSS Base Score: 4.3 CVSS V2 Vector: AV:A/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4480</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:A/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0090.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="134" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3158</Title>
         <Notes>
               <Note Audience="All" Ordinal="134" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The xrstor function in arch/x86/xstate.c in Xen 4.x does not properlyhandle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076. CVSS Base Score: 3.8 CVSS V2 Vector: AV:A/AC:M/Au:S/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3158</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.8</BaseScore>
               <Vector>AV:A/AC:M/Au:S/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0088.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="135" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3158</Title>
         <Notes>
               <Note Audience="All" Ordinal="135" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The xrstor function in arch/x86/xstate.c in Xen 4.x does not properlyhandle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076. CVSS Base Score: 3.8 CVSS V2 Vector: AV:A/AC:M/Au:S/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3158</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.8</BaseScore>
               <Vector>AV:A/AC:M/Au:S/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0089.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="136" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3159</Title>
         <Notes>
               <Note Audience="All" Ordinal="136" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does notproperly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076. CVSS Base Score: 3.8 CVSS V2 Vector: AV:A/AC:M/Au:S/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3159</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.8</BaseScore>
               <Vector>AV:A/AC:M/Au:S/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0088.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="137" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3159</Title>
         <Notes>
               <Note Audience="All" Ordinal="137" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does notproperly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076. CVSS Base Score: 3.8 CVSS V2 Vector: AV:A/AC:M/Au:S/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3159</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.8</BaseScore>
               <Vector>AV:A/AC:M/Au:S/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0089.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="138" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3712</Title>
         <Notes>
               <Note Audience="All" Ordinal="138" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. Integer overflow in the VGA module in QEMU allows local guest OS usersto cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode. CVSS Base Score: 3.8 CVSS V2 Vector: AV:A/AC:M/Au:S/C:P/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3712</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.8</BaseScore>
               <Vector>AV:A/AC:M/Au:S/C:P/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0088.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="139" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3712</Title>
         <Notes>
               <Note Audience="All" Ordinal="139" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. Integer overflow in the VGA module in QEMU allows local guest OS usersto cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode. CVSS Base Score: 3.8 CVSS V2 Vector: AV:A/AC:M/Au:S/C:P/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3712</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.8</BaseScore>
               <Vector>AV:A/AC:M/Au:S/C:P/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0089.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="140" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-8127</Title>
         <Notes>
               <Note Audience="All" Ordinal="140" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 3.6 CVSS V2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-8127</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.6</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0093.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="141" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-8129</Title>
         <Notes>
               <Note Audience="All" Ordinal="141" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 3.6 CVSS V2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-8129</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.6</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0093.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="142" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-1776</Title>
         <Notes>
               <Note Audience="All" Ordinal="142" Title="Details" Type="Details">This is a vulnerability in  sudo  in Oracle VM Server for x86. sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to a standard input, output, and error file descriptors of another terminal.  NOTE: this is one of three closely-related vulnerabilities that were originally assigned CVE-2013-1776, but they have been SPLIT because of different affected versions. CVSS Base Score: 3.6 CVSS V2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-1776</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.6</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0079.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="143" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-2776</Title>
         <Notes>
               <Note Audience="All" Ordinal="143" Title="Details" Type="Details">This is a vulnerability in  sudo  in Oracle VM Server for x86. sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the sysctl function with the tty_tickets option enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to a standard input, output, and error file descriptors of another terminal.  NOTE: this is one of three closely-related vulnerabilities that were originally assigned CVE-2013-1776, but they have been SPLIT because of different affected versions. CVSS Base Score: 3.6 CVSS V2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-2776</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.6</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0079.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="144" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8704</Title>
         <Notes>
               <Note Audience="All" Ordinal="144" Title="Details" Type="Details">This is a vulnerability in  bind  in Oracle VM Server for x86. apl_42.c in ISC BIND 9.x before 9.9.8-P3 and 9.9.x and 9.10.x before9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed Address Prefix List (APL) record. CVSS Base Score: 3.5 CVSS V2 Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8704</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.5</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0055.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="145" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2012-3571</Title>
         <Notes>
               <Note Audience="All" Ordinal="145" Title="Details" Type="Details">This is a vulnerability in  dhcp  in Oracle VM Server for x86. ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier. CVSS Base Score: 3.3 CVSS V2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2012-3571</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.3</BaseScore>
               <Vector>AV:A/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0058.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="146" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2117</Title>
         <Notes>
               <Note Audience="All" Ordinal="146" Title="Details" Type="Details">This is a vulnerability in  kernel-uek  in Oracle VM Server for x86. The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c inthe Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive information from kernel memory by reading packet data. CVSS Base Score: 2.6 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2117</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.6</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0091.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="147" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2117</Title>
         <Notes>
               <Note Audience="All" Ordinal="147" Title="Details" Type="Details">This is a vulnerability in  kernel-uek  in Oracle VM Server for x86. The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c inthe Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive information from kernel memory by reading packet data. CVSS Base Score: 2.6 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2117</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.6</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0092.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="148" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-1492</Title>
         <Notes>
               <Note Audience="All" Ordinal="148" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle VM Server for x86. It was found that the implementation of Internationalizing Domain Names in Applications (IDNA) hostname matching in NSS did not follow the RFC 6125 recommendations. This could lead to certain invalid certificates with international characters to be accepted as valid. CVSS Base Score: 2.6 CVSS V2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-1492</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.6</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0066.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="149" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0799</Title>
         <Notes>
               <Note Audience="All" Ordinal="149" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows remote attackers to cause a denial of service (overflow and out-of-bounds read) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-2842. CVSS Base Score: 2.6 CVSS V2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0799</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.6</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0086.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="150" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2012-5526</Title>
         <Notes>
               <Note Audience="All" Ordinal="150" Title="Details" Type="Details">This is a vulnerability in  perl  in Oracle VM Server for x86. CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm. CVSS Base Score: 2.6 CVSS V2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2012-5526</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.6</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0076.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="151" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-5403</Title>
         <Notes>
               <Note Audience="All" Ordinal="151" Title="Details" Type="Details">This is a vulnerability in  qemu-kvm  in Oracle VM Server for x86. The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows localguest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion. CVSS Base Score: 2.3 CVSS V2 Vector: AV:A/AC:M/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-5403</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.3</BaseScore>
               <Vector>AV:A/AC:M/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0096.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="152" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-8130</Title>
         <Notes>
               <Note Audience="All" Ordinal="152" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 2.1 CVSS V2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-8130</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.1</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0093.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
               <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="153" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-1775</Title>
         <Notes>
               <Note Audience="All" Ordinal="153" Title="Details" Type="Details">This is a vulnerability in  sudo  in Oracle VM Server for x86. sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically-proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by setting the system clock and sudo user timestamp to the epoch. CVSS Base Score: 2.1 CVSS V2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-1775</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.1</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0079.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="154" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-4242</Title>
         <Notes>
               <Note Audience="All" Ordinal="154" Title="Details" Type="Details">This is a vulnerability in  libgcrypt  in Oracle VM Server for x86. GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload. CVSS Base Score: 1.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-4242</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>1.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0062.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="155" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2109</Title>
         <Notes>
               <Note Audience="All" Ordinal="155" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle VM Server for x86. The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (memory consumption) via a short invalid encoding. CVSS Base Score: 1.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2109</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>1.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0086.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="156" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2012-2664</Title>
         <Notes>
               <Note Audience="All" Ordinal="156" Title="Details" Type="Details">This is a vulnerability in  sos  in Oracle VM Server for x86. The sosreport utility in the Red Hat sos package before 2.2-29 does not remove the root user password information from the Kickstart configuration file (/root/anaconda-ks.cfg) when creating an archive of debugging information, which might allow attackers to obtain passwords or password hashes. CVSS Base Score: 1.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2012-2664</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>1.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0078.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="157" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8555</Title>
         <Notes>
               <Note Audience="All" Ordinal="157" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPUstack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via unspecified vectors. CVSS Base Score: 1.8 CVSS V2 Vector: AV:A/AC:H/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8555</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>1.8</BaseScore>
               <Vector>AV:A/AC:H/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0081.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="158" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-7092</Title>
         <Notes>
               <Note Audience="All" Ordinal="158" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 0 CVSS V2 Vector: AV:N/AC:N/Au:N/C:N/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-7092</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>0</BaseScore>
               <Vector>AV:N/AC:N/Au:N/C:N/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0102.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="159" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-7092</Title>
         <Notes>
               <Note Audience="All" Ordinal="159" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 0 CVSS V2 Vector: AV:N/AC:N/Au:N/C:N/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-7092</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>0</BaseScore>
               <Vector>AV:N/AC:N/Au:N/C:N/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0103.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="160" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-7092</Title>
         <Notes>
               <Note Audience="All" Ordinal="160" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 0 CVSS V2 Vector: AV:N/AC:N/Au:N/C:N/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-7092</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>0</BaseScore>
               <Vector>AV:N/AC:N/Au:N/C:N/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0104.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="161" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-7094</Title>
         <Notes>
               <Note Audience="All" Ordinal="161" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 0 CVSS V2 Vector: AV:N/AC:N/Au:N/C:N/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-7094</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.4</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>0</BaseScore>
               <Vector>AV:N/AC:N/Au:N/C:N/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0102.html</URL>
                  <ProductID>P-4455V-3.4</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="162" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-7094</Title>
         <Notes>
               <Note Audience="All" Ordinal="162" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 0 CVSS V2 Vector: AV:N/AC:N/Au:N/C:N/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-7094</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.3</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>0</BaseScore>
               <Vector>AV:N/AC:N/Au:N/C:N/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0103.html</URL>
                  <ProductID>P-4455V-3.3</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="163" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-7094</Title>
         <Notes>
               <Note Audience="All" Ordinal="163" Title="Details" Type="Details">This is a vulnerability in  xen  in Oracle VM Server for x86. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 0 CVSS V2 Vector: AV:N/AC:N/Au:N/C:N/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-7094</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-4455V-3.2</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>0</BaseScore>
               <Vector>AV:N/AC:N/Au:N/C:N/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle VM Server for x86 Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle VM Server for x86 customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/OVMSA-2016-0104.html</URL>
                  <ProductID>P-4455V-3.2</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
</cvrf:cvrfdoc>
