<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">apache2-mod_php7-7.0.14-1.4 on GA media</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2024:10290-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-06-15T00:00:00Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-06-15T00:00:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-06-15T00:00:00Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">apache2-mod_php7-7.0.14-1.4 on GA media</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">These are all security issues fixed in the apache2-mod_php7-7.0.14-1.4 package on the GA media of openSUSE Tumbleweed.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-Tumbleweed-2024-10290</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2006-7243/</URL>
      <Description>SUSE CVE CVE-2006-7243 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2010-2225/</URL>
      <Description>SUSE CVE CVE-2010-2225 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2010-2950/</URL>
      <Description>SUSE CVE CVE-2010-2950 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2010-3436/</URL>
      <Description>SUSE CVE CVE-2010-3436 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2010-3709/</URL>
      <Description>SUSE CVE CVE-2010-3709 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2010-3710/</URL>
      <Description>SUSE CVE CVE-2010-3710 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2010-4150/</URL>
      <Description>SUSE CVE CVE-2010-4150 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2010-4645/</URL>
      <Description>SUSE CVE CVE-2010-4645 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-0420/</URL>
      <Description>SUSE CVE CVE-2011-0420 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-0421/</URL>
      <Description>SUSE CVE CVE-2011-0421 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-0708/</URL>
      <Description>SUSE CVE CVE-2011-0708 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-1092/</URL>
      <Description>SUSE CVE CVE-2011-1092 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-1153/</URL>
      <Description>SUSE CVE CVE-2011-1153 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-1466/</URL>
      <Description>SUSE CVE CVE-2011-1466 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-2202/</URL>
      <Description>SUSE CVE CVE-2011-2202 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-3379/</URL>
      <Description>SUSE CVE CVE-2011-3379 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-4153/</URL>
      <Description>SUSE CVE CVE-2011-4153 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-4566/</URL>
      <Description>SUSE CVE CVE-2011-4566 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-4718/</URL>
      <Description>SUSE CVE CVE-2011-4718 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-4885/</URL>
      <Description>SUSE CVE CVE-2011-4885 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-0830/</URL>
      <Description>SUSE CVE CVE-2012-0830 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-1823/</URL>
      <Description>SUSE CVE CVE-2012-1823 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-2311/</URL>
      <Description>SUSE CVE CVE-2012-2311 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-2335/</URL>
      <Description>SUSE CVE CVE-2012-2335 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-2336/</URL>
      <Description>SUSE CVE CVE-2012-2336 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-2688/</URL>
      <Description>SUSE CVE CVE-2012-2688 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-3365/</URL>
      <Description>SUSE CVE CVE-2012-3365 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-1635/</URL>
      <Description>SUSE CVE CVE-2013-1635 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-1643/</URL>
      <Description>SUSE CVE CVE-2013-1643 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-1824/</URL>
      <Description>SUSE CVE CVE-2013-1824 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-4113/</URL>
      <Description>SUSE CVE CVE-2013-4113 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-4248/</URL>
      <Description>SUSE CVE CVE-2013-4248 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-6420/</URL>
      <Description>SUSE CVE CVE-2013-6420 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-6712/</URL>
      <Description>SUSE CVE CVE-2013-6712 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-7327/</URL>
      <Description>SUSE CVE CVE-2013-7327 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-7345/</URL>
      <Description>SUSE CVE CVE-2013-7345 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-0185/</URL>
      <Description>SUSE CVE CVE-2014-0185 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-0237/</URL>
      <Description>SUSE CVE CVE-2014-0237 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-0238/</URL>
      <Description>SUSE CVE CVE-2014-0238 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-1943/</URL>
      <Description>SUSE CVE CVE-2014-1943 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-2270/</URL>
      <Description>SUSE CVE CVE-2014-2270 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-2497/</URL>
      <Description>SUSE CVE CVE-2014-2497 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-3538/</URL>
      <Description>SUSE CVE CVE-2014-3538 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-3587/</URL>
      <Description>SUSE CVE CVE-2014-3587 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-3597/</URL>
      <Description>SUSE CVE CVE-2014-3597 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-3622/</URL>
      <Description>SUSE CVE CVE-2014-3622 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-3668/</URL>
      <Description>SUSE CVE CVE-2014-3668 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-3669/</URL>
      <Description>SUSE CVE CVE-2014-3669 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-3670/</URL>
      <Description>SUSE CVE CVE-2014-3670 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-4049/</URL>
      <Description>SUSE CVE CVE-2014-4049 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-4670/</URL>
      <Description>SUSE CVE CVE-2014-4670 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-4698/</URL>
      <Description>SUSE CVE CVE-2014-4698 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-5120/</URL>
      <Description>SUSE CVE CVE-2014-5120 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-5459/</URL>
      <Description>SUSE CVE CVE-2014-5459 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-9426/</URL>
      <Description>SUSE CVE CVE-2014-9426 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-9427/</URL>
      <Description>SUSE CVE CVE-2014-9427 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-0231/</URL>
      <Description>SUSE CVE CVE-2015-0231 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-0232/</URL>
      <Description>SUSE CVE CVE-2015-0232 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-0235/</URL>
      <Description>SUSE CVE CVE-2015-0235 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-0273/</URL>
      <Description>SUSE CVE CVE-2015-0273 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-1351/</URL>
      <Description>SUSE CVE CVE-2015-1351 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-1352/</URL>
      <Description>SUSE CVE CVE-2015-1352 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-2305/</URL>
      <Description>SUSE CVE CVE-2015-2305 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-2325/</URL>
      <Description>SUSE CVE CVE-2015-2325 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-2326/</URL>
      <Description>SUSE CVE CVE-2015-2326 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-2331/</URL>
      <Description>SUSE CVE CVE-2015-2331 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-3152/</URL>
      <Description>SUSE CVE CVE-2015-3152 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-3414/</URL>
      <Description>SUSE CVE CVE-2015-3414 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-3415/</URL>
      <Description>SUSE CVE CVE-2015-3415 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-3416/</URL>
      <Description>SUSE CVE CVE-2015-3416 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="apache2-mod_php7-7.0.14-1.4">
      <FullProductName ProductID="apache2-mod_php7-7.0.14-1.4">apache2-mod_php7-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-7.0.14-1.4">
      <FullProductName ProductID="php7-7.0.14-1.4">php7-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-bcmath-7.0.14-1.4">
      <FullProductName ProductID="php7-bcmath-7.0.14-1.4">php7-bcmath-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-bz2-7.0.14-1.4">
      <FullProductName ProductID="php7-bz2-7.0.14-1.4">php7-bz2-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-calendar-7.0.14-1.4">
      <FullProductName ProductID="php7-calendar-7.0.14-1.4">php7-calendar-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-ctype-7.0.14-1.4">
      <FullProductName ProductID="php7-ctype-7.0.14-1.4">php7-ctype-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-curl-7.0.14-1.4">
      <FullProductName ProductID="php7-curl-7.0.14-1.4">php7-curl-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-dba-7.0.14-1.4">
      <FullProductName ProductID="php7-dba-7.0.14-1.4">php7-dba-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-devel-7.0.14-1.4">
      <FullProductName ProductID="php7-devel-7.0.14-1.4">php7-devel-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-dom-7.0.14-1.4">
      <FullProductName ProductID="php7-dom-7.0.14-1.4">php7-dom-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-enchant-7.0.14-1.4">
      <FullProductName ProductID="php7-enchant-7.0.14-1.4">php7-enchant-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-exif-7.0.14-1.4">
      <FullProductName ProductID="php7-exif-7.0.14-1.4">php7-exif-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-fastcgi-7.0.14-1.4">
      <FullProductName ProductID="php7-fastcgi-7.0.14-1.4">php7-fastcgi-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-fileinfo-7.0.14-1.4">
      <FullProductName ProductID="php7-fileinfo-7.0.14-1.4">php7-fileinfo-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-firebird-7.0.14-1.4">
      <FullProductName ProductID="php7-firebird-7.0.14-1.4">php7-firebird-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-fpm-7.0.14-1.4">
      <FullProductName ProductID="php7-fpm-7.0.14-1.4">php7-fpm-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-ftp-7.0.14-1.4">
      <FullProductName ProductID="php7-ftp-7.0.14-1.4">php7-ftp-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-gd-7.0.14-1.4">
      <FullProductName ProductID="php7-gd-7.0.14-1.4">php7-gd-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-gettext-7.0.14-1.4">
      <FullProductName ProductID="php7-gettext-7.0.14-1.4">php7-gettext-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-gmp-7.0.14-1.4">
      <FullProductName ProductID="php7-gmp-7.0.14-1.4">php7-gmp-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-iconv-7.0.14-1.4">
      <FullProductName ProductID="php7-iconv-7.0.14-1.4">php7-iconv-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-imap-7.0.14-1.4">
      <FullProductName ProductID="php7-imap-7.0.14-1.4">php7-imap-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-intl-7.0.14-1.4">
      <FullProductName ProductID="php7-intl-7.0.14-1.4">php7-intl-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-json-7.0.14-1.4">
      <FullProductName ProductID="php7-json-7.0.14-1.4">php7-json-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-ldap-7.0.14-1.4">
      <FullProductName ProductID="php7-ldap-7.0.14-1.4">php7-ldap-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-mbstring-7.0.14-1.4">
      <FullProductName ProductID="php7-mbstring-7.0.14-1.4">php7-mbstring-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-mcrypt-7.0.14-1.4">
      <FullProductName ProductID="php7-mcrypt-7.0.14-1.4">php7-mcrypt-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-mysql-7.0.14-1.4">
      <FullProductName ProductID="php7-mysql-7.0.14-1.4">php7-mysql-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-odbc-7.0.14-1.4">
      <FullProductName ProductID="php7-odbc-7.0.14-1.4">php7-odbc-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-opcache-7.0.14-1.4">
      <FullProductName ProductID="php7-opcache-7.0.14-1.4">php7-opcache-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-openssl-7.0.14-1.4">
      <FullProductName ProductID="php7-openssl-7.0.14-1.4">php7-openssl-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pcntl-7.0.14-1.4">
      <FullProductName ProductID="php7-pcntl-7.0.14-1.4">php7-pcntl-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pdo-7.0.14-1.4">
      <FullProductName ProductID="php7-pdo-7.0.14-1.4">php7-pdo-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pear-7.0.14-1.4">
      <FullProductName ProductID="php7-pear-7.0.14-1.4">php7-pear-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pear-Archive_Tar-7.0.14-1.4">
      <FullProductName ProductID="php7-pear-Archive_Tar-7.0.14-1.4">php7-pear-Archive_Tar-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pgsql-7.0.14-1.4">
      <FullProductName ProductID="php7-pgsql-7.0.14-1.4">php7-pgsql-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-phar-7.0.14-1.4">
      <FullProductName ProductID="php7-phar-7.0.14-1.4">php7-phar-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-posix-7.0.14-1.4">
      <FullProductName ProductID="php7-posix-7.0.14-1.4">php7-posix-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pspell-7.0.14-1.4">
      <FullProductName ProductID="php7-pspell-7.0.14-1.4">php7-pspell-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-readline-7.0.14-1.4">
      <FullProductName ProductID="php7-readline-7.0.14-1.4">php7-readline-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-shmop-7.0.14-1.4">
      <FullProductName ProductID="php7-shmop-7.0.14-1.4">php7-shmop-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-snmp-7.0.14-1.4">
      <FullProductName ProductID="php7-snmp-7.0.14-1.4">php7-snmp-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-soap-7.0.14-1.4">
      <FullProductName ProductID="php7-soap-7.0.14-1.4">php7-soap-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sockets-7.0.14-1.4">
      <FullProductName ProductID="php7-sockets-7.0.14-1.4">php7-sockets-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sqlite-7.0.14-1.4">
      <FullProductName ProductID="php7-sqlite-7.0.14-1.4">php7-sqlite-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sysvmsg-7.0.14-1.4">
      <FullProductName ProductID="php7-sysvmsg-7.0.14-1.4">php7-sysvmsg-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sysvsem-7.0.14-1.4">
      <FullProductName ProductID="php7-sysvsem-7.0.14-1.4">php7-sysvsem-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sysvshm-7.0.14-1.4">
      <FullProductName ProductID="php7-sysvshm-7.0.14-1.4">php7-sysvshm-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-tidy-7.0.14-1.4">
      <FullProductName ProductID="php7-tidy-7.0.14-1.4">php7-tidy-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-tokenizer-7.0.14-1.4">
      <FullProductName ProductID="php7-tokenizer-7.0.14-1.4">php7-tokenizer-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-wddx-7.0.14-1.4">
      <FullProductName ProductID="php7-wddx-7.0.14-1.4">php7-wddx-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-xmlreader-7.0.14-1.4">
      <FullProductName ProductID="php7-xmlreader-7.0.14-1.4">php7-xmlreader-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-xmlrpc-7.0.14-1.4">
      <FullProductName ProductID="php7-xmlrpc-7.0.14-1.4">php7-xmlrpc-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-xmlwriter-7.0.14-1.4">
      <FullProductName ProductID="php7-xmlwriter-7.0.14-1.4">php7-xmlwriter-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-xsl-7.0.14-1.4">
      <FullProductName ProductID="php7-xsl-7.0.14-1.4">php7-xsl-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-zip-7.0.14-1.4">
      <FullProductName ProductID="php7-zip-7.0.14-1.4">php7-zip-7.0.14-1.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-zlib-7.0.14-1.4">
      <FullProductName ProductID="php7-zlib-7.0.14-1.4">php7-zlib-7.0.14-1.4</FullProductName>
    </Branch>
    <Relationship ProductReference="apache2-mod_php7-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4">apache2-mod_php7-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-7.0.14-1.4">php7-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-bcmath-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4">php7-bcmath-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-bz2-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-bz2-7.0.14-1.4">php7-bz2-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-calendar-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-calendar-7.0.14-1.4">php7-calendar-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-ctype-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-ctype-7.0.14-1.4">php7-ctype-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-curl-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-curl-7.0.14-1.4">php7-curl-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-dba-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-dba-7.0.14-1.4">php7-dba-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-devel-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-devel-7.0.14-1.4">php7-devel-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-dom-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-dom-7.0.14-1.4">php7-dom-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-enchant-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-enchant-7.0.14-1.4">php7-enchant-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-exif-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-exif-7.0.14-1.4">php7-exif-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-fastcgi-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4">php7-fastcgi-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-fileinfo-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4">php7-fileinfo-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-firebird-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-firebird-7.0.14-1.4">php7-firebird-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-fpm-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-fpm-7.0.14-1.4">php7-fpm-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-ftp-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-ftp-7.0.14-1.4">php7-ftp-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-gd-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-gd-7.0.14-1.4">php7-gd-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-gettext-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-gettext-7.0.14-1.4">php7-gettext-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-gmp-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-gmp-7.0.14-1.4">php7-gmp-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-iconv-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-iconv-7.0.14-1.4">php7-iconv-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-imap-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-imap-7.0.14-1.4">php7-imap-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-intl-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-intl-7.0.14-1.4">php7-intl-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-json-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-json-7.0.14-1.4">php7-json-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-ldap-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-ldap-7.0.14-1.4">php7-ldap-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-mbstring-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4">php7-mbstring-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-mcrypt-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4">php7-mcrypt-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-mysql-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-mysql-7.0.14-1.4">php7-mysql-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-odbc-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-odbc-7.0.14-1.4">php7-odbc-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-opcache-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-opcache-7.0.14-1.4">php7-opcache-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-openssl-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-openssl-7.0.14-1.4">php7-openssl-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pcntl-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4">php7-pcntl-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pdo-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-pdo-7.0.14-1.4">php7-pdo-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pear-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-pear-7.0.14-1.4">php7-pear-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pear-Archive_Tar-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4">php7-pear-Archive_Tar-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pgsql-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4">php7-pgsql-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-phar-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-phar-7.0.14-1.4">php7-phar-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-posix-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-posix-7.0.14-1.4">php7-posix-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pspell-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-pspell-7.0.14-1.4">php7-pspell-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-readline-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-readline-7.0.14-1.4">php7-readline-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-shmop-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-shmop-7.0.14-1.4">php7-shmop-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-snmp-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-snmp-7.0.14-1.4">php7-snmp-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-soap-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-soap-7.0.14-1.4">php7-soap-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sockets-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-sockets-7.0.14-1.4">php7-sockets-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sqlite-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4">php7-sqlite-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sysvmsg-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4">php7-sysvmsg-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sysvsem-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4">php7-sysvsem-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sysvshm-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4">php7-sysvshm-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-tidy-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-tidy-7.0.14-1.4">php7-tidy-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-tokenizer-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4">php7-tokenizer-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-wddx-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-wddx-7.0.14-1.4">php7-wddx-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-xmlreader-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4">php7-xmlreader-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-xmlrpc-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4">php7-xmlrpc-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-xmlwriter-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4">php7-xmlwriter-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-xsl-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-xsl-7.0.14-1.4">php7-xsl-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-zip-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-zip-7.0.14-1.4">php7-zip-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-zlib-7.0.14-1.4" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php7-zlib-7.0.14-1.4">php7-zlib-7.0.14-1.4 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argument to the file_exists function.</Note>
    </Notes>
    <CVE>CVE-2006-7243</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2006-7243.html</URL>
        <Description>CVE-2006-7243</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1067090</URL>
        <Description>SUSE Bug 1067090</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/654853</URL>
        <Description>SUSE Bug 654853</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/893855</URL>
        <Description>SUSE Bug 893855</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/924970</URL>
        <Description>SUSE Bug 924970</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Use-after-free vulnerability in the SplObjectStorage unserializer in PHP 5.2.x and 5.3.x through 5.3.2 allows remote attackers to execute arbitrary code or obtain sensitive information via serialized data, related to the PHP unserialize function.</Note>
    </Notes>
    <CVE>CVE-2010-2225</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2010-2225.html</URL>
        <Description>CVE-2010-2225</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/616232</URL>
        <Description>SUSE Bug 616232</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Format string vulnerability in stream.c in the phar extension in PHP 5.3.x through 5.3.3 allows context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not properly handled by the phar_stream_flush function, leading to errors in the php_stream_wrapper_log_error function.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-2094.</Note>
    </Notes>
    <CVE>CVE-2010-2950</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2010-2950.html</URL>
        <Description>CVE-2010-2950</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/633934</URL>
        <Description>SUSE Bug 633934</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attackers to bypass open_basedir restrictions via vectors related to the length of a filename.</Note>
    </Notes>
    <CVE>CVE-2010-3436</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2010-3436.html</URL>
        <Description>CVE-2010-3436</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/642733</URL>
        <Description>SUSE Bug 642733</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive.</Note>
    </Notes>
    <CVE>CVE-2010-3709</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2010-3709.html</URL>
        <Description>CVE-2010-3709</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/660102</URL>
        <Description>SUSE Bug 660102</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Stack consumption vulnerability in the filter_var function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3, when FILTER_VALIDATE_EMAIL mode is used, allows remote attackers to cause a denial of service (memory consumption and application crash) via a long e-mail address string.</Note>
    </Notes>
    <CVE>CVE-2010-3710</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2010-3710.html</URL>
        <Description>CVE-2010-3710</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/649210</URL>
        <Description>SUSE Bug 649210</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Double free vulnerability in the imap_do_open function in the IMAP extension (ext/imap/php_imap.c) in PHP 5.2 before 5.2.15 and 5.3 before 5.3.4 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.</Note>
    </Notes>
    <CVE>CVE-2010-4150</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2010-4150.html</URL>
        <Description>CVE-2010-4150</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/655968</URL>
        <Description>SUSE Bug 655968</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to cause a denial of service (infinite loop) via a certain floating-point value in scientific notation, which is not properly handled in x87 FPU registers, as demonstrated using 2.2250738585072011e-308.</Note>
    </Notes>
    <CVE>CVE-2010-4645</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2010-4645.html</URL>
        <Description>CVE-2010-4645</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/662932</URL>
        <Description>SUSE Bug 662932</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The grapheme_extract function in the Internationalization extension (Intl) for ICU for PHP 5.3.5 allows context-dependent attackers to cause a denial of service (crash) via an invalid size argument, which triggers a NULL pointer dereference.</Note>
    </Notes>
    <CVE>CVE-2011-0420</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-0420.html</URL>
        <Description>CVE-2011-0420</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/672933</URL>
        <Description>SUSE Bug 672933</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (NULL pointer dereference) via an empty ZIP archive that is processed with a (1) locateName or (2) statName operation.</Note>
    </Notes>
    <CVE>CVE-2011-0421</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-0421.html</URL>
        <Description>CVE-2011-0421</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/681193</URL>
        <Description>SUSE Bug 681193</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">exif.c in the Exif extension in PHP before 5.3.6 on 64-bit platforms performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) via an image with a crafted Image File Directory (IFD) that triggers a buffer over-read.</Note>
    </Notes>
    <CVE>CVE-2011-0708</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-0708.html</URL>
        <Description>CVE-2011-0708</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/671710</URL>
        <Description>SUSE Bug 671710</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (crash) and possibly read sensitive memory via a large third argument to the shmop_read function.</Note>
    </Notes>
    <CVE>CVE-2011-1092</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-1092.html</URL>
        <Description>CVE-2011-1092</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/677782</URL>
        <Description>SUSE Bug 677782</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple format string vulnerabilities in phar_object.c in the phar extension in PHP 5.3.5 and earlier allow context-dependent attackers to obtain sensitive information from process memory, cause a denial of service (memory corruption), or possibly execute arbitrary code via format string specifiers in an argument to a class method, leading to an incorrect zend_throw_exception_ex call.</Note>
    </Notes>
    <CVE>CVE-2011-1153</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-1153.html</URL>
        <Description>CVE-2011-1153</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/778941</URL>
        <Description>SUSE Bug 778941</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the SdnToJulian function in the Calendar extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via a large integer in the first argument to the cal_from_jd function.</Note>
    </Notes>
    <CVE>CVE-2011-1466</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-1466.html</URL>
        <Description>CVE-2011-1466</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/733590</URL>
        <Description>SUSE Bug 733590</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/736169</URL>
        <Description>SUSE Bug 736169</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/738221</URL>
        <Description>SUSE Bug 738221</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741520</URL>
        <Description>SUSE Bug 741520</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741859</URL>
        <Description>SUSE Bug 741859</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742273</URL>
        <Description>SUSE Bug 742273</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742806</URL>
        <Description>SUSE Bug 742806</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/743308</URL>
        <Description>SUSE Bug 743308</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/744966</URL>
        <Description>SUSE Bug 744966</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/746661</URL>
        <Description>SUSE Bug 746661</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/749111</URL>
        <Description>SUSE Bug 749111</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The rfc1867_post_handler function in main/rfc1867.c in PHP before 5.3.7 does not properly restrict filenames in multipart/form-data POST requests, which allows remote attackers to conduct absolute path traversal attacks, and possibly create or overwrite arbitrary files, via a crafted upload request, related to a "file path injection vulnerability."</Note>
    </Notes>
    <CVE>CVE-2011-2202</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.4</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-2202.html</URL>
        <Description>CVE-2011-2202</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/699711</URL>
        <Description>SUSE Bug 699711</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.</Note>
    </Notes>
    <CVE>CVE-2011-3379</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-3379.html</URL>
        <Description>CVE-2011-3379</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/728350</URL>
        <Description>SUSE Bug 728350</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c, ext/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c, and main/php_open_temporary_file.c.</Note>
    </Notes>
    <CVE>CVE-2011-4153</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-4153.html</URL>
        <Description>CVE-2011-4153</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/733590</URL>
        <Description>SUSE Bug 733590</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/736169</URL>
        <Description>SUSE Bug 736169</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/738221</URL>
        <Description>SUSE Bug 738221</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741520</URL>
        <Description>SUSE Bug 741520</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741859</URL>
        <Description>SUSE Bug 741859</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742273</URL>
        <Description>SUSE Bug 742273</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742806</URL>
        <Description>SUSE Bug 742806</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/743308</URL>
        <Description>SUSE Bug 743308</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/744966</URL>
        <Description>SUSE Bug 744966</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/746661</URL>
        <Description>SUSE Bug 746661</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/749111</URL>
        <Description>SUSE Bug 749111</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="18">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a different vulnerability than CVE-2011-0708.</Note>
    </Notes>
    <CVE>CVE-2011-4566</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.4</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-4566.html</URL>
        <Description>CVE-2011-4566</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/733590</URL>
        <Description>SUSE Bug 733590</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/736169</URL>
        <Description>SUSE Bug 736169</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/738221</URL>
        <Description>SUSE Bug 738221</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741520</URL>
        <Description>SUSE Bug 741520</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741859</URL>
        <Description>SUSE Bug 741859</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742273</URL>
        <Description>SUSE Bug 742273</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742806</URL>
        <Description>SUSE Bug 742806</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/743308</URL>
        <Description>SUSE Bug 743308</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/744966</URL>
        <Description>SUSE Bug 744966</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/746661</URL>
        <Description>SUSE Bug 746661</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/749111</URL>
        <Description>SUSE Bug 749111</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="19">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Session fixation vulnerability in the Sessions subsystem in PHP before 5.5.2 allows remote attackers to hijack web sessions by specifying a session ID.</Note>
    </Notes>
    <CVE>CVE-2011-4718</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-4718.html</URL>
        <Description>CVE-2011-4718</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/834813</URL>
        <Description>SUSE Bug 834813</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="20">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.</Note>
    </Notes>
    <CVE>CVE-2011-4885</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-4885.html</URL>
        <Description>CVE-2011-4885</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/733590</URL>
        <Description>SUSE Bug 733590</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/736169</URL>
        <Description>SUSE Bug 736169</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/738221</URL>
        <Description>SUSE Bug 738221</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741520</URL>
        <Description>SUSE Bug 741520</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741859</URL>
        <Description>SUSE Bug 741859</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742273</URL>
        <Description>SUSE Bug 742273</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742806</URL>
        <Description>SUSE Bug 742806</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/743308</URL>
        <Description>SUSE Bug 743308</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/744966</URL>
        <Description>SUSE Bug 744966</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/746661</URL>
        <Description>SUSE Bug 746661</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/749111</URL>
        <Description>SUSE Bug 749111</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="21">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.</Note>
    </Notes>
    <CVE>CVE-2012-0830</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-0830.html</URL>
        <Description>CVE-2012-0830</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/733590</URL>
        <Description>SUSE Bug 733590</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/736169</URL>
        <Description>SUSE Bug 736169</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/738221</URL>
        <Description>SUSE Bug 738221</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741520</URL>
        <Description>SUSE Bug 741520</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741859</URL>
        <Description>SUSE Bug 741859</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742273</URL>
        <Description>SUSE Bug 742273</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742806</URL>
        <Description>SUSE Bug 742806</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/743308</URL>
        <Description>SUSE Bug 743308</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/744966</URL>
        <Description>SUSE Bug 744966</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/746661</URL>
        <Description>SUSE Bug 746661</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/749111</URL>
        <Description>SUSE Bug 749111</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="22">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.</Note>
    </Notes>
    <CVE>CVE-2012-1823</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-1823.html</URL>
        <Description>CVE-2012-1823</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1226072</URL>
        <Description>SUSE Bug 1226072</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1226073</URL>
        <Description>SUSE Bug 1226073</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1226074</URL>
        <Description>SUSE Bug 1226074</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/760536</URL>
        <Description>SUSE Bug 760536</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/761631</URL>
        <Description>SUSE Bug 761631</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/850694</URL>
        <Description>SUSE Bug 850694</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="23">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that contain a %3D sequence but no = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.</Note>
    </Notes>
    <CVE>CVE-2012-2311</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-2311.html</URL>
        <Description>CVE-2012-2311</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/760536</URL>
        <Description>SUSE Bug 760536</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/761631</URL>
        <Description>SUSE Bug 761631</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="24">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">php-wrapper.fcgi does not properly handle command-line arguments, which allows remote attackers to bypass a protection mechanism in PHP 5.3.12 and 5.4.2 and execute arbitrary code by leveraging improper interaction between the PHP sapi/cgi/cgi_main.c component and a query string beginning with a +- sequence.</Note>
    </Notes>
    <CVE>CVE-2012-2335</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-2335.html</URL>
        <Description>CVE-2012-2335</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/761631</URL>
        <Description>SUSE Bug 761631</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="25">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to cause a denial of service (resource consumption) by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'T' case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.</Note>
    </Notes>
    <CVE>CVE-2012-2336</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-2336.html</URL>
        <Description>CVE-2012-2336</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/761631</URL>
        <Description>SUSE Bug 761631</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="26">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."</Note>
    </Notes>
    <CVE>CVE-2012-2688</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>10</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-2688.html</URL>
        <Description>CVE-2012-2688</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/772582</URL>
        <Description>SUSE Bug 772582</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="27">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The SQLite functionality in PHP before 5.3.15 allows remote attackers to bypass the open_basedir protection mechanism via unspecified vectors.</Note>
    </Notes>
    <CVE>CVE-2012-3365</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-3365.html</URL>
        <Description>CVE-2012-3365</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/772580</URL>
        <Description>SUSE Bug 772580</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/772582</URL>
        <Description>SUSE Bug 772582</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="28">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ext/soap/soap.c in PHP before 5.3.22 and 5.4.x before 5.4.13 does not validate the relationship between the soap.wsdl_cache_dir directive and the open_basedir directive, which allows remote attackers to bypass intended access restrictions by triggering the creation of cached SOAP WSDL files in an arbitrary directory.</Note>
    </Notes>
    <CVE>CVE-2013-1635</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-1635.html</URL>
        <Description>CVE-2013-1635</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/807707</URL>
        <Description>SUSE Bug 807707</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="29">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The SOAP parser in PHP before 5.3.23 and 5.4.x before 5.4.13 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-1824.</Note>
    </Notes>
    <CVE>CVE-2013-1643</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-1643.html</URL>
        <Description>CVE-2013-1643</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/807707</URL>
        <Description>SUSE Bug 807707</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="30">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions.</Note>
    </Notes>
    <CVE>CVE-2013-1824</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-1824.html</URL>
        <Description>CVE-2013-1824</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/807707</URL>
        <Description>SUSE Bug 807707</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="31">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.</Note>
    </Notes>
    <CVE>CVE-2013-4113</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-4113.html</URL>
        <Description>CVE-2013-4113</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/829207</URL>
        <Description>SUSE Bug 829207</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="32">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</Note>
    </Notes>
    <CVE>CVE-2013-4248</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-4248.html</URL>
        <Description>CVE-2013-4248</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/837746</URL>
        <Description>SUSE Bug 837746</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="33">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.</Note>
    </Notes>
    <CVE>CVE-2013-6420</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-6420.html</URL>
        <Description>CVE-2013-6420</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/854880</URL>
        <Description>SUSE Bug 854880</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/880238</URL>
        <Description>SUSE Bug 880238</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="34">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.</Note>
    </Notes>
    <CVE>CVE-2013-6712</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-6712.html</URL>
        <Description>CVE-2013-6712</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/853045</URL>
        <Description>SUSE Bug 853045</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="35">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check return values, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via invalid imagecrop arguments that lead to use of a NULL pointer as a return value, a different vulnerability than CVE-2013-7226.</Note>
    </Notes>
    <CVE>CVE-2013-7327</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-7327.html</URL>
        <Description>CVE-2013-7327</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/864879</URL>
        <Description>SUSE Bug 864879</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="36">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted ASCII file that triggers a large amount of backtracking, as demonstrated via a file with many newline characters.</Note>
    </Notes>
    <CVE>CVE-2013-7345</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-7345.html</URL>
        <Description>CVE-2013-7345</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/869906</URL>
        <Description>SUSE Bug 869906</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/883306</URL>
        <Description>SUSE Bug 883306</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/987530</URL>
        <Description>SUSE Bug 987530</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="37">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client.</Note>
    </Notes>
    <CVE>CVE-2014-0185</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.2</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-0185.html</URL>
        <Description>CVE-2014-0185</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/868624</URL>
        <Description>SUSE Bug 868624</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/875826</URL>
        <Description>SUSE Bug 875826</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="38">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (performance degradation) by triggering many file_printf calls.</Note>
    </Notes>
    <CVE>CVE-2014-0237</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-0237.html</URL>
        <Description>CVE-2014-0237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/880905</URL>
        <Description>SUSE Bug 880905</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="39">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero length or (2) is too long.</Note>
    </Notes>
    <CVE>CVE-2014-0238</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-0238.html</URL>
        <Description>CVE-2014-0238</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/880904</URL>
        <Description>SUSE Bug 880904</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="40">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.</Note>
    </Notes>
    <CVE>CVE-2014-1943</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-1943.html</URL>
        <Description>CVE-2014-1943</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/864343</URL>
        <Description>SUSE Bug 864343</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/864589</URL>
        <Description>SUSE Bug 864589</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/883306</URL>
        <Description>SUSE Bug 883306</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="41">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.</Note>
    </Notes>
    <CVE>CVE-2014-2270</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-2270.html</URL>
        <Description>CVE-2014-2270</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/866750</URL>
        <Description>SUSE Bug 866750</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/883306</URL>
        <Description>SUSE Bug 883306</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="42">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.</Note>
    </Notes>
    <CVE>CVE-2014-2497</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-2497.html</URL>
        <Description>CVE-2014-2497</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/868624</URL>
        <Description>SUSE Bug 868624</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="43">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.</Note>
    </Notes>
    <CVE>CVE-2014-3538</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-3538.html</URL>
        <Description>CVE-2014-3538</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/935225</URL>
        <Description>SUSE Bug 935225</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/987530</URL>
        <Description>SUSE Bug 987530</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="44">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.</Note>
    </Notes>
    <CVE>CVE-2014-3587</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-3587.html</URL>
        <Description>CVE-2014-3587</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/987530</URL>
        <Description>SUSE Bug 987530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/998845</URL>
        <Description>SUSE Bug 998845</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="45">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple buffer overflows in the php_parserr function in ext/standard/dns.c in PHP before 5.4.32 and 5.5.x before 5.5.16 allow remote DNS servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted DNS record, related to the dns_get_record function and the dn_expand function.  NOTE: this issue exists because of an incomplete fix for CVE-2014-4049.</Note>
    </Notes>
    <CVE>CVE-2014-3597</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-3597.html</URL>
        <Description>CVE-2014-3597</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/893853</URL>
        <Description>SUSE Bug 893853</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980366</URL>
        <Description>SUSE Bug 980366</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="46">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execute arbitrary code by leveraging a third-party filter extension that accesses a certain ksep value.</Note>
    </Notes>
    <CVE>CVE-2014-3622</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-3622.html</URL>
        <Description>CVE-2014-3622</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/900934</URL>
        <Description>SUSE Bug 900934</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="47">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Buffer overflow in the date_from_ISO8601 function in the mkgmtime implementation in libxmlrpc/xmlrpc.c in the XMLRPC extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) via (1) a crafted first argument to the xmlrpc_set_type function or (2) a crafted argument to the xmlrpc_decode function, related to an out-of-bounds read operation.</Note>
    </Notes>
    <CVE>CVE-2014-3668</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-3668.html</URL>
        <Description>CVE-2014-3668</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/902368</URL>
        <Description>SUSE Bug 902368</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980366</URL>
        <Description>SUSE Bug 980366</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="48">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function that triggers calculation of a large length value.</Note>
    </Notes>
    <CVE>CVE-2014-3669</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-3669.html</URL>
        <Description>CVE-2014-3669</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/902360</URL>
        <Description>SUSE Bug 902360</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980366</URL>
        <Description>SUSE Bug 980366</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="49">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted JPEG image with TIFF thumbnail data that is improperly handled by the exif_thumbnail function.</Note>
    </Notes>
    <CVE>CVE-2014-3670</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-3670.html</URL>
        <Description>CVE-2014-3670</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/902357</URL>
        <Description>SUSE Bug 902357</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980366</URL>
        <Description>SUSE Bug 980366</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="50">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS TXT record, related to the dns_get_record function.</Note>
    </Notes>
    <CVE>CVE-2014-4049</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-4049.html</URL>
        <Description>CVE-2014-4049</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/882992</URL>
        <Description>SUSE Bug 882992</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/893853</URL>
        <Description>SUSE Bug 893853</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="51">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Use-after-free vulnerability in ext/spl/spl_dllist.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted iterator usage within applications in certain web-hosting environments.</Note>
    </Notes>
    <CVE>CVE-2014-4670</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.6</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-4670.html</URL>
        <Description>CVE-2014-4670</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/886059</URL>
        <Description>SUSE Bug 886059</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980366</URL>
        <Description>SUSE Bug 980366</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="52">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Use-after-free vulnerability in ext/spl/spl_array.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted ArrayIterator usage within applications in certain web-hosting environments.</Note>
    </Notes>
    <CVE>CVE-2014-4698</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.6</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-4698.html</URL>
        <Description>CVE-2014-4698</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/886060</URL>
        <Description>SUSE Bug 886060</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980366</URL>
        <Description>SUSE Bug 980366</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="53">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">gd_ctx.c in the GD component in PHP 5.4.x before 5.4.32 and 5.5.x before 5.5.16 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to overwrite arbitrary files via crafted input to an application that calls the (1) imagegd, (2) imagegd2, (3) imagegif, (4) imagejpeg, (5) imagepng, (6) imagewbmp, or (7) imagewebp function.</Note>
    </Notes>
    <CVE>CVE-2014-5120</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.4</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-5120.html</URL>
        <Description>CVE-2014-5120</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1067090</URL>
        <Description>SUSE Bug 1067090</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/893855</URL>
        <Description>SUSE Bug 893855</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="54">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to arbitrary files via a symlink attack on a (1) rest.cachefile or (2) rest.cacheid file in /tmp/pear/cache/, related to the retrieveCacheFirst and useLocalCache functions.</Note>
    </Notes>
    <CVE>CVE-2014-5459</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>3.6</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-5459.html</URL>
        <Description>CVE-2014-5459</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/893849</URL>
        <Description>SUSE Bug 893849</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980366</URL>
        <Description>SUSE Bug 980366</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="55">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** DISPUTED ** The apprentice_load function in libmagic/apprentice.c in the Fileinfo component in PHP through 5.6.4 attempts to perform a free operation on a stack-based character array, which allows remote attackers to cause a denial of service (memory corruption or application crash) or possibly have unspecified other impact via unknown vectors.  NOTE: this is disputed by the vendor because the standard erealloc behavior makes the free operation unreachable.</Note>
    </Notes>
    <CVE>CVE-2014-9426</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-9426.html</URL>
        <Description>CVE-2014-9426</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/911663</URL>
        <Description>SUSE Bug 911663</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="56">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">sapi/cgi/cgi_main.c in the CGI component in PHP through 5.4.36, 5.5.x through 5.5.20, and 5.6.x through 5.6.4, when mmap is used to read a .php file, does not properly consider the mapping's length during processing of an invalid file that begins with a # character and lacks a newline character, which causes an out-of-bounds read and might (1) allow remote attackers to obtain sensitive information from php-cgi process memory by leveraging the ability to upload a .php file or (2) trigger unexpected code execution if a valid PHP script is present in memory locations adjacent to the mapping.</Note>
    </Notes>
    <CVE>CVE-2014-9427</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-9427.html</URL>
        <Description>CVE-2014-9427</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/911664</URL>
        <Description>SUSE Bug 911664</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="57">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.</Note>
    </Notes>
    <CVE>CVE-2015-0231</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-0231.html</URL>
        <Description>CVE-2015-0231</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/910659</URL>
        <Description>SUSE Bug 910659</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/924972</URL>
        <Description>SUSE Bug 924972</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980366</URL>
        <Description>SUSE Bug 980366</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="58">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The exif_process_unicode function in ext/exif/exif.c in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized pointer free and application crash) via crafted EXIF data in a JPEG image.</Note>
    </Notes>
    <CVE>CVE-2015-0232</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-0232.html</URL>
        <Description>CVE-2015-0232</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/914690</URL>
        <Description>SUSE Bug 914690</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980366</URL>
        <Description>SUSE Bug 980366</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="59">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."</Note>
    </Notes>
    <CVE>CVE-2015-0235</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>10</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-0235.html</URL>
        <Description>CVE-2015-0235</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/844309</URL>
        <Description>SUSE Bug 844309</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/913646</URL>
        <Description>SUSE Bug 913646</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/949238</URL>
        <Description>SUSE Bug 949238</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/954983</URL>
        <Description>SUSE Bug 954983</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="60">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allow remote attackers to execute arbitrary code via crafted serialized input containing a (1) R or (2) r type specifier in (a) DateTimeZone data handled by the php_date_timezone_initialize_from_hash function or (b) DateTime data handled by the php_date_initialize_from_hash function.</Note>
    </Notes>
    <CVE>CVE-2015-0273</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-0273.html</URL>
        <Description>CVE-2015-0273</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/917302</URL>
        <Description>SUSE Bug 917302</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/918768</URL>
        <Description>SUSE Bug 918768</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980366</URL>
        <Description>SUSE Bug 980366</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="61">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Use-after-free vulnerability in the _zend_shared_memdup function in zend_shared_alloc.c in the OPcache extension in PHP through 5.6.7 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.</Note>
    </Notes>
    <CVE>CVE-2015-1351</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-1351.html</URL>
        <Description>CVE-2015-1351</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1137633</URL>
        <Description>SUSE Bug 1137633</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="62">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.</Note>
    </Notes>
    <CVE>CVE-2015-1352</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-1352.html</URL>
        <Description>CVE-2015-1352</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/935274</URL>
        <Description>SUSE Bug 935274</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="63">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent attackers to execute arbitrary code via a large regular expression that leads to a heap-based buffer overflow.</Note>
    </Notes>
    <CVE>CVE-2015-2305</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-2305.html</URL>
        <Description>CVE-2015-2305</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1040662</URL>
        <Description>SUSE Bug 1040662</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/921950</URL>
        <Description>SUSE Bug 921950</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/922022</URL>
        <Description>SUSE Bug 922022</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/922028</URL>
        <Description>SUSE Bug 922028</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/922030</URL>
        <Description>SUSE Bug 922030</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/922043</URL>
        <Description>SUSE Bug 922043</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/922560</URL>
        <Description>SUSE Bug 922560</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/922567</URL>
        <Description>SUSE Bug 922567</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/929192</URL>
        <Description>SUSE Bug 929192</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980366</URL>
        <Description>SUSE Bug 980366</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="64">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier.</Note>
    </Notes>
    <CVE>CVE-2015-2325</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-2325.html</URL>
        <Description>CVE-2015-2325</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/924960</URL>
        <Description>SUSE Bug 924960</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/933288</URL>
        <Description>SUSE Bug 933288</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/936408</URL>
        <Description>SUSE Bug 936408</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="65">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward referencing subroutine call and a recursive back reference, as demonstrated by "((?+1)(\1))/".</Note>
    </Notes>
    <CVE>CVE-2015-2326</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-2326.html</URL>
        <Description>CVE-2015-2326</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/924960</URL>
        <Description>SUSE Bug 924960</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/924961</URL>
        <Description>SUSE Bug 924961</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/933288</URL>
        <Description>SUSE Bug 933288</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/936408</URL>
        <Description>SUSE Bug 936408</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="66">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ZIP archive that contains many entries, leading to a heap-based buffer overflow.</Note>
    </Notes>
    <CVE>CVE-2015-2331</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-2331.html</URL>
        <Description>CVE-2015-2331</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/922894</URL>
        <Description>SUSE Bug 922894</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/923240</URL>
        <Description>SUSE Bug 923240</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="67">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.</Note>
    </Notes>
    <CVE>CVE-2015-3152</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-3152.html</URL>
        <Description>CVE-2015-3152</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1037590</URL>
        <Description>SUSE Bug 1037590</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1047059</URL>
        <Description>SUSE Bug 1047059</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1088681</URL>
        <Description>SUSE Bug 1088681</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/924663</URL>
        <Description>SUSE Bug 924663</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/928962</URL>
        <Description>SUSE Bug 928962</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/936407</URL>
        <Description>SUSE Bug 936407</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="68">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted COLLATE clause, as demonstrated by COLLATE"""""""" at the end of a SELECT statement.</Note>
    </Notes>
    <CVE>CVE-2015-3414</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-3414.html</URL>
        <Description>CVE-2015-3414</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1085790</URL>
        <Description>SUSE Bug 1085790</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1190372</URL>
        <Description>SUSE Bug 1190372</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1193078</URL>
        <Description>SUSE Bug 1193078</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/928700</URL>
        <Description>SUSE Bug 928700</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/928701</URL>
        <Description>SUSE Bug 928701</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/928702</URL>
        <Description>SUSE Bug 928702</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="69">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&amp;O&gt;O) in a CREATE TABLE statement.</Note>
    </Notes>
    <CVE>CVE-2015-3415</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-3415.html</URL>
        <Description>CVE-2015-3415</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1190372</URL>
        <Description>SUSE Bug 1190372</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/928700</URL>
        <Description>SUSE Bug 928700</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/928701</URL>
        <Description>SUSE Bug 928701</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/928702</URL>
        <Description>SUSE Bug 928702</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="70">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-based buffer overflow) or possibly have unspecified other impact via large integers in a crafted printf function call in a SELECT statement.</Note>
    </Notes>
    <CVE>CVE-2015-3416</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:apache2-mod_php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bcmath-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-bz2-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-calendar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ctype-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-curl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dba-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-devel-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-dom-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-enchant-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-exif-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fastcgi-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fileinfo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-firebird-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-fpm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ftp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gd-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gettext-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-gmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-iconv-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-imap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-intl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-json-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-ldap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mbstring-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mcrypt-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-mysql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-odbc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-opcache-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-openssl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pcntl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pdo-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pear-Archive_Tar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pgsql-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-phar-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-posix-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-pspell-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-readline-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-shmop-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-snmp-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-soap-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sockets-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sqlite-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvmsg-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvsem-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-sysvshm-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tidy-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-tokenizer-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-wddx-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlreader-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlrpc-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xmlwriter-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-xsl-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zip-7.0.14-1.4</ProductID>
        <ProductID>openSUSE Tumbleweed:php7-zlib-7.0.14-1.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-3416.html</URL>
        <Description>CVE-2015-3416</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1190372</URL>
        <Description>SUSE Bug 1190372</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/928700</URL>
        <Description>SUSE Bug 928700</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/928701</URL>
        <Description>SUSE Bug 928701</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/928702</URL>
        <Description>SUSE Bug 928702</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
