XMB Forum

Summary of Official Vendor Statements

miqrogroove - 9-10-2008 at 12:16 AM

The following information will be submitted to the National Vulnerability Database upon approval. All current staff, please reply "Yea" or "Nay"

---------------------------

CVE-2002-0316
XMB versions 1.9.8 and later were checked and are not vulnerable.

CVE-2003-0375
XMB versions 1.9.8 and later were checked and are not vulnerable.

CVE-2003-0483
XMB versions 1.9.8 SP2 and later were checked and are not vulnerable.

CVE-2004-0322
XMB versions 1.9.8 SP2 and later were checked and are not vulnerable.

CVE-2004-0323
XMB versions 1.9.8 SP2 and later were checked and are not vulnerable.

CVE-2004-1862
XMB version 1.9.10 or later must be installed to prevent attacks described by this CVE. All earlier versions of XMB are vulnerable until upgraded. Upgrades are available at http://www.xmbforum.com/

CVE-2004-1863
XMB versions 1.9.8 SP2 and later were checked and are not vulnerable.

CVE-2004-1864
XMB versions 1.9.8 SP2 and later were checked and are not vulnerable.

CVE-2004-2588
XMB versions 1.9.8 and later were checked and are not vulnerable.

CVE-2005-0885
XMB versions 1.9.8 and later were checked and are not vulnerable.

CVE-2005-2574
XMB version 1.9.10 or later must be installed to prevent attacks described by this CVE. A patch is also included in the third service pack for version 1.9.8 only. All other versions of XMB are vulnerable until upgraded. Upgrades are available at http://www.xmbforum.com/

CVE-2005-2575
XMB versions 1.9.8 and later were checked and are not vulnerable.

CVE-2005-3544
XMB versions 1.9.8 and later were checked and are not vulnerable.

CVE-2005-3688
This CVE is considered invalid because it duplicates CVE-2005-0885, "XMB versions 1.9.8 and later were checked and are not vulnerable."

CVE-2005-3689
XMB versions 1.9.8 SP2 and later were checked and are not vulnerable.

CVE-2006-0365
This CVE is considered invalid because it provides neither a description nor a version number adequate to identiy any vulnerability in XMB.

CVE-2006-0778
XMB versions 1.9.8 and later were checked and are not vulnerable.

CVE-2006-0779
This CVE is considered invalid because it duplicates CVE-2005-3544, "XMB versions 1.9.8 and later were checked and are not vulnerable."

CVE-2006-1748
XMB version 1.9.10 or later must be installed to prevent attacks described by this CVE. A patch is also included in the third service pack for version 1.9.8 only. All other versions of XMB are vulnerable until upgraded. Upgrades are available at http://www.xmbforum.com/

CVE-2006-3994
XMB versions 1.9.8 and later were checked and are not vulnerable.

CVE-2006-4191
XMB versions 1.9.8 and later were checked and are not vulnerable.

CVE-2007-0519
XMB version 1.9.10 or later must be installed to prevent attacks described by this CVE. A patch is also included in the third service pack for version 1.9.8 only. All other versions of XMB are vulnerable until upgraded. Upgrades are available at http://www.xmbforum.com/

kuba1 - 9-10-2008 at 12:23 AM

100% Approval of the submittal - yay

crimsontears - 9-10-2008 at 05:15 AM

Quote:
Originally posted by kuba1
100% Approval of the submittal - yay

Kurt21 - 9-10-2008 at 06:49 AM

Yea

RichJ - 9-10-2008 at 03:53 PM

yes

Mouser - 9-10-2008 at 05:32 PM

I'd say, yes

Daniel Gouveia - 9-10-2008 at 07:47 PM

Quote:
Originally posted by kuba1
100% Approval of the submittal - yay

LANLocked - 9-11-2008 at 02:54 PM

Absolutely, and very nice work btw Rob!

100% yea!

TannerJ - 9-11-2008 at 05:53 PM

Sounds good.

quibel_nz - 9-15-2008 at 08:44 PM

yip

vanderaj - 10-1-2008 at 02:50 AM

Yea