{"cves":[{"id":"CVE-2010-4485","published":"2010-12-07T21:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 8.0.552.215 does not properly restrict the generation\nof file dialogs, which allows remote attackers to cause a denial of service\n(reduced usability and possible application crash) via a crafted web site.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-4485"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"8.0.552.215~r67652-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"8.0.552.215~r67652-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.0.552.215","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-4484","published":"2010-12-07T21:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 8.0.552.215 does not properly handle HTML5 databases,\nwhich allows attackers to cause a denial of service (application crash) via\nunspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-4484"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"released","description":"8.0.552.215~r67652-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"8.0.552.215~r67652-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.0.552.215","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-4483","published":"2010-12-07T21:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 8.0.552.215 does not properly restrict read access to\nvideos derived from CANVAS elements, which allows remote attackers to\nbypass the Same Origin Policy and obtain potentially sensitive video data\nvia a crafted web site.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-4483"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"8.0.552.215~r67652-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"8.0.552.215~r67652-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.0.552.215","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-4482","published":"2010-12-07T21:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Google Chrome before 8.0.552.215 allows remote\nattackers to bypass the pop-up blocker via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-4482"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"8.0.552.215~r67652-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"8.0.552.215~r67652-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.0.552.215","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-4259","published":"2010-12-07T13:53:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in FontForge 20100501 allows remote attackers\nto cause a denial of service (application crash) or possibly execute\narbitrary code via a long CHARSET_REGISTRY header in a BDF font file.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"stack protections in 8.04 LTS and later should reduce this to a DoS"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-4259"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=605537"],"patches":{"fontforge":[]},"tags":{},"packages":[{"name":"fontforge","source":"https://ubuntu.com/security/cve?package=fontforge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fontforge","debian":"https://tracker.debian.org/pkg/fontforge","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"0.0.20100501-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"0.0.20100501-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"0.0.20100501-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"0.0.20100501-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"0.0.20100501-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-4257","published":"2010-12-07T13:53:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSQL injection vulnerability in the do_trackbacks function in\nwp-includes/comment.php in WordPress before 3.0.2 allows remote\nauthenticated users to execute arbitrary SQL commands via the Send\nTrackbacks field.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-4257"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=605603"],"patches":{"wordpress":["upstream: http://core.trac.wordpress.org/changeset/16625","vendor: http://www.debian.org/security/2010/dsa-2138","debdiff: https://bugs.launchpad.net/ubuntu/+source/wordpress/+bug/716641"]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.9.2-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.0.1-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.0.2-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.0.2-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-4493","published":"2010-12-07T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Google Chrome before 8.0.552.215 allows\nremote attackers to cause a denial of service via vectors related to the\nhandling of mouse dragging events.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1195-1","https://www.cve.org/CVERecord?id=CVE-2010-4493"],"bugs":[""],"patches":{"chromium-browser":[],"webkit":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"8.0.552.215~r67652-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"8.0.552.215~r67652-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"8.0.552.215~r67652-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.0.552.215","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.7-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.2.7-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.7","component":null,"pocket":"security"}]}],"notices_ids":["USN-1195-1"],"notices":[{"id":"USN-1195-1","title":"WebKit vulnerabilities","summary":"Multiple security vulnerabilities were fixed in WebKit.\n","instructions":"After a standard system update you need to restart any applications that\nuse WebKit, such as Epiphany and Midori, to make all the necessary changes.\n","references":[],"published":"2011-08-23T07:30:12.299135","description":"A large number of security issues were discovered in the WebKit browser and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of\nservice attacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"webkit","version":"1.2.7-0ubuntu0.10.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libwebkit-1.0-2","version":"1.2.7-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit","version_link":"https://launchpad.net/ubuntu/+source/webkit/1.2.7-0ubuntu0.10.04.1"}],"maverick":[{"name":"webkit","version":"1.2.7-0ubuntu0.10.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libwebkit-1.0-2","version":"1.2.7-0ubuntu0.10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit","version_link":"https://launchpad.net/ubuntu/+source/webkit/1.2.7-0ubuntu0.10.10.1"}]},"type":"USN","cves_ids":["CVE-2010-1824","CVE-2010-2646","CVE-2010-2651","CVE-2010-2900","CVE-2010-2901","CVE-2010-3120","CVE-2010-3254","CVE-2010-3812","CVE-2010-3813","CVE-2010-4040","CVE-2010-4042","CVE-2010-4197","CVE-2010-4198","CVE-2010-4199","CVE-2010-4204","CVE-2010-4206","CVE-2010-4492","CVE-2010-4493","CVE-2010-4577","CVE-2010-4578","CVE-2011-0482","CVE-2011-0778"]}]},{"id":"CVE-2010-4492","published":"2010-12-07T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Google Chrome before 8.0.552.215 allows\nremote attackers to cause a denial of service or possibly have unspecified\nother impact via vectors involving SVG animations.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1195-1","https://www.cve.org/CVERecord?id=CVE-2010-4492"],"bugs":[""],"patches":{"chromium-browser":[],"webkit":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"8.0.552.215~r67652-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"8.0.552.215~r67652-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"8.0.552.215~r67652-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.0.552.215","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.7-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.2.7-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.7","component":null,"pocket":"security"}]}],"notices_ids":["USN-1195-1"],"notices":[{"id":"USN-1195-1","title":"WebKit vulnerabilities","summary":"Multiple security vulnerabilities were fixed in WebKit.\n","instructions":"After a standard system update you need to restart any applications that\nuse WebKit, such as Epiphany and Midori, to make all the necessary changes.\n","references":[],"published":"2011-08-23T07:30:12.299135","description":"A large number of security issues were discovered in the WebKit browser and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of\nservice attacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"webkit","version":"1.2.7-0ubuntu0.10.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libwebkit-1.0-2","version":"1.2.7-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit","version_link":"https://launchpad.net/ubuntu/+source/webkit/1.2.7-0ubuntu0.10.04.1"}],"maverick":[{"name":"webkit","version":"1.2.7-0ubuntu0.10.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libwebkit-1.0-2","version":"1.2.7-0ubuntu0.10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit","version_link":"https://launchpad.net/ubuntu/+source/webkit/1.2.7-0ubuntu0.10.10.1"}]},"type":"USN","cves_ids":["CVE-2010-1824","CVE-2010-2646","CVE-2010-2651","CVE-2010-2900","CVE-2010-2901","CVE-2010-3120","CVE-2010-3254","CVE-2010-3812","CVE-2010-3813","CVE-2010-4040","CVE-2010-4042","CVE-2010-4197","CVE-2010-4198","CVE-2010-4199","CVE-2010-4204","CVE-2010-4206","CVE-2010-4492","CVE-2010-4493","CVE-2010-4577","CVE-2010-4578","CVE-2011-0482","CVE-2011-0778"]}]},{"id":"CVE-2010-4489","published":"2010-12-07T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlibvpx, as used in Google Chrome before 8.0.552.215 and possibly other\nproducts, allows remote attackers to cause a denial of service\n(out-of-bounds read) via a crafted WebM video. NOTE: this vulnerability\nexists because of a regression.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1087-1","https://www.cve.org/CVERecord?id=CVE-2010-4489"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610510"],"patches":{"chromium-browser":[],"libvpx":["upstream: http://review.webmproject.org/#change,1098"]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.0.552.215","component":null,"pocket":"security"}]},{"name":"libvpx","source":"https://ubuntu.com/security/cve?package=libvpx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvpx","debian":"https://tracker.debian.org/pkg/libvpx","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.9.5-2~build0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"0.9.5-2~build0.10.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.5-2","component":null,"pocket":"security"}]}],"notices_ids":["USN-1087-1"],"notices":[{"id":"USN-1087-1","title":"libvpx vulnerability","summary":"libvpx DOS bad read\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.\n","references":[],"published":"2011-03-11T19:00:54.343572","description":"\nChris Evans discovered that libvpx did not properly perform bounds\nchecking. If an application using libvpx opened a specially crafted WebM\nfile, an attacker could cause a denial of service. \n\n","is_hidden":false,"release_packages":{"maverick":[{"name":"libvpx","version":"0.9.5-2~build0.10.10.1","description":"VP8 video codec (development files)","is_source":true},{"name":"libvpx0","version":"0.9.5-2~build0.10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":"https://launchpad.net/ubuntu/+source/libvpx/0.9.5-2~build0.10.10.1"}]},"type":"USN","cves_ids":["CVE-2010-4489"]}]},{"id":"CVE-2010-4479","published":"2010-12-07T00:00:00","updated_at":"2025-05-26T12:47:21.762813+00:00","description":"\nUnspecified vulnerability in pdf.c in libclamav in ClamAV before 0.96.5\nallows remote attackers to cause a denial of service (application crash) or\npossibly execute arbitrary code via a crafted PDF document, aka \"bb #2380,\"\na different vulnerability than CVE-2010-4260.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-4479","https://ubuntu.com/security/notices/USN-1031-1"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/clamav/+bug/673654"],"patches":{"clamav":["debdiff: https://bugs.launchpad.net/ubuntu/+source/clamav/+bug/673654"]},"tags":{"clamav":["apparmor"]},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.96.3+dfsg-2ubuntu1.0.10.04.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"0.96.3+dfsg-2ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.96.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-1031-1"],"notices":[{"id":"USN-1031-1","title":"ClamAV vulnerabilities","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-12-10T00:13:43.772905","description":"Arkadiusz Miskiewicz and others discovered that the PDF processing\ncode in libclamav improperly validated input. This could allow a\nremote attacker to craft a PDF document that could crash clamav or\npossibly execute arbitrary code. (CVE-2010-4260, CVE-2010-4479)\n\nIt was discovered that an off-by-one error in the icon_cb function\nin pe_icons.c in libclamav could allow an attacker to corrupt\nmemory, causing clamav to crash or possibly execute arbitrary code.\n(CVE-2010-4261)\n\nIn the default installation, attackers would be isolated by the\nclamav AppArmor profile.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"clamav","version":"0.96.3+dfsg-2ubuntu1.0.10.04.2","description":"","is_source":true},{"name":"libclamav6","version":"0.96.3+dfsg-2ubuntu1.0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.96.3+dfsg-2ubuntu1.0.10.04.2"}],"maverick":[{"name":"clamav","version":"0.96.3+dfsg-2ubuntu1.2","description":"","is_source":true},{"name":"libclamav6","version":"0.96.3+dfsg-2ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.96.3+dfsg-2ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2010-4479","CVE-2010-4261","CVE-2010-4260"]}]},{"id":"CVE-2010-4261","published":"2010-12-07T00:00:00","updated_at":"2025-08-04T19:23:54.522316+00:00","description":"\nOff-by-one error in the icon_cb function in pe_icons.c in libclamav in\nClamAV before 0.96.5 allows remote attackers to cause a denial of service\n(memory corruption and application crash) or possibly execute arbitrary\ncode via unspecified vectors. NOTE: some of these details are obtained\nfrom third party information.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"pe_icons.c was introduced in 0.96"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-4261","https://ubuntu.com/security/notices/USN-1031-1"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/clamav/+bug/673654"],"patches":{"clamav":["debdiff: https://bugs.launchpad.net/ubuntu/+source/clamav/+bug/673654"]},"tags":{"clamav":["apparmor"]},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.96.3+dfsg-2ubuntu1.0.10.04.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"0.96.3+dfsg-2ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.96.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-1031-1"],"notices":[{"id":"USN-1031-1","title":"ClamAV vulnerabilities","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-12-10T00:13:43.772905","description":"Arkadiusz Miskiewicz and others discovered that the PDF processing\ncode in libclamav improperly validated input. This could allow a\nremote attacker to craft a PDF document that could crash clamav or\npossibly execute arbitrary code. (CVE-2010-4260, CVE-2010-4479)\n\nIt was discovered that an off-by-one error in the icon_cb function\nin pe_icons.c in libclamav could allow an attacker to corrupt\nmemory, causing clamav to crash or possibly execute arbitrary code.\n(CVE-2010-4261)\n\nIn the default installation, attackers would be isolated by the\nclamav AppArmor profile.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"clamav","version":"0.96.3+dfsg-2ubuntu1.0.10.04.2","description":"","is_source":true},{"name":"libclamav6","version":"0.96.3+dfsg-2ubuntu1.0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.96.3+dfsg-2ubuntu1.0.10.04.2"}],"maverick":[{"name":"clamav","version":"0.96.3+dfsg-2ubuntu1.2","description":"","is_source":true},{"name":"libclamav6","version":"0.96.3+dfsg-2ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.96.3+dfsg-2ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2010-4479","CVE-2010-4261","CVE-2010-4260"]}]},{"id":"CVE-2010-4260","published":"2010-12-07T00:00:00","updated_at":"2025-05-26T12:47:21.762813+00:00","description":"\nMultiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before\n0.96.5 allow remote attackers to cause a denial of service (application\ncrash) or possibly execute arbitrary code via a crafted PDF document, aka\n(1) \"bb #2358\" and (2) \"bb #2396.\"","ubuntu_description":"","notes":[{"author":"jdstrand","note":"0.96 only. Affected code in libclamav/pdf.c:find_stream_bounds(),\nfilter_flatedecode(), and find_length(), none of which are in 0.95.\nthe affected code was introduced in patch series culminating in\n208ecece9c657b4e2a3e9d3ce9b6c58f471d7884 (\"New PDF parser with better\njavascript support (bb #1596)\""}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-4260","https://ubuntu.com/security/notices/USN-1031-1"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/clamav/+bug/673654"],"patches":{"clamav":["debdiff: https://bugs.launchpad.net/ubuntu/+source/clamav/+bug/673654"]},"tags":{"clamav":["apparmor"]},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.96.3+dfsg-2ubuntu1.0.10.04.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"0.96.3+dfsg-2ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.96.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-1031-1"],"notices":[{"id":"USN-1031-1","title":"ClamAV vulnerabilities","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-12-10T00:13:43.772905","description":"Arkadiusz Miskiewicz and others discovered that the PDF processing\ncode in libclamav improperly validated input. This could allow a\nremote attacker to craft a PDF document that could crash clamav or\npossibly execute arbitrary code. (CVE-2010-4260, CVE-2010-4479)\n\nIt was discovered that an off-by-one error in the icon_cb function\nin pe_icons.c in libclamav could allow an attacker to corrupt\nmemory, causing clamav to crash or possibly execute arbitrary code.\n(CVE-2010-4261)\n\nIn the default installation, attackers would be isolated by the\nclamav AppArmor profile.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"clamav","version":"0.96.3+dfsg-2ubuntu1.0.10.04.2","description":"","is_source":true},{"name":"libclamav6","version":"0.96.3+dfsg-2ubuntu1.0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.96.3+dfsg-2ubuntu1.0.10.04.2"}],"maverick":[{"name":"clamav","version":"0.96.3+dfsg-2ubuntu1.2","description":"","is_source":true},{"name":"libclamav6","version":"0.96.3+dfsg-2ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.96.3+dfsg-2ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2010-4479","CVE-2010-4261","CVE-2010-4260"]}]},{"id":"CVE-2010-4478","published":"2010-12-06T22:30:00","updated_at":"2026-06-06T01:52:54.117299+00:00","description":"\nOpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate\nthe public parameters in the J-PAKE protocol, which allows remote attackers\nto bypass the need for knowledge of the shared secret, and successfully\nauthenticate, by sending crafted values in each round of the protocol, a\nrelated issue to CVE-2010-4252.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"openssh in karmic and prior does not include J-PAKE auth\nsupport; in lucid and maverick it's present but not enabled at compile\ntime. Added a QRT regression test that looks for client-side support."}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-4478"],"bugs":[""],"patches":{"openssh":["upstream: http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/jpake.c.diff?r1=1.4;r2=1.5"]},"tags":{},"packages":[{"name":"openssh","source":"https://ubuntu.com/security/cve?package=openssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh","debian":"https://tracker.debian.org/pkg/openssh","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"not enabled at compile time","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"not enabled at compile time","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-7270","published":"2010-12-06T22:30:00","updated_at":"2025-05-26T12:47:06.895653+00:00","description":"\nOpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is\nenabled, does not prevent modification of the ciphersuite in the session\ncache, which allows remote attackers to force the use of a disabled cipher\nvia vectors involving sniffing network traffic to discover a session\nidentifier, a different vulnerability than CVE-2010-4180.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per sbeattie, \"the same fix for CVE-2010-4180 that's backported will\nfix it, as the whole SL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG block gets\nifdef'd out\""}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-7270","https://ubuntu.com/security/notices/USN-1029-1"],"bugs":[""],"patches":{"openssl":[]},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"dapper","status":"released","description":"0.9.8a-7ubuntu0.14","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.9.8g-4ubuntu3.13","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.9.8g-16ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"0.9.8k-7ubuntu8.4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.8j","component":null,"pocket":"security"}]}],"notices_ids":["USN-1029-1"],"notices":[{"id":"USN-1029-1","title":"OpenSSL vulnerabilities","summary":"","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2010-12-08T00:00:21.184582","description":"It was discovered that an old bug workaround in the SSL/TLS\nserver code allowed an attacker to modify the stored session cache\nciphersuite. This could possibly allow an attacker to downgrade the\nciphersuite to a weaker one on subsequent connections. (CVE-2010-4180)\n\nIt was discovered that an old bug workaround in the SSL/TLS\nserver code allowed an attacker to modify the stored session cache\nciphersuite. An attacker could possibly take advantage of this to\nforce the use of a disabled cipher. This vulnerability only affects\nthe versions of OpenSSL in Ubuntu 6.06 LTS, Ubuntu 8.04 LTS, and\nUbuntu 9.10. (CVE-2008-7270)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"openssl","version":"0.9.8g-4ubuntu3.13","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8g-4ubuntu3.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8g-4ubuntu3.13"}],"lucid":[{"name":"openssl","version":"0.9.8k-7ubuntu8.5","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8k-7ubuntu8.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8k-7ubuntu8.5"}],"maverick":[{"name":"openssl","version":"0.9.8o-1ubuntu4.3","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8o-1ubuntu4.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8o-1ubuntu4.3"}],"dapper":[{"name":"openssl","version":"0.9.8a-7ubuntu0.14","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8a-7ubuntu0.14","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8a-7ubuntu0.14"}],"karmic":[{"name":"openssl","version":"0.9.8g-16ubuntu3.5","description":"","is_source":true},{"name":"libssl0.9.8","version":"0.9.8g-16ubuntu3.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8g-16ubuntu3.5"}]},"type":"USN","cves_ids":["CVE-2010-4180","CVE-2008-7270"]}]},{"id":"CVE-2010-4252","published":"2010-12-06T21:05:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOpenSSL before 1.0.0c, when J-PAKE is enabled, does not properly validate\nthe public parameters in the J-PAKE protocol, which allows remote attackers\nto bypass the need for knowledge of the shared secret, and successfully\nauthenticate, by sending crafted values in each round of the protocol.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Ubuntu 10.04 LTS and later have J-PAKE code, but openssl is compiled\nwith OPENSSL_NO_JPAKE"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-4252"],"bugs":[""],"patches":{"openssl":[]},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3066","published":"2010-12-06T20:12:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe io_submit_one function in fs/aio.c in the Linux kernel before 2.6.23\nallows local users to cause a denial of service (NULL pointer dereference)\nvia a crafted io_submit system call with an IOCB_FLAG_RESFD flag.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3066"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=87e2831c3fa39cbf6f7ab676bb5aef039b9659e2"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.23","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.23","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-4254","published":"2010-12-06T13:44:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used,\ndoes not properly validate arguments to generic methods, which allows\nremote attackers to bypass generic constraints, and possibly execute\narbitrary code, via a crafted method call.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"upstream note: The bug (and fix) is in mono source code but can\nonly be exploited (by untrusted applications) when used by\nMoonlight.\nSetting severity to negligile."}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-4254"],"bugs":["https://bugs.edge.launchpad.net/ubuntu/+source/moon/+bug/691780","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608288"],"patches":{"mono":["upstream: https://github.com/mono/mono/commit/4905ef1130feb26c3150b28b97e4a96752e0d399","upstream: https://github.com/mono/mono/commit/65292a69c837b8a5f7a392d34db63de592153358","upstream: https://github.com/mono/mono/commit/cf1ec146f7c6acdc6697032b3aaafc68ffacdcac"]},"tags":{},"packages":[{"name":"mono","source":"https://ubuntu.com/security/cve?package=mono","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mono","debian":"https://tracker.debian.org/pkg/mono","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.6.7-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.6.7-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"2.6.7-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"2.6.7-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"2.6.7-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.7-5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3615","published":"2010-12-06T13:44:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nnamed in ISC BIND 9.7.2-P2 does not check all intended locations for\nallow-query ACLs, which might allow remote attackers to make successful\nrequests for private DNS records via the standard DNS query mechanism.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"affects 9.7.2-P2 only"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.isc.org/software/bind/advisories/cve-2010-3615","https://www.cve.org/CVERecord?id=CVE-2010-3615"],"bugs":[""],"patches":{"bind9":[]},"tags":{},"packages":[{"name":"bind9","source":"https://ubuntu.com/security/cve?package=bind9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bind9","debian":"https://tracker.debian.org/pkg/bind9","statuses":[{"release_codename":"dapper","status":"not-affected","description":"1:9.3.2-2ubuntu1.11","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1:9.4.2.dfsg.P2-2ubuntu0.5","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1:9.6.1.dfsg.P1-3ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1:9.7.0.dfsg.P1-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1:9.7.1.dfsg.P2-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.7.2-P3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-4403","published":"2010-12-06T13:37:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Register Plus plugin 3.5.1 and earlier for WordPress allows remote\nattackers to obtain sensitive information via a direct request to (1)\ndash_widget.php and (2) register-plus.php, which reveals the installation\npath in an error message.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"code not present:\nwp-content/plugins/register-plus/register-plus.php"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-4403"],"bugs":[""],"patches":{"wordpress":[]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-4402","published":"2010-12-06T13:37:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the\nRegister Plus plugin 3.5.1 and earlier for WordPress allow remote attackers\nto inject arbitrary web script or HTML via the (1) firstname, (2) lastname,\n(3) website, (4) aim, (5) yahoo, (6) jabber, (7) about, (8) pass1, and (9)\npass2 parameters in a register action.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"code not present:\nwp-content/plugins/register-plus/dash_widget.php\nwp-content/plugins/register-plus/register-plus.php"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-4402"],"bugs":[""],"patches":{"wordpress":[]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":71960,"limit":20,"total_results":79316}