{"cves":[{"id":"CVE-2010-2995","published":"2010-08-13T18:43:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark\n0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to\ncause a denial of service (crash) and possibly execute arbitrary code via\nvectors related to sigcomp-udvm.c and an off-by-one error, which triggers a\nbuffer overflow, different vulnerabilities than CVE-2010-2287.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4837","https://www.cve.org/CVERecord?id=CVE-2010-2995"],"bugs":[""],"patches":{"wireshark":["upstream: http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=33087"],"ethereal":[]},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.15","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.10","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2994","published":"2010-08-13T18:43:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13\nthrough 1.0.14 and 1.2.0 through 1.2.9 has unknown impact and remote attack\nvectors.  NOTE: this issue exists because of a CVE-2010-2284 regression.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4984","https://www.cve.org/CVERecord?id=CVE-2010-2994"],"bugs":[""],"patches":{"wireshark":[],"ethereal":[]},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.15","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.10","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2993","published":"2010-08-13T18:43:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe IPMI dissector in Wireshark 1.2.0 through 1.2.9 allows remote attackers\nto cause a denial of service (infinite loop) via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2993"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.0.0-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.0.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.10","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2992","published":"2010-08-13T18:43:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\npacket-gsm_a_rr.c in the GSM A RR dissector in Wireshark 1.2.2 through\n1.2.9 allows remote attackers to cause a denial of service (crash) via\nunknown vectors that trigger a NULL pointer dereference.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"reproducer pcap file:\nhttp://www.wireshark.org/download/automated/captures/fuzz-2010-06-20-7873.pcap"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2992"],"bugs":[""],"patches":{"wireshark":["upstream: http://anonsvn.wireshark.org/viewvc?view=rev&revision=33280"]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.0.0-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.0.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.10","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2808","published":"2010-08-12T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in\nFreeType before 2.4.2 allows remote attackers to cause a denial of service\n(memory corruption and application crash) or possibly execute arbitrary\ncode via a crafted Adobe Type 1 Mac Font File (aka LWFN) font.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-972-1","https://www.cve.org/CVERecord?id=CVE-2010-2808"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/freetype/+bug/617019","https://savannah.nongnu.org/bugs/?30658","https://bugzilla.redhat.com/show_bug.cgi?id=621907"],"patches":{"freetype":["upstream: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=81f3472c0ba7b8f6466e2e214fa8c1c17fade975"]},"tags":{},"packages":[{"name":"freetype","source":"https://ubuntu.com/security/cve?package=freetype","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freetype","debian":"https://tracker.debian.org/pkg/freetype","statuses":[{"release_codename":"dapper","status":"released","description":"2.1.10-1ubuntu2.8","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.3.5-1ubuntu4.8.04.4","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.3.9-4ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.3.9-5ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.3.11-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-972-1"],"notices":[{"id":"USN-972-1","title":"FreeType vulnerabilities","summary":"","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2010-08-17T16:55:17.889169","description":"It was discovered that FreeType did not correctly handle certain malformed\nfont files. If a user were tricked into using a specially crafted font\nfile, a remote attacker could cause FreeType to crash or possibly execute\narbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"karmic":[{"name":"freetype","version":"2.3.9-5ubuntu0.2","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.9-5ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.9-5ubuntu0.2"}],"hardy":[{"name":"freetype","version":"2.3.5-1ubuntu4.8.04.4","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.5-1ubuntu4.8.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.5-1ubuntu4.8.04.4"}],"lucid":[{"name":"freetype","version":"2.3.11-1ubuntu2.2","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.11-1ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.11-1ubuntu2.2"}],"dapper":[{"name":"freetype","version":"2.1.10-1ubuntu2.8","description":"","is_source":true},{"name":"libfreetype6","version":"2.1.10-1ubuntu2.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.1.10-1ubuntu2.8"}],"jaunty":[{"name":"freetype","version":"2.3.9-4ubuntu0.3","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.9-4ubuntu0.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.9-4ubuntu0.3"}]},"type":"USN","cves_ids":["CVE-2010-1797","CVE-2010-2807","CVE-2010-2806","CVE-2010-2808","CVE-2010-2805","CVE-2010-2541"]}]},{"id":"CVE-2010-2807","published":"2010-08-12T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nFreeType before 2.4.2 uses incorrect integer data types during bounds\nchecking, which allows remote attackers to cause a denial of service\n(application crash) or possibly execute arbitrary code via a crafted font\nfile.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-972-1","https://www.cve.org/CVERecord?id=CVE-2010-2807"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/freetype/+bug/617019","https://savannah.nongnu.org/bugs/?30657","https://savannah.nongnu.org/bugs/?30719"],"patches":{"freetype":["upstream: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=346f1867fd32dae8f56e5b482d1af98f626804ac","upstream: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=a205b3ca85d2d78aac71ea3c1df104972031d6ad"]},"tags":{},"packages":[{"name":"freetype","source":"https://ubuntu.com/security/cve?package=freetype","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freetype","debian":"https://tracker.debian.org/pkg/freetype","statuses":[{"release_codename":"dapper","status":"released","description":"2.1.10-1ubuntu2.8","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.3.5-1ubuntu4.8.04.4","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.3.9-4ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.3.9-5ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.3.11-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-972-1"],"notices":[{"id":"USN-972-1","title":"FreeType vulnerabilities","summary":"","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2010-08-17T16:55:17.889169","description":"It was discovered that FreeType did not correctly handle certain malformed\nfont files. If a user were tricked into using a specially crafted font\nfile, a remote attacker could cause FreeType to crash or possibly execute\narbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"karmic":[{"name":"freetype","version":"2.3.9-5ubuntu0.2","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.9-5ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.9-5ubuntu0.2"}],"hardy":[{"name":"freetype","version":"2.3.5-1ubuntu4.8.04.4","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.5-1ubuntu4.8.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.5-1ubuntu4.8.04.4"}],"lucid":[{"name":"freetype","version":"2.3.11-1ubuntu2.2","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.11-1ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.11-1ubuntu2.2"}],"dapper":[{"name":"freetype","version":"2.1.10-1ubuntu2.8","description":"","is_source":true},{"name":"libfreetype6","version":"2.1.10-1ubuntu2.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.1.10-1ubuntu2.8"}],"jaunty":[{"name":"freetype","version":"2.3.9-4ubuntu0.3","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.9-4ubuntu0.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.9-4ubuntu0.3"}]},"type":"USN","cves_ids":["CVE-2010-1797","CVE-2010-2807","CVE-2010-2806","CVE-2010-2808","CVE-2010-2805","CVE-2010-2541"]}]},{"id":"CVE-2010-2806","published":"2010-08-12T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nArray index error in the t42_parse_sfnts function in type42/t42parse.c in\nFreeType before 2.4.2 allows remote attackers to cause a denial of service\n(application crash) or possibly execute arbitrary code via negative size\nvalues for certain strings in FontType42 font files, leading to a\nheap-based buffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-972-1","https://www.cve.org/CVERecord?id=CVE-2010-2806"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/freetype/+bug/617019","https://savannah.nongnu.org/bugs/?30656","https://bugzilla.redhat.com/show_bug.cgi?id=621980"],"patches":{"freetype":["upstream: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=c06da1ad34663da7b6fc39b030dc3ae185b96557"]},"tags":{},"packages":[{"name":"freetype","source":"https://ubuntu.com/security/cve?package=freetype","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freetype","debian":"https://tracker.debian.org/pkg/freetype","statuses":[{"release_codename":"dapper","status":"released","description":"2.1.10-1ubuntu2.8","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.3.5-1ubuntu4.8.04.4","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.3.9-4ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.3.9-5ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.3.11-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-972-1"],"notices":[{"id":"USN-972-1","title":"FreeType vulnerabilities","summary":"","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2010-08-17T16:55:17.889169","description":"It was discovered that FreeType did not correctly handle certain malformed\nfont files. If a user were tricked into using a specially crafted font\nfile, a remote attacker could cause FreeType to crash or possibly execute\narbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"karmic":[{"name":"freetype","version":"2.3.9-5ubuntu0.2","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.9-5ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.9-5ubuntu0.2"}],"hardy":[{"name":"freetype","version":"2.3.5-1ubuntu4.8.04.4","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.5-1ubuntu4.8.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.5-1ubuntu4.8.04.4"}],"lucid":[{"name":"freetype","version":"2.3.11-1ubuntu2.2","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.11-1ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.11-1ubuntu2.2"}],"dapper":[{"name":"freetype","version":"2.1.10-1ubuntu2.8","description":"","is_source":true},{"name":"libfreetype6","version":"2.1.10-1ubuntu2.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.1.10-1ubuntu2.8"}],"jaunty":[{"name":"freetype","version":"2.3.9-4ubuntu0.3","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.9-4ubuntu0.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.9-4ubuntu0.3"}]},"type":"USN","cves_ids":["CVE-2010-1797","CVE-2010-2807","CVE-2010-2806","CVE-2010-2808","CVE-2010-2805","CVE-2010-2541"]}]},{"id":"CVE-2010-2805","published":"2010-08-12T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe FT_Stream_EnterFrame function in base/ftstream.c in FreeType before\n2.4.2 does not properly validate certain position values, which allows\nremote attackers to cause a denial of service (application crash) or\npossibly execute arbitrary code via a crafted font file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-972-1","https://www.cve.org/CVERecord?id=CVE-2010-2805"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/freetype/+bug/617019","https://savannah.nongnu.org/bugs/?30644"],"patches":{"freetype":["upstream: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=45a3c76b547511fa9d97aca34b150a0663257375"]},"tags":{},"packages":[{"name":"freetype","source":"https://ubuntu.com/security/cve?package=freetype","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freetype","debian":"https://tracker.debian.org/pkg/freetype","statuses":[{"release_codename":"dapper","status":"released","description":"2.1.10-1ubuntu2.8","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.3.5-1ubuntu4.8.04.4","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.3.9-4ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.3.9-5ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.3.11-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-972-1"],"notices":[{"id":"USN-972-1","title":"FreeType vulnerabilities","summary":"","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2010-08-17T16:55:17.889169","description":"It was discovered that FreeType did not correctly handle certain malformed\nfont files. If a user were tricked into using a specially crafted font\nfile, a remote attacker could cause FreeType to crash or possibly execute\narbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"karmic":[{"name":"freetype","version":"2.3.9-5ubuntu0.2","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.9-5ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.9-5ubuntu0.2"}],"hardy":[{"name":"freetype","version":"2.3.5-1ubuntu4.8.04.4","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.5-1ubuntu4.8.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.5-1ubuntu4.8.04.4"}],"lucid":[{"name":"freetype","version":"2.3.11-1ubuntu2.2","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.11-1ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.11-1ubuntu2.2"}],"dapper":[{"name":"freetype","version":"2.1.10-1ubuntu2.8","description":"","is_source":true},{"name":"libfreetype6","version":"2.1.10-1ubuntu2.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.1.10-1ubuntu2.8"}],"jaunty":[{"name":"freetype","version":"2.3.9-4ubuntu0.3","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.9-4ubuntu0.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.9-4ubuntu0.3"}]},"type":"USN","cves_ids":["CVE-2010-1797","CVE-2010-2807","CVE-2010-2806","CVE-2010-2808","CVE-2010-2805","CVE-2010-2541"]}]},{"id":"CVE-2010-2541","published":"2010-08-12T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in ftmulti.c in the ftmulti demo program in FreeType before\n2.4.2 allows remote attackers to cause a denial of service (application\ncrash) or possibly execute arbitrary code via a crafted font file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-972-1","https://www.cve.org/CVERecord?id=CVE-2010-2541"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/freetype/+bug/617019","https://bugzilla.redhat.com/show_bug.cgi?id=617342"],"patches":{"freetype":["upstream: http://git.savannah.gnu.org/cgit/freetype/freetype2-demos.git/commit/?id=3636982a7666bcfa0e47fb31d565314d1b3e7d78","upstream: http://git.savannah.gnu.org/cgit/freetype/freetype2-demos.git/commit/?id=b4d857b39fb4fcc20b5fa5cf03fde61a4919eb46","upstream: http://git.savannah.gnu.org/cgit/freetype/freetype2-demos.git/commit/?id=8dceb1f3f5a821ad1e8d6d53c323f4336e619ff4"]},"tags":{},"packages":[{"name":"freetype","source":"https://ubuntu.com/security/cve?package=freetype","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freetype","debian":"https://tracker.debian.org/pkg/freetype","statuses":[{"release_codename":"dapper","status":"released","description":"2.1.10-1ubuntu2.8","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.3.5-1ubuntu4.8.04.4","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.3.9-4ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.3.9-5ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.3.11-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-972-1"],"notices":[{"id":"USN-972-1","title":"FreeType vulnerabilities","summary":"","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2010-08-17T16:55:17.889169","description":"It was discovered that FreeType did not correctly handle certain malformed\nfont files. If a user were tricked into using a specially crafted font\nfile, a remote attacker could cause FreeType to crash or possibly execute\narbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"karmic":[{"name":"freetype","version":"2.3.9-5ubuntu0.2","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.9-5ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.9-5ubuntu0.2"}],"hardy":[{"name":"freetype","version":"2.3.5-1ubuntu4.8.04.4","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.5-1ubuntu4.8.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.5-1ubuntu4.8.04.4"}],"lucid":[{"name":"freetype","version":"2.3.11-1ubuntu2.2","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.11-1ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.11-1ubuntu2.2"}],"dapper":[{"name":"freetype","version":"2.1.10-1ubuntu2.8","description":"","is_source":true},{"name":"libfreetype6","version":"2.1.10-1ubuntu2.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.1.10-1ubuntu2.8"}],"jaunty":[{"name":"freetype","version":"2.3.9-4ubuntu0.3","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.9-4ubuntu0.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.9-4ubuntu0.3"}]},"type":"USN","cves_ids":["CVE-2010-1797","CVE-2010-2807","CVE-2010-2806","CVE-2010-2808","CVE-2010-2805","CVE-2010-2541"]}]},{"id":"CVE-2010-1797","published":"2010-08-12T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple stack-based buffer overflows in the cff_decoder_parse_charstrings\nfunction in the CFF Type2 CharStrings interpreter in cff/cffgload.c in\nFreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and\niPod touch and before 3.2.2 on the iPad, allow remote attackers to execute\narbitrary code or cause a denial of service (memory corruption) via crafted\nCFF opcodes in embedded fonts in a PDF document, as demonstrated by\nJailbreakMe. NOTE: some of these details are obtained from third party\ninformation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.f-secure.com/weblog/archives/00002002.html","https://ubuntu.com/security/notices/USN-972-1","https://www.cve.org/CVERecord?id=CVE-2010-1797"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/freetype/+bug/617019","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-1797"],"patches":{"freetype":["upstream: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=11d65e8a1f1f14e56148fd991965424d9bd1cdbc"]},"tags":{},"packages":[{"name":"freetype","source":"https://ubuntu.com/security/cve?package=freetype","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freetype","debian":"https://tracker.debian.org/pkg/freetype","statuses":[{"release_codename":"dapper","status":"released","description":"2.1.10-1ubuntu2.8","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.3.5-1ubuntu4.8.04.4","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.3.9-4ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.3.9-5ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.3.11-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-972-1"],"notices":[{"id":"USN-972-1","title":"FreeType vulnerabilities","summary":"","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2010-08-17T16:55:17.889169","description":"It was discovered that FreeType did not correctly handle certain malformed\nfont files. If a user were tricked into using a specially crafted font\nfile, a remote attacker could cause FreeType to crash or possibly execute\narbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"karmic":[{"name":"freetype","version":"2.3.9-5ubuntu0.2","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.9-5ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.9-5ubuntu0.2"}],"hardy":[{"name":"freetype","version":"2.3.5-1ubuntu4.8.04.4","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.5-1ubuntu4.8.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.5-1ubuntu4.8.04.4"}],"lucid":[{"name":"freetype","version":"2.3.11-1ubuntu2.2","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.11-1ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.11-1ubuntu2.2"}],"dapper":[{"name":"freetype","version":"2.1.10-1ubuntu2.8","description":"","is_source":true},{"name":"libfreetype6","version":"2.1.10-1ubuntu2.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.1.10-1ubuntu2.8"}],"jaunty":[{"name":"freetype","version":"2.3.9-4ubuntu0.3","description":"","is_source":true},{"name":"libfreetype6","version":"2.3.9-4ubuntu0.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freetype","version_link":"https://launchpad.net/ubuntu/+source/freetype/2.3.9-4ubuntu0.3"}]},"type":"USN","cves_ids":["CVE-2010-1797","CVE-2010-2807","CVE-2010-2806","CVE-2010-2808","CVE-2010-2805","CVE-2010-2541"]}]},{"id":"CVE-2010-2542","published":"2010-08-11T18:47:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in the is_git_directory function in setup.c in\nGit before 1.7.2.1 allows local users to gain privileges via a long gitdir:\nfield in a .git file in a working copy.","ubuntu_description":"","notes":[{"author":"kees","note":"git from hardy and earlier is not what was \"git-core\".\nThis is a non-issue due to stack-protector."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2542"],"bugs":[""],"patches":{"git-core":[],"git":[]},"tags":{"git":["stack-protector"]},"packages":[{"name":"git","source":"https://ubuntu.com/security/cve?package=git","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=git","debian":"https://tracker.debian.org/pkg/git","statuses":[{"release_codename":"dapper","status":"not-affected","description":"not the same software","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"not the same software","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.7.2","component":null,"pocket":"security"}]},{"name":"git-core","source":"https://ubuntu.com/security/cve?package=git-core","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=git-core","debian":"https://tracker.debian.org/pkg/git-core","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2216","published":"2010-08-11T18:47:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR\nbefore 2.0.3, allows attackers to execute arbitrary code or cause a denial\nof service (memory corruption) via unspecified vectors, a different\nvulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2214.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.adobe.com/support/security/bulletins/apsb10-16.html","https://www.cve.org/CVERecord?id=CVE-2010-2216"],"bugs":["https://edge.launchpad.net/bugs/616167"],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"10.1.82.76-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"10.1.82.76-1jaunty1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"10.1.82.76-1karmic1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"10.1.82.76-1lucid1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.82.76,9.0.280.0","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"10.0.1.218+really9.0.280.0ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"10.1.82.76ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"10.1.82.76ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"10.1.82.76ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.82.76,9.0.280.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2215","published":"2010-08-11T18:47:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR\nbefore 2.0.3, allows attackers to trick a user into (1) selecting a link or\n(2) completing a dialog, related to a \"click-jacking\" issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.adobe.com/support/security/bulletins/apsb10-16.html","https://www.cve.org/CVERecord?id=CVE-2010-2215"],"bugs":["https://edge.launchpad.net/bugs/616167"],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"10.1.82.76-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"10.1.82.76-1jaunty1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"10.1.82.76-1karmic1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"10.1.82.76-1lucid1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.82.76,9.0.280.0","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"10.0.1.218+really9.0.280.0ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"10.1.82.76ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"10.1.82.76ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"10.1.82.76ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.82.76,9.0.280.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2214","published":"2010-08-11T18:47:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR\nbefore 2.0.3, allows attackers to execute arbitrary code or cause a denial\nof service (memory corruption) via unspecified vectors, a different\nvulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2216.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.adobe.com/support/security/bulletins/apsb10-16.html","https://www.cve.org/CVERecord?id=CVE-2010-2214"],"bugs":["https://edge.launchpad.net/bugs/616167"],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"10.1.82.76-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"10.1.82.76-1jaunty1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"10.1.82.76-1karmic1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"10.1.82.76-1lucid1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.82.76,9.0.280.0","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"10.0.1.218+really9.0.280.0ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"10.1.82.76ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"10.1.82.76ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"10.1.82.76ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.82.76,9.0.280.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2213","published":"2010-08-11T18:47:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR\nbefore 2.0.3, allows attackers to execute arbitrary code or cause a denial\nof service (memory corruption) via unspecified vectors, a different\nvulnerability than CVE-2010-0209, CVE-2010-2214, and CVE-2010-2216.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.adobe.com/support/security/bulletins/apsb10-16.html","https://www.cve.org/CVERecord?id=CVE-2010-2213"],"bugs":["https://edge.launchpad.net/bugs/616167"],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"10.1.82.76-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"10.1.82.76-1jaunty1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"10.1.82.76-1karmic1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"10.1.82.76-1lucid1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.82.76,9.0.280.0","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"10.0.1.218+really9.0.280.0ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"10.1.82.76ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"10.1.82.76ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"10.1.82.76ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.82.76,9.0.280.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0209","published":"2010-08-11T18:47:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR\nbefore 2.0.3, allows attackers to execute arbitrary code or cause a denial\nof service (memory corruption) via unspecified vectors, a different\nvulnerability than CVE-2010-2213, CVE-2010-2214, and CVE-2010-2216.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.adobe.com/support/security/bulletins/apsb10-16.html","https://www.cve.org/CVERecord?id=CVE-2010-0209"],"bugs":["https://edge.launchpad.net/bugs/616167"],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"10.1.82.76-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"10.1.82.76-1jaunty1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"10.1.82.76-1karmic1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"10.1.82.76-1lucid1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.82.76,9.0.280.0","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"10.0.1.218+really9.0.280.0ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"10.1.82.76ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"10.1.82.76ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"10.1.82.76ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.82.76,9.0.280.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2574","published":"2010-08-10T12:23:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in manage_proj_cat_add.php in\nMantisBT 1.2.2 allows remote authenticated administrators to inject\narbitrary web script or HTML via the name parameter in an Add Category\naction.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://jira.jboss.org/browse/SOA-2105","https://www.cve.org/CVERecord?id=CVE-2010-2574"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=595510"],"patches":{"mantis":["upstream: http://git.mantisbt.org/?p=mantisbt.git;a=commitdiff;h=083c34f06ca927b16e781bae3ae324f450c35ea4"]},"tags":{},"packages":[{"name":"mantis","source":"https://ubuntu.com/security/cve?package=mantis","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mantis","debian":"https://tracker.debian.org/pkg/mantis","statuses":[{"release_codename":"raring","status":"not-affected","description":"1.1.8+dfsg-6","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.1.8+dfsg-6","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.1.8+dfsg-6","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.1.8+dfsg-6","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.1.8+dfsg-6","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.1.8+dfsg-6","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.1.8+dfsg-6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2493","published":"2010-08-10T12:23:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe default configuration of the deployment descriptor (aka web.xml) in\npicketlink-sts.war in (1) the security_saml quickstart, (2) the\nwebservice_proxy_security quickstart, (3) the web-console application, (4)\nthe http-invoker application, (5) the gpd-deployer application, (6) the\njbpm-console application, (7) the contract application, and (8) the\nuddi-console application in JBoss Enterprise SOA Platform before 5.0.2\ncontains GET and POST http-method elements, which allows remote attackers\nto bypass intended access restrictions via a crafted HTTP request.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2493"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=614774","https://jira.jboss.org/browse/SOA-2105"],"patches":{"jbossas4":[]},"tags":{},"packages":[{"name":"jbossas4","source":"https://ubuntu.com/security/cve?package=jbossas4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jbossas4","debian":"https://tracker.debian.org/pkg/jbossas4","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needed]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2474","published":"2010-08-10T12:23:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nJBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA\nPlatform before 5.0.2 does not properly consider the security domain with\nwhich a service is secured, which might allow remote attackers to gain\nprivileges by executing a service.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2474"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=609442","https://jira.jboss.org/browse/JBESB-3345"],"patches":{"jbossas4":[]},"tags":{},"packages":[{"name":"jbossas4","source":"https://ubuntu.com/security/cve?package=jbossas4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jbossas4","debian":"https://tracker.debian.org/pkg/jbossas4","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needed]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2801","published":"2010-08-09T11:58:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger signedness error in the Quantum decompressor in cabextract before\n1.3, when archive test mode is used, allows user-assisted remote attackers\nto cause a denial of service (application crash) or possibly execute\narbitrary code via a crafted Quantum archive in a .cab file, related to the\nlibmspack library.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.debian.org/security/2010/dsa-2087","https://www.cve.org/CVERecord?id=CVE-2010-2801"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/cabextract/+bug/609708","http://bugs.gentoo.org/show_bug.cgi?id=329891","https://bugzilla.redhat.com/show_bug.cgi?id=620454"],"patches":{"cabextract":["upstream: http://libmspack.svn.sourceforge.net/viewvc/libmspack/libmspack/trunk/mspack/qtmd.c?r1=114&r2=113","upstream: http://libmspack.svn.sourceforge.net/viewvc/libmspack?view=revision&revision=118"]},"tags":{},"packages":[{"name":"cabextract","source":"https://ubuntu.com/security/cve?package=cabextract","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cabextract","debian":"https://tracker.debian.org/pkg/cabextract","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.2-3+lenny1build0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2-3+lenny1build0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2-3+lenny1build0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.3-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.3-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.3-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":72500,"limit":20,"total_results":79316}