{"cves":[{"id":"CVE-2010-2693","published":"2010-07-13T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nFreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when\ncreating a duplicate mbuf buffer reference, which allows local users to\ncause a denial of service (system file corruption) and gain privileges via\nthe sendfile system call.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2693"],"bugs":[""],"patches":{"kfreebsd-7":[],"kfreebsd-8":["upstream: http://security.freebsd.org/patches/SA-10:07/mbuf.patch"]},"tags":{},"packages":[{"name":"kfreebsd-7","source":"https://ubuntu.com/security/cve?package=kfreebsd-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kfreebsd-7","debian":"https://tracker.debian.org/pkg/kfreebsd-7","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"kfreebsd-8","source":"https://ubuntu.com/security/cve?package=kfreebsd-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kfreebsd-8","debian":"https://tracker.debian.org/pkg/kfreebsd-8","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2227","published":"2010-07-13T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nApache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta\ndoes not properly handle an invalid Transfer-Encoding header, which allows\nremote attackers to cause a denial of service (application outage) or\nobtain sensitive information via a crafted header that interferes with\n\"recycling of a buffer.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-976-1","https://www.cve.org/CVERecord?id=CVE-2010-2227"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2227","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=588813"],"patches":{"tomcat6":["upstream: http://svn.apache.org/viewvc?view=revision&revision=958977"],"tomcat5":["upstream: http://svn.apache.org/viewvc?view=revision&revision=959428"],"tomcat5.5":["upstream: http://svn.apache.org/viewvc?view=revision&revision=959428"]},"tags":{},"packages":[{"name":"tomcat5","source":"https://ubuntu.com/security/cve?package=tomcat5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat5","debian":"https://tracker.debian.org/pkg/tomcat5","statuses":[{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.30","component":null,"pocket":"security"}]},{"name":"tomcat5.5","source":"https://ubuntu.com/security/cve?package=tomcat5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat5.5","debian":"https://tracker.debian.org/pkg/tomcat5.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.30","component":null,"pocket":"security"}]},{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.0.18-0ubuntu6.3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6.0.20-2ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.24-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"6.0.28-2","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"6.0.28-2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6.0.28-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.28","component":null,"pocket":"security"}]}],"notices_ids":["USN-976-1"],"notices":[{"id":"USN-976-1","title":"Tomcat vulnerability","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-08-25T14:38:36.645385","description":"It was discovered that Tomcat incorrectly handled invalid Transfer-Encoding\nheaders. A remote attacker could send specially crafted requests containing\ninvalid headers to the server and cause a denial of service, or possibly\nobtain sensitive information from other requests.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"tomcat6","version":"6.0.24-2ubuntu1.3","description":"","is_source":true},{"name":"libtomcat6-java","version":"6.0.24-2ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.24-2ubuntu1.3"}],"jaunty":[{"name":"tomcat6","version":"6.0.18-0ubuntu6.3","description":"","is_source":true},{"name":"libtomcat6-java","version":"6.0.18-0ubuntu6.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.18-0ubuntu6.3"}],"karmic":[{"name":"tomcat6","version":"6.0.20-2ubuntu2.2","description":"","is_source":true},{"name":"libtomcat6-java","version":"6.0.20-2ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.20-2ubuntu2.2"}]},"type":"USN","cves_ids":["CVE-2010-2227"]}]},{"id":"CVE-2010-2008","published":"2010-07-13T00:00:00","updated_at":"2025-05-26T12:47:11.882847+00:00","description":"\nMySQL before 5.1.48 allows remote authenticated users with alter database\nprivileges to cause a denial of service (server crash and database loss)\nvia an ALTER DATABASE command with a #mysql50# string followed by a .\n(dot), .. (dot dot), ../ (dot dot slash) or similar sequence, and an\nUPGRADE DATA DIRECTORY NAME command, which causes MySQL to move certain\ndirectories to the server data directory.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"PoC in upstream report (remeber to add UPGRADE DATA DIRECTORY NAME)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1017-1","https://www.cve.org/CVERecord?id=CVE-2010-2008","https://ubuntu.com/security/notices/USN-1397-1"],"bugs":["http://bugs.mysql.com/bug.php?id=53804","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2008"],"patches":{"mysql-dfsg-5.0":[],"mysql-dfsg-5.1":["upstream: http://bazaar.launchpad.net/~mysql/mysql-server/mysql-5.1/revision/3351.58.14"],"mysql-5.1":[],"mysql-dfsg-4.1":[]},"tags":{},"packages":[{"name":"mysql-5.1","source":"https://ubuntu.com/security/cve?package=mysql-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.1","debian":"https://tracker.debian.org/pkg/mysql-5.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"5.1.48-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.48, 5.5.5","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-4.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-4.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-4.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-4.1","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.0","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.0","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.0","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"5.1.37-1ubuntu5.5","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.1.41-3ubuntu12.7","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.48","component":null,"pocket":"security"}]}],"notices_ids":["USN-1017-1","USN-1397-1"],"notices":[{"id":"USN-1017-1","title":"MySQL vulnerabilities","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-11-11T15:09:51.664559","description":"It was discovered that MySQL incorrectly handled certain requests with the\nUPGRADE DATA DIRECTORY NAME command. An authenticated user could exploit\nthis to make MySQL crash, causing a denial of service. This issue only\naffected Ubuntu 9.10 and 10.04 LTS. (CVE-2010-2008)\n\nIt was discovered that MySQL incorrectly handled joins involving a table\nwith a unique SET column. An authenticated user could exploit this to make\nMySQL crash, causing a denial of service. This issue only affected Ubuntu\n6.06 LTS, 8.04 LTS, 9.10 and 10.04 LTS. (CVE-2010-3677)\n\nIt was discovered that MySQL incorrectly handled NULL arguments to IN() or\nCASE operations. An authenticated user could exploit this to make MySQL\ncrash, causing a denial of service. This issue only affected Ubuntu 9.10\nand 10.04 LTS. (CVE-2010-3678)\n\nIt was discovered that MySQL incorrectly handled malformed arguments to the\nBINLOG statement. An authenticated user could exploit this to make MySQL\ncrash, causing a denial of service. This issue only affected Ubuntu 9.10\nand 10.04 LTS. (CVE-2010-3679)\n\nIt was discovered that MySQL incorrectly handled the use of TEMPORARY\nInnoDB tables with nullable columns. An authenticated user could exploit\nthis to make MySQL crash, causing a denial of service. This issue only\naffected Ubuntu 6.06 LTS, 8.04 LTS, 9.10 and 10.04 LTS. (CVE-2010-3680)\n\nIt was discovered that MySQL incorrectly handled alternate reads from two\nindexes on a table using the HANDLER interface. An authenticated user could\nexploit this to make MySQL crash, causing a denial of service. This issue\nonly affected Ubuntu 6.06 LTS, 8.04 LTS, 9.10 and 10.04 LTS.\n(CVE-2010-3681)\n\nIt was discovered that MySQL incorrectly handled use of EXPLAIN with\ncertain queries. An authenticated user could exploit this to make MySQL\ncrash, causing a denial of service. This issue only affected Ubuntu\n6.06 LTS, 8.04 LTS, 9.10 and 10.04 LTS. (CVE-2010-3682)\n\nIt was discovered that MySQL incorrectly handled error reporting when using\nLOAD DATA INFILE and would incorrectly raise an assert in certain\ncircumstances. An authenticated user could exploit this to make MySQL\ncrash, causing a denial of service. This issue only affected Ubuntu 9.10\nand 10.04 LTS. (CVE-2010-3683)\n\nIt was discovered that MySQL incorrectly handled propagation during\nevaluation of arguments to extreme-value functions. An authenticated user\ncould exploit this to make MySQL crash, causing a denial of service. This\nissue only affected Ubuntu 8.04 LTS, 9.10, 10.04 LTS and 10.10.\n(CVE-2010-3833)\n\nIt was discovered that MySQL incorrectly handled materializing a derived\ntable that required a temporary table for grouping. An authenticated user\ncould exploit this to make MySQL crash, causing a denial of service.\n(CVE-2010-3834)\n\nIt was discovered that MySQL incorrectly handled certain user-variable\nassignment expressions that are evaluated in a logical expression context.\nAn authenticated user could exploit this to make MySQL crash, causing a\ndenial of service. This issue only affected Ubuntu 8.04 LTS, 9.10,\n10.04 LTS and 10.10. (CVE-2010-3835)\n\nIt was discovered that MySQL incorrectly handled pre-evaluation of LIKE\npredicates during view preparation. An authenticated user could exploit\nthis to make MySQL crash, causing a denial of service. (CVE-2010-3836)\n\nIt was discovered that MySQL incorrectly handled using GROUP_CONCAT() and\nWITH ROLLUP together. An authenticated user could exploit this to make\nMySQL crash, causing a denial of service. (CVE-2010-3837)\n\nIt was discovered that MySQL incorrectly handled certain queries using a\nmixed list of numeric and LONGBLOB arguments to the GREATEST() or LEAST()\nfunctions. An authenticated user could exploit this to make MySQL crash,\ncausing a denial of service. (CVE-2010-3838)\n\nIt was discovered that MySQL incorrectly handled queries with nested joins\nwhen used from stored procedures and prepared statements. An authenticated\nuser could exploit this to make MySQL hang, causing a denial of service.\nThis issue only affected Ubuntu 9.10, 10.04 LTS and 10.10. (CVE-2010-3839)\n\nIt was discovered that MySQL incorrectly handled improper WKB data passed\nto the PolyFromWKB() function. An authenticated user could exploit this to\nmake MySQL crash, causing a denial of service. (CVE-2010-3840)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"mysql-dfsg-5.0","version":"5.0.51a-3ubuntu5.8","description":"","is_source":true},{"name":"mysql-server-5.0","version":"5.0.51a-3ubuntu5.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0/5.0.51a-3ubuntu5.8"}],"lucid":[{"name":"mysql-dfsg-5.1","version":"5.1.41-3ubuntu12.7","description":"","is_source":true},{"name":"mysql-server-5.1","version":"5.1.41-3ubuntu12.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1/5.1.41-3ubuntu12.7"}],"maverick":[{"name":"mysql-5.1","version":"5.1.49-1ubuntu8.1","description":"","is_source":true},{"name":"mysql-server-5.1","version":"5.1.49-1ubuntu8.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.1/5.1.49-1ubuntu8.1"}],"dapper":[{"name":"mysql-dfsg-5.0","version":"5.0.22-0ubuntu6.06.15","description":"","is_source":true},{"name":"mysql-server-5.0","version":"5.0.22-0ubuntu6.06.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0/5.0.22-0ubuntu6.06.15"}],"karmic":[{"name":"mysql-dfsg-5.1","version":"5.1.37-1ubuntu5.5","description":"","is_source":true},{"name":"mysql-server-5.1","version":"5.1.37-1ubuntu5.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1/5.1.37-1ubuntu5.5"}]},"type":"USN","cves_ids":["CVE-2010-2008","CVE-2010-3677","CVE-2010-3678","CVE-2010-3679","CVE-2010-3680","CVE-2010-3681","CVE-2010-3682","CVE-2010-3683","CVE-2010-3833","CVE-2010-3834","CVE-2010-3835","CVE-2010-3836","CVE-2010-3837","CVE-2010-3838","CVE-2010-3839","CVE-2010-3840"]},{"id":"USN-1397-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-03-12T14:37:53.714964","description":"Multiple security issues were discovered in MySQL and this update includes\nnew upstream MySQL versions to fix these issues.\n\nMySQL has been updated to 5.1.61 in Ubuntu 10.04 LTS, Ubuntu 10.10,\nUbuntu 11.04 and Ubuntu 11.10. Ubuntu 8.04 LTS has been updated to\nMySQL 5.0.95.\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\n\nhttp://dev.mysql.com/doc/refman/5.1/en/news-5-1-x.html\nhttp://dev.mysql.com/doc/refman/5.0/en/news-5-0-x.html\nhttp://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html\n","is_hidden":false,"release_packages":{"hardy":[{"name":"mysql-dfsg-5.0","version":"5.0.95-0ubuntu1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.0","version":"5.0.95-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0/5.0.95-0ubuntu1"}],"lucid":[{"name":"mysql-dfsg-5.1","version":"5.1.61-0ubuntu0.10.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1/5.1.61-0ubuntu0.10.04.1"}],"maverick":[{"name":"mysql-5.1","version":"5.1.61-0ubuntu0.10.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.1/5.1.61-0ubuntu0.10.10.1"}],"natty":[{"name":"mysql-5.1","version":"5.1.61-0ubuntu0.11.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.1/5.1.61-0ubuntu0.11.04.1"}],"oneiric":[{"name":"mysql-5.1","version":"5.1.61-0ubuntu0.11.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.61-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.1/5.1.61-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2007-5925","CVE-2008-3963","CVE-2008-4098","CVE-2008-4456","CVE-2008-7247","CVE-2009-2446","CVE-2009-4019","CVE-2009-4030","CVE-2009-4484","CVE-2010-1621","CVE-2010-1626","CVE-2010-1848","CVE-2010-1849","CVE-2010-1850","CVE-2010-2008","CVE-2010-3677","CVE-2010-3678","CVE-2010-3679","CVE-2010-3680","CVE-2010-3681","CVE-2010-3682","CVE-2010-3683","CVE-2010-3833","CVE-2010-3834","CVE-2010-3835","CVE-2010-3836","CVE-2010-3837","CVE-2010-3838","CVE-2010-3839","CVE-2010-3840","CVE-2011-2262","CVE-2012-0075","CVE-2012-0087","CVE-2012-0101","CVE-2012-0102","CVE-2012-0112","CVE-2012-0113","CVE-2012-0114","CVE-2012-0115","CVE-2012-0116","CVE-2012-0117","CVE-2012-0118","CVE-2012-0119","CVE-2012-0120","CVE-2012-0484","CVE-2012-0485","CVE-2012-0486","CVE-2012-0487","CVE-2012-0488","CVE-2012-0489","CVE-2012-0490","CVE-2012-0491","CVE-2012-0492","CVE-2012-0493","CVE-2012-0494","CVE-2012-0495","CVE-2012-0496"]}]},{"id":"CVE-2010-2448","published":"2010-07-12T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nznc.cpp in ZNC before 0.092 allows remote authenticated users to cause a\ndenial of service (crash) by requesting traffic statistics when there is an\nactive unauthenticated connection, which triggers a NULL pointer\ndereference, as demonstrated using (1) a traffic link in the web\nadministration pages or (2) the traffic command in the /znc shell.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"debian's CVE tracker for some reason references gitolite with\nthis CVE; I think it's an editing mistake."},{"author":"mdeslaur","note":"this is actually a typo. CVE-2010-2488 is the actual CVE number."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2010/07/14/1","https://www.cve.org/CVERecord?id=CVE-2010-2448"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/znc/+bug/1090195","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=584929"],"patches":{"znc":["upstream: http://znc.svn.sourceforge.net/viewvc/znc/trunk/znc.cpp?r1=2025&r2=2026&pathrev=2026"]},"tags":{},"packages":[{"name":"znc","source":"https://ubuntu.com/security/cve?package=znc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=znc","debian":"https://tracker.debian.org/pkg/znc","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.078-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"0.090-2","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"0.090-2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"0.090-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"0.090-2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"0.090-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.092","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2489","published":"2010-07-12T13:27:00","updated_at":"2025-07-17T16:42:31.366623+00:00","description":"\nBuffer overflow in Ruby 1.9.x before 1.9.1-p429 on Windows might allow\nlocal users to gain privileges via a crafted ARGF.inplace_mode value that\nis not properly handled when constructing the filenames of the backup\nfiles.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"Windows only"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2489"],"bugs":[""],"patches":{"ruby1.8":[],"ruby1.9.1":[]},"tags":{},"packages":[{"name":"ruby1.8","source":"https://ubuntu.com/security/cve?package=ruby1.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.8","debian":"https://tracker.debian.org/pkg/ruby1.8","statuses":[{"release_codename":"dapper","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"ruby1.9.1","source":"https://ubuntu.com/security/cve?package=ruby1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.9.1","debian":"https://tracker.debian.org/pkg/ruby1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.1-p429, 1.9.2-RC1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2445","published":"2010-07-08T12:54:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nfreeciv 2.2 before 2.2.1 and 2.3 before 2.3.0 allows attackers to read\narbitrary files or execute arbitrary commands via a scenario that contains\nLua functionality, related to the (1) os, (2) io, (3) package, (4) dofile,\n(5) loadfile, (6) loadlib, (7) module, and (8) require modules or\nfunctions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2445"],"bugs":["http://gna.org/bugs/?15624"],"patches":{"freeciv":[]},"tags":{},"packages":[{"name":"freeciv","source":"https://ubuntu.com/security/cve?package=freeciv","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freeciv","debian":"https://tracker.debian.org/pkg/freeciv","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.4.2-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.4.2-1","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.1,2.3.0","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.2-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.2-1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2494","published":"2010-07-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple buffer underflows in the base64 decoder in base64.c in (1)\nbogofilter and (2) bogolexer in bogofilter before 1.2.2 allow remote\nattackers to cause a denial of service (heap memory corruption and\napplication crash) via an e-mail message with invalid base64 data that\nbegins with an = (equals) character.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bogofilter.sourceforge.net/security/bogofilter-SA-2010-01","https://ubuntu.com/security/notices/USN-980-1","https://www.cve.org/CVERecord?id=CVE-2010-2494"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=611551"],"patches":{"bogofilter":["upstream: http://bogofilter.svn.sourceforge.net/viewvc/bogofilter/trunk/bogofilter/src/base64.c?view=patch&r1=6906&r2=6903","upstream: http://bogofilter.svn.sourceforge.net/viewvc/bogofilter?view=revision&revision=6905"]},"tags":{},"packages":[{"name":"bogofilter","source":"https://ubuntu.com/security/cve?package=bogofilter","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bogofilter","debian":"https://tracker.debian.org/pkg/bogofilter","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.5-2ubuntu5.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.7-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.0-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.1-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-980-1"],"notices":[{"id":"USN-980-1","title":"bogofilter vulnerability","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-08-31T12:46:56.025925","description":"Julius Plenz discovered that bogofilter incorrectly handled certain\nmalformed encodings. By sending a specially crafted email, a remote\nattacker could exploit this and cause bogofilter to crash, resulting in a\ndenial of service.\n","is_hidden":false,"release_packages":{"hardy":[{"name":"bogofilter","version":"1.1.5-2ubuntu5.1","description":"","is_source":true},{"name":"bogofilter-bdb","version":"1.1.5-2ubuntu5.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bogofilter","version_link":"https://launchpad.net/ubuntu/+source/bogofilter/1.1.5-2ubuntu5.1"},{"name":"bogofilter-sqlite","version":"1.1.5-2ubuntu5.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bogofilter","version_link":"https://launchpad.net/ubuntu/+source/bogofilter/1.1.5-2ubuntu5.1"}],"lucid":[{"name":"bogofilter","version":"1.2.1-0ubuntu1.1","description":"","is_source":true},{"name":"bogofilter-bdb","version":"1.2.1-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bogofilter","version_link":"https://launchpad.net/ubuntu/+source/bogofilter/1.2.1-0ubuntu1.1"},{"name":"bogofilter-sqlite","version":"1.2.1-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bogofilter","version_link":"https://launchpad.net/ubuntu/+source/bogofilter/1.2.1-0ubuntu1.1"}],"jaunty":[{"name":"bogofilter","version":"1.1.7-1ubuntu1.1","description":"","is_source":true},{"name":"bogofilter-bdb","version":"1.1.7-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bogofilter","version_link":"https://launchpad.net/ubuntu/+source/bogofilter/1.1.7-1ubuntu1.1"},{"name":"bogofilter-sqlite","version":"1.1.7-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bogofilter","version_link":"https://launchpad.net/ubuntu/+source/bogofilter/1.1.7-1ubuntu1.1"}],"karmic":[{"name":"bogofilter","version":"1.2.0-3ubuntu1.1","description":"","is_source":true},{"name":"bogofilter-bdb","version":"1.2.0-3ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bogofilter","version_link":"https://launchpad.net/ubuntu/+source/bogofilter/1.2.0-3ubuntu1.1"},{"name":"bogofilter-sqlite","version":"1.2.0-3ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/bogofilter","version_link":"https://launchpad.net/ubuntu/+source/bogofilter/1.2.0-3ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2010-2494"]}]},{"id":"CVE-2010-2244","published":"2010-07-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe AvahiDnsPacket function in avahi-core/socket.c in avahi-daemon in Avahi\n0.6.16 and 0.6.25 allows remote attackers to cause a denial of service\n(assertion failure and daemon exit) via a DNS packet with an invalid\nchecksum followed by a DNS packet with a valid checksum, a different\nvulnerability than CVE-2008-5081.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2010/06/23/4","https://ubuntu.com/security/notices/USN-992-1","https://www.cve.org/CVERecord?id=CVE-2010-2244"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=607293"],"patches":{"avahi":["upstream: http://git.0pointer.de/?p=avahi.git;a=commit;h=2b2844b10d7b7e5c97f9c667d664d9418bb7769a"]},"tags":{},"packages":[{"name":"avahi","source":"https://ubuntu.com/security/cve?package=avahi","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=avahi","debian":"https://tracker.debian.org/pkg/avahi","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.6.22-2ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.6.23-4ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.6.25-1ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.6.25-1ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.6.26","component":null,"pocket":"security"}]}],"notices_ids":["USN-992-1"],"notices":[{"id":"USN-992-1","title":"Avahi vulnerabilities","summary":"","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2010-09-29T13:41:58.994871","description":"It was discovered that Avahi incorrectly handled certain mDNS query packets\nwhen the reflector feature is enabled, which is not the default\nconfiguration on Ubuntu. A remote attacker could send crafted mDNS queries\nand perform a denial of service on the server and on the network. This\nissue only affected Ubuntu 8.04 LTS and 9.04. (CVE-2009-0758)\n\nIt was discovered that Avahi incorrectly handled mDNS packets with\ncorrupted checksums. A remote attacker could send crafted mDNS packets and\ncause Avahi to crash, resulting in a denial of service. (CVE-2010-2244)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"avahi","version":"0.6.22-2ubuntu4.2","description":"","is_source":true},{"name":"libavahi-core5","version":"0.6.22-2ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/avahi","version_link":"https://launchpad.net/ubuntu/+source/avahi/0.6.22-2ubuntu4.2"}],"lucid":[{"name":"avahi","version":"0.6.25-1ubuntu6.1","description":"","is_source":true},{"name":"libavahi-core6","version":"0.6.25-1ubuntu6.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/avahi","version_link":"https://launchpad.net/ubuntu/+source/avahi/0.6.25-1ubuntu6.1"}],"jaunty":[{"name":"avahi","version":"0.6.23-4ubuntu4.1","description":"","is_source":true},{"name":"libavahi-core5","version":"0.6.23-4ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/avahi","version_link":"https://launchpad.net/ubuntu/+source/avahi/0.6.23-4ubuntu4.1"}],"karmic":[{"name":"avahi","version":"0.6.25-1ubuntu5.2","description":"","is_source":true},{"name":"libavahi-core6","version":"0.6.25-1ubuntu5.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/avahi","version_link":"https://launchpad.net/ubuntu/+source/avahi/0.6.25-1ubuntu5.2"}]},"type":"USN","cves_ids":["CVE-2009-0758","CVE-2010-2244"]}]},{"id":"CVE-2010-2221","published":"2010-07-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple buffer overflows in the iSNS implementation in isns.c in (1) Linux\nSCSI target framework (aka tgt or scsi-target-utils) before 1.0.6, (2)\niSCSI Enterprise Target (aka iscsitarget or IET) 1.4.20.1 and earlier, and\n(3) Generic SCSI Target Subsystem for Linux (aka SCST or iscsi-scst)\n1.0.1.1 and earlier allow remote attackers to cause a denial of service\n(memory corruption and daemon crash) or possibly execute arbitrary code via\n(a) a long iSCSI Name string in an SCN message or (b) an invalid PDU.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://archives.neohapsis.com/archives/fulldisclosure/2010-07/0058.html","https://ubuntu.com/security/notices/USN-1156-1","https://www.cve.org/CVERecord?id=CVE-2010-2221"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=593877"],"patches":{"iscsitarget":["vendor: http://www.mandriva.com/security/advisories?name=MDVSA-2010:131","upstream: http://scst.svn.sourceforge.net/viewvc/scst?view=revision&revision=1793"],"tgt":["vendor: https://bugzilla.redhat.com/attachment.cgi?id=422756","vendor: https://bugzilla.redhat.com/attachment.cgi?id=424334"]},"tags":{},"packages":[{"name":"iscsitarget","source":"https://ubuntu.com/security/cve?package=iscsitarget","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=iscsitarget","debian":"https://tracker.debian.org/pkg/iscsitarget","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.20.1-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.20.3+svn499-0ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.20.3+svn499-0ubuntu2.3]","component":null,"pocket":"security"}]},{"name":"tgt","source":"https://ubuntu.com/security/cve?package=tgt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tgt","debian":"https://tracker.debian.org/pkg/tgt","statuses":[{"release_codename":"vivid","status":"not-affected","description":"1:1.0.13-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"1:1.0.13-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:1.0.13-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:1.0.13-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1:1.0.4-1ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1:1.0.13-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1:1.0.13-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1:1.0.13-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1:1.0.13-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1:1.0.13-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1:1.0.13-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1:1.0.13-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1:1.0.13-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1:1.0.13-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1:1.0.13-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1:1.0.13-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1:1.0.13-0ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":["USN-1156-1"],"notices":[{"id":"USN-1156-1","title":"tgt vulnerabilities","summary":"An attacker could send crafted input to tgt and cause it to crash or run\narbitrary programs.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-06-21T12:10:30.020001","description":"It was discovered that tgt incorrectly handled long iSCSI name strings, and\ninvalid PDUs. A remote attacker could exploit this to cause tgt to crash,\nresulting in a denial of service, or possibly execute arbitrary code. This\nissue only affected Ubuntu 10.10. (CVE-2010-2221)\n\nEmmanuel Bouillon discovered that tgt incorrectly handled certain iSCSI\nlogins. A remote attacker could exploit this to cause tgt to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2011-0001)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"tgt","version":"1:1.0.4-1ubuntu4.1","description":"Linux SCSI target user-space tools","is_source":true},{"name":"tgt","version":"1:1.0.4-1ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tgt","version_link":"https://launchpad.net/ubuntu/+source/tgt/1:1.0.4-1ubuntu4.1"}],"natty":[{"name":"tgt","version":"1:1.0.13-0ubuntu2.1","description":"Linux SCSI target user-space tools","is_source":true},{"name":"tgt","version":"1:1.0.13-0ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tgt","version_link":"https://launchpad.net/ubuntu/+source/tgt/1:1.0.13-0ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2010-2221","CVE-2011-0001"]}]},{"id":"CVE-2010-0832","published":"2010-07-07T00:00:00","updated_at":"2025-05-26T12:47:11.882847+00:00","description":"\npam_motd (aka the MOTD module) in libpam-modules before 1.1.0-2ubuntu1.1 in\nPAM on Ubuntu 9.10 and libpam-modules before 1.1.1-2ubuntu5 in PAM on\nUbuntu 10.04 LTS allows local users to change the ownership of arbitrary\nfiles via a symlink attack on .cache in a user's home directory, related to\n\"user file stamps\" and the motd.legal-notice file.","ubuntu_description":"\nDenis Excoffier discovered that the PAM MOTD module in Ubuntu did not\ncorrectly handle path permissions when creating user file stamps. A\nlocal attacker could exploit this to gain root privilieges.","notes":[{"author":"kees","note":"Ubuntu-specific patch."}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-959-1","https://www.cve.org/CVERecord?id=CVE-2010-0832","https://ubuntu.com/security/notices/USN-959-2"],"bugs":[""],"patches":{"pam":[]},"tags":{},"packages":[{"name":"pam","source":"https://ubuntu.com/security/cve?package=pam","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pam","debian":"https://tracker.debian.org/pkg/pam","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.1.0-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.1.1-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-959-1","USN-959-2"],"notices":[{"id":"USN-959-1","title":"PAM vulnerability","summary":"Root privilege escalation via symlink following.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-07-07T22:05:24.123707","description":"Denis Excoffier discovered that the PAM MOTD module in Ubuntu did\nnot correctly handle path permissions when creating user file stamps.\nA local attacker could exploit this to gain root privilieges.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"pam","version":"1.1.1-2ubuntu5","description":"Pluggable Authentication Modules library","is_source":true},{"name":"libpam-modules","version":"1.1.1-2ubuntu5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.1-2ubuntu5"}],"karmic":[{"name":"pam","version":"1.1.0-2ubuntu1.1","description":"Pluggable Authentication Modules library","is_source":true},{"name":"libpam-modules","version":"1.1.0-2ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.0-2ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2010-0832"]},{"id":"USN-959-2","title":"PAM vulnerability","summary":"Gain root by following symlinks.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-10-25T15:19:42.042408","description":"USN-959-1 fixed vulnerabilities in PAM. This update provides the\ncorresponding updates for Ubuntu 10.10.\n\nOriginal advisory details:\n\n Denis Excoffier discovered that the PAM MOTD module in Ubuntu did\n not correctly handle path permissions when creating user file stamps.\n A local attacker could exploit this to gain root privilieges.\n","is_hidden":false,"release_packages":{"maverick":[{"name":"pam","version":"1.1.1-4ubuntu2","description":"Pluggable Authentication Modules","is_source":true},{"name":"libpam-modules","version":"1.1.1-4ubuntu2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.1-4ubuntu2"}]},"type":"USN","cves_ids":["CVE-2010-0832"]}]},{"id":"CVE-2010-2652","published":"2010-07-06T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 5.0.375.99 does not properly implement modal dialogs,\nwhich allows attackers to cause a denial of service (application crash) via\nunspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2010/07/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2010-2652"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=47056"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.472.53~r57914-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.375.99","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2650","published":"2010-07-06T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Google Chrome before 5.0.375.99 has unknown\nimpact and attack vectors, related to an \"annoyance with print dialogs.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2010/07/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2010-2650"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=46575"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"upstream","status":"released","description":"5.0.375.99","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.472.53~r57914-0ubuntu0.10.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2649","published":"2010-07-06T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Google Chrome before 5.0.375.99 allows remote\nattackers to cause a denial of service (application crash) via an invalid\nimage.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2010/07/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2010-2649"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=45164"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.472.53~r57914-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.375.99","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2648","published":"2010-07-06T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe implementation of the Unicode Bidirectional Algorithm (aka Bidi\nalgorithm or UBA) in Google Chrome before 5.0.375.99 allows remote\nattackers to cause a denial of service (memory corruption) or possibly have\nunspecified other impact via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2010/07/stable-channel-update.html","https://ubuntu.com/security/notices/USN-1006-1","https://www.cve.org/CVERecord?id=CVE-2010-2648"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=44424","https://bugs.webkit.org/show_bug.cgi?id=39305"],"patches":{"chromium-browser":[],"webkit":["upstream: http://trac.webkit.org/projects/webkit/changeset/61921"]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.472.53~r57914-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"5.0.375.99~r51029-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"5.0.375.99~r51029-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.375.99","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.5-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.2.0-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.2.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.2.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2647","published":"2010-07-06T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 5.0.375.99 allows remote attackers to cause a denial\nof service (memory corruption) or possibly have unspecified other impact\nvia an invalid SVG document.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2010/07/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2010-2647"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=43488"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.472.53~r57914-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.375.99","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2645","published":"2010-07-06T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Google Chrome before 5.0.375.99, when WebGL is\nused, allows remote attackers to cause a denial of service (out-of-bounds\nread) via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2010/07/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2010-2645"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=42396"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.472.53~r57914-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.375.99","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2631","published":"2010-07-06T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nLibTIFF 3.9.0 ignores tags in certain situations during the first stage of\nTIFF file processing and does not properly handle this during the second\nstage, which allows remote attackers to cause a denial of service\n(application crash) via a crafted file, a different vulnerability than\nCVE-2010-2481.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"same patch as CVE-2010-2481"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2631"],"bugs":["http://bugzilla.maptools.org/show_bug.cgi?id=2210"],"patches":{"tiff":[]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"dapper","status":"released","description":"3.7.4-1ubuntu3.8","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.8.2-7ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.8.2-13ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.9.2-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.9.4-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.9.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2481","published":"2010-07-06T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe TIFFExtractData macro in LibTIFF before 3.9.4 does not properly handle\nunknown tag types in TIFF directory entries, which allows remote attackers\nto cause a denial of service (out-of-bounds read and application crash) via\na crafted TIFF file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"see CVE-2010-2630 for second commit to fix regression\nin lucid, this is the fix-unknown-tags.patch patch"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2481"],"bugs":["http://bugzilla.maptools.org/show_bug.cgi?id=2210","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2481"],"patches":{"tiff":["upstream: r1.92.2.9"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"dapper","status":"released","description":"3.7.4-1ubuntu3.8","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.8.2-7ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.8.2-13ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.9.2-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.9.4-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.9.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2479","published":"2010-07-06T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in HTML Purifier before 4.1.1, as\nused in Mahara and other products, when the browser is Internet Explorer,\nallows remote attackers to inject arbitrary web script or HTML via\nunspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://htmlpurifier.org/news/2010/0531-4.1.1-released","http://wiki.mahara.org/Release_Notes/1.2.5","http://wiki.mahara.org/Release_Notes/1.1.9","http://wiki.mahara.org/Release_Notes/1.0.15","https://www.cve.org/CVERecord?id=CVE-2010-2479"],"bugs":[""],"patches":{"mahara":["upstream: http://repo.or.cz/w/htmlpurifier.git/commitdiff/18e538317a877a0509ae71a860429c41770da230","debdiff: https://bugs.launchpad.net/ubuntu/+source/mahara/+bug/602772"],"php-htmlpurifier":["upstream: http://repo.or.cz/w/htmlpurifier.git/commitdiff/18e538317a877a0509ae71a860429c41770da230"]},"tags":{},"packages":[{"name":"mahara","source":"https://ubuntu.com/security/cve?package=mahara","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mahara","debian":"https://tracker.debian.org/pkg/mahara","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.0.9-2ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.1.5-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.4-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.2.5-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.15,1.1.9,1.2.5","component":null,"pocket":"security"}]},{"name":"php-htmlpurifier","source":"https://ubuntu.com/security/cve?package=php-htmlpurifier","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-htmlpurifier","debian":"https://tracker.debian.org/pkg/php-htmlpurifier","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.3.0-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"4.0.0+dfsg1-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"4.1.1+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.1.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1670","published":"2010-07-06T17:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 has\nimproper configuration options for authentication plugins associated with\nlogins that use the single sign-on (SSO) functionality, which allows remote\nattackers to bypass authentication via an empty password. NOTE: some of\nthese details are obtained from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://wiki.mahara.org/Release_Notes/1.0.15","http://wiki.mahara.org/Release_Notes/1.1.9","http://wiki.mahara.org/Release_Notes/1.2.5","https://www.cve.org/CVERecord?id=CVE-2010-1670"],"bugs":[""],"patches":{"mahara":["debdiff: https://bugs.launchpad.net/ubuntu/+source/mahara/+bug/602772"]},"tags":{},"packages":[{"name":"mahara","source":"https://ubuntu.com/security/cve?package=mahara","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mahara","debian":"https://tracker.debian.org/pkg/mahara","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.0.9-2ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.1.5-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.4-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.15,1.1.9,1.2.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":72600,"limit":20,"total_results":79316}