{"cves":[{"id":"CVE-2010-1166","published":"2010-04-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe fbComposite function in fbpict.c in the Render extension in the X\nserver in X.Org X11R7.1 allows remote authenticated users to cause a denial\nof service (memory corruption and daemon crash) or possibly execute\narbitrary code via a crafted request, related to an incorrect macro\ndefinition.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-939-1","https://www.cve.org/CVERecord?id=CVE-2010-1166"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/xorg-server/+bug/551193"],"patches":{"xorg-server":["vendor: http://launchpadlibrarian.net/47954537/112_xaa-fbcomposite-fix-negative-size.patch"]},"tags":{},"packages":[{"name":"xorg-server","source":"https://ubuntu.com/security/cve?package=xorg-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server","debian":"https://tracker.debian.org/pkg/xorg-server","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2:1.4.1~git20080131-1ubuntu9.3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2:1.6.0-0ubuntu14.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2:1.6.4-2ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-939-1"],"notices":[{"id":"USN-939-1","title":"X.org vulnerabilities","summary":"A remote attacker could trigger a crash in X.org. In addition, the\nxvfb-run tool left the session cookie visible when launching X.org.\n","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2010-05-18T21:29:47.722120","description":"Loïc Minier discovered that xvfb-run did not correctly keep the\nX.org session cookie private. A local attacker could gain access\nto any local sessions started by xvfb-run. Ubuntu 9.10 was not\naffected. (CVE-2009-1573)\n\nIt was discovered that the X.org server did not correctly handle\ncertain calculations. A remote attacker could exploit this to\ncrash the X.org session or possibly run arbitrary code with root\nprivileges. (CVE-2010-1166)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"xorg-server","version":"2:1.4.1~git20080131-1ubuntu9.3","description":"The core X.org windowing server","is_source":true},{"name":"xserver-xorg-core","version":"2:1.4.1~git20080131-1ubuntu9.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.4.1~git20080131-1ubuntu9.3"},{"name":"xvfb","version":"2:1.4.1~git20080131-1ubuntu9.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.4.1~git20080131-1ubuntu9.3"}],"jaunty":[{"name":"xorg-server","version":"2:1.6.0-0ubuntu14.2","description":"The core X.org windowing server","is_source":true},{"name":"xserver-xorg-core","version":"2:1.6.0-0ubuntu14.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.6.0-0ubuntu14.2"},{"name":"xvfb","version":"2:1.6.0-0ubuntu14.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.6.0-0ubuntu14.2"}],"karmic":[{"name":"xorg-server","version":"2:1.6.4-2ubuntu4.3","description":"The core X.org windowing server","is_source":true},{"name":"xserver-xorg-core","version":"2:1.6.4-2ubuntu4.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.6.4-2ubuntu4.3"}]},"type":"USN","cves_ids":["CVE-2009-1573","CVE-2010-1166"]}]},{"id":"CVE-2010-1585","published":"2010-04-28T00:00:00","updated_at":"2025-05-26T12:47:11.882847+00:00","description":"\nThe nsIScriptableUnescapeHTML.parseFragment method in the\nParanoidFragmentSink protection mechanism in Mozilla Firefox before 3.5.17\nand 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before\n2.0.12 does not properly sanitize HTML in a chrome document, which makes it\neasier for remote attackers to execute arbitrary JavaScript with chrome\nprivileges via a javascript: URI in input to an extension, as demonstrated\nby a javascript:alert sequence in (1) the HREF attribute of an A element or\n(2) the ACTION attribute of a FORM element.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"CVEs in Firefox are tracked in the xulrunner source packages. The\nmapping of xulrunner sources to firefox is:\nxulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS\nxulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS\nxulrunner-1.9: firefox-3.0\nxulrunner-1.9.1: firefox-3.5\nUbuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not\nthe system xulrunner-1.9.2, so it is tracked in the firefox source package."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1049-1","https://ubuntu.com/security/notices/USN-1050-1","https://www.cve.org/CVERecord?id=CVE-2010-1585","https://ubuntu.com/security/notices/USN-1123-1"],"bugs":[""],"patches":{"firefox":[],"firefox-3.0":[],"firefox-3.5":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.6.14+build3+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.6.14+build3+nobinonly-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"4.0~b12+build1+nobinonly-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"4.0~b12+build1+nobinonly-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"4.0~b12+build1+nobinonly-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"4.0~b12+build1+nobinonly-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"4.0~b12+build1+nobinonly-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"4.0~b12+build1+nobinonly-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.6.14","component":null,"pocket":"security"}]},{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.6.14+build3+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"Ubuntu source uses 3.6.x","component":null,"pocket":"security"}]},{"name":"firefox-3.5","source":"https://ubuntu.com/security/cve?package=firefox-3.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-3.5","debian":"https://tracker.debian.org/pkg/firefox-3.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.6.14+build3+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"Ubuntu source uses 3.6.x","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.0.13+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.0.13+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.12","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.1.8+build3+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.1.8+build3+nobinonly-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.1.9+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.1.9+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.1.9+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.1.9+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"3.1.9+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"3.1.9+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1.8","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.2.14+build3+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.2.14+build3+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.9.2.14+build3+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.9.2.14+build3+nobinonly-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.9.2.14+build3+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.2.14","component":null,"pocket":"security"}]}],"notices_ids":["USN-1049-1","USN-1123-1","USN-1050-1"],"notices":[{"id":"USN-1049-1","title":"Firefox and Xulrunner vulnerabilities","summary":"Multiple browser flaws\n","instructions":"After a standard system update you need to restart Firefox and any\napplications which use Xulrunner to make all the necessary changes.\n","references":[],"published":"2011-03-03T01:20:16.388618","description":"Jesse Ruderman, Igor Bukanov, Olli Pettay, Gary Kwong, Jeff Walden, Henry\nSivonen, Martijn Wargers, David Baron and Marcia Knous discovered several\nmemory issues in the browser engine. An attacker could exploit these to\ncrash the browser or possibly run arbitrary code as the user invoking the\nprogram. (CVE-2011-0053, CVE-2011-0062)\n\nZach Hoffman discovered that a recursive call to eval() wrapped in a\ntry/catch statement places the browser into a inconsistent state. An\nattacker could exploit this to force a user to accept any dialog.\n(CVE-2011-0051)\n\nIt was discovered that memory was used after being freed in a method used\nby JSON.stringify. An attacker could exploit this to crash the browser or\npossibly run arbitrary code as the user invoking the program.\n(CVE-2011-0055)\n\nChristian Holler discovered multiple buffer overflows in the JavaScript\nengine. An attacker could exploit these to crash the browser or possibly\nrun arbitrary code as the user invoking the program. (CVE-2011-0054,\nCVE-2011-0056)\n\nDaniel Kozlowski discovered that a JavaScript Worker kept a reference to\nmemory after it was freed. An attacker could exploit this to crash the\nbrowser or possibly run arbitrary code as the user invoking the program.\n(CVE-2011-0057)\n\nAlex Miller discovered a buffer overflow in the browser rendering engine.\nAn attacker could exploit this to crash the browser or possibly run\narbitrary code as the user invoking the program. (CVE-2011-0058)\n\nRoberto Suggi Liverani discovered a possible issue with unsafe JavaScript\nexecution in chrome documents. A malicious extension could exploit this to\nexecute arbitrary code with chrome privlieges. (CVE-2010-1585)\n\nJordi Chancel discovered a buffer overlow in the JPEG decoding engine. An\nattacker could exploit this to crash the browser or possibly run arbitrary\ncode as the user invoking the program. (CVE-2011-0061)\n\nPeleus Uhley discovered a CSRF vulnerability in the plugin code related to\n307 redirects. This could allow custom headers to be forwarded across\norigins. (CVE-2011-0059)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.6.14+build3+nobinonly-0ubuntu0.8.04.1","description":"placeholder upgrade package for firefox-3.0 -> firefox","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.14+build3+nobinonly-0ubuntu0.8.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"firefox","version":"3.6.14+build3+nobinonly-0ubuntu0.8.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.14+build3+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.14+build3+nobinonly-0ubuntu0.8.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.14+build3+nobinonly-0ubuntu0.8.04.1"}],"karmic":[{"name":"firefox-3.5","version":"3.6.14+build3+nobinonly-0ubuntu0.9.10.1","description":"placeholder upgrade package for firefox-3.5 -> firefox","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.14+build3+nobinonly-0ubuntu0.9.10.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"firefox","version":"3.6.14+build3+nobinonly-0ubuntu0.9.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.6.14+build3+nobinonly-0ubuntu0.9.10.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.14+build3+nobinonly-0ubuntu0.9.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.14+build3+nobinonly-0ubuntu0.9.10.1"}],"lucid":[{"name":"firefox","version":"3.6.14+build3+nobinonly-0ubuntu0.10.04.1","description":"safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.14+build3+nobinonly-0ubuntu0.10.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"firefox","version":"3.6.14+build3+nobinonly-0ubuntu0.10.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.14+build3+nobinonly-0ubuntu0.10.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.14+build3+nobinonly-0ubuntu0.10.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.14+build3+nobinonly-0ubuntu0.10.04.1"}],"maverick":[{"name":"firefox","version":"3.6.14+build3+nobinonly-0ubuntu0.10.10.1","description":"safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.14+build3+nobinonly-0ubuntu0.10.10.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"firefox","version":"3.6.14+build3+nobinonly-0ubuntu0.10.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.14+build3+nobinonly-0ubuntu0.10.10.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.14+build3+nobinonly-0ubuntu0.10.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.14+build3+nobinonly-0ubuntu0.10.10.1"}]},"type":"USN","cves_ids":["CVE-2011-0053","CVE-2011-0062","CVE-2011-0051","CVE-2011-0055","CVE-2011-0054","CVE-2011-0056","CVE-2011-0057","CVE-2011-0058","CVE-2010-1585","CVE-2011-0061","CVE-2011-0059"]},{"id":"USN-1123-1","title":"Xulrunner vulnerabilities","summary":"Multiple xulrunner-1.9.1 vulnerabilities\n","instructions":"After a standard system update you need to restart any applications which\nuse Xulrunner to make all the necessary changes.\n","references":[],"published":"2011-04-30T00:18:45.936131","description":"A large number of security issues were discovered in the Gecko rendering\nengine. If a user were tricked into viewing a malicious website, a remote\nattacker could exploit a variety of issues related to web browser security,\nincluding cross-site scripting attacks, denial of service attacks, and\narbitrary code execution.\n","is_hidden":false,"release_packages":{"karmic":[{"name":"xulrunner-1.9.1","version":"1.9.1.19+build2+nobinonly-0ubuntu0.9.10.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"xulrunner-1.9.1","version":"1.9.1.19+build2+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1/1.9.1.19+build2+nobinonly-0ubuntu0.9.10.1"}]},"type":"USN","cves_ids":["CVE-2011-0077","CVE-2011-0065","CVE-2011-0066","CVE-2010-3776","CVE-2010-3778","CVE-2011-0067","CVE-2011-0073","CVE-2011-0074","CVE-2011-0071","CVE-2011-0080","CVE-2011-0078","CVE-2011-0075","CVE-2011-0072","CVE-2011-0070","CVE-2011-0069","CVE-2011-0053","CVE-2011-0062","CVE-2011-0051","CVE-2011-0055","CVE-2011-0054","CVE-2011-0056","CVE-2011-0057","CVE-2011-0058","CVE-2010-1585","CVE-2011-0059","CVE-2011-1202"]},{"id":"USN-1050-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird could be made to crash or run programs as your login if it\nopened specially crafted mail.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":[],"published":"2011-03-03T03:54:51.966342","description":"Jesse Ruderman, Igor Bukanov, Olli Pettay, Gary Kwong, Jeff Walden, Henry\nSivonen, Martijn Wargers, David Baron and Marcia Knous discovered several\nmemory issues in the browser engine. An attacker could exploit these to\ncrash the browser or possibly run arbitrary code as the user invoking the\nprogram. (CVE-2011-0053, CVE-2011-0062)\n\nRoberto Suggi Liverani discovered a possible issue with unsafe JavaScript\nexecution in chrome documents. A malicious extension could exploit this to\nexecute arbitrary code with chrome privlieges. (CVE-2010-1585)\n\nJordi Chancel discovered a buffer overlow in the JPEG decoding engine. An\nattacker could exploit this to crash the browser or possibly run arbitrary\ncode as the user invoking the program. (CVE-2011-0061)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"thunderbird","version":"3.1.8+build3+nobinonly-0ubuntu0.10.04.1","description":"mail/news client with RSS and integrated spam filter support","is_source":true},{"name":"thunderbird","version":"3.1.8+build3+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/3.1.8+build3+nobinonly-0ubuntu0.10.04.1"}],"maverick":[{"name":"thunderbird","version":"3.1.8+build3+nobinonly-0ubuntu0.10.10.1","description":"mail/news client with RSS and integrated spam filter support","is_source":true},{"name":"thunderbird","version":"3.1.8+build3+nobinonly-0ubuntu0.10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/3.1.8+build3+nobinonly-0ubuntu0.10.10.1"}]},"type":"USN","cves_ids":["CVE-2011-0061","CVE-2010-1585","CVE-2011-0053","CVE-2011-0062"]}]},{"id":"CVE-2009-4824","published":"2010-04-27T15:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Kolab Webclient before 1.2.0 in Kolab Server\nbefore 2.2.3 allows attackers to have an unspecified impact via vectors\nrelated to an \"image upload form.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4824"],"bugs":[""],"patches":{"kolabd":[]},"tags":{},"packages":[{"name":"kolabd","source":"https://ubuntu.com/security/cve?package=kolabd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kolabd","debian":"https://tracker.debian.org/pkg/kolabd","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1506","published":"2010-04-23T14:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Google V8 bindings in Google Chrome before 4.1.249.1059 allow attackers\nto cause a denial of service (memory corruption) via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html","https://www.cve.org/CVERecord?id=CVE-2010-1506"],"bugs":["http://bugs.chromium.org/40635","https://bugs.webkit.org/show_bug.cgi?id=37210"],"patches":{"chromium-browser":["upstream: http://trac.webkit.org/changeset/57224","upstream: http://src.chromium.org/viewvc/chrome?view=rev&revision=43874"]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.0.375.38~r46659-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1505","published":"2010-04-23T14:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 4.1.249.1059 does not prevent pages from loading with\nthe New Tab page's privileges, which has unknown impact and attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html","https://www.cve.org/CVERecord?id=CVE-2010-1505"],"bugs":["http://bugs.chromium.org/40575"],"patches":{"chromium-browser":["upstream: http://src.chromium.org/viewvc/chrome?view=rev&revision=43879","upstream: http://src.chromium.org/viewvc/chrome?view=rev&revision=43962","upstream: http://src.chromium.org/viewvc/chrome?view=rev&revision=44112"]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.0.375.38~r46659-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1504","published":"2010-04-23T14:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Google Chrome before\n4.1.249.1059 allows remote attackers to inject arbitrary web script or HTML\nvia vectors related to a chrome://downloads URI.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html","https://www.cve.org/CVERecord?id=CVE-2010-1504"],"bugs":["http://bugs.chromium.org/40138"],"patches":{"chromium-browser":["upstream: http://src.chromium.org/viewvc/chrome?view=rev&revision=43414"]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.0.375.38~r46659-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1503","published":"2010-04-23T14:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Google Chrome before\n4.1.249.1059 allows remote attackers to inject arbitrary web script or HTML\nvia vectors related to a chrome://net-internals URI.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html","https://www.cve.org/CVERecord?id=CVE-2010-1503"],"bugs":["http://bugs.chromium.org/40137"],"patches":{"chromium-browser":["upstream: http://src.chromium.org/viewvc/chrome?view=rev&revision=43398"]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.0.375.38~r46659-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1502","published":"2010-04-23T14:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Google Chrome before 4.1.249.1059 allows\nremote attackers to access local files via vectors related to \"developer\ntools.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html","https://www.cve.org/CVERecord?id=CVE-2010-1502"],"bugs":["http://bugs.chromium.org/40136"],"patches":{"chromium-browser":["upstream: http://src.chromium.org/viewvc/chrome?view=rev&revision=43560"]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.0.375.38~r46659-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1501","published":"2010-04-23T14:30:00","updated_at":"2025-08-04T19:23:46.919224+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:\nCVE-2010-1767. Reason: This candidate is a duplicate of CVE-2010-1767.\nNotes: All CVE users should reference CVE-2010-1767 instead of this\ncandidate. All references and descriptions in this candidate have been\nremoved to prevent accidental usage","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced in webkit r47291"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html","https://www.cve.org/CVERecord?id=CVE-2010-1501"],"bugs":["https://bugs.webkit.org/show_bug.cgi?id=36843","http://code.google.com/p/chromium/issues/detail?id=39698"],"patches":{"chromium-browser":["upstream: http://trac.webkit.org/changeset/57041","upstream: http://src.chromium.org/viewvc/chrome?view=rev&revision=43595"]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.0.375.38~r46659-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1500","published":"2010-04-23T14:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 4.1.249.1059 does not properly support forms, which\nhas unknown impact and attack vectors, related to a \"type confusion error.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html","https://www.cve.org/CVERecord?id=CVE-2010-1500"],"bugs":["http://bugs.chromium.org/39443"],"patches":{"chromium-browser":["upstream: http://trac.webkit.org/changeset/55346","upstream: http://trac.webkit.org/changeset/56098","upstream: http://src.chromium.org/viewvc/chrome?view=rev&revision=43027","upstream: http://src.chromium.org/viewvc/chrome?view=rev&revision=43028"]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.0.375.38~r46659-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1157","published":"2010-04-23T14:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nApache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow\nremote attackers to discover the server's hostname or IP address by sending\na request for a resource that requires (1) BASIC or (2) DIGEST\nauthentication, and then reading the realm field in the WWW-Authenticate\nheader in the reply.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"upstream patch changes the default realm name. This may have\ntoo great an impact of existing installations to be worthwhile\nbackporting. Ignoring."}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://tomcat.apache.org/security-6.html","http://tomcat.apache.org/security-5.html","https://www.cve.org/CVERecord?id=CVE-2010-1157"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-1157","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=587447"],"patches":{"tomcat5":[],"tomcat5.5":["upstream: http://svn.apache.org/viewvc?view=revision&revision=936541"],"tomcat6":["upstream: http://svn.apache.org/viewvc?view=revision&revision=936540"]},"tags":{},"packages":[{"name":"tomcat5","source":"https://ubuntu.com/security/cve?package=tomcat5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat5","debian":"https://tracker.debian.org/pkg/tomcat5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"tomcat5.5","source":"https://ubuntu.com/security/cve?package=tomcat5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat5.5","debian":"https://tracker.debian.org/pkg/tomcat5.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.30","component":null,"pocket":"security"}]},{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.28","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4810","published":"2010-04-23T14:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Secure Remote Password (SRP) implementation in Samhain before 2.5.4\ndoes not check for a certain zero value where required by the protocol,\nwhich allows remote attackers to bypass authentication via crafted input.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4810"],"bugs":["http://trac.la-samhna.de/samhain/ticket/150"],"patches":{"samhain":["upstream: http://trac.la-samhna.de/samhain/changeset/225"]},"tags":{},"packages":[{"name":"samhain","source":"https://ubuntu.com/security/cve?package=samhain","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samhain","debian":"https://tracker.debian.org/pkg/samhain","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.6.2-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.6.2-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.6.2-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"2.6.2-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"2.6.2-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"2.6.2-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"2.6.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0991","published":"2010-04-22T14:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple heap-based buffer overflows in imlib2 1.4.3 allow\ncontext-dependent attackers to execute arbitrary code via a crafted (1)\nARGB, (2) XPM, or (3) BMP file, related to the IMAGE_DIMENSIONS_OK macro in\nlib/image.h.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"only affects 1.4.3"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://seclists.org/bugtraq/2010/Apr/196","https://www.cve.org/CVERecord?id=CVE-2010-0991"],"bugs":[""],"patches":{"imlib2":[]},"tags":{},"packages":[{"name":"imlib2","source":"https://ubuntu.com/security/cve?package=imlib2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imlib2","debian":"https://tracker.debian.org/pkg/imlib2","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.4.0-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"1.4.0-1.1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.4.2-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.4.2-5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1320","published":"2010-04-22T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDouble free vulnerability in do_tgs_req.c in the Key Distribution Center\n(KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows\nremote authenticated users to cause a denial of service (daemon crash) or\npossibly execute arbitrary code via a request associated with (1) renewal\nor (2) validation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-004.txt","https://ubuntu.com/security/notices/USN-940-1","https://www.cve.org/CVERecord?id=CVE-2010-1320"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=577490"],"patches":{"krb5":[]},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.7dfsg~beta3-1ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-940-1"],"notices":[{"id":"USN-940-1","title":"Kerberos vulnerabilities","summary":"Unauthenticated remote attackers could cause Kerberos servers to crash,\nleading to a denial of service.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-05-19T19:01:05.925867","description":"It was discovered that Kerberos did not correctly free memory in the\nGSSAPI and kdb libraries. If a remote attacker were able to manipulate\nan application using these libraries carefully, the service could\ncrash, leading to a denial of service. (Only Ubuntu 6.06 LTS was\naffected.) (CVE-2007-5902, CVE-2007-5971, CVE-2007-5972)\n\nJoel Johnson, Brian Almeida, and Shawn Emery discovered that Kerberos\ndid not correctly verify certain packet structures. An unauthenticated\nremote attacker could send specially crafted traffic to cause the KDC or\nkadmind services to crash, leading to a denial of service. (CVE-2010-1320,\nCVE-2010-1321)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"krb5","version":"1.6.dfsg.3~beta1-2ubuntu1.5","description":"MIT Kerberos authentication services","is_source":true},{"name":"krb5-admin-server","version":"1.6.dfsg.3~beta1-2ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.6.dfsg.3~beta1-2ubuntu1.5"},{"name":"krb5-kdc","version":"1.6.dfsg.3~beta1-2ubuntu1.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.6.dfsg.3~beta1-2ubuntu1.5"}],"dapper":[{"name":"krb5","version":"1.4.3-5ubuntu0.11","description":"MIT Kerberos authentication services","is_source":true},{"name":"libkrb53","version":"1.4.3-5ubuntu0.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.4.3-5ubuntu0.11"},{"name":"krb5-kdc","version":"1.4.3-5ubuntu0.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.4.3-5ubuntu0.11"}],"jaunty":[{"name":"krb5","version":"1.6.dfsg.4~beta1-5ubuntu2.4","description":"MIT Kerberos authentication services","is_source":true},{"name":"krb5-admin-server","version":"1.6.dfsg.4~beta1-5ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.6.dfsg.4~beta1-5ubuntu2.4"},{"name":"krb5-kdc","version":"1.6.dfsg.4~beta1-5ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.6.dfsg.4~beta1-5ubuntu2.4"}],"karmic":[{"name":"krb5","version":"1.7dfsg~beta3-1ubuntu0.6","description":"MIT Kerberos authentication services","is_source":true},{"name":"krb5-admin-server","version":"1.7dfsg~beta3-1ubuntu0.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.7dfsg~beta3-1ubuntu0.6"},{"name":"krb5-kdc","version":"1.7dfsg~beta3-1ubuntu0.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.7dfsg~beta3-1ubuntu0.6"}]},"type":"USN","cves_ids":["CVE-2007-5971","CVE-2010-1320","CVE-2007-5902","CVE-2007-5972","CVE-2010-1321"]}]},{"id":"CVE-2010-1153","published":"2010-04-20T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPHP remote file inclusion vulnerability in the autoloader in TYPO3 4.3.x\nbefore 4.3.3 allows remote attackers to execute arbitrary PHP code via a\nURL in an input field associated with the className variable.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-008/","https://www.cve.org/CVERecord?id=CVE-2010-1153"],"bugs":[""],"patches":{"typo3-src":[]},"tags":{},"packages":[{"name":"typo3-src","source":"https://ubuntu.com/security/cve?package=typo3-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=typo3-src","debian":"https://tracker.debian.org/pkg/typo3-src","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"4.3.3-2","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"4.3.3-2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"4.3.3-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"4.3.3-2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"4.3.3-2","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"4.3.3-2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"4.3.3-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.3.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0887","published":"2010-04-20T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the New Java Plug-in component in Oracle Java\nSE and Java for Business JDK and JRE 6 Update 18 and 19 allows remote\nattackers to affect confidentiality, integrity, and availability via\nunknown vectors.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"probably doesn't apply to plugin in openjdk"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0887"],"bugs":[""],"patches":{"sun-java6":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.20dlj-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.20dlj-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6.20dlj-0ubuntu1.9.10","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6.20dlj-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.20","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0886","published":"2010-04-20T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Deployment Toolkit component in\nOracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19\nallows remote attackers to affect confidentiality, integrity, and\navailability via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0886"],"bugs":[""],"patches":{"sun-java6":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6.20dlj-0ubuntu1.8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"6.20dlj-0ubuntu1.9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"6.20dlj-0ubuntu1.9.10","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6.20dlj-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.20","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1151","published":"2010-04-20T16:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nRace condition in the mod_auth_shadow module for the Apache HTTP Server\nallows remote attackers to bypass authentication, and read and possibly\nmodify data, via vectors related to improper interaction with an external\nhelper application for validation of credentials.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.vupen.com/english/advisories/2010/0908","https://www.cve.org/CVERecord?id=CVE-2010-1151"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=578168"],"patches":{"libapache2-mod-auth-shadow":[]},"tags":{},"packages":[{"name":"libapache2-mod-auth-shadow","source":"https://ubuntu.com/security/cve?package=libapache2-mod-auth-shadow","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libapache2-mod-auth-shadow","debian":"https://tracker.debian.org/pkg/libapache2-mod-auth-shadow","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-7255","published":"2010-04-20T16:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlogin_screen.tcl in aMSN (aka Alvaro's Messenger) before 0.97.1 saves a\npassword after logout, which allows physically proximate attackers to\nhijack a session by visiting an unattended workstation.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-7255"],"bugs":[""],"patches":{"amsn":[]},"tags":{},"packages":[{"name":"amsn","source":"https://ubuntu.com/security/cve?package=amsn","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=amsn","debian":"https://tracker.debian.org/pkg/amsn","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"0.97.2~debian-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"0.97.2~debian-2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"0.98.1~debian-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"0.98.3-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"0.98.3-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"0.98.3-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"0.98.3-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.97.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1158","published":"2010-04-20T15:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the regular expression engine in Perl 5.8.x allows\ncontext-dependent attackers to cause a denial of service (stack consumption\nand application crash) by matching a crafted regular expression against a\nlong string.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"this is a denial of service issue that stems from the re engine\nbeing recursive. The engine was rewritten in 5.10, and the\npatch is intrusive so backporting it may be more trouble than\nit's worth. Marking as ignored for now since this is more a\nlimitation in the engine design than a security issue."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://perldoc.perl.org/perl5100delta.html","https://www.cve.org/CVERecord?id=CVE-2010-1158"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=580605","http://bugs.gentoo.org/show_bug.cgi?id=313565"],"patches":{"perl":["upstream: http://perl5.git.perl.org/perl.git/commitdiff/95b2444054"]},"tags":{},"packages":[{"name":"perl","source":"https://ubuntu.com/security/cve?package=perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=perl","debian":"https://tracker.debian.org/pkg/perl","statuses":[{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"5.10.0-11.1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"5.10.0-19ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"5.10.0-24ubuntu4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"5.10.1-8ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.10.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":72940,"limit":20,"total_results":79316}