{"cves":[{"id":"CVE-2009-1241","published":"2009-04-03T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in ClamAV before 0.95 allows remote attackers to\nbypass detection of malware via a modified RAR archive.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"this is because Ubuntu and Debian use an external unrar. Upstream\nsays support for external unrar will be removed in a future release"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-1241"],"bugs":["https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1050","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=484642"],"patches":{"clamav":[]},"tags":{},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.95.3+dfsg-1ubuntu0.09.04~hardy2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"0.95+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"0.95+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"0.95+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.95+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-6603","published":"2009-04-03T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when\nacl_hierarchic is set to True, which might allow remote attackers to bypass\nintended access restrictions, a different vulnerability than CVE-2008-1937.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://moinmo.in/SecurityFixes","https://www.cve.org/CVERecord?id=CVE-2008-6603"],"bugs":["http://moinmo.in/MoinMoinBugs/AclHierarchicPageAclSupercededByAclRightsAfter"],"patches":{"moin":[]},"tags":{},"packages":[{"name":"moin","source":"https://ubuntu.com/security/cve?package=moin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=moin","debian":"https://tracker.debian.org/pkg/moin","statuses":[{"release_codename":"dapper","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"already fixed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"already fixed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-6594","published":"2009-04-03T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSQL injection vulnerability in the cm_rdfexport extension for TYPO3 allows\nremote attackers to execute arbitrary SQL commands via unspecified vectors.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"we don't ship this extension"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-6594"],"bugs":[""],"patches":{"typo3-src":[]},"tags":{},"packages":[{"name":"typo3-src","source":"https://ubuntu.com/security/cve?package=typo3-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=typo3-src","debian":"https://tracker.debian.org/pkg/typo3-src","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-6587","published":"2009-04-03T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in index.tmpl in Vuze\n(formerly Azureus HTML WebUI), probably 0.7.6, allows remote attackers to\nhijack the authentication of users for requests that force the download of\narbitrary torrent files via the upurl parameter.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"we don't ship the WebUI plugin"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-6587"],"bugs":[""],"patches":{"azureus":[]},"tags":{},"packages":[{"name":"azureus","source":"https://ubuntu.com/security/cve?package=azureus","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=azureus","debian":"https://tracker.debian.org/pkg/azureus","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-6585","published":"2009-04-03T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in html/admin.php in\nTorrentFlux 2.3 allows remote attackers to hijack the authentication of\nadministrators for requests that add new accounts via the addUser action.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Debian packaging has a different directory layout rendering\nit not-affected."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-6585"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=531614"],"patches":{"torrentflux":[]},"tags":{},"packages":[{"name":"torrentflux","source":"https://ubuntu.com/security/cve?package=torrentflux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=torrentflux","debian":"https://tracker.debian.org/pkg/torrentflux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-6584","published":"2009-04-03T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nhtml/index.php in TorrentFlux 2.3 allows remote authenticated users to\nexecute arbitrary code via a URL with a file containing an executable\nextension in the url_upload parameter, which is downloaded by TorrentFlux\nand can be accessed via a direct request in a html/downloads/ user\ndirectory.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Debian packaging has a different directory layout rendering\nit not-affected."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-6584"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=531614"],"patches":{"torrentflux":[]},"tags":{},"packages":[{"name":"torrentflux","source":"https://ubuntu.com/security/cve?package=torrentflux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=torrentflux","debian":"https://tracker.debian.org/pkg/torrentflux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-1234","published":"2009-04-02T17:30:00","updated_at":"2025-07-17T16:42:26.795874+00:00","description":"\nOpera 9.64 allows remote attackers to cause a denial of service\n(application crash) via an XML document containing a long series of\nstart-tags with no corresponding end-tags.  NOTE: it was later reported\nthat 9.52 is also affected.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-1234"],"bugs":[""],"patches":{"opera":[]},"tags":{},"packages":[{"name":"opera","source":"https://ubuntu.com/security/cve?package=opera","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=opera","debian":"https://tracker.debian.org/pkg/opera","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-1232","published":"2009-04-02T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to\ncause a denial of service (memory corruption) via an XML document composed\nof a long series of start-tags with no corresponding end-tags. NOTE: it was\nlater reported that 3.0.10 and earlier are also affected.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"CVEs in Firefox are tracked in the xulrunner source packages. The\nmapping of xulrunner sources to firefox is:\nxulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS\nxulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS\nxulrunner-1.9: firefox-3.0\nxulrunner-1.9.1: firefox-3.5\nUbuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not\nthe system xulrunner-1.9.2, so it is tracked in the firefox source package."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-1232"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=485941"],"patches":{"firefox":[],"xulrunner":[],"xulrunner-1.9":[],"xulrunner-1.9.1":[],"xulrunner-1.9.2":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-1215","published":"2009-04-01T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nRace condition in GNU screen 4.0.3 allows local users to create or\noverwrite arbitrary files via a symlink attack on the /tmp/screen-exchange\ntemporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-1215"],"bugs":["https://bugs.edge.launchpad.net/ubuntu/+source/screen/+bug/315993"],"patches":{"screen":[]},"tags":{},"packages":[{"name":"screen","source":"https://ubuntu.com/security/cve?package=screen","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=screen","debian":"https://tracker.debian.org/pkg/screen","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.3-13","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-1214","published":"2009-04-01T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with\nworld-readable permissions, which might allow local users to obtain\nsensitive session information.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-1214"],"bugs":["https://bugs.edge.launchpad.net/ubuntu/+source/screen/+bug/315993"],"patches":{"screen":[]},"tags":{},"packages":[{"name":"screen","source":"https://ubuntu.com/security/cve?package=screen","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=screen","debian":"https://tracker.debian.org/pkg/screen","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.3-13","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-1213","published":"2009-04-01T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in attachment.cgi in\nBugzilla 3.2 before 3.2.3, 3.3 before 3.3.4, and earlier versions allows\nremote attackers to hijack the authentication of arbitrary users for\nrequests that use attachment editing.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-1213"],"bugs":[""],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.4.0-3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-1210","published":"2009-04-01T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nFormat string vulnerability in the PROFINET/DCP (PN-DCP) dissector in\nWireshark 1.0.6 and earlier allows remote attackers to execute arbitrary\ncode via a PN-DCP packet with format string specifiers in the station name.\n NOTE: some of these details are obtained from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-1210"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.2.7-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.2.7-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.2.7-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.7-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.7","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-1209","published":"2009-04-01T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote\nattackers to execute arbitrary code via a script tag with a long defer\nattribute.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-1209"],"bugs":[""],"patches":{"amaya":[]},"tags":{},"packages":[{"name":"amaya","source":"https://ubuntu.com/security/cve?package=amaya","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=amaya","debian":"https://tracker.debian.org/pkg/amaya","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-1208","published":"2009-04-01T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSQL injection vulnerability in auth2db 0.2.5, and possibly other versions\nbefore 0.2.7, uses the addslashes function instead of the\nmysql_real_escape_string function, which allows remote attackers to conduct\nSQL injection attacks using multibyte character encodings.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-1208"],"bugs":[""],"patches":{"auth2db":[]},"tags":{},"packages":[{"name":"auth2db","source":"https://ubuntu.com/security/cve?package=auth2db","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=auth2db","debian":"https://tracker.debian.org/pkg/auth2db","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"0.2.5-2+dfsg-1.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.2.5-2+dfsg-1.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0790","published":"2009-04-01T10:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.21 and\n2.4 before 2.4.14, and Strongswan 4.2 before 4.2.14 and 2.8 before 2.8.9,\nallows remote attackers to cause a denial of service (daemon crash and\nrestart) via a crafted (1) R_U_THERE or (2) R_U_THERE_ACK Dead Peer\nDetection (DPD) IPsec IKE Notification message that triggers a NULL pointer\ndereference related to inconsistent ISAKMP state and the lack of a phase2\nstate association in DPD.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0790"],"bugs":[""],"patches":{"strongswan":[],"openswan":[]},"tags":{},"packages":[{"name":"openswan","source":"https://ubuntu.com/security/cve?package=openswan","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openswan","debian":"https://tracker.debian.org/pkg/openswan","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1:2.4.9+dfsg-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1:2.6.22+dfsg-1.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:2.6.21+dfsg-1","component":null,"pocket":"security"}]},{"name":"strongswan","source":"https://ubuntu.com/security/cve?package=strongswan","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=strongswan","debian":"https://tracker.debian.org/pkg/strongswan","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"4.3.2-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.2.14-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-1204","published":"2009-04-01T01:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware\n2.2 allows remote attackers to inject arbitrary web script or HTML via the\nPHP_SELF portion of a URI to (1) tiki-galleries.php, (2)\ntiki-list_file_gallery.php, (3) tiki-listpages.php, and (4)\ntiki-orphan_pages.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-1204"],"bugs":[""],"patches":{"tikiwiki":[]},"tags":{},"packages":[{"name":"tikiwiki","source":"https://ubuntu.com/security/cve?package=tikiwiki","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tikiwiki","debian":"https://tracker.debian.org/pkg/tikiwiki","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-1177","published":"2009-03-31T18:24:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple stack-based buffer overflows in maptemplate.c in mapserv in\nMapServer 4.x before 4.10.4 and 5.x before 5.2.2 have unknown impact and\nremote attack vectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"this looks to be a dupe of CVE-2009-0839. See ticket #2944"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://trac.osgeo.org/mapserver/ticket/2944","https://www.cve.org/CVERecord?id=CVE-2009-1177"],"bugs":[""],"patches":{"mapserver":[]},"tags":{},"packages":[{"name":"mapserver","source":"https://ubuntu.com/security/cve?package=mapserver","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mapserver","debian":"https://tracker.debian.org/pkg/mapserver","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.0.0-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"5.0.3-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"5.0.3-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"5.4.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-1176","published":"2009-03-31T18:24:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2\ndoes not ensure that the string holding the id parameter ends in a '\\0'\ncharacter, which allows remote attackers to conduct buffer-overflow attacks\nor have unspecified other impact via a long id parameter in a query action.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-1176"],"bugs":[""],"patches":{"mapserver":[]},"tags":{},"packages":[{"name":"mapserver","source":"https://ubuntu.com/security/cve?package=mapserver","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mapserver","debian":"https://tracker.debian.org/pkg/mapserver","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.0.0-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"5.0.3-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"5.0.3-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"5.4.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-1073","published":"2009-03-31T18:24:00","updated_at":"2025-08-25T19:45:33.482148+00:00","description":"\nnss-ldapd before 0.6.8 uses world-readable permissions for the\n/etc/nss-ldapd.conf file, which allows local users to obtain a cleartext\npassword for the LDAP server by reading the bindpw field.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-1073"],"bugs":[""],"patches":{"nss-ldapd":[]},"tags":{},"packages":[{"name":"nss-ldapd","source":"https://ubuntu.com/security/cve?package=nss-ldapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nss-ldapd","debian":"https://tracker.debian.org/pkg/nss-ldapd","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"0.6.9","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.6.8","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0843","published":"2009-03-31T18:24:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe msLoadQuery function in mapserv in MapServer 4.x before 4.10.4 and 5.x\nbefore 5.2.2 allows remote attackers to determine the existence of\narbitrary files via a full pathname in the queryfile parameter, which\ntriggers different error messages depending on whether this pathname\nexists.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"this can only probe for files that are not present, useless when not\nin combination with another attack"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0843"],"bugs":[""],"patches":{"mapserver":[]},"tags":{},"packages":[{"name":"mapserver","source":"https://ubuntu.com/security/cve?package=mapserver","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mapserver","debian":"https://tracker.debian.org/pkg/mapserver","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.0.0-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"5.0.3-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"5.0.3-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"5.4.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":74220,"limit":20,"total_results":79316}