{"cves":[{"id":"CVE-2007-4306","published":"2007-08-13T21:17:00","updated_at":"2025-07-17T16:42:01.322060+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.10.3\nallow remote attackers to inject arbitrary web script or HTML via the (1)\nunlim_num_rows, (2) sql_query, or (3) pos parameter to (a) tbl_export.php;\nthe (4) session_max_rows or (5) pos parameter to (b) sql.php; the (6)\nusername parameter to (c) server_privileges.php; or the (7) sql_query\nparameter to (d) main.php. NOTE: vector 5 might be a regression or\nincomplete fix for CVE-2006-6942.7.","ubuntu_description":"","notes":[{"author":"fujitsu","note":"Not exploitable, as knowledge of the session token is required."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4306"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3851","published":"2007-08-13T19:17:00","updated_at":"2025-07-17T16:41:54.036995+00:00","description":"\nThe drm/i915 component in the Linux kernel before 2.6.22.2, when used with\ni965G and later chipsets, allows local users with access to an X11 session\nand Direct Rendering Manager (DRM) to write to arbitrary memory locations\nand gain privileges via a crafted batchbuffer.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-510-1","https://ubuntu.com/security/notices/USN-509-1","https://www.cve.org/CVERecord?id=CVE-2007-3851"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.40","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20-16.31","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-510-1","USN-509-1"],"notices":[{"id":"USN-510-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2007-08-31T17:39:43.796283","description":"A flaw was discovered in the PPP over Ethernet implementation. Local\nattackers could manipulate ioctls and cause kernel memory consumption\nleading to a denial of service. (CVE-2007-2525)\n\nAn integer underflow was discovered in the cpuset filesystem. If mounted,\nlocal attackers could obtain kernel memory using large file offsets while\nreading the tasks file. This could disclose sensitive data. (CVE-2007-2875)\n\nVilmos Nebehaj discovered that the SCTP netfilter code did not correctly\nvalidate certain states. A remote attacker could send a specially crafted\npacket causing a denial of service. (CVE-2007-2876)\n\nLuca Tettamanti discovered a flaw in the VFAT compat ioctls on 64-bit\nsystems. A local attacker could corrupt a kernel_dirent struct and cause\na denial of service. (CVE-2007-2878)\n\nA flaw in the sysfs_readdir function allowed a local user to cause a\ndenial of service by dereferencing a NULL pointer. (CVE-2007-3104)\n\nA buffer overflow was discovered in the random number generator. In\nenvironments with granular assignment of root privileges, a local attacker\ncould gain additional privileges. (CVE-2007-3105)\n\nA flaw was discovered in the usblcd driver. A local attacker could cause\nlarge amounts of kernel memory consumption, leading to a denial of service.\n(CVE-2007-3513)\n\nZhongling Wen discovered that the h323 conntrack handler did not correctly\nhandle certain bitfields. A remote attacker could send a specially crafted\npacket and cause a denial of service. (CVE-2007-3642)\n\nA flaw was discovered in the CIFS mount security checking. Remote attackers\ncould spoof CIFS network traffic, which could lead a client to trust the\nconnection. (CVE-2007-3843)\n\nIt was discovered that certain setuid-root processes did not correctly\nreset process death signal handlers. A local user could manipulate this\nto send signals to processes they would not normally have access to.\n(CVE-2007-3848)\n\nThe Direct Rendering Manager for the i915 driver could be made to write\nto arbitrary memory locations. An attacker with access to a running X11\nsession could send a specially crafted buffer and gain root privileges.\n(CVE-2007-3851)\n\nIt was discovered that the aacraid SCSI driver did not correctly check\npermissions on certain ioctls. A local attacker could cause a denial\nof service or gain privileges. (CVE-2007-4308)\n","is_hidden":false,"release_packages":{"feisty":[{"name":"linux-source-2.6.20","version":"2.6.20-16.31","description":"","is_source":true},{"name":"linux-image-2.6.20-16-386","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-powerpc","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-server","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-mckinley","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-sparc64-smp","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-hppa32","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-powerpc64-smp","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-itanium","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-powerpc-smp","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-generic","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-sparc64","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-hppa64","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-lowlatency","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-server-bigiron","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"}]},"type":"USN","cves_ids":["CVE-2007-2525","CVE-2007-2875","CVE-2007-2876","CVE-2007-2878","CVE-2007-3104","CVE-2007-3105","CVE-2007-3513","CVE-2007-3642","CVE-2007-3843","CVE-2007-3848","CVE-2007-3851","CVE-2007-4308"]},{"id":"USN-509-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2007-08-30T23:55:46.418455","description":"A flaw in the sysfs_readdir function allowed a local user to cause a\ndenial of service by dereferencing a NULL pointer. (CVE-2007-3104)\n\nA buffer overflow was discovered in the random number generator. In\nenvironments with granular assignment of root privileges, a local attacker\ncould gain additional privileges. (CVE-2007-3105)\n\nA flaw was discovered in the usblcd driver. A local attacker could cause\nlarge amounts of kernel memory consumption, leading to a denial of service.\n(CVE-2007-3513)\n\nIt was discovered that certain setuid-root processes did not correctly\nreset process death signal handlers. A local user could manipulate this\nto send signals to processes they would not normally have access to.\n(CVE-2007-3848)\n\nThe Direct Rendering Manager for the i915 driver could be made to write\nto arbitrary memory locations. An attacker with access to a running X11\nsession could send a specially crafted buffer and gain root privileges.\n(CVE-2007-3851)\n\nIt was discovered that the aacraid SCSI driver did not correctly check\npermissions on certain ioctls. A local attacker could cause a denial\nof service or gain privileges. (CVE-2007-4308)\n","is_hidden":false,"release_packages":{"edgy":[{"name":"linux-source-2.6.17","version":"2.6.17.1-12.40","description":"","is_source":true},{"name":"linux-image-2.6.17-12-mckinley","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-powerpc64-smp","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-hppa32","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-hppa64","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-sparc64-smp","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-generic","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-powerpc-smp","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-386","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-server-bigiron","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-itanium","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-powerpc","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-sparc64","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-server","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"}]},"type":"USN","cves_ids":["CVE-2007-3104","CVE-2007-3105","CVE-2007-3513","CVE-2007-3848","CVE-2007-3851","CVE-2007-4308"]}]},{"id":"CVE-2007-4282","published":"2007-08-09T21:17:00","updated_at":"2025-07-17T16:42:01.322060+00:00","description":"\nThe \"Extended properties for entries\" (entryproperties) plugin in\nserendipity_event_entryproperties.php in Serendipity 1.1.3 allows remote\nauthenticated users to bypass password protection and \"deliver custom\nentryproperties settings to the Serendipity Frontend\" via a certain request\nthat modifies the password being checked.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4282"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"serendipity","source":"https://ubuntu.com/security/cve?package=serendipity","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=serendipity","debian":"https://tracker.debian.org/pkg/serendipity","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4280","published":"2007-08-09T21:17:00","updated_at":"2025-07-17T16:42:01.322060+00:00","description":"\nThe Skinny channel driver (chan_skinny) in Asterisk Open Source before\n1.4.10, AsteriskNOW before beta7, Appliance Developer Kit before 0.7.0, and\nAppliance s800i before 1.0.3 allows remote authenticated users to cause a\ndenial of service (application crash) via a CAPABILITIES_RES_MESSAGE packet\nwith a capabilities count larger than the capabilities_res_message array\npopulation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4280"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"asterisk","source":"https://ubuntu.com/security/cve?package=asterisk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=asterisk","debian":"https://tracker.debian.org/pkg/asterisk","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3843","published":"2007-08-09T21:17:00","updated_at":"2025-07-17T16:41:54.036995+00:00","description":"\nThe Linux kernel before 2.6.23-rc1 checks the wrong global variable for the\nCIFS sec mount option, which might allow remote attackers to spoof CIFS\nnetwork traffic that the client configured for security signatures, as\ndemonstrated by lack of signing despite sec=ntlmv2i in a SetupAndX request.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-510-1","https://www.cve.org/CVERecord?id=CVE-2007-3843"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20-16.31","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-510-1"],"notices":[{"id":"USN-510-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2007-08-31T17:39:43.796283","description":"A flaw was discovered in the PPP over Ethernet implementation. Local\nattackers could manipulate ioctls and cause kernel memory consumption\nleading to a denial of service. (CVE-2007-2525)\n\nAn integer underflow was discovered in the cpuset filesystem. If mounted,\nlocal attackers could obtain kernel memory using large file offsets while\nreading the tasks file. This could disclose sensitive data. (CVE-2007-2875)\n\nVilmos Nebehaj discovered that the SCTP netfilter code did not correctly\nvalidate certain states. A remote attacker could send a specially crafted\npacket causing a denial of service. (CVE-2007-2876)\n\nLuca Tettamanti discovered a flaw in the VFAT compat ioctls on 64-bit\nsystems. A local attacker could corrupt a kernel_dirent struct and cause\na denial of service. (CVE-2007-2878)\n\nA flaw in the sysfs_readdir function allowed a local user to cause a\ndenial of service by dereferencing a NULL pointer. (CVE-2007-3104)\n\nA buffer overflow was discovered in the random number generator. In\nenvironments with granular assignment of root privileges, a local attacker\ncould gain additional privileges. (CVE-2007-3105)\n\nA flaw was discovered in the usblcd driver. A local attacker could cause\nlarge amounts of kernel memory consumption, leading to a denial of service.\n(CVE-2007-3513)\n\nZhongling Wen discovered that the h323 conntrack handler did not correctly\nhandle certain bitfields. A remote attacker could send a specially crafted\npacket and cause a denial of service. (CVE-2007-3642)\n\nA flaw was discovered in the CIFS mount security checking. Remote attackers\ncould spoof CIFS network traffic, which could lead a client to trust the\nconnection. (CVE-2007-3843)\n\nIt was discovered that certain setuid-root processes did not correctly\nreset process death signal handlers. A local user could manipulate this\nto send signals to processes they would not normally have access to.\n(CVE-2007-3848)\n\nThe Direct Rendering Manager for the i915 driver could be made to write\nto arbitrary memory locations. An attacker with access to a running X11\nsession could send a specially crafted buffer and gain root privileges.\n(CVE-2007-3851)\n\nIt was discovered that the aacraid SCSI driver did not correctly check\npermissions on certain ioctls. A local attacker could cause a denial\nof service or gain privileges. (CVE-2007-4308)\n","is_hidden":false,"release_packages":{"feisty":[{"name":"linux-source-2.6.20","version":"2.6.20-16.31","description":"","is_source":true},{"name":"linux-image-2.6.20-16-386","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-powerpc","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-server","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-mckinley","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-sparc64-smp","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-hppa32","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-powerpc64-smp","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-itanium","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-powerpc-smp","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-generic","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-sparc64","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-hppa64","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-lowlatency","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-server-bigiron","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"}]},"type":"USN","cves_ids":["CVE-2007-2525","CVE-2007-2875","CVE-2007-2876","CVE-2007-2878","CVE-2007-3104","CVE-2007-3105","CVE-2007-3513","CVE-2007-3642","CVE-2007-3843","CVE-2007-3848","CVE-2007-3851","CVE-2007-4308"]}]},{"id":"CVE-2007-4255","published":"2007-08-08T23:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the mSQL extension in PHP 5.2.3 allows context-dependent\nattackers to execute arbitrary code via a long first argument to the\nmsql_connect function.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"needs malicious script to be effective"},{"author":"kees","note":"mSQL connector is not built in Debian/Ubuntu"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4255"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4251","published":"2007-08-08T23:17:00","updated_at":"2025-07-17T16:42:01.322060+00:00","description":"\nOpenOffice.org (OOo) 2.2 does not properly handle files with multiple\nextensions, which allows user-assisted remote attackers to cause a denial\nof service.","ubuntu_description":"","notes":[{"author":"kees","note":"crasher, not memory corruption"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4251"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"openoffice.org","source":"https://ubuntu.com/security/cve?package=openoffice.org","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openoffice.org","debian":"https://tracker.debian.org/pkg/openoffice.org","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4229","published":"2007-08-08T22:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in KDE Konqueror 3.5.7 and earlier allows remote\nattackers to cause a denial of service (failed assertion and application\ncrash) via certain malformed HTML, as demonstrated by a document containing\nTEXTAREA, BUTTON, BR, BDO, PRE, FRAMESET, and A tags. NOTE: the provenance\nof this information is unknown; the details are obtained solely from third\nparty information.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"as of 2009-08-21, no details on this issue\nand browser DoS is not a security issue, ignoring."}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4229"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kdebase","source":"https://ubuntu.com/security/cve?package=kdebase","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kdebase","debian":"https://tracker.debian.org/pkg/kdebase","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4224","published":"2007-08-08T21:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nKDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar by\ncalling setInterval with a small interval and changing the window.location\nproperty.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-502-1","https://www.cve.org/CVERecord?id=CVE-2007-4224"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kdebase","source":"https://ubuntu.com/security/cve?package=kdebase","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kdebase","debian":"https://tracker.debian.org/pkg/kdebase","statuses":[{"release_codename":"dapper","status":"released","description":"3.5.2-0ubuntu27.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.5.5-0ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.5.6-0ubuntu20.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.5.8","component":null,"pocket":"security"}]}],"notices_ids":["USN-502-1"],"notices":[{"id":"USN-502-1","title":"KDE vulnerabilities","summary":"KDE vulnerabilities","instructions":"After a standard system upgrade you need to restart your session to\neffect the necessary changes.\n","references":[],"published":"2007-08-26T07:24:28.706969","description":"It was discovered that Konqueror could be tricked into displaying\nincorrect URLs. Remote attackers could exploit this to increase their\nchances of tricking a user into visiting a phishing URL, which could\nlead to credential theft.\n","is_hidden":false,"release_packages":{"dapper":[{"name":"kdelibs","version":"4:3.5.2-0ubuntu18.5","description":"","is_source":true},{"name":"kdebase","version":"4:3.5.2-0ubuntu27.1","description":"","is_source":true},{"name":"kdelibs4c2a","version":"4:3.5.2-0ubuntu18.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/kdelibs","version_link":"https://launchpad.net/ubuntu/+source/kdelibs/4:3.5.2-0ubuntu18.5"},{"name":"konqueror","version":"4:3.5.2-0ubuntu27.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/kdebase","version_link":"https://launchpad.net/ubuntu/+source/kdebase/4:3.5.2-0ubuntu27.1"}],"feisty":[{"name":"kdelibs","version":"4:3.5.6-0ubuntu14.1","description":"","is_source":true},{"name":"kdebase","version":"4:3.5.6-0ubuntu20.2","description":"","is_source":true},{"name":"kdelibs4c2a","version":"4:3.5.6-0ubuntu14.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/kdelibs","version_link":"https://launchpad.net/ubuntu/+source/kdelibs/4:3.5.6-0ubuntu14.1"},{"name":"konqueror","version":"4:3.5.6-0ubuntu20.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/kdebase","version_link":"https://launchpad.net/ubuntu/+source/kdebase/4:3.5.6-0ubuntu20.2"}],"edgy":[{"name":"kdelibs","version":"4:3.5.5-0ubuntu3.5","description":"","is_source":true},{"name":"kdebase","version":"4:3.5.5-0ubuntu3.5","description":"","is_source":true},{"name":"kdelibs4c2a","version":"4:3.5.5-0ubuntu3.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/kdelibs","version_link":"https://launchpad.net/ubuntu/+source/kdelibs/4:3.5.5-0ubuntu3.5"},{"name":"konqueror","version":"4:3.5.5-0ubuntu3.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/kdelibs","version_link":"https://launchpad.net/ubuntu/+source/kdelibs/4:3.5.5-0ubuntu3.5"}]},"type":"USN","cves_ids":["CVE-2007-3820","CVE-2007-4224","CVE-2007-4225"]}]},{"id":"CVE-2007-4211","published":"2007-08-08T02:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ACL plugin in Dovecot before 1.0.3 allows remote authenticated users\nwith the insert right to save certain flags via a (1) COPY or (2) APPEND\ncommand.","ubuntu_description":"","notes":[{"author":"kees","note":"this is an extremely special case for an rare configuration."}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4211"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4200","published":"2007-08-08T01:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nntfs.c in fsstat in Brian Carrier The Sleuth Kit (TSK) before 2.09\ninterprets a certain variable as a byte count rather than a count of 32-bit\nintegers, which allows user-assisted remote attackers to cause a denial of\nservice (application crash) and prevent examination of certain NTFS files\nvia a malformed NTFS image.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4200"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sleuthkit","source":"https://ubuntu.com/security/cve?package=sleuthkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sleuthkit","debian":"https://tracker.debian.org/pkg/sleuthkit","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.09","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4199","published":"2007-08-08T01:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBrian Carrier The Sleuth Kit (TSK) before 2.09 allows user-assisted remote\nattackers to cause a denial of service (application crash) and prevent\nexamination of certain NTFS files via a malformed NTFS image that triggers\n(1) dereference of a certain integer value by ntfs_dent.c in fls, or (2)\ndereference of a certain other integer value by ntfs.c in fsstat.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4199"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sleuthkit","source":"https://ubuntu.com/security/cve?package=sleuthkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sleuthkit","debian":"https://tracker.debian.org/pkg/sleuthkit","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.09","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4198","published":"2007-08-08T01:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe fs_data_put_str function in ntfs.c in fls in Brian Carrier The Sleuth\nKit (TSK) before 2.09 does not validate a certain length value, which\nallows user-assisted remote attackers to cause a denial of service\n(application crash) and prevent examination of certain NTFS files via a\nmalformed NTFS image, which triggers a buffer over-read.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4198"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sleuthkit","source":"https://ubuntu.com/security/cve?package=sleuthkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sleuthkit","debian":"https://tracker.debian.org/pkg/sleuthkit","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.09","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4197","published":"2007-08-08T01:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nicat in Brian Carrier The Sleuth Kit (TSK) before 2.09 omits NULL pointer\nchecks in certain code paths, which allows user-assisted remote attackers\nto cause a denial of service (NULL dereference and application crash) and\nprevent examination of certain NTFS files via a malformed NTFS image.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4197"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sleuthkit","source":"https://ubuntu.com/security/cve?package=sleuthkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sleuthkit","debian":"https://tracker.debian.org/pkg/sleuthkit","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.09","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4196","published":"2007-08-08T01:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nicat in Brian Carrier The Sleuth Kit (TSK) before 2.09 misinterprets a\ncertain memory location as the holder of a loop iteration count, which\nallows user-assisted remote attackers to cause a denial of service (long\nloop) and prevent examination of certain NTFS files via a malformed NTFS\nimage.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4196"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sleuthkit","source":"https://ubuntu.com/security/cve?package=sleuthkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sleuthkit","debian":"https://tracker.debian.org/pkg/sleuthkit","statuses":[{"release_codename":"karmic","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.09","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4195","published":"2007-08-08T01:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in ext2fs.c in Brian Carrier The Sleuth Kit\n(TSK) before 2.09 allows user-assisted remote attackers to cause a denial\nof service (application crash) and prevent examination of certain ext2fs\nfiles via a malformed ext2fs image.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4195"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sleuthkit","source":"https://ubuntu.com/security/cve?package=sleuthkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sleuthkit","debian":"https://tracker.debian.org/pkg/sleuthkit","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.09-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.09","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3845","published":"2007-08-08T01:17:00","updated_at":"2025-08-04T19:18:44.067576+00:00","description":"\nMozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before\n2.0.0.6, and SeaMonkey before 1.1.4 allow remote attackers to execute\narbitrary commands via certain vectors associated with launching \"a file\nhandling program based on the file extension at the end of the URI,\" a\nvariant of CVE-2007-4041. NOTE: the vendor states that \"it is still\npossible to launch a filetype handler based on extension rather than the\nregistered protocol handler.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-493-1","https://ubuntu.com/security/notices/USN-503-1","https://www.cve.org/CVERecord?id=CVE-2007-3845"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.0.6+0dfsg-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.0.6+1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"iceape","source":"https://ubuntu.com/security/cve?package=iceape","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=iceape","debian":"https://tracker.debian.org/pkg/iceape","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0.13-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0.13-0ubuntu0.7.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-503-1","USN-493-1"],"notices":[{"id":"USN-503-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2007-08-25T00:37:44.763474","description":"Various flaws were discovered in the layout and JavaScript engines. By\ntricking a user into opening a malicious email, an attacker could execute\narbitrary code with the user's privileges. Please note that JavaScript\nis disabled by default for emails, and it is not recommended to enable it.\n(CVE-2007-3734, CVE-2007-3735, CVE-2007-3844)\n\nJesper Johansson discovered that spaces and double-quotes were\nnot correctly handled when launching external programs. In rare\nconfigurations, after tricking a user into opening a malicious email,\nan attacker could execute helpers with arbitrary arguments with the\nuser's privileges. (CVE-2007-3670, CVE-2007-3845)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"mozilla-thunderbird","version":"1.5.0.13-0ubuntu0.6.06","description":"","is_source":true},{"name":"mozilla-thunderbird","version":"1.5.0.13-0ubuntu0.6.06","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird","version_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird/1.5.0.13-0ubuntu0.6.06"}],"feisty":[{"name":"mozilla-thunderbird","version":"1.5.0.13-0ubuntu0.7.04","description":"","is_source":true},{"name":"mozilla-thunderbird","version":"1.5.0.13-0ubuntu0.7.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird","version_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird/1.5.0.13-0ubuntu0.7.04"}],"edgy":[{"name":"mozilla-thunderbird","version":"1.5.0.13-0ubuntu0.6.10","description":"","is_source":true},{"name":"mozilla-thunderbird","version":"1.5.0.13-0ubuntu0.6.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird","version_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird/1.5.0.13-0ubuntu0.6.10"}]},"type":"USN","cves_ids":["CVE-2007-3845","CVE-2007-3844","CVE-2007-3670","CVE-2007-3735","CVE-2007-3734"]},{"id":"USN-493-1","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.","references":[],"published":"2007-08-01T02:12:32","description":"A flaw was discovered in handling of \"about:blank\" windows used by\naddons. A malicious web site could exploit this to modify the contents,\nor steal confidential data (such as passwords), of other web pages.\n(CVE-2007-3844)\n\nJesper Johansson discovered that spaces and double-quotes were\nnot correctly handled when launching external programs. In rare\nconfigurations, after tricking a user into opening a malicious web page,\nan attacker could execute helpers with arbitrary arguments with the\nuser's privileges. (CVE-2007-3845)","is_hidden":false,"release_packages":{"dapper":[{"name":"firefox","version":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"firefox","version":"2.0.0.6+1-0ubuntu1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"firefox","version":"2.0.0.6+0dfsg-0ubuntu0.6.10","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-3844","CVE-2007-3845"]}]},{"id":"CVE-2007-3844","published":"2007-08-08T01:17:00","updated_at":"2025-07-17T16:41:54.036995+00:00","description":"\nMozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and\nSeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting\n(XSS) attacks with chrome privileges via an addon that inserts a (1)\njavascript: or (2) data: link into an about:blank document loaded by chrome\nvia (a) the window.open function or (b) a content.location assignment, aka\n\"Cross Context Scripting.\" NOTE: this issue is caused by a CVE-2007-3089\nregression.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-493-1","https://ubuntu.com/security/notices/USN-503-1","https://www.cve.org/CVERecord?id=CVE-2007-3844"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.0.6+0dfsg-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.0.6+1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"iceape","source":"https://ubuntu.com/security/cve?package=iceape","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=iceape","debian":"https://tracker.debian.org/pkg/iceape","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0.13-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0.13-0ubuntu0.7.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-503-1","USN-493-1"],"notices":[{"id":"USN-503-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2007-08-25T00:37:44.763474","description":"Various flaws were discovered in the layout and JavaScript engines. By\ntricking a user into opening a malicious email, an attacker could execute\narbitrary code with the user's privileges. Please note that JavaScript\nis disabled by default for emails, and it is not recommended to enable it.\n(CVE-2007-3734, CVE-2007-3735, CVE-2007-3844)\n\nJesper Johansson discovered that spaces and double-quotes were\nnot correctly handled when launching external programs. In rare\nconfigurations, after tricking a user into opening a malicious email,\nan attacker could execute helpers with arbitrary arguments with the\nuser's privileges. (CVE-2007-3670, CVE-2007-3845)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"mozilla-thunderbird","version":"1.5.0.13-0ubuntu0.6.06","description":"","is_source":true},{"name":"mozilla-thunderbird","version":"1.5.0.13-0ubuntu0.6.06","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird","version_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird/1.5.0.13-0ubuntu0.6.06"}],"feisty":[{"name":"mozilla-thunderbird","version":"1.5.0.13-0ubuntu0.7.04","description":"","is_source":true},{"name":"mozilla-thunderbird","version":"1.5.0.13-0ubuntu0.7.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird","version_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird/1.5.0.13-0ubuntu0.7.04"}],"edgy":[{"name":"mozilla-thunderbird","version":"1.5.0.13-0ubuntu0.6.10","description":"","is_source":true},{"name":"mozilla-thunderbird","version":"1.5.0.13-0ubuntu0.6.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird","version_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird/1.5.0.13-0ubuntu0.6.10"}]},"type":"USN","cves_ids":["CVE-2007-3845","CVE-2007-3844","CVE-2007-3670","CVE-2007-3735","CVE-2007-3734"]},{"id":"USN-493-1","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.","references":[],"published":"2007-08-01T02:12:32","description":"A flaw was discovered in handling of \"about:blank\" windows used by\naddons. A malicious web site could exploit this to modify the contents,\nor steal confidential data (such as passwords), of other web pages.\n(CVE-2007-3844)\n\nJesper Johansson discovered that spaces and double-quotes were\nnot correctly handled when launching external programs. In rare\nconfigurations, after tricking a user into opening a malicious web page,\nan attacker could execute helpers with arbitrary arguments with the\nuser's privileges. (CVE-2007-3845)","is_hidden":false,"release_packages":{"dapper":[{"name":"firefox","version":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"firefox","version":"2.0.0.6+1-0ubuntu1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"firefox","version":"2.0.0.6+0dfsg-0ubuntu0.6.10","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-3844","CVE-2007-3845"]}]},{"id":"CVE-2007-4174","published":"2007-08-07T10:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nTor before 0.1.2.16, when ControlPort is enabled, does not properly\nrestrict commands to localhost port 9051, which allows remote attackers to\nmodify the torrc configuration file, compromise anonymity, and have other\nunspecified impact via HTTP POST data containing commands without valid\nauthentication, as demonstrated by an HTML form (1) hosted on a web site or\n(2) injected by a Tor exit node.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4174"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"tor","source":"https://ubuntu.com/security/cve?package=tor","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tor","debian":"https://tracker.debian.org/pkg/tor","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4165","published":"2007-08-07T10:17:00","updated_at":"2025-07-17T16:42:01.322060+00:00","description":"\nCross-site scripting (XSS) vulnerability in index.php in the Blue Memories\ntheme 1.5 for WordPress allows remote attackers to inject arbitrary web\nscript or HTML via the s parameter, possibly a related issue to\nCVE-2007-2757 and CVE-2007-4014. NOTE: the provenance of this information\nis unknown; the details are obtained solely from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4165"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":76280,"limit":20,"total_results":79316}