{"cves":[{"id":"CVE-2007-4039","published":"2007-07-27T22:30:00","updated_at":"2025-07-17T16:41:58.173645+00:00","description":"\nArgument injection vulnerability involving Mozilla, when certain URIs are\nregistered, allows remote attackers to conduct cross-browser scripting\nattacks and execute arbitrary commands via shell metacharacters in an\nunspecified URI, which are inserted into the command line when invoking the\nhandling process, a similar issue to CVE-2007-3670.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4039"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4038","published":"2007-07-27T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nArgument injection vulnerability in Mozilla Firefox before 2.0.0.5, when\nrunning on systems with Thunderbird 1.5 installed and certain URIs\nregistered, allows remote attackers to conduct cross-browser scripting\nattacks and execute arbitrary commands via shell metacharacters in a mailto\nURI, which are inserted into the command line that is created when invoking\nThunderbird.exe, a similar issue to CVE-2007-3670.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"apparently requires thunderbird 1.5 to be installed to exploit\nper https://bugzilla.mozilla.org/attachment.cgi?id=278375, Windows\nonly"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4038"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4033","published":"2007-07-27T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the intT1_EnvGetCompletePath function in\nlib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to\nexecute arbitrary code via a long FileName parameter. NOTE: this issue was\noriginally reported to be in the imagepsloadfont function in php_gd2.dll in\nthe gd (PHP_GD2) extension in PHP 5.2.3.","ubuntu_description":"\nIt was discovered that t1lib does not properly perform bounds checking\nwhich can result in a buffer overflow vulnerability. An attacker could\nsend specially crafted input to applications linked against t1lib which\ncould result in a DoS or arbitrary code execution.","notes":[{"author":"jdstrand","note":"while tetex-bin and texlive-bin have embedded t1lib code, it's\nnot used"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-515-1","https://www.cve.org/CVERecord?id=CVE-2007-4033"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"t1lib","source":"https://ubuntu.com/security/cve?package=t1lib","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=t1lib","debian":"https://tracker.debian.org/pkg/t1lib","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.0-2ubuntu0.6.06.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.0-2ubuntu0.6.10.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.1.0-2ubuntu0.7.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tetex-bin","source":"https://ubuntu.com/security/cve?package=tetex-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tetex-bin","debian":"https://tracker.debian.org/pkg/tetex-bin","statuses":[{"release_codename":"dapper","status":"not-affected","description":"links to t1lib","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"links to t1lib","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"links to t1lib","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"links to t1lib","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"links to t1lib","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"links to t1lib","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-515-1"],"notices":[{"id":"USN-515-1","title":"t1lib vulnerability","summary":"t1lib vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2007-09-19T16:49:23.883549","description":"It was discovered that t1lib does not properly perform bounds checking\nwhich can result in a buffer overflow vulnerability. An attacker could\nsend specially crafted input to applications linked against t1lib which\ncould result in a DoS or arbitrary code execution.\n","is_hidden":false,"release_packages":{"dapper":[{"name":"t1lib","version":"5.1.0-2ubuntu0.6.06.1","description":"","is_source":true},{"name":"libt1-5","version":"5.1.0-2ubuntu0.6.06.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/t1lib","version_link":"https://launchpad.net/ubuntu/+source/t1lib/5.1.0-2ubuntu0.6.06.1"}],"feisty":[{"name":"t1lib","version":"5.1.0-2ubuntu0.7.04.1","description":"","is_source":true},{"name":"libt1-5","version":"5.1.0-2ubuntu0.7.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/t1lib","version_link":"https://launchpad.net/ubuntu/+source/t1lib/5.1.0-2ubuntu0.7.04.1"}],"edgy":[{"name":"t1lib","version":"5.1.0-2ubuntu0.6.10.1","description":"","is_source":true},{"name":"libt1-5","version":"5.1.0-2ubuntu0.6.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/t1lib","version_link":"https://launchpad.net/ubuntu/+source/t1lib/5.1.0-2ubuntu0.6.10.1"}]},"type":"USN","cves_ids":["CVE-2007-4033"]}]},{"id":"CVE-2007-3532","published":"2007-07-27T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nNVIDIA drivers (nvidia-drivers) before 1.0.7185, 1.0.9639, and 100.14.11,\nas used in Gentoo Linux and possibly other distributions, creates\n/dev/nvidia* device files with insecure permissions, which allows local\nusers to modify video card settings, cause a denial of service (crash or\nphysical video card damage), and obtain sensitive information.","ubuntu_description":"","notes":[{"author":"kees","note":"the device files seem bad only on systems that are actively using the\nnvidia drivers."},{"author":"mdeslaur","note":"dapper desktop is EOL now"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3532"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-restricted-modules","source":"https://ubuntu.com/security/cve?package=linux-restricted-modules","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-restricted-modules","debian":"https://tracker.debian.org/pkg/linux-restricted-modules","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-restricted-modules-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-restricted-modules-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-restricted-modules-2.6.15","debian":"https://tracker.debian.org/pkg/linux-restricted-modules-2.6.15","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"linux-restricted-modules-2.6.24","source":"https://ubuntu.com/security/cve?package=linux-restricted-modules-2.6.24","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-restricted-modules-2.6.24","debian":"https://tracker.debian.org/pkg/linux-restricted-modules-2.6.24","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3105","published":"2007-07-27T21:30:00","updated_at":"2025-08-04T19:18:44.067576+00:00","description":"\nStack-based buffer overflow in the random number generator (RNG)\nimplementation in the Linux kernel before 2.6.22 might allow local root\nusers to cause a denial of service or gain privileges by setting the\ndefault wakeup threshold to a value greater than the output pool size,\nwhich triggers writing random numbers to the stack by the pool transfer\nfunction involving \"bound check ordering\". NOTE: this issue might only\ncross privilege boundaries in environments that have granular assignment of\nprivileges for root.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-510-1","https://ubuntu.com/security/notices/USN-509-1","https://ubuntu.com/security/notices/USN-508-1","https://www.cve.org/CVERecord?id=CVE-2007-3105"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-29.58","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.40","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20-16.31","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-510-1","USN-509-1","USN-508-1"],"notices":[{"id":"USN-510-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2007-08-31T17:39:43.796283","description":"A flaw was discovered in the PPP over Ethernet implementation. Local\nattackers could manipulate ioctls and cause kernel memory consumption\nleading to a denial of service. (CVE-2007-2525)\n\nAn integer underflow was discovered in the cpuset filesystem. If mounted,\nlocal attackers could obtain kernel memory using large file offsets while\nreading the tasks file. This could disclose sensitive data. (CVE-2007-2875)\n\nVilmos Nebehaj discovered that the SCTP netfilter code did not correctly\nvalidate certain states. A remote attacker could send a specially crafted\npacket causing a denial of service. (CVE-2007-2876)\n\nLuca Tettamanti discovered a flaw in the VFAT compat ioctls on 64-bit\nsystems. A local attacker could corrupt a kernel_dirent struct and cause\na denial of service. (CVE-2007-2878)\n\nA flaw in the sysfs_readdir function allowed a local user to cause a\ndenial of service by dereferencing a NULL pointer. (CVE-2007-3104)\n\nA buffer overflow was discovered in the random number generator. In\nenvironments with granular assignment of root privileges, a local attacker\ncould gain additional privileges. (CVE-2007-3105)\n\nA flaw was discovered in the usblcd driver. A local attacker could cause\nlarge amounts of kernel memory consumption, leading to a denial of service.\n(CVE-2007-3513)\n\nZhongling Wen discovered that the h323 conntrack handler did not correctly\nhandle certain bitfields. A remote attacker could send a specially crafted\npacket and cause a denial of service. (CVE-2007-3642)\n\nA flaw was discovered in the CIFS mount security checking. Remote attackers\ncould spoof CIFS network traffic, which could lead a client to trust the\nconnection. (CVE-2007-3843)\n\nIt was discovered that certain setuid-root processes did not correctly\nreset process death signal handlers. A local user could manipulate this\nto send signals to processes they would not normally have access to.\n(CVE-2007-3848)\n\nThe Direct Rendering Manager for the i915 driver could be made to write\nto arbitrary memory locations. An attacker with access to a running X11\nsession could send a specially crafted buffer and gain root privileges.\n(CVE-2007-3851)\n\nIt was discovered that the aacraid SCSI driver did not correctly check\npermissions on certain ioctls. A local attacker could cause a denial\nof service or gain privileges. (CVE-2007-4308)\n","is_hidden":false,"release_packages":{"feisty":[{"name":"linux-source-2.6.20","version":"2.6.20-16.31","description":"","is_source":true},{"name":"linux-image-2.6.20-16-386","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-powerpc","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-server","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-mckinley","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-sparc64-smp","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-hppa32","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-powerpc64-smp","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-itanium","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-powerpc-smp","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-generic","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-sparc64","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-hppa64","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-lowlatency","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-server-bigiron","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"}]},"type":"USN","cves_ids":["CVE-2007-2525","CVE-2007-2875","CVE-2007-2876","CVE-2007-2878","CVE-2007-3104","CVE-2007-3105","CVE-2007-3513","CVE-2007-3642","CVE-2007-3843","CVE-2007-3848","CVE-2007-3851","CVE-2007-4308"]},{"id":"USN-509-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2007-08-30T23:55:46.418455","description":"A flaw in the sysfs_readdir function allowed a local user to cause a\ndenial of service by dereferencing a NULL pointer. (CVE-2007-3104)\n\nA buffer overflow was discovered in the random number generator. In\nenvironments with granular assignment of root privileges, a local attacker\ncould gain additional privileges. (CVE-2007-3105)\n\nA flaw was discovered in the usblcd driver. A local attacker could cause\nlarge amounts of kernel memory consumption, leading to a denial of service.\n(CVE-2007-3513)\n\nIt was discovered that certain setuid-root processes did not correctly\nreset process death signal handlers. A local user could manipulate this\nto send signals to processes they would not normally have access to.\n(CVE-2007-3848)\n\nThe Direct Rendering Manager for the i915 driver could be made to write\nto arbitrary memory locations. An attacker with access to a running X11\nsession could send a specially crafted buffer and gain root privileges.\n(CVE-2007-3851)\n\nIt was discovered that the aacraid SCSI driver did not correctly check\npermissions on certain ioctls. A local attacker could cause a denial\nof service or gain privileges. (CVE-2007-4308)\n","is_hidden":false,"release_packages":{"edgy":[{"name":"linux-source-2.6.17","version":"2.6.17.1-12.40","description":"","is_source":true},{"name":"linux-image-2.6.17-12-mckinley","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-powerpc64-smp","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-hppa32","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-hppa64","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-sparc64-smp","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-generic","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-powerpc-smp","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-386","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-server-bigiron","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-itanium","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-powerpc","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-sparc64","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"},{"name":"linux-image-2.6.17-12-server","version":"2.6.17.1-12.40","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.40"}]},"type":"USN","cves_ids":["CVE-2007-3104","CVE-2007-3105","CVE-2007-3513","CVE-2007-3848","CVE-2007-3851","CVE-2007-4308"]},{"id":"USN-508-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-386,\nlinux-powerpc, linux-amd64-generic), a standard system upgrade will\nautomatically perform this as well.\n","references":[],"published":"2007-08-31T04:16:11.939627","description":"A buffer overflow was discovered in the Moxa serial driver. Local\nattackers could execute arbitrary code and gain root privileges.\n(CVE-2005-0504)\n\nA flaw was discovered in the IPv6 stack's handling of type 0 route headers.\nBy sending a specially crafted IPv6 packet, a remote attacker could cause\na denial of service between two IPv6 hosts. (CVE-2007-2242)\n\nA flaw in the sysfs_readdir function allowed a local user to cause a\ndenial of service by dereferencing a NULL pointer. (CVE-2007-3104)\n\nA buffer overflow was discovered in the random number generator. In\nenvironments with granular assignment of root privileges, a local attacker\ncould gain additional privileges. (CVE-2007-3105)\n\nIt was discovered that certain setuid-root processes did not correctly\nreset process death signal handlers. A local user could manipulate this\nto send signals to processes they would not normally have access to.\n(CVE-2007-3848)\n\nIt was discovered that the aacraid SCSI driver did not correctly check\npermissions on certain ioctls. A local attacker could cause a denial\nof service or gain privileges. (CVE-2007-4308)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-29.58","description":"","is_source":true},{"name":"linux-image-2.6.15-29-amd64-xeon","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-hppa32-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-server-bigiron","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-386","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-686","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-powerpc","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-sparc64","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-amd64-k8","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-hppa32","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-k7","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-hppa64-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-mckinley-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-amd64-generic","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-itanium-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-amd64-server","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-itanium","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-powerpc-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-powerpc64-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-server","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-mckinley","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-hppa64","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"},{"name":"linux-image-2.6.15-29-sparc64-smp","version":"2.6.15-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-29.58"}]},"type":"USN","cves_ids":["CVE-2005-0504","CVE-2007-2242","CVE-2007-3104","CVE-2007-3105","CVE-2007-3848","CVE-2007-4308"]}]},{"id":"CVE-2007-2874","published":"2007-07-27T21:30:00","updated_at":"2025-07-17T16:41:32.290995+00:00","description":"\nBuffer overflow in the wpa_printf function in the debugging code in\nwpa_supplicant in the Fedora NetworkManager package before 0.6.5-3.fc7\nallows user-assisted remote attackers to execute arbitrary code via\nmalformed frames on a WPA2 network. NOTE: some of these details are\nobtained from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-2874"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wpasupplicant","source":"https://ubuntu.com/security/cve?package=wpasupplicant","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wpasupplicant","debian":"https://tracker.debian.org/pkg/wpasupplicant","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-4029","published":"2007-07-26T22:30:00","updated_at":"2025-07-17T16:41:58.173645+00:00","description":"\nlibvorbis 1.1.2, and possibly other versions before 1.2.0, allows\ncontext-dependent attackers to cause a denial of service via (1) an invalid\nmapping type, which triggers an out-of-bounds read in the vorbis_info_clear\nfunction in info.c, and (2) invalid blocksize values that trigger a\nsegmentation fault in the read function in block.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-498-1","https://www.cve.org/CVERecord?id=CVE-2007-4029"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libvorbis","source":"https://ubuntu.com/security/cve?package=libvorbis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvorbis","debian":"https://tracker.debian.org/pkg/libvorbis","statuses":[{"release_codename":"dapper","status":"released","description":"1.1.2-0ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.1.2-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.1.2.dfsg-1.2ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-498-1"],"notices":[{"id":"USN-498-1","title":"libvorbis vulnerabilities","summary":"libvorbis vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-08-16T05:23:12","description":"David Thiel discovered that libvorbis did not correctly verify the size\nof certain headers, and did not correctly clean up a broken stream.\nIf a user were tricked into processing a specially crafted Vorbis stream,\na remote attacker could execute arbitrary code with the user's privileges.","is_hidden":false,"release_packages":{"dapper":[{"name":"libvorbis0a","version":"1.1.2-0ubuntu2.2","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"libvorbis0a","version":"1.1.2.dfsg-1.2ubuntu2","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libvorbis0a","version":"1.1.2-1ubuntu1.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-3106","CVE-2007-4029"]}]},{"id":"CVE-2007-3106","published":"2007-07-26T21:30:00","updated_at":"2025-08-04T19:18:44.067576+00:00","description":"\nlib/info.c in libvorbis 1.1.2, and possibly other versions before 1.2.0,\nallows context-dependent attackers to cause a denial of service and\npossibly execute arbitrary code via invalid (1) blocksize_0 and (2)\nblocksize_1 values, which trigger a \"heap overwrite\" in the _01inverse\nfunction in res0.c. NOTE: this issue has been RECAST so that CVE-2007-4029\nhandles additional vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-498-1","https://www.cve.org/CVERecord?id=CVE-2007-3106"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libvorbis","source":"https://ubuntu.com/security/cve?package=libvorbis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvorbis","debian":"https://tracker.debian.org/pkg/libvorbis","statuses":[{"release_codename":"dapper","status":"released","description":"1.1.2-0ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.1.2-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.1.2.dfsg-1.2ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-498-1"],"notices":[{"id":"USN-498-1","title":"libvorbis vulnerabilities","summary":"libvorbis vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-08-16T05:23:12","description":"David Thiel discovered that libvorbis did not correctly verify the size\nof certain headers, and did not correctly clean up a broken stream.\nIf a user were tricked into processing a specially crafted Vorbis stream,\na remote attacker could execute arbitrary code with the user's privileges.","is_hidden":false,"release_packages":{"dapper":[{"name":"libvorbis0a","version":"1.1.2-0ubuntu2.2","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"libvorbis0a","version":"1.1.2.dfsg-1.2ubuntu2","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libvorbis0a","version":"1.1.2-1ubuntu1.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-3106","CVE-2007-4029"]}]},{"id":"CVE-2007-4010","published":"2007-07-26T00:30:00","updated_at":"2025-07-17T16:41:58.173645+00:00","description":"\nThe win32std extension in PHP 5.2.3 does not follow safe_mode and\ndisable_functions restrictions, which allows remote attackers to execute\narbitrary commands via the win_shell_execute function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-4010"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3962","published":"2007-07-25T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple stack-based buffer overflows in fsplib.c in fsplib before 0.9\nmight allow remote attackers to execute arbitrary code via (1) a long\nfilename that is not properly handled by the fsp_readdir_native function\nwhen MAXNAMLEN is greater than 255, or (2) a long d_name directory (dirent)\nfield in the fsp_readdir function.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3962"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/gftp/+bug/185040"],"patches":{"gftp":["vendor: http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:018"]},"tags":{},"packages":[{"name":"gftp","source":"https://ubuntu.com/security/cve?package=gftp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gftp","debian":"https://tracker.debian.org/pkg/gftp","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3961","published":"2007-07-25T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOff-by-one error in the fsp_readdir_r function in fsplib.c in fsplib before\n0.9 allows remote attackers to cause a denial of service via a directory\nentry whose length is exactly MAXNAMELEN, which prevents a terminating null\nbyte from being added.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3961"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/gftp/+bug/185040"],"patches":{"gftp":["vendor: http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:018"]},"tags":{},"packages":[{"name":"gftp","source":"https://ubuntu.com/security/cve?package=gftp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gftp","debian":"https://tracker.debian.org/pkg/gftp","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3531","published":"2007-07-25T17:30:00","updated_at":"2025-07-17T16:41:47.196312+00:00","description":"\nThe set_default_speeds function in backend/backend.c in NVidia NVClock\nbefore 0.8b2 allows local users to overwrite arbitrary files via a symlink\nattack on the /tmp/nvclock temporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3531"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"nvclock","source":"https://ubuntu.com/security/cve?package=nvclock","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nvclock","debian":"https://tracker.debian.org/pkg/nvclock","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3383","published":"2007-07-25T17:30:00","updated_at":"2025-07-17T16:41:43.741697+00:00","description":"\nCross-site scripting (XSS) vulnerability in SendMailServlet in the examples\nweb application (examples/jsp/mail/sendmail.jsp) in Apache Tomcat 4.0.0\nthrough 4.0.6 and 4.1.0 through 4.1.36 allows remote attackers to inject\narbitrary web script or HTML via the From field and possibly other fields,\nrelated to generation of error messages.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3383"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"tomcat4","source":"https://ubuntu.com/security/cve?package=tomcat4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat4","debian":"https://tracker.debian.org/pkg/tomcat4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-7221","published":"2007-07-25T17:30:00","updated_at":"2025-07-17T16:40:22.851454+00:00","description":"\nMultiple off-by-one errors in fsplib.c in fsplib before 0.8 allow attackers\nto cause a denial of service via unspecified vectors involving the (1) name\nand (2) d_name entry attributes.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-7221"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gftp","source":"https://ubuntu.com/security/cve?package=gftp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gftp","debian":"https://tracker.debian.org/pkg/gftp","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.19","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3956","published":"2007-07-24T18:30:00","updated_at":"2025-07-17T16:41:58.173645+00:00","description":"\nTeamSpeak WebServer 2.0 for Windows does not validate parameter value\nlengths and does not expire TCP sessions, which allows remote attackers to\ncause a denial of service (CPU and memory consumption) via long username\nand password parameters in a request to login.tscmd on TCP port 14534.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3956"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"teamspeak-server","source":"https://ubuntu.com/security/cve?package=teamspeak-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=teamspeak-server","debian":"https://tracker.debian.org/pkg/teamspeak-server","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-2926","published":"2007-07-24T17:30:00","updated_at":"2025-07-17T16:41:32.290995+00:00","description":"\nISC BIND 9 through 9.5.0a5 uses a weak random number generator during\ngeneration of DNS query ids when answering resolver questions or sending\nNOTIFY messages to slave name servers, which makes it easier for remote\nattackers to guess the next query id and perform DNS cache poisoning.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-491-1","https://www.cve.org/CVERecord?id=CVE-2007-2926"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"bind9","source":"https://ubuntu.com/security/cve?package=bind9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bind9","debian":"https://tracker.debian.org/pkg/bind9","statuses":[{"release_codename":"dapper","status":"released","description":"9.3.2-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"9.3.2-2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"9.3.4-2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-491-1"],"notices":[{"id":"USN-491-1","title":"Bind vulnerability","summary":"Bind vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-07-25T14:09:05","description":"A flaw was discovered in Bind's sequence number generator. A remote\nattacker could calculate future sequence numbers and send forged DNS\nquery responses. This could lead to client connections being directed\nto attacker-controlled hosts, resulting in credential theft and other\nattacks.","is_hidden":false,"release_packages":{"dapper":[{"name":"libdns21","version":"1:9.3.2-2ubuntu1.3","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"libdns22","version":"1:9.3.4-2ubuntu2.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libdns21","version":"1:9.3.2-2ubuntu3.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-2926"]}]},{"id":"CVE-2007-2925","published":"2007-07-24T17:30:00","updated_at":"2025-07-17T16:41:32.290995+00:00","description":"\nThe default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and\n9.5.0a1 through 9.5.0a5 do not set the allow-recursion and\nallow-query-cache ACLs, which allows remote attackers to make recursive\nqueries and query the cache.","ubuntu_description":"","notes":[{"author":"kees","note":"recursion should be a admin policy, and is already mediated by edgy+ bind default configs"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-2925"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"bind9","source":"https://ubuntu.com/security/cve?package=bind9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bind9","debian":"https://tracker.debian.org/pkg/bind9","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3950","published":"2007-07-24T00:30:00","updated_at":"2025-07-17T16:41:58.173645+00:00","description":"\nlighttpd 1.4.15, when run on 32 bit platforms, allows remote attackers to\ncause a denial of service (daemon crash) via unspecified vectors involving\nthe use of incompatible format specifiers in certain debugging messages in\nthe (1) mod_scgi, (2) mod_fastcgi, and (3) mod_webdav modules.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3950"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"lighttpd","source":"https://ubuntu.com/security/cve?package=lighttpd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lighttpd","debian":"https://tracker.debian.org/pkg/lighttpd","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.11-3ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.13~r1370-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.13-9ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.16","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3949","published":"2007-07-24T00:30:00","updated_at":"2025-07-17T16:41:55.483691+00:00","description":"\nmod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in\nthe URL, which allows remote attackers to bypass url.access-deny settings.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3949"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"lighttpd","source":"https://ubuntu.com/security/cve?package=lighttpd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lighttpd","debian":"https://tracker.debian.org/pkg/lighttpd","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.11-3ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.13~r1370-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.13-9ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.16","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3948","published":"2007-07-24T00:30:00","updated_at":"2025-07-17T16:41:55.483691+00:00","description":"\nconnections.c in lighttpd before 1.4.16 might accept more connections than\nthe configured maximum, which allows remote attackers to cause a denial of\nservice (failed assertion) via a large number of connection attempts.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3948"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"lighttpd","source":"https://ubuntu.com/security/cve?package=lighttpd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lighttpd","debian":"https://tracker.debian.org/pkg/lighttpd","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.11-3ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.13~r1370-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.13-9ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.16","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":76320,"limit":20,"total_results":79316}