{"cves":[{"id":"CVE-2007-3716","published":"2007-07-11T23:30:00","updated_at":"2025-07-17T16:41:50.378968+00:00","description":"\nThe Java XML Digital Signature implementation in Sun JDK and JRE 6 before\nUpdate 2 does not properly process XSLT stylesheets in XSLT transforms in\nXML signatures, which allows context-dependent attackers to execute\narbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3716"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"6-02-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"6-02-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3713","published":"2007-07-11T23:30:00","updated_at":"2025-07-17T16:41:50.378968+00:00","description":"\nMultiple buffer overflows in Konst CenterICQ 4.9.11 through 4.21 allow\nremote attackers to execute arbitrary code via unspecified vectors. NOTE:\nthe provenance of this information is unknown; the details are obtained\nsolely from third party information.  NOTE: this might overlap\nCVE-2007-0160.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.debian.org/security/2007/dsa-1433","https://www.cve.org/CVERecord?id=CVE-2007-3713"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/centericq/+bug/176917"],"patches":{},"tags":{},"packages":[{"name":"centericq","source":"https://ubuntu.com/security/cve?package=centericq","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=centericq","debian":"https://tracker.debian.org/pkg/centericq","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"centerim","source":"https://ubuntu.com/security/cve?package=centerim","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=centerim","debian":"https://tracker.debian.org/pkg/centerim","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"4.22.1-2.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"4.22.1-2.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"4.22.1-2.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"4.22.1-2.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"4.22.1-2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3698","published":"2007-07-11T22:30:00","updated_at":"2025-07-17T16:41:50.378968+00:00","description":"\nThe Java Secure Socket Extension (JSSE) in Sun JDK and JRE 6 Update 1 and\nearlier, JDK and JRE 5.0 Updates 7 through 11, and SDK and JRE 1.4.2_11\nthrough 1.4.2_14, when using JSSE for SSL/TLS support, allows remote\nattackers to cause a denial of service (CPU consumption) via certain\nSSL/TLS handshake requests.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3698"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.5.0-12-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.5.0-12-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.5.0-12-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.5.0-12-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3457","published":"2007-07-11T16:30:00","updated_at":"2025-07-17T16:41:45.616295+00:00","description":"\nAdobe Flash Player 8.0.34.0 and earlier insufficiently validates HTTP\nReferer headers, which might allow remote attackers to conduct a CSRF\nattack via a crafted SWF file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3457"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"9.0.48.0.0ubuntu1~7.04.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"9.0.48.0.0ubuntu10","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"9.0.48.0.0ubuntu10","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"9.0.48.0.0ubuntu10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"9.0.48.0.0ubuntu10","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"9.0.48.0.0ubuntu10","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3456","published":"2007-07-11T16:30:00","updated_at":"2025-07-17T16:41:45.616295+00:00","description":"\nInteger overflow in Adobe Flash Player 9.0.45.0 and earlier might allow\nremote attackers to execute arbitrary code via a large length value for a\n(1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF\nfile, related to an \"input validation error,\" including a signed comparison\nof values that are assumed to be non-negative.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3456"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"9.0.48.0.0ubuntu1~7.04.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"9.0.48.0.0ubuntu10","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"9.0.48.0.0ubuntu10","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"9.0.48.0.0ubuntu10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"9.0.48.0.0ubuntu10","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"9.0.48.0.0ubuntu10","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3107","published":"2007-07-10T22:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe signal handling in the Linux kernel before 2.6.22, including 2.6.2,\nwhen running on PowerPC systems using HTX, allows local users to cause a\ndenial of service via unspecified vectors involving floating point\ncorruption and concurrency, related to clearing of MSR bits.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-574-1","https://www.cve.org/CVERecord?id=CVE-2007-3107"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"upstream","status":"released","description":"2.6.22","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.43","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"feisty","status":"released","description":"2.6.20-16.34","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"gutsy","status":"released","description":"2.6.22-12.39","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-574-1"],"notices":[{"id":"USN-574-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2008-02-04T16:25:54.511756","description":"The minix filesystem did not properly validate certain filesystem\nvalues. If a local attacker could trick the system into attempting\nto mount a corrupted minix filesystem, the kernel could be made to\nhang for long periods of time, resulting in a denial of service.\nThis was only vulnerable in Ubuntu 7.04 and 7.10. (CVE-2006-6058)\n\nThe signal handling on PowerPC systems using HTX allowed local users\nto cause a denial of service via floating point corruption. This was\nonly vulnerable in Ubuntu 6.10 and 7.04. (CVE-2007-3107)\n\nThe Linux kernel did not properly validate the hop-by-hop IPv6\nextended header. Remote attackers could send a crafted IPv6 packet\nand cause a denial of service via kernel panic. This was only\nvulnerable in Ubuntu 7.04. (CVE-2007-4567)\n\nThe JFFS2 filesystem with ACL support enabled did not properly store\npermissions during inode creation and ACL setting. Local users could\npossibly access restricted files after a remount.  This was only\nvulnerable in Ubuntu 7.04 and 7.10. (CVE-2007-4849)\n\nChris Evans discovered an issue with certain drivers that use the\nieee80211_rx function. Remote attackers could send a crafted 802.11\nframe and cause a denial of service via crash. This was only\nvulnerable in Ubuntu 7.04 and 7.10. (CVE-2007-4997)\n\nAlex Smith discovered an issue with the pwc driver for certain webcam\ndevices. A local user with physical access to the system could remove\nthe device while a userspace application had it open and cause the USB\nsubsystem to block. This was only vulnerable in Ubuntu 7.04.\n(CVE-2007-5093)\n\nScott James Remnant discovered a coding error in ptrace. Local users\ncould exploit this and cause the kernel to enter an infinite loop.\nThis was only vulnerable in Ubuntu 7.04 and 7.10. (CVE-2007-5500)\n\nIt was discovered that the Linux kernel could dereference a NULL\npointer when processing certain IPv4 TCP packets. A remote attacker\ncould send a crafted TCP ACK response and cause a denial of service\nvia crash. This was only vulnerable in Ubuntu 7.10. (CVE-2007-5501)\n\nWarren Togami discovered that the hrtimer subsystem did not properly\ncheck for large relative timeouts. A local user could exploit this and\ncause a denial of service via soft lockup. (CVE-2007-5966)\n\nVenustech AD-LAB discovered a buffer overflow in the isdn net\nsubsystem. This issue is exploitable by local users via crafted input\nto the isdn_ioctl function. (CVE-2007-6063)\n\nIt was discovered that the isdn subsystem did not properly check for\nNULL termination when performing ioctl handling. A local user could\nexploit this to cause a denial of service. (CVE-2007-6151)\n\nBlake Frantz discovered that when a root process overwrote an existing\ncore file, the resulting core file retained the previous core file's\nownership. Local users could exploit this to gain access to sensitive\ninformation. (CVE-2007-6206)\n\nHugh Dickins discovered the when using the tmpfs filesystem, under\nrare circumstances, a kernel page may be improperly cleared. A local\nuser may be able to exploit this and read sensitive kernel data or\ncause a denial of service via crash. (CVE-2007-6417)\n\nBill Roman discovered that the VFS subsystem did not properly check\naccess modes. A local user may be able to gain removal privileges on\ndirectories. (CVE-2008-0001)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"linux-source-2.6.22","version":"2.6.22-14.51","description":"","is_source":true},{"name":"linux-image-2.6.22-14-itanium","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-xen","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-lpia","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-hppa32","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-powerpc-smp","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-386","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-mckinley","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-sparc64-smp","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-sparc64","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-generic","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-virtual","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-powerpc","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-cell","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-rt","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-hppa64","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-lpiacompat","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-ume","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-powerpc64-smp","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"},{"name":"linux-image-2.6.22-14-server","version":"2.6.22-14.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.22/2.6.22-14.51"}],"feisty":[{"name":"linux-source-2.6.20","version":"2.6.20-16.34","description":"","is_source":true},{"name":"linux-image-2.6.20-16-386","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-powerpc","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-server","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-mckinley","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-sparc64-smp","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-hppa32","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-powerpc64-smp","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-itanium","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-powerpc-smp","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-generic","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-sparc64","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-hppa64","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-lowlatency","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"},{"name":"linux-image-2.6.20-16-server-bigiron","version":"2.6.20-16.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.34"}],"edgy":[{"name":"linux-source-2.6.17","version":"2.6.17.1-12.43","description":"","is_source":true},{"name":"linux-image-2.6.17-12-mckinley","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-powerpc64-smp","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-hppa32","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-hppa64","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-sparc64-smp","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-generic","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-powerpc-smp","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-386","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-server-bigiron","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-itanium","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-powerpc","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-sparc64","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"},{"name":"linux-image-2.6.17-12-server","version":"2.6.17.1-12.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.17/2.6.17.1-12.43"}]},"type":"USN","cves_ids":["CVE-2006-6058","CVE-2007-3107","CVE-2007-4567","CVE-2007-4849","CVE-2007-4997","CVE-2007-5093","CVE-2007-5500","CVE-2007-5501","CVE-2007-5966","CVE-2007-6063","CVE-2007-6151","CVE-2007-6206","CVE-2007-6417","CVE-2008-0001"]}]},{"id":"CVE-2007-3670","published":"2007-07-10T19:30:00","updated_at":"2025-07-17T16:41:50.378968+00:00","description":"\nArgument injection vulnerability in Microsoft Internet Explorer, when\nrunning on systems with Firefox installed and certain URIs registered,\nallows remote attackers to conduct cross-browser scripting attacks and\nexecute arbitrary commands via shell metacharacters in a (1) FirefoxURL or\n(2) FirefoxHTML URI, which are inserted into the command line that is\ncreated when invoking firefox.exe.  NOTE: it has been debated as to whether\nthe issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's\nopinion that IE appears to be failing to properly delimit the URL argument\nwhen invoking Firefox, and this issue could arise with other protocol\nhandlers in IE as well. However, Mozilla has stated that it will address\nthe issue with a \"defense in depth\" fix that will \"prevent IE from sending\nFirefox malicious data.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-503-1","https://www.cve.org/CVERecord?id=CVE-2007-3670"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.0.6+0dfsg-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.0.6+1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0.13-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0.13-0ubuntu0.7.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-503-1"],"notices":[{"id":"USN-503-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2007-08-25T00:37:44.763474","description":"Various flaws were discovered in the layout and JavaScript engines. By\ntricking a user into opening a malicious email, an attacker could execute\narbitrary code with the user's privileges. Please note that JavaScript\nis disabled by default for emails, and it is not recommended to enable it.\n(CVE-2007-3734, CVE-2007-3735, CVE-2007-3844)\n\nJesper Johansson discovered that spaces and double-quotes were\nnot correctly handled when launching external programs. In rare\nconfigurations, after tricking a user into opening a malicious email,\nan attacker could execute helpers with arbitrary arguments with the\nuser's privileges. (CVE-2007-3670, CVE-2007-3845)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"mozilla-thunderbird","version":"1.5.0.13-0ubuntu0.6.06","description":"","is_source":true},{"name":"mozilla-thunderbird","version":"1.5.0.13-0ubuntu0.6.06","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird","version_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird/1.5.0.13-0ubuntu0.6.06"}],"feisty":[{"name":"mozilla-thunderbird","version":"1.5.0.13-0ubuntu0.7.04","description":"","is_source":true},{"name":"mozilla-thunderbird","version":"1.5.0.13-0ubuntu0.7.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird","version_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird/1.5.0.13-0ubuntu0.7.04"}],"edgy":[{"name":"mozilla-thunderbird","version":"1.5.0.13-0ubuntu0.6.10","description":"","is_source":true},{"name":"mozilla-thunderbird","version":"1.5.0.13-0ubuntu0.6.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird","version_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird/1.5.0.13-0ubuntu0.6.10"}]},"type":"USN","cves_ids":["CVE-2007-3845","CVE-2007-3844","CVE-2007-3670","CVE-2007-3735","CVE-2007-3734"]}]},{"id":"CVE-2007-3657","published":"2007-07-10T19:30:00","updated_at":"2025-08-04T19:18:44.067576+00:00","description":"\nMozilla Firefox 2.0.0.4 allows remote attackers to cause a denial of\nservice by opening multiple tabs in a popup window.  NOTE: this issue has\nbeen disputed by third party researchers, stating that \"this does not crash\non me, and I can't see a likely mechanism of action that would lead to a\nDoS condition.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"click 'pwnd' in the first window, then click 'pwnd' in the popup.\nfirefox goes into a loop opening window after window.\nmarking as ignored-- upstream not interested and we don't consider\nbrowser DoS as security vulnerability"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3657"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3656","published":"2007-07-10T19:30:00","updated_at":"2025-07-17T16:41:50.378968+00:00","description":"\nMozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform\na security zone check when processing a wyciwyg URI, which allows remote\nattackers to obtain sensitive information, poison the browser cache, and\npossibly enable further attack vectors via (1) HTTP 302 redirect controls,\n(2) XMLHttpRequest, or (3) view-source URIs.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-490-1","https://www.cve.org/CVERecord?id=CVE-2007-3656"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.0.6+0dfsg-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.0.6+1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"iceape","source":"https://ubuntu.com/security/cve?package=iceape","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=iceape","debian":"https://tracker.debian.org/pkg/iceape","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-490-1"],"notices":[{"id":"USN-490-1","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.","references":[],"published":"2007-07-20T01:12:02","description":"Various flaws were discovered in the layout and JavaScript engines. By\ntricking a user into opening a malicious web page, an attacker could\nexecute arbitrary code with the user's privileges. (CVE-2007-3734,\nCVE-2007-3735)\n\nFlaws were discovered in the JavaScript methods addEventListener and\nsetTimeout which could be used to inject script into another site in\nviolation of the browser's same-origin policy.  A malicious web site\ncould exploit this to modify the contents, or steal confidential data\n(such as passwords), of other web pages. (CVE-2007-3736)\n\nRonen Zilberman and Michal Zalewski discovered timing attacks in the\nJavaScript engine's use of about:blank frames.  A malicious web site\ncould exploit this to modify the contents, or steal confidential data\n(such as passwords), of other web pages. (CVE-2007-3089)\n\nA flaw was discovered in the JavaScript event handling code.  By tricking\na user into opening a malicious web page, an attacker could execute\narbitrary code with the user's privileges. (CVE-2007-3737)\n\nRonald van den Heetkamp discovered that filename URLs including an encoded\nnull byte could confuse the extension matching code.  By tricking a user\ninto opening a malicious web page, an attacker could execute arbitrary\nhelper programs. (CVE-2007-3285)\n\nMichal Zalewski discovered flaws in the same-origin handling of cached\n\"wyciwyg://\" documents.  A malicious web site could exploit this to\nmodify the contents, or steal confidential data (such as passwords),\nof other web pages. (CVE-2007-3656)\n\nVarious flaws were discovered in the XPCNativeWrapper method. By tricking\na user into opening a malicious web page, an attacker could execute\narbitrary code with the user's privileges. (CVE-2007-3738).","is_hidden":false,"release_packages":{"dapper":[{"name":"firefox","version":"1.5.dfsg+1.5.0.13~prepatch070716-0ubuntu1","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"firefox","version":"2.0.0.5+1-0ubuntu1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"firefox","version":"2.0.0.5+0dfsg-0ubuntu0.6.10","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-3089","CVE-2007-3737","CVE-2007-3738","CVE-2007-3285","CVE-2007-3735","CVE-2007-3656","CVE-2007-3736","CVE-2007-3734"]}]},{"id":"CVE-2007-3655","published":"2007-07-10T19:30:00","updated_at":"2025-07-17T16:41:48.480948+00:00","description":"\nStack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0\nUpdate 11 and earlier, and 6.0 Update 1 and earlier, allows remote\nattackers to execute arbitrary code via a long codebase attribute in a JNLP\nfile.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3655"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-4519","published":"2007-07-10T18:30:00","updated_at":"2025-07-17T16:39:41.039195+00:00","description":"\nMultiple integer overflows in the image loader plug-ins in GIMP before\n2.2.16 allow user-assisted remote attackers to execute arbitrary code via\ncrafted length values in (1) DICOM, (2) PNM, (3) PSD, (4) PSP, (5) Sun RAS,\n(6) XBM, and (7) XWD files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-494-1","https://www.cve.org/CVERecord?id=CVE-2006-4519"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gimp","source":"https://ubuntu.com/security/cve?package=gimp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gimp","debian":"https://tracker.debian.org/pkg/gimp","statuses":[{"release_codename":"dapper","status":"released","description":"2.2.11-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.2.13-1ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.2.13-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.17","component":null,"pocket":"security"}]}],"notices_ids":["USN-494-1"],"notices":[{"id":"USN-494-1","title":"Gimp vulnerability","summary":"Gimp vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-08-02T06:15:37","description":"Sean Larsson discovered multiple integer overflows in Gimp.  By tricking\na user into opening a specially crafted DICOM, PNM, PSD, PSP, RAS, XBM,\nor XWD image, a remote attacker could exploit this to execute arbitrary\ncode with the user's privileges.","is_hidden":false,"release_packages":{"dapper":[{"name":"gimp","version":"2.2.11-1ubuntu3.4","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"gimp","version":"2.2.13-1ubuntu4.3","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"gimp","version":"2.2.13-1ubuntu3.3","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-4519"]}]},{"id":"CVE-2007-3642","published":"2007-07-10T01:30:00","updated_at":"2025-07-17T16:41:48.480948+00:00","description":"\nThe decode_choice function in net/netfilter/nf_conntrack_h323_asn1.c in the\nLinux kernel before 2.6.20.15, 2.6.21.x before 2.6.21.6, and before 2.6.22\nallows remote attackers to cause a denial of service (crash) via an\nencoded, out-of-range index value for a choice field, which triggers a NULL\npointer dereference.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-510-1","https://www.cve.org/CVERecord?id=CVE-2007-3642"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20-16.31","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-510-1"],"notices":[{"id":"USN-510-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n","references":[],"published":"2007-08-31T17:39:43.796283","description":"A flaw was discovered in the PPP over Ethernet implementation.  Local\nattackers could manipulate ioctls and cause kernel memory consumption\nleading to a denial of service. (CVE-2007-2525)\n\nAn integer underflow was discovered in the cpuset filesystem.  If mounted,\nlocal attackers could obtain kernel memory using large file offsets while\nreading the tasks file. This could disclose sensitive data. (CVE-2007-2875)\n\nVilmos Nebehaj discovered that the SCTP netfilter code did not correctly\nvalidate certain states.  A remote attacker could send a specially crafted\npacket causing a denial of service. (CVE-2007-2876)\n\nLuca Tettamanti discovered a flaw in the VFAT compat ioctls on 64-bit\nsystems.  A local attacker could corrupt a kernel_dirent struct and cause\na denial of service. (CVE-2007-2878)\n\nA flaw in the sysfs_readdir function allowed a local user to cause a\ndenial of service by dereferencing a NULL pointer. (CVE-2007-3104)\n\nA buffer overflow was discovered in the random number generator.  In\nenvironments with granular assignment of root privileges, a local attacker\ncould gain additional privileges. (CVE-2007-3105)\n\nA flaw was discovered in the usblcd driver.  A local attacker could cause\nlarge amounts of kernel memory consumption, leading to a denial of service.\n(CVE-2007-3513)\n\nZhongling Wen discovered that the h323 conntrack handler did not correctly\nhandle certain bitfields.  A remote attacker could send a specially crafted\npacket and cause a denial of service. (CVE-2007-3642)\n\nA flaw was discovered in the CIFS mount security checking.  Remote attackers\ncould spoof CIFS network traffic, which could lead a client to trust the\nconnection. (CVE-2007-3843)\n\nIt was discovered that certain setuid-root processes did not correctly\nreset process death signal handlers.  A local user could manipulate this\nto send signals to processes they would not normally have access to.\n(CVE-2007-3848)\n\nThe Direct Rendering Manager for the i915 driver could be made to write\nto arbitrary memory locations.  An attacker with access to a running X11\nsession could send a specially crafted buffer and gain root privileges.\n(CVE-2007-3851)\n\nIt was discovered that the aacraid SCSI driver did not correctly check\npermissions on certain ioctls.  A local attacker could cause a denial\nof service or gain privileges. (CVE-2007-4308)\n","is_hidden":false,"release_packages":{"feisty":[{"name":"linux-source-2.6.20","version":"2.6.20-16.31","description":"","is_source":true},{"name":"linux-image-2.6.20-16-386","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-powerpc","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-server","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-mckinley","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-sparc64-smp","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-hppa32","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-powerpc64-smp","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-itanium","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-powerpc-smp","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-generic","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-sparc64","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-hppa64","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-lowlatency","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"},{"name":"linux-image-2.6.20-16-server-bigiron","version":"2.6.20-16.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.20/2.6.20-16.31"}]},"type":"USN","cves_ids":["CVE-2007-2525","CVE-2007-2875","CVE-2007-2876","CVE-2007-2878","CVE-2007-3104","CVE-2007-3105","CVE-2007-3513","CVE-2007-3642","CVE-2007-3843","CVE-2007-3848","CVE-2007-3851","CVE-2007-4308"]}]},{"id":"CVE-2007-3639","published":"2007-07-10T00:30:00","updated_at":"2025-07-17T16:41:48.480948+00:00","description":"\nWordPress before 2.2.2 allows remote attackers to redirect visitors to\nother websites and potentially obtain sensitive information via (1) the\n_wp_http_referer parameter to wp-pass.php, related to the wp_get_referer\nfunction in wp-includes/functions.php; and possibly other vectors related\nto (2) wp-includes/pluggable.php and (3) the wp_nonce_ays function in\nwp-includes/functions.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3639"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/wordpress/+bug/227307"],"patches":{"wordpress":["vendor: http://www.debian.org/security/2008/dsa-1564"]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-7219","published":"2007-07-06T19:30:00","updated_at":"2025-07-17T16:40:22.851454+00:00","description":"\neZ publish before 3.8.5 does not properly enforce permissions for editing\nin a specific language, which allows remote authenticated users to create a\ndraft in an unauthorized language by editing an archived version of an\nobject, and then using Manage Versions to copy this version to a new draft.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-7219"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ezpublish","source":"https://ubuntu.com/security/cve?package=ezpublish","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ezpublish","debian":"https://tracker.debian.org/pkg/ezpublish","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-7218","published":"2007-07-06T19:30:00","updated_at":"2025-07-17T16:40:22.851454+00:00","description":"\neZ publish before 3.8.1 does not properly enforce permissions for \"content\nedit Language\" when there are four or more languages, which allows remote\nauthenticated users to perform translations into languages that are not\nlisted in a Module Function Limitation policy.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-7218"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ezpublish","source":"https://ubuntu.com/security/cve?package=ezpublish","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ezpublish","debian":"https://tracker.debian.org/pkg/ezpublish","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-2839","published":"2007-07-05T21:30:00","updated_at":"2025-07-17T16:41:30.602237+00:00","description":"\ngfax 0.4.2 and probably other versions creates temporary files insecurely,\nwhich allows local users to execute arbitrary commands via unknown vectors.","ubuntu_description":"","notes":[{"author":"fujitsu","note":"Doesn't affect >= 0.6."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-2839"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gfax","source":"https://ubuntu.com/security/cve?package=gfax","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gfax","debian":"https://tracker.debian.org/pkg/gfax","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3568","published":"2007-07-05T19:30:00","updated_at":"2025-07-17T16:41:48.480948+00:00","description":"\nThe _LoadBMP function in imlib 1.9.15 and earlier allows context-dependent\nattackers to cause a denial of service (infinite loop) via a BMP image with\na Bits Per Page (BPP) value of 0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3568"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"imlib","source":"https://ubuntu.com/security/cve?package=imlib","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=imlib","debian":"https://tracker.debian.org/pkg/imlib","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.9.15-3ubuntu3","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.15-3ubuntu3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.15-3ubuntu3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.15-3ubuntu3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-3555","published":"2007-07-04T15:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1\nallows remote attackers to inject arbitrary web script or HTML via a style\nexpression in the search parameter, a different vulnerability than\nCVE-2004-1424.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-3555"],"bugs":["http://tracker.moodle.org/browse/MDL-10341"],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.7.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-2949","published":"2007-07-04T15:30:00","updated_at":"2025-07-17T16:41:32.290995+00:00","description":"\nInteger overflow in the seek_to_and_unpack_pixeldata function in the psd.c\nplugin in Gimp 2.2.15 allows remote attackers to execute arbitrary code via\na crafted PSD file that contains a large (1) width or (2) height value.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-480-1","https://www.cve.org/CVERecord?id=CVE-2007-2949"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gimp","source":"https://ubuntu.com/security/cve?package=gimp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gimp","debian":"https://tracker.debian.org/pkg/gimp","statuses":[{"release_codename":"dapper","status":"released","description":"2.2.11-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.2.13-1ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.2.13-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-480-1"],"notices":[{"id":"USN-480-1","title":"Gimp vulnerability","summary":"Gimp vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-07-04T22:48:40","description":"Stefan Cornelius discovered that Gimp could miscalculate the size of heap\nbuffers when processing PSD images.  By tricking a user into opening a\nspecially crafted PSD file with Gimp, an attacker could exploit this to\nexecute arbitrary code with the user's privileges.","is_hidden":false,"release_packages":{"dapper":[{"name":"gimp","version":"2.2.11-1ubuntu3.3","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"gimp","version":"2.2.13-1ubuntu4.2","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"gimp","version":"2.2.13-1ubuntu3.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-2949"]}]},{"id":"CVE-2007-3508","published":"2007-07-03T21:30:00","updated_at":"2025-08-04T19:18:44.067576+00:00","description":"\nInteger overflow in the process_envvars function in elf/rtld.c in glibc\nbefore 2.5-rc4 might allow local users to execute arbitrary code via a\nlarge LD_HWCAP_MASK environment variable value.  NOTE: the glibc\nmaintainers state that they do not believe that this issue is exploitable\nfor code execution","ubuntu_description":"","notes":[{"author":"jdstrand","note":"upstream believes this to be unexploitable"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=431858","https://www.cve.org/CVERecord?id=CVE-2007-3508"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"glibc","source":"https://ubuntu.com/security/cve?package=glibc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=glibc","debian":"https://tracker.debian.org/pkg/glibc","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.6.1-1ubuntu8","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":76380,"limit":20,"total_results":79316}