{"cves":[{"id":"CVE-2007-1894","published":"2007-04-09T20:19:00","updated_at":"2025-07-17T16:41:17.059848+00:00","description":"\nCross-site scripting (XSS) vulnerability in\nwp-includes/general-template.php in WordPress before 20070309 allows remote\nattackers to inject arbitrary web script or HTML via the year parameter in\nthe wp_title function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1894"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1893","published":"2007-04-09T20:19:00","updated_at":"2025-07-17T16:41:15.812199+00:00","description":"\nxmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote\nauthenticated users with the contributor role to bypass intended access\nrestrictions and invoke the publish_posts functionality, which can be used\nto \"publish a previously saved post.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1893"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1890","published":"2007-04-06T01:19:00","updated_at":"2025-07-17T16:41:15.812199+00:00","description":"\nInteger overflow in the msg_receive function in PHP 4 before 4.4.5 and PHP\n5 before 5.2.1, on FreeBSD and possibly other platforms, allows\ncontext-dependent attackers to execute arbitrary code via certain maxsize\nvalues, as demonstrated by 0xffffffff.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1890"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1889","published":"2007-04-06T01:19:00","updated_at":"2025-07-17T16:41:15.812199+00:00","description":"\nInteger signedness error in the _zend_mm_alloc_int function in the Zend\nMemory Manager in PHP 5.2.0 allows remote attackers to execute arbitrary\ncode via a large emalloc request, related to an incorrect signed long cast,\nas demonstrated via the HTTP SOAP client in PHP, and via a call to\nmsg_receive with the largest positive integer value of maxsize.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1889"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1888","published":"2007-04-06T01:19:00","updated_at":"2025-07-17T16:41:15.812199+00:00","description":"\nBuffer overflow in the sqlite_decode_binary function in src/encode.c in\nSQLite 2, as used by PHP 4.x through 5.x and other applications, allows\ncontext-dependent attackers to execute arbitrary code via an empty value of\nthe in parameter. NOTE: some PHP installations use a bundled version of\nsqlite without this vulnerability. The SQLite developer has argued that\nthis issue could be due to a misuse of the sqlite_decode_binary() API.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-455-1","https://www.cve.org/CVERecord?id=CVE-2007-1888"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.2","component":null,"pocket":"security"}]},{"name":"sqlite","source":"https://ubuntu.com/security/cve?package=sqlite","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sqlite","debian":"https://tracker.debian.org/pkg/sqlite","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-455-1"],"notices":[{"id":"USN-455-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-04-27T21:10:26","description":"Stefan Esser discovered multiple vulnerabilities in the \"Month of PHP\nbugs\".\n\nThe substr_compare() function did not sufficiently verify its length\nargument. This might be exploited to read otherwise unaccessible\nmemory, which might lead to information disclosure. (CVE-2007-1375)\n\nThe shared memory (shmop) functions did not verify resource types,\nthus they could be called with a wrong resource type that might\ncontain user supplied data. This could be exploited to read and write\narbitrary memory addresses of the PHP interpreter. This issue does\nnot affect Ubuntu 7.04. (CVE-2007-1376)\n\nThe php_binary handler of the session extension was missing a boundary\ncheck. When unserializing overly long variable names this could be\nexploited to read up to 126 bytes of memory, which might lead to\ninformation disclosure. (CVE-2007-1380)\n\nThe internal array_user_key_compare() function, as used for example by\nthe PHP function uksort(), incorrectly handled memory unreferencing of\nits arguments. This could have been exploited to execute arbitrary\ncode with the privileges of the PHP interpreter, and thus\ncircumventing any disable_functions, open_basedir, or safe_mode\nrestrictions. (CVE-2007-1484)\n\nThe session_regenerate_id() function did not properly clean up the\nformer session identifier variable. This could be exploited to crash\nthe PHP interpreter, possibly also remotely. (CVE-2007-1521)\n\nUnder certain conditions the mb_parse_str() could cause the\nregister_globals configuration option to become permanently enabled.\nThis opened an attack vector for a large and common class of\nvulnerabilities. (CVE-2007-1583)\n\nThe session extension did not set the correct reference count value\nfor the session variables. By unsetting _SESSION and HTTP_SESSION_VARS\n(or tricking a PHP script into doing that) this could be exploited to\nexecute arbitrary code with the privileges of the PHP interpreter. This\nissue does not affect Ubuntu 7.04. (CVE-2007-1700)\n\nThe mail() function did not correctly escape control characters in\nmultiline email headers. This could be remotely exploited to inject\narbitrary email headers. (CVE-2007-1718)\n\nThe php_stream_filter_create() function had an off-by-one buffer\noverflow in the handling of wildcards. This could be exploited to\nremotely crash the PHP interpreter. This issue does not affect Ubuntu\n7.04. (CVE-2007-1824)\n\nWhen calling the sqlite_udf_decode_binary() with special arguments, a\nbuffer overflow happened. Depending on the application this could be\nlocally or remotely exploited to execute arbitrary code with the\nprivileges of the PHP interpreter. (CVE-2007-1887 CVE-2007-1888)\n\nThe FILTER_VALIDATE_EMAIL filter extension used a wrong\nregular expression that allowed injecting a newline character at the\nend of the email string. This could be exploited to inject \narbitrary email headers. This issue only affects Ubuntu 7.04.\n(CVE-2007-1900)","is_hidden":false,"release_packages":{"dapper":[{"name":"php5-cli","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-sqlite","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"php5-cli","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""},{"name":"php5-sqlite","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"php5-cli","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""},{"name":"php5-sqlite","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1888","CVE-2007-1700","CVE-2007-1380","CVE-2007-1900","CVE-2007-1375","CVE-2007-1887","CVE-2007-1521","CVE-2007-1718","CVE-2007-1484","CVE-2007-1376","CVE-2007-1824","CVE-2007-1583"]}]},{"id":"CVE-2007-1887","published":"2007-04-06T01:19:00","updated_at":"2025-07-17T16:41:15.812199+00:00","description":"\nBuffer overflow in the sqlite_decode_binary function in the bundled sqlite\nlibrary in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows\ncontext-dependent attackers to execute arbitrary code via an empty value of\nthe in parameter, as demonstrated by calling the sqlite_udf_decode_binary\nfunction with a 0x01 character.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-455-1","https://www.cve.org/CVERecord?id=CVE-2007-1887"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-455-1"],"notices":[{"id":"USN-455-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-04-27T21:10:26","description":"Stefan Esser discovered multiple vulnerabilities in the \"Month of PHP\nbugs\".\n\nThe substr_compare() function did not sufficiently verify its length\nargument. This might be exploited to read otherwise unaccessible\nmemory, which might lead to information disclosure. (CVE-2007-1375)\n\nThe shared memory (shmop) functions did not verify resource types,\nthus they could be called with a wrong resource type that might\ncontain user supplied data. This could be exploited to read and write\narbitrary memory addresses of the PHP interpreter. This issue does\nnot affect Ubuntu 7.04. (CVE-2007-1376)\n\nThe php_binary handler of the session extension was missing a boundary\ncheck. When unserializing overly long variable names this could be\nexploited to read up to 126 bytes of memory, which might lead to\ninformation disclosure. (CVE-2007-1380)\n\nThe internal array_user_key_compare() function, as used for example by\nthe PHP function uksort(), incorrectly handled memory unreferencing of\nits arguments. This could have been exploited to execute arbitrary\ncode with the privileges of the PHP interpreter, and thus\ncircumventing any disable_functions, open_basedir, or safe_mode\nrestrictions. (CVE-2007-1484)\n\nThe session_regenerate_id() function did not properly clean up the\nformer session identifier variable. This could be exploited to crash\nthe PHP interpreter, possibly also remotely. (CVE-2007-1521)\n\nUnder certain conditions the mb_parse_str() could cause the\nregister_globals configuration option to become permanently enabled.\nThis opened an attack vector for a large and common class of\nvulnerabilities. (CVE-2007-1583)\n\nThe session extension did not set the correct reference count value\nfor the session variables. By unsetting _SESSION and HTTP_SESSION_VARS\n(or tricking a PHP script into doing that) this could be exploited to\nexecute arbitrary code with the privileges of the PHP interpreter. This\nissue does not affect Ubuntu 7.04. (CVE-2007-1700)\n\nThe mail() function did not correctly escape control characters in\nmultiline email headers. This could be remotely exploited to inject\narbitrary email headers. (CVE-2007-1718)\n\nThe php_stream_filter_create() function had an off-by-one buffer\noverflow in the handling of wildcards. This could be exploited to\nremotely crash the PHP interpreter. This issue does not affect Ubuntu\n7.04. (CVE-2007-1824)\n\nWhen calling the sqlite_udf_decode_binary() with special arguments, a\nbuffer overflow happened. Depending on the application this could be\nlocally or remotely exploited to execute arbitrary code with the\nprivileges of the PHP interpreter. (CVE-2007-1887 CVE-2007-1888)\n\nThe FILTER_VALIDATE_EMAIL filter extension used a wrong\nregular expression that allowed injecting a newline character at the\nend of the email string. This could be exploited to inject \narbitrary email headers. This issue only affects Ubuntu 7.04.\n(CVE-2007-1900)","is_hidden":false,"release_packages":{"dapper":[{"name":"php5-cli","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-sqlite","version":"5.1.2-1ubuntu3.7","is_source":false,"source_link":"","version_link":""}],"feisty":[{"name":"php5-cli","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""},{"name":"php5-sqlite","version":"5.2.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"php5-cli","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""},{"name":"php5-sqlite","version":"5.1.6-1ubuntu2.4","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1888","CVE-2007-1700","CVE-2007-1380","CVE-2007-1900","CVE-2007-1375","CVE-2007-1887","CVE-2007-1521","CVE-2007-1718","CVE-2007-1484","CVE-2007-1376","CVE-2007-1824","CVE-2007-1583"]}]},{"id":"CVE-2007-1885","published":"2007-04-06T01:19:00","updated_at":"2025-07-17T16:41:15.812199+00:00","description":"\nInteger overflow in the str_replace function in PHP 4 before 4.4.5 and PHP\n5 before 5.2.1 allows context-dependent attackers to execute arbitrary code\nvia a single character search string in conjunction with a long replacement\nstring, which overflows a 32 bit length counter. NOTE: this is probably\nthe same issue as CVE-2007-0906.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1885"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1884","published":"2007-04-06T01:19:00","updated_at":"2025-07-17T16:41:15.812199+00:00","description":"\nMultiple integer signedness errors in the printf function family in PHP 4\nbefore 4.4.5 and PHP 5 before 5.2.1 on 64 bit machines allow\ncontext-dependent attackers to execute arbitrary code via (1) certain\nnegative argument numbers that arise in the php_formatted_print function\nbecause of 64 to 32 bit truncation, and bypass a check for the maximum\nallowable value; and (2) a width and precision of -1, which make it\npossible for the php_sprintf_appendstring function to place an internal\nbuffer at an arbitrary memory location.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1884"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1883","published":"2007-04-06T01:19:00","updated_at":"2025-07-17T16:41:15.812199+00:00","description":"\nPHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent\nattackers to read arbitrary memory locations via an interruption that\ntriggers a user space error handler that changes a parameter to an\narbitrary pointer, as demonstrated via the iptcembed function, which calls\ncertain convert_to_* functions with its input parameters.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1883"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1352","published":"2007-04-06T01:19:00","updated_at":"2025-07-17T16:40:55.017532+00:00","description":"\nInteger overflow in the FontFileInitTable function in X.Org libXfont before\n20070403 allows remote authenticated users to execute arbitrary code via a\nlong first line in the fonts.dir file, which results in a heap overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-448-1","https://www.cve.org/CVERecord?id=CVE-2007-1352"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libxfont","source":"https://ubuntu.com/security/cve?package=libxfont","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxfont","debian":"https://tracker.debian.org/pkg/libxfont","statuses":[{"release_codename":"dapper","status":"released","description":"1.0.0-0ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.2.0-0ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.2.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-448-1"],"notices":[{"id":"USN-448-1","title":"X.org vulnerabilities","summary":"X.org vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.","references":[],"published":"2007-04-03T23:51:51","description":"Sean Larsson of iDefense Labs discovered that the MISC-XC extension of \nXorg did not correctly verify the size of allocated memory. An \nauthenticated user could send a specially crafted X11 request and \nexecute arbitrary code with root privileges. (CVE-2007-1003)\n\nGreg MacManus of iDefense Labs discovered that the BDF font handling \ncode in Xorg and FreeType did not correctly verify the size of allocated \nmemory. If a user were tricked into using a specially crafted font, a \nremote attacker could execute arbitrary code with root privileges. \n(CVE-2007-1351, CVE-2007-1352)","is_hidden":false,"release_packages":{"dapper":[{"name":"libxfont1","version":"1:1.0.0-0ubuntu3.3","is_source":false,"source_link":"","version_link":""},{"name":"xserver-xorg-core","version":"1:1.0.2-0ubuntu10.6","is_source":false,"source_link":"","version_link":""},{"name":"libfreetype6","version":"2.1.10-1ubuntu2.3","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"libxfont1","version":"1:0.99.0+cvs.20050909-1.3","is_source":false,"source_link":"","version_link":""},{"name":"xserver-xorg-core","version":"6.8.2-77.3","is_source":false,"source_link":"","version_link":""},{"name":"libfreetype6","version":"2.1.7-2.4ubuntu1.3","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libxfont1","version":"1:1.2.0-0ubuntu3.1","is_source":false,"source_link":"","version_link":""},{"name":"xserver-xorg-core","version":"1:1.1.1-0ubuntu12.2","is_source":false,"source_link":"","version_link":""},{"name":"libfreetype6","version":"2.2.1-5ubuntu0.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1351","CVE-2007-1003","CVE-2007-1352"]}]},{"id":"CVE-2007-1351","published":"2007-04-06T01:19:00","updated_at":"2025-07-17T16:40:52.862747+00:00","description":"\nInteger overflow in the bdfReadCharacters function in bdfread.c in (1)\nX.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows\nremote authenticated users to execute arbitrary code via crafted BDF fonts,\nwhich result in a heap overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-448-1","https://www.cve.org/CVERecord?id=CVE-2007-1351"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"freetype","source":"https://ubuntu.com/security/cve?package=freetype","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freetype","debian":"https://tracker.debian.org/pkg/freetype","statuses":[{"release_codename":"dapper","status":"released","description":"2.1.10-1ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.2.1-5ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.2.1-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.3.3","component":null,"pocket":"security"}]},{"name":"libxfont","source":"https://ubuntu.com/security/cve?package=libxfont","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxfont","debian":"https://tracker.debian.org/pkg/libxfont","statuses":[{"release_codename":"dapper","status":"released","description":"1.0.0-0ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.2.0-0ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.2.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-448-1"],"notices":[{"id":"USN-448-1","title":"X.org vulnerabilities","summary":"X.org vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.","references":[],"published":"2007-04-03T23:51:51","description":"Sean Larsson of iDefense Labs discovered that the MISC-XC extension of \nXorg did not correctly verify the size of allocated memory. An \nauthenticated user could send a specially crafted X11 request and \nexecute arbitrary code with root privileges. (CVE-2007-1003)\n\nGreg MacManus of iDefense Labs discovered that the BDF font handling \ncode in Xorg and FreeType did not correctly verify the size of allocated \nmemory. If a user were tricked into using a specially crafted font, a \nremote attacker could execute arbitrary code with root privileges. \n(CVE-2007-1351, CVE-2007-1352)","is_hidden":false,"release_packages":{"dapper":[{"name":"libxfont1","version":"1:1.0.0-0ubuntu3.3","is_source":false,"source_link":"","version_link":""},{"name":"xserver-xorg-core","version":"1:1.0.2-0ubuntu10.6","is_source":false,"source_link":"","version_link":""},{"name":"libfreetype6","version":"2.1.10-1ubuntu2.3","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"libxfont1","version":"1:0.99.0+cvs.20050909-1.3","is_source":false,"source_link":"","version_link":""},{"name":"xserver-xorg-core","version":"6.8.2-77.3","is_source":false,"source_link":"","version_link":""},{"name":"libfreetype6","version":"2.1.7-2.4ubuntu1.3","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libxfont1","version":"1:1.2.0-0ubuntu3.1","is_source":false,"source_link":"","version_link":""},{"name":"xserver-xorg-core","version":"1:1.1.1-0ubuntu12.2","is_source":false,"source_link":"","version_link":""},{"name":"libfreetype6","version":"2.2.1-5ubuntu0.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1351","CVE-2007-1003","CVE-2007-1352"]}]},{"id":"CVE-2007-1216","published":"2007-04-06T01:19:00","updated_at":"2025-07-17T16:40:49.386873+00:00","description":"\nDouble free vulnerability in the GSS-API library\n(lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon\n(kadmind) in MIT krb5 before 1.6.1, when used with the authentication\nmethod provided by the RPCSEC_GSS RPC library, allows remote authenticated\nusers to execute arbitrary code and modify the Kerberos key database via a\nmessage with an \"an invalid direction encoding\".","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-449-1","https://www.cve.org/CVERecord?id=CVE-2007-1216"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.3-5ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.3-9ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.4-5ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-449-1"],"notices":[{"id":"USN-449-1","title":"krb5 vulnerabilities","summary":"krb5 vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-04-04T01:34:13","description":"The krb5 telnet service did not appropriately verify user names. A \nremote attacker could log in as the root user by requesting a specially \ncrafted user name. (CVE-2007-0956)\n\nThe krb5 syslog library did not correctly verify the size of log \nmessages. A remote attacker could send a specially crafted message and \nexecute arbitrary code with root privileges. (CVE-2007-0957)\n\nThe krb5 administration service was vulnerable to a double-free in the \nGSS RPC library. A remote attacker could send a specially crafted \nrequest and execute arbitrary code with root privileges. (CVE-2007-1216)","is_hidden":false,"release_packages":{"dapper":[{"name":"krb5-telnetd","version":"1.4.3-5ubuntu0.3","is_source":false,"source_link":"","version_link":""},{"name":"libkrb53","version":"1.4.3-5ubuntu0.3","is_source":false,"source_link":"","version_link":""},{"name":"libkadm55","version":"1.4.3-5ubuntu0.3","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"krb5-telnetd","version":"1.3.6-4ubuntu0.2","is_source":false,"source_link":"","version_link":""},{"name":"libkrb53","version":"1.3.6-4ubuntu0.2","is_source":false,"source_link":"","version_link":""},{"name":"libkadm55","version":"1.3.6-4ubuntu0.2","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"krb5-telnetd","version":"1.4.3-9ubuntu1.2","is_source":false,"source_link":"","version_link":""},{"name":"libkrb53","version":"1.4.3-9ubuntu1.2","is_source":false,"source_link":"","version_link":""},{"name":"libkadm55","version":"1.4.3-9ubuntu1.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0956","CVE-2007-0957","CVE-2007-1216"]}]},{"id":"CVE-2007-1003","published":"2007-04-06T01:19:00","updated_at":"2025-07-17T16:40:47.803698+00:00","description":"\nInteger overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in\nthe XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and\nother versions before 20070403, allows remote authenticated users to\nexecute arbitrary code via a large expression, which results in memory\ncorruption.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-448-1","https://www.cve.org/CVERecord?id=CVE-2007-1003"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"xorg-server","source":"https://ubuntu.com/security/cve?package=xorg-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server","debian":"https://tracker.debian.org/pkg/xorg-server","statuses":[{"release_codename":"dapper","status":"released","description":"1.0.2-0ubuntu10.7","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.1.1-0ubuntu12.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.2.0-3ubuntu8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-448-1"],"notices":[{"id":"USN-448-1","title":"X.org vulnerabilities","summary":"X.org vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.","references":[],"published":"2007-04-03T23:51:51","description":"Sean Larsson of iDefense Labs discovered that the MISC-XC extension of \nXorg did not correctly verify the size of allocated memory. An \nauthenticated user could send a specially crafted X11 request and \nexecute arbitrary code with root privileges. (CVE-2007-1003)\n\nGreg MacManus of iDefense Labs discovered that the BDF font handling \ncode in Xorg and FreeType did not correctly verify the size of allocated \nmemory. If a user were tricked into using a specially crafted font, a \nremote attacker could execute arbitrary code with root privileges. \n(CVE-2007-1351, CVE-2007-1352)","is_hidden":false,"release_packages":{"dapper":[{"name":"libxfont1","version":"1:1.0.0-0ubuntu3.3","is_source":false,"source_link":"","version_link":""},{"name":"xserver-xorg-core","version":"1:1.0.2-0ubuntu10.6","is_source":false,"source_link":"","version_link":""},{"name":"libfreetype6","version":"2.1.10-1ubuntu2.3","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"libxfont1","version":"1:0.99.0+cvs.20050909-1.3","is_source":false,"source_link":"","version_link":""},{"name":"xserver-xorg-core","version":"6.8.2-77.3","is_source":false,"source_link":"","version_link":""},{"name":"libfreetype6","version":"2.1.7-2.4ubuntu1.3","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libxfont1","version":"1:1.2.0-0ubuntu3.1","is_source":false,"source_link":"","version_link":""},{"name":"xserver-xorg-core","version":"1:1.1.1-0ubuntu12.2","is_source":false,"source_link":"","version_link":""},{"name":"libfreetype6","version":"2.2.1-5ubuntu0.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1351","CVE-2007-1003","CVE-2007-1352"]}]},{"id":"CVE-2007-0957","published":"2007-04-06T01:19:00","updated_at":"2025-07-17T16:40:44.808470+00:00","description":"\nStack-based buffer overflow in the krb5_klog_syslog function in the kadm5\nlibrary, as used by the Kerberos administration daemon (kadmind) and Key\nDistribution Center (KDC), in MIT krb5 before 1.6.1 allows remote\nauthenticated users to execute arbitrary code and modify the Kerberos key\ndatabase via crafted arguments, possibly involving certain format string\nspecifiers.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-449-1","https://www.cve.org/CVERecord?id=CVE-2007-0957"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.3-5ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.3-9ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.4-5ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-449-1"],"notices":[{"id":"USN-449-1","title":"krb5 vulnerabilities","summary":"krb5 vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-04-04T01:34:13","description":"The krb5 telnet service did not appropriately verify user names. A \nremote attacker could log in as the root user by requesting a specially \ncrafted user name. (CVE-2007-0956)\n\nThe krb5 syslog library did not correctly verify the size of log \nmessages. A remote attacker could send a specially crafted message and \nexecute arbitrary code with root privileges. (CVE-2007-0957)\n\nThe krb5 administration service was vulnerable to a double-free in the \nGSS RPC library. A remote attacker could send a specially crafted \nrequest and execute arbitrary code with root privileges. (CVE-2007-1216)","is_hidden":false,"release_packages":{"dapper":[{"name":"krb5-telnetd","version":"1.4.3-5ubuntu0.3","is_source":false,"source_link":"","version_link":""},{"name":"libkrb53","version":"1.4.3-5ubuntu0.3","is_source":false,"source_link":"","version_link":""},{"name":"libkadm55","version":"1.4.3-5ubuntu0.3","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"krb5-telnetd","version":"1.3.6-4ubuntu0.2","is_source":false,"source_link":"","version_link":""},{"name":"libkrb53","version":"1.3.6-4ubuntu0.2","is_source":false,"source_link":"","version_link":""},{"name":"libkadm55","version":"1.3.6-4ubuntu0.2","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"krb5-telnetd","version":"1.4.3-9ubuntu1.2","is_source":false,"source_link":"","version_link":""},{"name":"libkrb53","version":"1.4.3-9ubuntu1.2","is_source":false,"source_link":"","version_link":""},{"name":"libkadm55","version":"1.4.3-9ubuntu1.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0956","CVE-2007-0957","CVE-2007-1216"]}]},{"id":"CVE-2007-0956","published":"2007-04-06T01:19:00","updated_at":"2025-07-17T16:40:44.808470+00:00","description":"\nThe telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote\nattackers to bypass authentication and gain system access via a username\nbeginning with a '-' character, a similar issue to CVE-2007-0882.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-449-1","https://www.cve.org/CVERecord?id=CVE-2007-0956"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.3-5ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.3-9ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.4-5ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-449-1"],"notices":[{"id":"USN-449-1","title":"krb5 vulnerabilities","summary":"krb5 vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-04-04T01:34:13","description":"The krb5 telnet service did not appropriately verify user names. A \nremote attacker could log in as the root user by requesting a specially \ncrafted user name. (CVE-2007-0956)\n\nThe krb5 syslog library did not correctly verify the size of log \nmessages. A remote attacker could send a specially crafted message and \nexecute arbitrary code with root privileges. (CVE-2007-0957)\n\nThe krb5 administration service was vulnerable to a double-free in the \nGSS RPC library. A remote attacker could send a specially crafted \nrequest and execute arbitrary code with root privileges. (CVE-2007-1216)","is_hidden":false,"release_packages":{"dapper":[{"name":"krb5-telnetd","version":"1.4.3-5ubuntu0.3","is_source":false,"source_link":"","version_link":""},{"name":"libkrb53","version":"1.4.3-5ubuntu0.3","is_source":false,"source_link":"","version_link":""},{"name":"libkadm55","version":"1.4.3-5ubuntu0.3","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"krb5-telnetd","version":"1.3.6-4ubuntu0.2","is_source":false,"source_link":"","version_link":""},{"name":"libkrb53","version":"1.3.6-4ubuntu0.2","is_source":false,"source_link":"","version_link":""},{"name":"libkadm55","version":"1.3.6-4ubuntu0.2","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"krb5-telnetd","version":"1.4.3-9ubuntu1.2","is_source":false,"source_link":"","version_link":""},{"name":"libkrb53","version":"1.4.3-9ubuntu1.2","is_source":false,"source_link":"","version_link":""},{"name":"libkadm55","version":"1.4.3-9ubuntu1.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0956","CVE-2007-0957","CVE-2007-1216"]}]},{"id":"CVE-2007-1001","published":"2007-04-06T00:19:00","updated_at":"2025-07-17T16:40:47.803698+00:00","description":"\nMultiple integer overflows in the (1) createwbmp and (2) readwbmp functions\nin wbmp.c in the GD library (libgd) in PHP 4.0.0 through 4.4.6 and 5.0.0\nthrough 5.2.1 allow context-dependent attackers to execute arbitrary code\nvia Wireless Bitmap (WBMP) images with large width or height values.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1001"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libgd2","source":"https://ubuntu.com/security/cve?package=libgd2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgd2","debian":"https://tracker.debian.org/pkg/libgd2","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0242","published":"2007-04-03T16:19:00","updated_at":"2025-07-17T16:40:29.668646+00:00","description":"\nThe UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not\nreject long UTF-8 sequences as required by the standard, which allows\nremote attackers to conduct cross-site scripting (XSS) and directory\ntraversal attacks via long sequences that decode to dangerous\nmetacharacters.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-452-1","https://www.cve.org/CVERecord?id=CVE-2007-0242"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kdelibs","source":"https://ubuntu.com/security/cve?package=kdelibs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kdelibs","debian":"https://tracker.debian.org/pkg/kdelibs","statuses":[{"release_codename":"dapper","status":"released","description":"3.5.2-0ubuntu18.5","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.5.5-0ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.5.6-0ubuntu14.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qt-x11-free","source":"https://ubuntu.com/security/cve?package=qt-x11-free","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qt-x11-free","debian":"https://tracker.debian.org/pkg/qt-x11-free","statuses":[{"release_codename":"dapper","status":"released","description":"3.3.6-1ubuntu6.4","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.3.6-3ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.3.8really3.3.7-0ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-452-1"],"notices":[{"id":"USN-452-1","title":"KDE library vulnerability","summary":"KDE library vulnerability","instructions":"After a standard system upgrade you need to restart your session or \nreboot your computer to effect the necessary changes.","references":[],"published":"2007-04-11T22:22:11","description":"The Qt library did not correctly handle truncated UTF8 strings, which \ncould cause some applications to incorrectly filter malicious strings. \nIf a Konqueror user were tricked into visiting a web site containing \nspecially crafted strings, normal XSS prevention could be bypassed \nallowing a remote attacker to steal confidential data.","is_hidden":false,"release_packages":{"dapper":[{"name":"libqt3-mt","version":"3:3.3.6-1ubuntu6.2","is_source":false,"source_link":"","version_link":""},{"name":"kdelibs4c2a","version":"4:3.5.2-0ubuntu18.4","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"libqt3-mt","version":"3:3.3.4-8ubuntu5.2","is_source":false,"source_link":"","version_link":""},{"name":"kdelibs4c2","version":"4:3.4.3-0ubuntu2.4","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libqt3-mt","version":"3:3.3.6-3ubuntu3.1","is_source":false,"source_link":"","version_link":""},{"name":"kdelibs4c2a","version":"4:3.5.5-0ubuntu3.4","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0242"]}]},{"id":"CVE-2007-1840","published":"2007-04-03T00:19:00","updated_at":"2025-07-17T16:41:14.047699+00:00","description":"\nlib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape\nHTML special characters in LDAP data, which allows remote attackers to have\nan unknown impact, probably cross-site scripting (XSS).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1840"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ldap-account-manager","source":"https://ubuntu.com/security/cve?package=ldap-account-manager","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ldap-account-manager","debian":"https://tracker.debian.org/pkg/ldap-account-manager","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.1.1-2","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.1.1-2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.1-2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.1.1-2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.1-2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.1.1-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1835","published":"2007-04-03T00:19:00","updated_at":"2025-07-17T16:41:11.950899+00:00","description":"\nPHP 4 before 4.4.5 and PHP 5 before 5.2.1, when using an empty session save\npath (session.save_path), uses the TMPDIR default after checking the\nrestrictions, which allows local users to bypass open_basedir restrictions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1835"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-7191","published":"2007-04-03T00:19:00","updated_at":"2025-07-17T16:40:21.076075+00:00","description":"\nUntrusted search path vulnerability in lamdaemon.pl in LDAP Account Manager\n(LAM) before 1.0.0 allows local users to gain privileges via a modified\nPATH that points to a malicious rm program.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-7191"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ldap-account-manager","source":"https://ubuntu.com/security/cve?package=ldap-account-manager","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ldap-account-manager","debian":"https://tracker.debian.org/pkg/ldap-account-manager","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":76660,"limit":20,"total_results":79316}