{"cves":[{"id":"CVE-2007-1474","published":"2007-03-16T21:19:00","updated_at":"2025-07-17T16:41:01.308699+00:00","description":"\nArgument injection vulnerability in the cleanup cron script in Horde\nProject Horde and IMP before Horde Application Framework 3.1.4 allows local\nusers to delete arbitrary files and possibly gain privileges via multiple\nspace-delimited pathnames.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1474"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"horde3","source":"https://ubuntu.com/security/cve?package=horde3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=horde3","debian":"https://tracker.debian.org/pkg/horde3","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.1.3-4","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"3.1.3-4","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.1.3-4","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.1.3-4","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.1.3-4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.1.3-4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1473","published":"2007-03-16T21:19:00","updated_at":"2025-07-17T16:41:01.308699+00:00","description":"\nCross-site scripting (XSS) vulnerability in framework/NLS/NLS.php in Horde\nFramework before 3.1.4 RC1, when the login page contains a language\nselection box, allows remote attackers to inject arbitrary web script or\nHTML via the new_lang parameter to login.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1473"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"horde3","source":"https://ubuntu.com/security/cve?package=horde3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=horde3","debian":"https://tracker.debian.org/pkg/horde3","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"3.1.4-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.1.4-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.1.4-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.1.4-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.1.4-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1466","published":"2007-03-16T21:19:00","updated_at":"2025-07-17T16:41:01.308699+00:00","description":"\nInteger overflow in the WP6GeneralTextPacket::_readContents function in\nWordPerfect Document importer/exporter (libwpd) before 0.8.9 allows\nuser-assisted remote attackers to cause a denial of service (application\ncrash) and possibly execute arbitrary code via a crafted WordPerfect file,\na different vulnerability than CVE-2007-0002.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1466"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libwpd","source":"https://ubuntu.com/security/cve?package=libwpd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libwpd","debian":"https://tracker.debian.org/pkg/libwpd","statuses":[{"release_codename":"dapper","status":"released","description":"0.8.4-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.8.6-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.8.9-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0002","published":"2007-03-16T21:19:00","updated_at":"2025-07-17T16:40:24.719687+00:00","description":"\nMultiple heap-based buffer overflows in WordPerfect Document\nimporter/exporter (libwpd) before 0.8.9 allow user-assisted remote\nattackers to cause a denial of service (application crash) and possibly\nexecute arbitrary code via a crafted WordPerfect file in which values to\nloop counters are not properly handled in the (1)\nWP3TablesGroup::_readContents and (2)\nWP5DefinitionGroup_DefineTablesSubGroup::WP5DefinitionGroup_DefineTablesSubGroup\nfunctions. NOTE: the integer overflow has been split into CVE-2007-1466.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-437-1","https://www.cve.org/CVERecord?id=CVE-2007-0002"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libwpd","source":"https://ubuntu.com/security/cve?package=libwpd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libwpd","debian":"https://tracker.debian.org/pkg/libwpd","statuses":[{"release_codename":"dapper","status":"released","description":"0.8.4-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.8.6-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.8.9-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openoffice.org","source":"https://ubuntu.com/security/cve?package=openoffice.org","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openoffice.org","debian":"https://tracker.debian.org/pkg/openoffice.org","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.2-2ubuntu12.4","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.4-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.2.0-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openoffice.org-amd64","source":"https://ubuntu.com/security/cve?package=openoffice.org-amd64","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openoffice.org-amd64","debian":"https://tracker.debian.org/pkg/openoffice.org-amd64","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.2-2ubuntu12.4-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openoffice.org-l10n","source":"https://ubuntu.com/security/cve?package=openoffice.org-l10n","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openoffice.org-l10n","debian":"https://tracker.debian.org/pkg/openoffice.org-l10n","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.2.0-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-437-1"],"notices":[{"id":"USN-437-1","title":"libwpd vulnerability","summary":"libwpd vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-03-19T22:22:43","description":"Sean Larsson of iDefense Labs discovered that libwpd was vulnerable to \ninteger overflows. If a user were tricked into opening a specially \ncrafted WordPerfect document with an application that used libwpd, an \nattacker could execute arbitrary code with user privileges.","is_hidden":false,"release_packages":{"dapper":[{"name":"libwpd8c2a","version":"0.8.4-2ubuntu0.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"libwpd8c2","version":"0.8.2-2ubuntu0.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libwpd8c2a","version":"0.8.6-1ubuntu0.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0002"]}]},{"id":"CVE-2007-1461","published":"2007-03-14T18:19:00","updated_at":"2025-07-17T16:40:59.552276+00:00","description":"\nThe compress.bzip2:// URL wrapper provided by the bz2 extension in PHP\nbefore 4.4.7, and 5.x before 5.2.2, does not implement safemode or\nopen_basedir checks, which allows remote attackers to read bzip2 archives\nlocated outside of the intended directories.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1461"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1460","published":"2007-03-14T18:19:00","updated_at":"2025-07-17T16:40:59.552276+00:00","description":"\nThe zip:// URL wrapper provided by the PECL zip extension in PHP before\n4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir\nchecks, which allows remote attackers to read ZIP archives located outside\nof the intended directories.","ubuntu_description":"","notes":[{"author":"kees","note":"safe-mode bypass"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1460"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1454","published":"2007-03-14T18:19:00","updated_at":"2025-07-17T16:40:59.552276+00:00","description":"\next/filter in PHP 5.2.0, when FILTER_SANITIZE_STRING is used with the\nFILTER_FLAG_STRIP_LOW flag, does not properly strip HTML tags, which allows\nremote attackers to conduct cross-site scripting (XSS) attacks via HTML\nwith a '<' character followed by certain whitespace characters, which\npasses one filter but is collapsed into a valid tag, as demonstrated using\n%0b.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1454"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1453","published":"2007-03-14T18:19:00","updated_at":"2025-07-17T16:40:59.552276+00:00","description":"\nBuffer underflow in the PHP_FILTER_TRIM_DEFAULT macro in the filtering\nextension (ext/filter) in PHP 5.2.0 allows context-dependent attackers to\nexecute arbitrary code by calling filter_var with certain modes such as\nFILTER_VALIDATE_INT, which causes filter to write a null byte in whitespace\nthat precedes the buffer.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1453"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1452","published":"2007-03-14T18:19:00","updated_at":"2025-07-17T16:40:59.552276+00:00","description":"\nThe FDF support (ext/fdf) in PHP 5.2.0 and earlier does not implement the\ninput filtering hooks for ext/filter, which allows remote attackers to\nbypass web site filters via an application/vnd.fdf formatted POST.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1452"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1444","published":"2007-03-14T00:19:00","updated_at":"2025-07-17T16:40:59.552276+00:00","description":"\nnetserver in netperf 2.4.3 allows local users to overwrite arbitrary files\nvia a symlink attack on /tmp/netperf.debug.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1444"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"netperf","source":"https://ubuntu.com/security/cve?package=netperf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netperf","debian":"https://tracker.debian.org/pkg/netperf","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.4.3-7","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.4.3-7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0720","published":"2007-03-13T21:19:00","updated_at":"2025-07-17T16:40:38.948054+00:00","description":"\nThe CUPS service on multiple platforms allows remote attackers to cause a\ndenial of service (service hang) via a \"partially-negotiated\" SSL\nconnection, which prevents other requests from being accepted.","ubuntu_description":"","notes":[{"author":"kees","note":"The \"fix\" isn't really a fix, and just worsens the diagnostics available to an admin seeking the DoS. This is a design problem with CUPS."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0720"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"cupsys","source":"https://ubuntu.com/security/cve?package=cupsys","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cupsys","debian":"https://tracker.debian.org/pkg/cupsys","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1437","published":"2007-03-13T19:19:00","updated_at":"2025-07-17T16:40:59.552276+00:00","description":"\nUnspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before\n2.6.25 allows remote attackers to overwrite files and possibly bypass\nauthentication, and remote authenticated users to execute unauthorized\ncode, by calling a custom error function that returns from execution.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1437"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sql-ledger","source":"https://ubuntu.com/security/cve?package=sql-ledger","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sql-ledger","debian":"https://tracker.debian.org/pkg/sql-ledger","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.22-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1436","published":"2007-03-13T19:19:00","updated_at":"2025-07-17T16:40:59.552276+00:00","description":"\nUnspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and\nLedgerSMB before 1.1.9 allows remote attackers to bypass authentication via\nunknown vectors that prevents a password check from occurring.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1436"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sql-ledger","source":"https://ubuntu.com/security/cve?package=sql-ledger","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sql-ledger","debian":"https://tracker.debian.org/pkg/sql-ledger","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.22-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1431","published":"2007-03-13T19:19:00","updated_at":"2025-07-17T16:40:59.552276+00:00","description":"\nMultiple unspecified vulnerabilities in PennMUSH 1.8.3 before 1.8.3p1 and\n1.8.2 before 1.8.2p3 allow attackers to cause a denial of service (crash)\nrelated to the (1) speak and (2) buy functions.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"fixed in Debian"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1431"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/pennmush/+bug/153135"],"patches":{},"tags":{},"packages":[{"name":"pennmush","source":"https://ubuntu.com/security/cve?package=pennmush","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pennmush","debian":"https://tracker.debian.org/pkg/pennmush","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.8.2p7-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.8.2p7-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.8.2p7-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.8.2p7-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8.2p3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1387","published":"2007-03-13T19:19:00","updated_at":"2025-07-17T16:40:56.630897+00:00","description":"\nThe DirectShow loader (loader/dshow/DS_VideoDecoder.c) in MPlayer 1.0rc1\nand earlier, as used in xine-lib, does not set the biSize before use in a\nmemcpy, which allows user-assisted remote attackers to cause a buffer\noverflow and possibly execute arbitrary code, a different vulnerability\nthan CVE-2007-1246.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-435-1","https://www.cve.org/CVERecord?id=CVE-2007-1387"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"xine-lib","source":"https://ubuntu.com/security/cve?package=xine-lib","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xine-lib","debian":"https://tracker.debian.org/pkg/xine-lib","statuses":[{"release_codename":"dapper","status":"released","description":"1.1.1+ubuntu2-7.7","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.1.2+repacked1-0ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-435-1"],"notices":[{"id":"USN-435-1","title":"Xine vulnerability","summary":"Xine vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-03-12T23:35:12","description":"Moritz Jodeit discovered that the DirectShow loader of Xine did not \ncorrectly validate the size of an allocated buffer. By tricking a user \ninto opening a specially crafted media file, an attacker could execute \narbitrary code with the user's privileges.","is_hidden":false,"release_packages":{"dapper":[{"name":"libxine-main1","version":"1.1.1+ubuntu2-7.7","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"libxine1c2","version":"1.0.1-1ubuntu10.9","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libxine1","version":"1.1.2+repacked1-0ubuntu3.4","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1387"]}]},{"id":"CVE-2007-1429","published":"2007-03-13T01:19:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow\nremote attackers to execute arbitrary PHP code via a URL in the cmd\nparameter to (1) admin/utfdbmigrate.php or (2) filter.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1429"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"1.8.2-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"1.8.2-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"1.8.2-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.8.2-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.8.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1420","published":"2007-03-12T23:19:00","updated_at":"2025-07-17T16:40:59.552276+00:00","description":"\nMySQL 5.x before 5.0.36 allows local users to cause a denial of service\n(database crash) by performing information_schema table subselects and\nusing ORDER BY to sort a single-row result, which prevents certain\nstructure elements from being initialized and triggers a NULL dereference\nin the filesort function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-440-1","https://www.cve.org/CVERecord?id=CVE-2007-1420"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mysql-dfsg-5.0","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.0","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.0","statuses":[{"release_codename":"dapper","status":"released","description":"5.0.22-0ubuntu6.06.3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.0.24a-9ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.0.38-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-440-1"],"notices":[{"id":"USN-440-1","title":"MySQL vulnerability","summary":"MySQL vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-03-22T02:15:38","description":"Stefan Streichbier and B. Mueller of SEC Consult discovered that MySQL \nsubselect queries using \"ORDER BY\" could be made to crash the MySQL \nserver. An attacker with access to a MySQL instance could cause an\nintermitant denial of service.","is_hidden":false,"release_packages":{"dapper":[{"name":"mysql-server-5.0","version":"5.0.22-0ubuntu6.06.3","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"mysql-server-5.0","version":"5.0.24a-9ubuntu0.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1420"]}]},{"id":"CVE-2007-1413","published":"2007-03-12T23:19:00","updated_at":"2025-07-17T16:40:58.061112+00:00","description":"\nBuffer overflow in the snmpget function in the snmp extension in PHP 5.2.3\nand earlier, including PHP 4.4.6 and probably other PHP 4 versions, allows\ncontext-dependent attackers to execute arbitrary code via a long value in\nthe third argument (object id).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1413"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1412","published":"2007-03-12T23:19:00","updated_at":"2025-07-17T16:40:58.061112+00:00","description":"\nThe cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows\ncontext-dependent attackers to obtain sensitive information (script source\ncode) via a long string in the second argument.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1412"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1000","published":"2007-03-12T23:19:00","updated_at":"2025-07-17T16:40:46.307731+00:00","description":"\nThe ipv6_getsockopt_sticky function in net/ipv6/ipv6_sockglue.c in the\nLinux kernel before 2.6.20.2 allows local users to read arbitrary kernel\nmemory via certain getsockopt calls that trigger a NULL dereference.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-489-1","https://ubuntu.com/security/notices/USN-486-1","https://www.cve.org/CVERecord?id=CVE-2007-1000"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-29.58","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.40","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20-16.31","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-489-1","USN-486-1"],"notices":[{"id":"USN-489-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.","references":[],"published":"2007-07-19T13:57:31","description":"A flaw was discovered in dvb ULE decapsulation. A remote attacker could\nsend a specially crafted message and cause a denial of service.\n(CVE-2006-4623)\n\nThe compat_sys_mount function allowed local users to cause a denial of\nservice when mounting a smbfs filesystem in compatibility mode.\n(CVE-2006-7203)\n\nThe Omnikey CardMan 4040 driver (cm4040_cs) did not limit the size of\nbuffers passed to read() and write(). A local attacker could exploit\nthis to execute arbitrary code with kernel privileges. (CVE-2007-0005)\n\nDue to an variable handling flaw in the ipv6_getsockopt_sticky()\nfunction a local attacker could exploit the getsockopt() calls to read\narbitrary kernel memory. This could disclose sensitive data.\n(CVE-2007-1000)\n\nIlja van Sprundel discovered that Bluetooth setsockopt calls could\nleak kernel memory contents via an uninitialized stack buffer. A local\nattacker could exploit this flaw to view sensitive kernel information.\n(CVE-2007-1353)\n\nA flaw was discovered in the handling of netlink messages. Local\nattackers could cause infinite recursion leading to a denial of service.\n(CVE-2007-1861)\n\nThe random number generator was hashing a subset of the available entropy,\nleading to slightly less random numbers. Additionally, systems without\nan entropy source would be seeded with the same inputs at boot time,\nleading to a repeatable series of random numbers. (CVE-2007-2453)\n\nA flaw was discovered in the PPP over Ethernet implementation. Local\nattackers could manipulate ioctls and cause kernel memory consumption\nleading to a denial of service. (CVE-2007-2525)\n\nAn integer underflow was discovered in the cpuset filesystem. If mounted,\nlocal attackers could obtain kernel memory using large file offsets\nwhile reading the tasks file. This could disclose sensitive data.\n(CVE-2007-2875)\n\nVilmos Nebehaj discovered that the SCTP netfilter code did not correctly\nvalidate certain states. A remote attacker could send a specially\ncrafted packet causing a denial of service. (CVE-2007-2876)\n\nLuca Tettamanti discovered a flaw in the VFAT compat ioctls on 64-bit\nsystems. A local attacker could corrupt a kernel_dirent struct and\ncause a denial of service. (CVE-2007-2878)\n\nA flaw was discovered in the cluster manager. A remote attacker could\nconnect to the DLM port and block further DLM operations.\n(CVE-2007-3380)\n\nA flaw was discovered in the usblcd driver. A local attacker could\ncause large amounts of kernel memory consumption, leading to a denial\nof service. (CVE-2007-3513)","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-image-2.6.15-28-amd64-generic","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-powerpc-smp","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-amd64-k8","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-686","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-powerpc64-smp","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-server-bigiron","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-sparc64-smp","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-mckinley","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-server","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-k7","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-mckinley-smp","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-amd64-server","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-amd64-xeon","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-386","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-powerpc","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-sparc64","version":"2.6.15-28.57","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-4623","CVE-2006-7203","CVE-2007-0005","CVE-2007-1000","CVE-2007-1353","CVE-2007-1861","CVE-2007-2453","CVE-2007-2525","CVE-2007-2875","CVE-2007-2876","CVE-2007-2878","CVE-2007-3380","CVE-2007-3513"]},{"id":"USN-486-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the Ubuntu 6.10 kernel updates\nhave been given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If you\nuse linux-restricted-modules, you have to update that package as well to\nget modules which work with the new kernel version. Unless you manually\nuninstalled the standard kernel metapackages (linux-386, linux-powerpc,\nlinux-amd64-generic, etc), a standard system upgrade will automatically\nperform this as well.","references":[],"published":"2007-07-18T22:57:48","description":"The compat_sys_mount function allowed local users to cause a denial of\nservice when mounting a smbfs filesystem in compatibility mode.\n(CVE-2006-7203)\n\nThe Omnikey CardMan 4040 driver (cm4040_cs) did not limit the size of\nbuffers passed to read() and write(). A local attacker could exploit\nthis to execute arbitrary code with kernel privileges. (CVE-2007-0005)\n\nDue to a variable handling flaw in the ipv6_getsockopt_sticky()\nfunction a local attacker could exploit the getsockopt() calls to\nread arbitrary kernel memory. This could disclose sensitive data.\n(CVE-2007-1000)\n\nIlja van Sprundel discovered that Bluetooth setsockopt calls could leak\nkernel memory contents via an uninitialized stack buffer. A local \nattacker could exploit this flaw to view sensitive kernel information.\n(CVE-2007-1353)\n\nA flaw was discovered in the handling of netlink messages. Local\nattackers could cause infinite recursion leading to a denial of service.\n(CVE-2007-1861)\n\nA flaw was discovered in the IPv6 stack's handling of type 0 route\nheaders. By sending a specially crafted IPv6 packet, a remote attacker\ncould cause a denial of service between two IPv6 hosts. (CVE-2007-2242)\n\nThe random number generator was hashing a subset of the available\nentropy, leading to slightly less random numbers. Additionally, systems\nwithout an entropy source would be seeded with the same inputs at boot\ntime, leading to a repeatable series of random numbers. (CVE-2007-2453)\n\nA flaw was discovered in the PPP over Ethernet implementation. Local\nattackers could manipulate ioctls and cause kernel memory consumption\nleading to a denial of service. (CVE-2007-2525)\n\nAn integer underflow was discovered in the cpuset filesystem. If mounted,\nlocal attackers could obtain kernel memory using large file offsets\nwhile reading the tasks file. This could disclose sensitive data.\n(CVE-2007-2875)\n\nVilmos Nebehaj discovered that the SCTP netfilter code did not correctly\nvalidate certain states. A remote attacker could send a specially\ncrafted packet causing a denial of service. (CVE-2007-2876)\n\nLuca Tettamanti discovered a flaw in the VFAT compat ioctls on 64-bit\nsystems. A local attacker could corrupt a kernel_dirent struct and\ncause a denial of service. (CVE-2007-2878)","is_hidden":false,"release_packages":{"edgy":[{"name":"linux-image-2.6.17-12-mckinley","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-powerpc64-smp","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-hppa32","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-hppa64","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-sparc64-smp","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-generic","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-powerpc-smp","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-386","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-server-bigiron","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-itanium","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-powerpc","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-sparc64","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-12-server","version":"2.6.17.1-12.39","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-2242","CVE-2006-7203","CVE-2007-0005","CVE-2007-1000","CVE-2007-1353","CVE-2007-1861","CVE-2007-2453","CVE-2007-2525","CVE-2007-2875","CVE-2007-2876","CVE-2007-2878"]}]}],"offset":76760,"limit":20,"total_results":79316}