{"cves":[{"id":"CVE-2007-1264","published":"2007-03-06T20:19:00","updated_at":"2025-07-17T16:40:51.108389+00:00","description":"\nEnigmail 0.94.2 and earlier does not properly use the --status-fd argument\nwhen invoking GnuPG, which prevents Enigmail from visually distinguishing\nbetween signed and unsigned portions of OpenPGP messages with multiple\ncomponents, which allows remote attackers to forge the contents of a\nmessage without detection.","ubuntu_description":"","notes":[{"author":"kees","note":"feature-request not security issue since gpg is fixed with CVE-2007-1263"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1264"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"enigmail","source":"https://ubuntu.com/security/cve?package=enigmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=enigmail","debian":"https://tracker.debian.org/pkg/enigmail","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1282","published":"2007-03-06T02:19:00","updated_at":"2025-07-17T16:40:51.108389+00:00","description":"\nInteger overflow in Mozilla Thunderbird before 1.5.0.10 and SeaMonkey\nbefore 1.0.8 allows remote attackers to trigger a buffer overflow and\npossibly execute arbitrary code via a text/enhanced or text/richtext e-mail\nmessage with an extremely long line.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1282"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0.13-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0.13-0ubuntu0.7.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0994","published":"2007-03-06T00:19:00","updated_at":"2025-07-17T16:40:46.307731+00:00","description":"\nA regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before\n1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows\nremote attackers to execute arbitrary JavaScript as the user via an HTML\nmail message with a javascript: URI in an (1) img, (2) link, or (3) style\ntag, which bypasses the access checks and executes code with chrome\nprivileges.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0994"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.0.6+0dfsg-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.0.6+1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1263","published":"2007-03-06T00:00:00","updated_at":"2025-07-17T16:40:51.108389+00:00","description":"\nGnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command\nline, does not visually distinguish signed and unsigned portions of OpenPGP\nmessages with multiple components, which might allow remote attackers to\nforge the contents of a message without detection.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-432-1","https://ubuntu.com/security/notices/USN-432-2","https://www.cve.org/CVERecord?id=CVE-2007-1263"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gnupg","source":"https://ubuntu.com/security/cve?package=gnupg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnupg","debian":"https://tracker.debian.org/pkg/gnupg","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.2.2-1ubuntu2.5","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.3-2ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.6-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.4.6-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.4.6-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.4.6-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.4.6-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.4.6-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gnupg2","source":"https://ubuntu.com/security/cve?package=gnupg2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnupg2","debian":"https://tracker.debian.org/pkg/gnupg2","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.9.21-0ubuntu5.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.3-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.3-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.3-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.3-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.3-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.3-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gpgme1.0","source":"https://ubuntu.com/security/cve?package=gpgme1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpgme1.0","debian":"https://tracker.debian.org/pkg/gpgme1.0","statuses":[{"release_codename":"dapper","status":"released","description":"1.1.0-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.1.2-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.1.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.1.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.1.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.1.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-432-1","USN-432-2"],"notices":[{"id":"USN-432-1","title":"GnuPG vulnerability","summary":"GnuPG vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-03-08T07:04:49","description":"Gerardo Richarte from Core Security Technologies discovered that when \ngnupg is used without --status-fd, there is no way to distinguish \ninitial unsigned messages from a following signed message. An attacker \ncould inject an unsigned message, which could fool the user into \nthinking the message was entirely signed by the original sender.","is_hidden":false,"release_packages":{"dapper":[{"name":"gnupg","version":"1.4.2.2-1ubuntu2.5","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"gnupg","version":"1.4.1-1ubuntu1.7","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"gnupg","version":"1.4.3-2ubuntu3.3","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1263"]},{"id":"USN-432-2","title":"GnuPG2, GPGME vulnerability","summary":"GnuPG2, GPGME vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-03-13T15:39:05","description":"USN-432-1 fixed a vulnerability in GnuPG. This update provides the \ncorresponding updates for GnuPG2 and the GPGME library.\n\nOriginal advisory details:\n\n Gerardo Richarte from Core Security Technologies discovered that when\n gnupg is used without --status-fd, there is no way to distinguish\n initial unsigned messages from a following signed message. An attacker\n could inject an unsigned message, which could fool the user into\n thinking the message was entirely signed by the original sender.","is_hidden":false,"release_packages":{"dapper":[{"name":"libgpgme11","version":"1.1.0-1ubuntu0.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libgpgme11","version":"1.1.2-2ubuntu0.1","is_source":false,"source_link":"","version_link":""},{"name":"gnupg2","version":"1.9.21-0ubuntu5.3","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1263"]}]},{"id":"CVE-2007-1277","published":"2007-03-05T20:19:00","updated_at":"2025-07-17T16:40:51.108389+00:00","description":"\nWordPress 2.1.1, as downloaded from some official distribution sites during\nFebruary and March 2007, contains an externally introduced backdoor that\nallows remote attackers to execute arbitrary commands via (1) an eval\ninjection vulnerability in the ix parameter to wp-includes/feed.php, and\n(2) an untrusted passthru call in the iz parameter to\nwp-includes/theme.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1277"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0774","published":"2007-03-04T22:19:00","updated_at":"2025-07-17T16:40:38.948054+00:00","description":"\nStack-based buffer overflow in the map_uri_to_worker function\n(native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web\nServer Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20,\nallows remote attackers to execute arbitrary code via a long URL that\ntriggers the overflow in a URI worker map routine.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0774"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"tomcat5.5","source":"https://ubuntu.com/security/cve?package=tomcat5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat5.5","debian":"https://tracker.debian.org/pkg/tomcat5.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-7108","published":"2007-03-04T22:19:00","updated_at":"2025-07-17T16:40:19.497075+00:00","description":"\nlogin in util-linux-2.12a skips pam_acct_mgmt and chauth_tok when\nauthentication is skipped, such as when a Kerberos krlogin session has been\nestablished, which might allow users to bypass intended access policies\nthat would be enforced by pam_acct_mgmt and chauth_tok.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-7108"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"util-linux","source":"https://ubuntu.com/security/cve?package=util-linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=util-linux","debian":"https://tracker.debian.org/pkg/util-linux","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-7105","published":"2007-03-03T21:19:00","updated_at":"2025-08-04T19:18:39.145764+00:00","description":"\nPHP remote file inclusion vulnerability in libs/Smarty.class.php in Smarty\n2.6.9 allows remote attackers to execute arbitrary PHP code via a URL in\nthe filename parameter. NOTE: in the original disclosure, filename is used\nin a function definition, so this report is probably incorrect","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-7105"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"smarty","source":"https://ubuntu.com/security/cve?package=smarty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=smarty","debian":"https://tracker.debian.org/pkg/smarty","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1256","published":"2007-03-03T20:19:00","updated_at":"2025-07-17T16:40:51.108389+00:00","description":"\nMozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar,\nfavicons, and document source, and perform updates in the context of\narbitrary websites, by repeatedly setting document.location in the onunload\nattribute when linking to another website, a variant of CVE-2007-1092.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1256"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1253","published":"2007-03-03T20:19:00","updated_at":"2025-07-17T16:40:51.108389+00:00","description":"\nEval injection vulnerability in the (a) kmz_ImportWithMesh.py Script for\nBlender 0.1.9h, as used in (b) Blender before 2.43, allows user-assisted\nremote attackers to execute arbitrary Python code by importing a crafted\n(1) KML or (2) KMZ file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1253"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"blender","source":"https://ubuntu.com/security/cve?package=blender","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=blender","debian":"https://tracker.debian.org/pkg/blender","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.42a-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.43-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1246","published":"2007-03-03T19:19:00","updated_at":"2025-07-17T16:40:49.386873+00:00","description":"\nThe DMO_VideoDecoder_Open function in loader/dmo/DMO_VideoDecoder.c in\nMPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize\nbefore use in a memcpy, which allows user-assisted remote attackers to\ncause a buffer overflow and possibly execute arbitrary code, a different\nvulnerability than CVE-2007-1387.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-433-1","https://www.cve.org/CVERecord?id=CVE-2007-1246"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/mplayer/+bug/92968"],"patches":{},"tags":{},"packages":[{"name":"mplayer","source":"https://ubuntu.com/security/cve?package=mplayer","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mplayer","debian":"https://tracker.debian.org/pkg/mplayer","statuses":[{"release_codename":"dapper","status":"released","description":"2:0.99+1.0pre7try2+cvs20060117-0ubuntu8.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2:0.99+1.0pre8-0ubuntu8.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2:1.0~rc1-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]},{"name":"xine-lib","source":"https://ubuntu.com/security/cve?package=xine-lib","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xine-lib","debian":"https://tracker.debian.org/pkg/xine-lib","statuses":[{"release_codename":"dapper","status":"released","description":"1.1.1+ubuntu2-7.7","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.1.2+repacked1-0ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.1.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.1.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-433-1"],"notices":[{"id":"USN-433-1","title":"Xine vulnerability","summary":"Xine vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-03-09T02:39:34","description":"Moritz Jodeit discovered that the DMO loader of Xine did not correctly \nvalidate the size of an allocated buffer. By tricking a user into \nopening a specially crafted media file, an attacker could execute \narbitrary code with the user's privileges.","is_hidden":false,"release_packages":{"dapper":[{"name":"libxine-main1","version":"1.1.1+ubuntu2-7.6","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"libxine1c2","version":"1.0.1-1ubuntu10.8","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libxine1","version":"1.1.2+repacked1-0ubuntu3.3","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1246"]}]},{"id":"CVE-2007-1244","published":"2007-03-03T19:19:00","updated_at":"2025-07-17T16:40:49.386873+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in the AdminPanel in\nWordPress 2.1.1 and earlier allows remote attackers to perform privileged\nactions as administrators, as demonstrated using the delete action in\nwp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site\nscripting (XSS) attacks and steal cookies via the post parameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1244"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.10","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-7098","published":"2007-03-03T19:19:00","updated_at":"2025-07-17T16:40:19.497075+00:00","description":"\nThe Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server\n1.3.34-4 does not properly disassociate httpd from a controlling tty when\nhttpd is started interactively, which allows local users to gain privileges\nto that tty via a CGI program that calls the TIOCSTI ioctl.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-7098"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"apache","source":"https://ubuntu.com/security/cve?package=apache","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache","debian":"https://tracker.debian.org/pkg/apache","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1230","published":"2007-03-02T22:19:00","updated_at":"2025-07-17T16:40:49.386873+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in\nwp-includes/functions.php in WordPress before 2.1.2-alpha allow remote\nattackers to inject arbitrary web script or HTML via (1) the Referer HTTP\nheader or (2) the URI, a different vulnerability than CVE-2007-1049.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1230"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.9","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1218","published":"2007-03-02T21:18:00","updated_at":"2025-07-17T16:40:49.386873+00:00","description":"\nOff-by-one buffer overflow in the parse_elements function in the 802.11\nprinter code (print-802_11.c) for tcpdump 3.9.5 and earlier allows remote\nattackers to cause a denial of service (crash) via a crafted 802.11 frame.\nNOTE: this was originally referred to as heap-based, but it might be\nstack-based.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-429-1","https://www.cve.org/CVERecord?id=CVE-2007-1218"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"tcpdump","source":"https://ubuntu.com/security/cve?package=tcpdump","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tcpdump","debian":"https://tracker.debian.org/pkg/tcpdump","statuses":[{"release_codename":"dapper","status":"released","description":"3.9.4-2ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.9.4-4ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.9.5-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-429-1"],"notices":[{"id":"USN-429-1","title":"tcpdump vulnerability","summary":"tcpdump vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-03-06T22:01:41","description":"Moritz Jodeit discovered that tcpdump had an overflow in the 802.11 \npacket parser. Remote attackers could send specially crafted packets, \ncrashing tcpdump, possibly leading to a denial of service.","is_hidden":false,"release_packages":{"dapper":[{"name":"tcpdump","version":"3.9.4-2ubuntu0.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"tcpdump","version":"3.9.1-1ubuntu1.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"tcpdump","version":"3.9.4-4ubuntu0.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1218"]}]},{"id":"CVE-2007-1217","published":"2007-03-02T21:18:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the bufprint function in capiutil.c in libcapi, as used\nin Linux kernel 2.6.9 to 2.6.20 and isdn4k-utils, allows local users to\ncause a denial of service (crash) and possibly gain privileges via a\ncrafted CAPI packet.","ubuntu_description":"","notes":[{"author":"kees","note":"This doesn't appear exploitable unless debugging has been enabled\nand the other physical end of the ISDN connection is the attacker."}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1217"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"isdnutils","source":"https://ubuntu.com/security/cve?package=isdnutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=isdnutils","debian":"https://tracker.debian.org/pkg/isdnutils","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:3.9.20060704-3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1199","published":"2007-03-02T21:18:00","updated_at":"2025-07-17T16:40:49.386873+00:00","description":"\nAdobe Reader and Acrobat Trial allow remote attackers to read arbitrary\nfiles via a file:// URI in a PDF document, as demonstrated with\n<>, a different issue than CVE-2007-0045.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1199"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"9.1.0-7hardy1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-7094","published":"2007-03-02T21:18:00","updated_at":"2025-07-17T16:40:19.497075+00:00","description":"\nftpd, as used by Gentoo and Debian Linux, sets the gid to the effective uid\ninstead of the effective group id before executing /bin/ls, which allows\nremote authenticated users to list arbitrary directories with the\nprivileges of gid 0 and possibly enable additional attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-7094"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-ftpd","source":"https://ubuntu.com/security/cve?package=linux-ftpd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ftpd","debian":"https://tracker.debian.org/pkg/linux-ftpd","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.17-24","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0996","published":"2007-02-27T02:28:00","updated_at":"2025-07-17T16:40:46.307731+00:00","description":"\nThe child frames in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2,\nand SeaMonkey before 1.0.8 inherit the default charset from the parent\nwindow, which allows remote attackers to conduct cross-site scripting (XSS)\nattacks, as demonstrated using the UTF-7 character set.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-428-1","https://www.cve.org/CVERecord?id=CVE-2007-0996"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.0.6+0dfsg-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.0.6+1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-428-1"],"notices":[{"id":"USN-428-1","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.","references":[],"published":"2007-03-01T02:56:42","description":"Several flaws have been found that could be used to perform Cross-site\nscripting attacks. A malicious web site could exploit these to modify\nthe contents or steal confidential data (such as passwords) from other\nopened web pages. (CVE-2006-6077, CVE-2007-0780, CVE-2007-0800,\nCVE-2007-0981, CVE-2007-0995, CVE-2007-0996)\n\nThe SSLv2 protocol support in the NSS library did not sufficiently\ncheck the validity of public keys presented with a SSL certificate. A\nmalicious SSL web site using SSLv2 could potentially exploit this to\nexecute arbitrary code with the user's privileges. (CVE-2007-0008)\n\nThe SSLv2 protocol support in the NSS library did not sufficiently\nverify the validity of client master keys presented in an SSL client\ncertificate. A remote attacker could exploit this to execute arbitrary\ncode in a server application that uses the NSS library.\n(CVE-2007-0009)\n\nVarious flaws have been reported that could allow an attacker to\nexecute arbitrary code with user privileges by tricking the user into\nopening a malicious web page. (CVE-2007-0775, CVE-2007-0776,\nCVE-2007-0777, CVE-2007-1092)\n\nTwo web pages could collide in the disk cache with the result that\ndepending on order loaded the end of the longer document could be\nappended to the shorter when the shorter one was reloaded from the\ncache. It is possible a determined hacker could construct a targeted\nattack to steal some sensitive data from a particular web page. The\npotential victim would have to be already logged into the targeted\nservice (or be fooled into doing so) and then visit the malicious\nsite. (CVE-2007-0778)\n\nDavid Eckel reported that browser UI elements--such as the host name\nand security indicators--could be spoofed by using custom cursor\nimages and a specially crafted style sheet. (CVE-2007-0779)","is_hidden":false,"release_packages":{"dapper":[{"name":"libnspr4","version":"1.5.dfsg+1.5.0.10-0ubuntu0.6.06.1","is_source":false,"source_link":"","version_link":""},{"name":"firefox","version":"1.5.dfsg+1.5.0.10-0ubuntu0.6.06.1","is_source":false,"source_link":"","version_link":""},{"name":"libnss3","version":"1.5.dfsg+1.5.0.10-0ubuntu0.6.06.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"firefox","version":"1.5.dfsg+1.5.0.10-0ubuntu0.5.10.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libnspr4","version":"2.0.0.2+0dfsg-0ubuntu0.6.10","is_source":false,"source_link":"","version_link":""},{"name":"firefox","version":"2.0.0.2+0dfsg-0ubuntu0.6.10","is_source":false,"source_link":"","version_link":""},{"name":"libnss3","version":"2.0.0.2+0dfsg-0ubuntu0.6.10","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1092","CVE-2007-0780","CVE-2007-0775","CVE-2007-0008","CVE-2007-0995","CVE-2007-0009","CVE-2007-0778","CVE-2007-0981","CVE-2007-0779","CVE-2007-0996","CVE-2007-0776","CVE-2006-6077","CVE-2007-0800","CVE-2007-0777"]}]},{"id":"CVE-2007-1116","published":"2007-02-26T23:28:00","updated_at":"2025-07-17T16:40:49.386873+00:00","description":"\nThe CheckLoadURI function in Mozilla Firefox 1.8 lists the about: URI as a\nChromeProtocol and can be loaded via JavaScript, which allows remote\nattackers to obtain sensitive information by querying the browser's session\nhistory.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1116"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.8.1.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.8.1.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":76820,"limit":20,"total_results":79316}