{"cves":[{"id":"CVE-2007-1049","published":"2007-02-21T17:28:00","updated_at":"2025-07-17T16:40:47.803698+00:00","description":"\nCross-site scripting (XSS) vulnerability in the wp_explain_nonce function\nin the nonce AYS functionality (wp-includes/functions.php) for WordPress\n2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject\narbitrary web script or HTML via the file parameter to\nwp-admin/templates.php, and possibly other vectors involving the action\nvariable.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1049"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.9","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1047","published":"2007-02-21T17:28:00","updated_at":"2025-07-17T16:40:47.803698+00:00","description":"\nUnspecified vulnerability in Distributed Checksum Clearinghouse (DCC)\nbefore 1.3.51 allows remote attackers to delete or add hosts in\n/var/dcc/maps.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1047"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"dcc","source":"https://ubuntu.com/security/cve?package=dcc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dcc","debian":"https://tracker.debian.org/pkg/dcc","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1030","published":"2007-02-21T11:28:00","updated_at":"2025-07-17T16:40:47.803698+00:00","description":"\nNiels Provos libevent 1.2 and 1.2a allows remote attackers to cause a\ndenial of service (infinite loop) via a DNS response containing a label\npointer that references its own offset.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1030"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libevent","source":"https://ubuntu.com/security/cve?package=libevent","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libevent","debian":"https://tracker.debian.org/pkg/libevent","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1007","published":"2007-02-20T17:28:00","updated_at":"2025-07-17T16:40:47.803698+00:00","description":"\nFormat string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote\nattackers to cause a denial of service (crash) and possibly execute\narbitrary code via format strings in the name, which is not properly\nhandled in a call to the gnomemeeting_log_insert function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-426-1","https://www.cve.org/CVERecord?id=CVE-2007-1007"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gnomemeeting","source":"https://ubuntu.com/security/cve?package=gnomemeeting","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnomemeeting","debian":"https://tracker.debian.org/pkg/gnomemeeting","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-426-1"],"notices":[{"id":"USN-426-1","title":"Ekiga vulnerabilities","summary":"Ekiga vulnerabilities","instructions":"After a standard system upgrade you need to restart Ekiga to effect the \nnecessary changes.","references":[],"published":"2007-02-22T07:38:51","description":"Mu Security discovered a format string vulnerability in Ekiga. If a \nuser was running Ekiga and listening for incoming calls, a remote \nattacker could send a crafted call request, and execute arbitrary code \nwith the user's privileges.","is_hidden":false,"release_packages":{"dapper":[{"name":"ekiga","version":"2.0.1-0ubuntu6.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"gnomemeeting","version":"1.2.2-1ubuntu1.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"ekiga","version":"2.0.3-0ubuntu3.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1006","CVE-2007-1007"]}]},{"id":"CVE-2007-0988","published":"2007-02-20T17:28:00","updated_at":"2025-07-17T16:40:46.307731+00:00","description":"\nThe zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 before 4.4.5,\nwhen running on a 64-bit platform, allows context-dependent attackers to\ncause a denial of service (infinite loop) by unserializing certain integer\nexpressions, which only cause 32-bit arguments to be used after the check\nfor a negative value, as demonstrated by an \"a:2147483649:{\" argument.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-424-1","https://www.cve.org/CVERecord?id=CVE-2007-0988"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-424-1"],"notices":[{"id":"USN-424-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"After a standard system upgrade you need to restart Apache or reboot\nyour computer to effect the necessary changes.","references":[],"published":"2007-02-22T01:42:17","description":"Multiple buffer overflows have been discovered in various PHP modules.\nIf a PHP application processes untrusted data with functions of the\nsession or zip module, or various string functions, a remote attacker\ncould exploit this to execute arbitrary code with the privileges of\nthe web server. (CVE-2007-0906)\n\nThe sapi_header_op() function had a buffer underflow that could be\nexploited to crash the PHP interpreter. (CVE-2007-0907)\n\nThe wddx unserialization handler did not correctly check for some\nbuffer boundaries and had an uninitialized variable. By unserializing\nuntrusted data, this could be exploited to expose memory regions that\nwere not meant to be accessible. Depending on the PHP application this\ncould lead to disclosure of potentially sensitive information.\n(CVE-2007-0908)\n\nOn 64 bit systems (the amd64 and sparc platforms), various print\nfunctions and the odbc_result_all() were susceptible to a format\nstring vulnerability. A remote attacker could exploit this to execute\narbitrary code with the privileges of the web server. (CVE-2007-0909)\n\nUnder certain circumstances it was possible to overwrite superglobal\nvariables (like the HTTP GET/POST arrays) with crafted session data.\n(CVE-2007-0910)\n\nWhen unserializing untrusted data on 64-bit platforms the\nzend_hash_init() function could be forced to enter an infinite loop,\nconsuming CPU resources, for a limited length of time, until the\nscript timeout alarm aborts the script. (CVE-2007-0988)","is_hidden":false,"release_packages":{"dapper":[{"name":"php5-cli","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"php5-common","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"php5-odbc","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"php5-cli","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-common","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-odbc","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"php5-cli","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-common","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-odbc","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0906","CVE-2007-0907","CVE-2007-0908","CVE-2007-0909","CVE-2007-0910","CVE-2007-0988"]}]},{"id":"CVE-2007-0772","published":"2007-02-20T17:28:00","updated_at":"2025-07-17T16:40:38.948054+00:00","description":"\nThe Linux kernel 2.6.13 and other versions before 2.6.20.1 allows remote\nattackers to cause a denial of service (oops) via a crafted NFSACL 2 ACCESS\nrequest that triggers a free of an incorrect pointer.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-451-1","https://www.cve.org/CVERecord?id=CVE-2007-0772"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-29.58","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.40","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.20-16.31","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-451-1"],"notices":[{"id":"USN-451-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.","references":[],"published":"2007-04-11T00:08:50","description":"The kernel key management code did not correctly handle key reuse. A \nlocal attacker could create many key requests, leading to a denial of \nservice. (CVE-2007-0006)\n\nThe kernel NFS code did not correctly validate NFSACL2 ACCESS requests. \nIf a system was serving NFS mounts, a remote attacker could send a \nspecially crafted packet, leading to a denial of service. \n(CVE-2007-0772)\n\nWhen dumping core, the kernel did not correctly handle PT_INTERP \nprocesses. A local attacker could create situations where they could \nread the contents of otherwise unreadable executable programs. \n(CVE-2007-0958)","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-image-2.6.15-28-amd64-generic","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-powerpc-smp","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-amd64-k8","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-686","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-powerpc64-smp","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-server-bigiron","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-sparc64-smp","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-server","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-k7","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-amd64-server","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-amd64-xeon","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-386","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-powerpc","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-sparc64","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"linux-image-2.6.17-11-generic","version":"2.6.17.1-11.37","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-server-bigiron","version":"2.6.17.1-11.37","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-sparc64-smp","version":"2.6.17.1-11.37","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-powerpc","version":"2.6.17.1-11.37","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-386","version":"2.6.17.1-11.37","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-powerpc-smp","version":"2.6.17.1-11.37","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-sparc64","version":"2.6.17.1-11.37","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-server","version":"2.6.17.1-11.37","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-powerpc64-smp","version":"2.6.17.1-11.37","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0006","CVE-2007-0772","CVE-2007-0958"]}]},{"id":"CVE-2007-1004","published":"2007-02-20T02:28:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox might allow remote attackers to conduct spoofing and\nphishing attacks by writing to an about:blank tab and overlaying the\nlocation bar.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"I have sanitized test code that demonstrates the vulnerability"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-1004"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=370555"],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0007","published":"2007-02-20T02:28:00","updated_at":"2025-07-17T16:40:24.719687+00:00","description":"\ngnucash 2.0.4 and earlier allows local users to overwrite arbitrary files\nvia a symlink attack on the (1) gnucash.trace, (2) qof.trace, and (3)\nqof.trace.[PID] temporary files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0007"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gnucash","source":"https://ubuntu.com/security/cve?package=gnucash","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnucash","debian":"https://tracker.debian.org/pkg/gnucash","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-1006","published":"2007-02-20T01:28:00","updated_at":"2025-07-17T16:40:47.803698+00:00","description":"\nMultiple format string vulnerabilities in the gm_main_window_flash_message\nfunction in Ekiga before 2.0.5 allow attackers to cause a denial of service\nand possibly execute arbitrary code via a crafted Q.931 SETUP packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-426-1","https://www.cve.org/CVERecord?id=CVE-2007-1006"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ekiga","source":"https://ubuntu.com/security/cve?package=ekiga","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ekiga","debian":"https://tracker.debian.org/pkg/ekiga","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.1-0ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.3-0ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.3-0ubuntu8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-426-1"],"notices":[{"id":"USN-426-1","title":"Ekiga vulnerabilities","summary":"Ekiga vulnerabilities","instructions":"After a standard system upgrade you need to restart Ekiga to effect the \nnecessary changes.","references":[],"published":"2007-02-22T07:38:51","description":"Mu Security discovered a format string vulnerability in Ekiga. If a \nuser was running Ekiga and listening for incoming calls, a remote \nattacker could send a crafted call request, and execute arbitrary code \nwith the user's privileges.","is_hidden":false,"release_packages":{"dapper":[{"name":"ekiga","version":"2.0.1-0ubuntu6.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"gnomemeeting","version":"1.2.2-1ubuntu1.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"ekiga","version":"2.0.3-0ubuntu3.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1006","CVE-2007-1007"]}]},{"id":"CVE-2006-5276","published":"2007-02-20T01:28:00","updated_at":"2025-07-17T16:39:50.384274+00:00","description":"\nStack-based buffer overflow in the DCE/RPC preprocessor in Snort before\n2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows\nremote attackers to execute arbitrary code via crafted SMB traffic.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-5276"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"snort","source":"https://ubuntu.com/security/cve?package=snort","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=snort","debian":"https://tracker.debian.org/pkg/snort","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0898","published":"2007-02-16T19:28:00","updated_at":"2025-07-17T16:40:42.080419+00:00","description":"\nDirectory traversal vulnerability in clamd in Clam AntiVirus ClamAV before\n0.90 allows remote attackers to overwrite arbitrary files via a .. (dot\ndot) in the id MIME header parameter in a multi-part message.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0898"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"dapper","status":"released","description":"0.92.1~dfsg2-1.1~dapper2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.90.2-0ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.91.2-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.91.2-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0897","published":"2007-02-16T19:28:00","updated_at":"2025-07-17T16:40:42.080419+00:00","description":"\nClam AntiVirus ClamAV before 0.90 does not close open file descriptors\nunder certain conditions, which allows remote attackers to cause a denial\nof service (file descriptor consumption and failed scans) via CAB archives\nwith a cabinet header record length of zero, which causes a function to\nreturn without closing a file descriptor.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0897"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"dapper","status":"released","description":"0.92.1~dfsg2-1.1~dapper2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.90.2-0ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.91.2-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.91.2-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0451","published":"2007-02-16T19:28:00","updated_at":"2025-07-17T16:40:31.809691+00:00","description":"\nApache SpamAssassin before 3.1.8 allows remote attackers to cause a denial\nof service via long URLs in malformed HTML, which triggers \"massive memory\nusage.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0451"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"spamassassin","source":"https://ubuntu.com/security/cve?package=spamassassin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=spamassassin","debian":"https://tracker.debian.org/pkg/spamassassin","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.1.7-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"3.1.7-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.1.7-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.1.7-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.1.7-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.1.7-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0981","published":"2007-02-16T01:28:00","updated_at":"2025-07-17T16:40:46.307731+00:00","description":"\nMozilla based browsers, including Firefox before 1.5.0.10 and 2.x before\n2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the\nsame origin policy, steal cookies, and conduct other attacks by writing a\nURI with a null byte to the hostname (location.hostname) DOM property, due\nto interactions with DNS resolver code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-428-1","https://www.cve.org/CVERecord?id=CVE-2007-0981"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.0.6+0dfsg-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.0.6+1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"iceape","source":"https://ubuntu.com/security/cve?package=iceape","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=iceape","debian":"https://tracker.debian.org/pkg/iceape","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.1.4-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.5-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.1.6b-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.8.0.10-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.8.0.10-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-428-1"],"notices":[{"id":"USN-428-1","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.","references":[],"published":"2007-03-01T02:56:42","description":"Several flaws have been found that could be used to perform Cross-site\nscripting attacks. A malicious web site could exploit these to modify\nthe contents or steal confidential data (such as passwords) from other\nopened web pages. (CVE-2006-6077, CVE-2007-0780, CVE-2007-0800,\nCVE-2007-0981, CVE-2007-0995, CVE-2007-0996)\n\nThe SSLv2 protocol support in the NSS library did not sufficiently\ncheck the validity of public keys presented with a SSL certificate. A\nmalicious SSL web site using SSLv2 could potentially exploit this to\nexecute arbitrary code with the user's privileges. (CVE-2007-0008)\n\nThe SSLv2 protocol support in the NSS library did not sufficiently\nverify the validity of client master keys presented in an SSL client\ncertificate. A remote attacker could exploit this to execute arbitrary\ncode in a server application that uses the NSS library.\n(CVE-2007-0009)\n\nVarious flaws have been reported that could allow an attacker to\nexecute arbitrary code with user privileges by tricking the user into\nopening a malicious web page. (CVE-2007-0775, CVE-2007-0776,\nCVE-2007-0777, CVE-2007-1092)\n\nTwo web pages could collide in the disk cache with the result that\ndepending on order loaded the end of the longer document could be\nappended to the shorter when the shorter one was reloaded from the\ncache. It is possible a determined hacker could construct a targeted\nattack to steal some sensitive data from a particular web page. The\npotential victim would have to be already logged into the targeted\nservice (or be fooled into doing so) and then visit the malicious\nsite. (CVE-2007-0778)\n\nDavid Eckel reported that browser UI elements--such as the host name\nand security indicators--could be spoofed by using custom cursor\nimages and a specially crafted style sheet. (CVE-2007-0779)","is_hidden":false,"release_packages":{"dapper":[{"name":"libnspr4","version":"1.5.dfsg+1.5.0.10-0ubuntu0.6.06.1","is_source":false,"source_link":"","version_link":""},{"name":"firefox","version":"1.5.dfsg+1.5.0.10-0ubuntu0.6.06.1","is_source":false,"source_link":"","version_link":""},{"name":"libnss3","version":"1.5.dfsg+1.5.0.10-0ubuntu0.6.06.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"firefox","version":"1.5.dfsg+1.5.0.10-0ubuntu0.5.10.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libnspr4","version":"2.0.0.2+0dfsg-0ubuntu0.6.10","is_source":false,"source_link":"","version_link":""},{"name":"firefox","version":"2.0.0.2+0dfsg-0ubuntu0.6.10","is_source":false,"source_link":"","version_link":""},{"name":"libnss3","version":"2.0.0.2+0dfsg-0ubuntu0.6.10","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-1092","CVE-2007-0780","CVE-2007-0775","CVE-2007-0008","CVE-2007-0995","CVE-2007-0009","CVE-2007-0778","CVE-2007-0981","CVE-2007-0779","CVE-2007-0996","CVE-2007-0776","CVE-2006-6077","CVE-2007-0800","CVE-2007-0777"]}]},{"id":"CVE-2007-0958","published":"2007-02-15T18:28:00","updated_at":"2025-07-17T16:40:46.307731+00:00","description":"\nLinux kernel 2.6.x before 2.6.20 allows local users to read unreadable\nbinaries by using the interpreter (PT_INTERP) functionality and triggering\na core dump, a variant of CVE-2004-1073.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-451-1","https://www.cve.org/CVERecord?id=CVE-2007-0958"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-29.58","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.40","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-451-1"],"notices":[{"id":"USN-451-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.","references":[],"published":"2007-04-11T00:08:50","description":"The kernel key management code did not correctly handle key reuse. A \nlocal attacker could create many key requests, leading to a denial of \nservice. (CVE-2007-0006)\n\nThe kernel NFS code did not correctly validate NFSACL2 ACCESS requests. \nIf a system was serving NFS mounts, a remote attacker could send a \nspecially crafted packet, leading to a denial of service. \n(CVE-2007-0772)\n\nWhen dumping core, the kernel did not correctly handle PT_INTERP \nprocesses. A local attacker could create situations where they could \nread the contents of otherwise unreadable executable programs. \n(CVE-2007-0958)","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-image-2.6.15-28-amd64-generic","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-powerpc-smp","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-amd64-k8","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-686","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-powerpc64-smp","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-server-bigiron","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-sparc64-smp","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-server","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-k7","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-amd64-server","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-amd64-xeon","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-386","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-powerpc","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-28-sparc64","version":"2.6.15-28.53","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"linux-image-2.6.17-11-generic","version":"2.6.17.1-11.37","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-server-bigiron","version":"2.6.17.1-11.37","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-sparc64-smp","version":"2.6.17.1-11.37","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-powerpc","version":"2.6.17.1-11.37","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-386","version":"2.6.17.1-11.37","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-powerpc-smp","version":"2.6.17.1-11.37","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-sparc64","version":"2.6.17.1-11.37","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-server","version":"2.6.17.1-11.37","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.17-11-powerpc64-smp","version":"2.6.17.1-11.37","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0006","CVE-2007-0772","CVE-2007-0958"]}]},{"id":"CVE-2007-0911","published":"2007-02-13T23:28:00","updated_at":"2025-07-17T16:40:44.808470+00:00","description":"\nOff-by-one error in the str_ireplace function in PHP 5.2.1 might allow\ncontext-dependent attackers to cause a denial of service (crash).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0911"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0910","published":"2007-02-13T23:28:00","updated_at":"2025-07-17T16:40:44.808470+00:00","description":"\nUnspecified vulnerability in PHP before 5.2.1 allows attackers to \"clobber\"\ncertain super-global variables via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-424-1","https://www.cve.org/CVERecord?id=CVE-2007-0910"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-424-1"],"notices":[{"id":"USN-424-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"After a standard system upgrade you need to restart Apache or reboot\nyour computer to effect the necessary changes.","references":[],"published":"2007-02-22T01:42:17","description":"Multiple buffer overflows have been discovered in various PHP modules.\nIf a PHP application processes untrusted data with functions of the\nsession or zip module, or various string functions, a remote attacker\ncould exploit this to execute arbitrary code with the privileges of\nthe web server. (CVE-2007-0906)\n\nThe sapi_header_op() function had a buffer underflow that could be\nexploited to crash the PHP interpreter. (CVE-2007-0907)\n\nThe wddx unserialization handler did not correctly check for some\nbuffer boundaries and had an uninitialized variable. By unserializing\nuntrusted data, this could be exploited to expose memory regions that\nwere not meant to be accessible. Depending on the PHP application this\ncould lead to disclosure of potentially sensitive information.\n(CVE-2007-0908)\n\nOn 64 bit systems (the amd64 and sparc platforms), various print\nfunctions and the odbc_result_all() were susceptible to a format\nstring vulnerability. A remote attacker could exploit this to execute\narbitrary code with the privileges of the web server. (CVE-2007-0909)\n\nUnder certain circumstances it was possible to overwrite superglobal\nvariables (like the HTTP GET/POST arrays) with crafted session data.\n(CVE-2007-0910)\n\nWhen unserializing untrusted data on 64-bit platforms the\nzend_hash_init() function could be forced to enter an infinite loop,\nconsuming CPU resources, for a limited length of time, until the\nscript timeout alarm aborts the script. (CVE-2007-0988)","is_hidden":false,"release_packages":{"dapper":[{"name":"php5-cli","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"php5-common","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"php5-odbc","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"php5-cli","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-common","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-odbc","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"php5-cli","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-common","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-odbc","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0906","CVE-2007-0907","CVE-2007-0908","CVE-2007-0909","CVE-2007-0910","CVE-2007-0988"]}]},{"id":"CVE-2007-0909","published":"2007-02-13T23:28:00","updated_at":"2025-07-17T16:40:44.808470+00:00","description":"\nMultiple format string vulnerabilities in PHP before 5.2.1 might allow\nattackers to execute arbitrary code via format string specifiers to (1) all\nof the *print functions on 64-bit systems, and (2) the odbc_result_all\nfunction.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-424-1","https://www.cve.org/CVERecord?id=CVE-2007-0909"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-424-1"],"notices":[{"id":"USN-424-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"After a standard system upgrade you need to restart Apache or reboot\nyour computer to effect the necessary changes.","references":[],"published":"2007-02-22T01:42:17","description":"Multiple buffer overflows have been discovered in various PHP modules.\nIf a PHP application processes untrusted data with functions of the\nsession or zip module, or various string functions, a remote attacker\ncould exploit this to execute arbitrary code with the privileges of\nthe web server. (CVE-2007-0906)\n\nThe sapi_header_op() function had a buffer underflow that could be\nexploited to crash the PHP interpreter. (CVE-2007-0907)\n\nThe wddx unserialization handler did not correctly check for some\nbuffer boundaries and had an uninitialized variable. By unserializing\nuntrusted data, this could be exploited to expose memory regions that\nwere not meant to be accessible. Depending on the PHP application this\ncould lead to disclosure of potentially sensitive information.\n(CVE-2007-0908)\n\nOn 64 bit systems (the amd64 and sparc platforms), various print\nfunctions and the odbc_result_all() were susceptible to a format\nstring vulnerability. A remote attacker could exploit this to execute\narbitrary code with the privileges of the web server. (CVE-2007-0909)\n\nUnder certain circumstances it was possible to overwrite superglobal\nvariables (like the HTTP GET/POST arrays) with crafted session data.\n(CVE-2007-0910)\n\nWhen unserializing untrusted data on 64-bit platforms the\nzend_hash_init() function could be forced to enter an infinite loop,\nconsuming CPU resources, for a limited length of time, until the\nscript timeout alarm aborts the script. (CVE-2007-0988)","is_hidden":false,"release_packages":{"dapper":[{"name":"php5-cli","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"php5-common","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"php5-odbc","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"php5-cli","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-common","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-odbc","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"php5-cli","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-common","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-odbc","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0906","CVE-2007-0907","CVE-2007-0908","CVE-2007-0909","CVE-2007-0910","CVE-2007-0988"]}]},{"id":"CVE-2007-0908","published":"2007-02-13T23:28:00","updated_at":"2025-07-17T16:40:44.808470+00:00","description":"\nThe WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4\nbefore 4.4.5 does not properly initialize the key_length variable for a\nnumerical key, which allows context-dependent attackers to read stack\nmemory via a wddxPacket element that contains a variable with a string name\nbefore a numerical variable.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-424-1","https://www.cve.org/CVERecord?id=CVE-2007-0908"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-424-1"],"notices":[{"id":"USN-424-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"After a standard system upgrade you need to restart Apache or reboot\nyour computer to effect the necessary changes.","references":[],"published":"2007-02-22T01:42:17","description":"Multiple buffer overflows have been discovered in various PHP modules.\nIf a PHP application processes untrusted data with functions of the\nsession or zip module, or various string functions, a remote attacker\ncould exploit this to execute arbitrary code with the privileges of\nthe web server. (CVE-2007-0906)\n\nThe sapi_header_op() function had a buffer underflow that could be\nexploited to crash the PHP interpreter. (CVE-2007-0907)\n\nThe wddx unserialization handler did not correctly check for some\nbuffer boundaries and had an uninitialized variable. By unserializing\nuntrusted data, this could be exploited to expose memory regions that\nwere not meant to be accessible. Depending on the PHP application this\ncould lead to disclosure of potentially sensitive information.\n(CVE-2007-0908)\n\nOn 64 bit systems (the amd64 and sparc platforms), various print\nfunctions and the odbc_result_all() were susceptible to a format\nstring vulnerability. A remote attacker could exploit this to execute\narbitrary code with the privileges of the web server. (CVE-2007-0909)\n\nUnder certain circumstances it was possible to overwrite superglobal\nvariables (like the HTTP GET/POST arrays) with crafted session data.\n(CVE-2007-0910)\n\nWhen unserializing untrusted data on 64-bit platforms the\nzend_hash_init() function could be forced to enter an infinite loop,\nconsuming CPU resources, for a limited length of time, until the\nscript timeout alarm aborts the script. (CVE-2007-0988)","is_hidden":false,"release_packages":{"dapper":[{"name":"php5-cli","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"php5-common","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"php5-odbc","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"php5-cli","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-common","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-odbc","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"php5-cli","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-common","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-odbc","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0906","CVE-2007-0907","CVE-2007-0908","CVE-2007-0909","CVE-2007-0910","CVE-2007-0988"]}]},{"id":"CVE-2007-0907","published":"2007-02-13T23:28:00","updated_at":"2025-07-17T16:40:44.808470+00:00","description":"\nBuffer underflow in PHP before 5.2.1 allows attackers to cause a denial of\nservice via unspecified vectors involving the sapi_header_op function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-424-1","https://www.cve.org/CVERecord?id=CVE-2007-0907"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-424-1"],"notices":[{"id":"USN-424-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"After a standard system upgrade you need to restart Apache or reboot\nyour computer to effect the necessary changes.","references":[],"published":"2007-02-22T01:42:17","description":"Multiple buffer overflows have been discovered in various PHP modules.\nIf a PHP application processes untrusted data with functions of the\nsession or zip module, or various string functions, a remote attacker\ncould exploit this to execute arbitrary code with the privileges of\nthe web server. (CVE-2007-0906)\n\nThe sapi_header_op() function had a buffer underflow that could be\nexploited to crash the PHP interpreter. (CVE-2007-0907)\n\nThe wddx unserialization handler did not correctly check for some\nbuffer boundaries and had an uninitialized variable. By unserializing\nuntrusted data, this could be exploited to expose memory regions that\nwere not meant to be accessible. Depending on the PHP application this\ncould lead to disclosure of potentially sensitive information.\n(CVE-2007-0908)\n\nOn 64 bit systems (the amd64 and sparc platforms), various print\nfunctions and the odbc_result_all() were susceptible to a format\nstring vulnerability. A remote attacker could exploit this to execute\narbitrary code with the privileges of the web server. (CVE-2007-0909)\n\nUnder certain circumstances it was possible to overwrite superglobal\nvariables (like the HTTP GET/POST arrays) with crafted session data.\n(CVE-2007-0910)\n\nWhen unserializing untrusted data on 64-bit platforms the\nzend_hash_init() function could be forced to enter an infinite loop,\nconsuming CPU resources, for a limited length of time, until the\nscript timeout alarm aborts the script. (CVE-2007-0988)","is_hidden":false,"release_packages":{"dapper":[{"name":"php5-cli","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"php5-common","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"php5-odbc","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"php5-cli","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-common","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-odbc","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"php5-cli","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-common","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-odbc","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0906","CVE-2007-0907","CVE-2007-0908","CVE-2007-0909","CVE-2007-0910","CVE-2007-0988"]}]}],"offset":76860,"limit":20,"total_results":79316}