{"cves":[{"id":"CVE-2007-0906","published":"2007-02-13T23:28:00","updated_at":"2025-07-17T16:40:44.808470+00:00","description":"\nMultiple buffer overflows in PHP before 5.2.1 allow attackers to cause a\ndenial of service and possibly execute arbitrary code via unspecified\nvectors in the (1) session, (2) zip, (3) imap, and (4) sqlite extensions;\n(5) stream filters; and the (6) str_replace, (7) mail, (8)\nibase_delete_user, (9) ibase_add_user, and (10) ibase_modify_user\nfunctions. NOTE: vector 6 might actually be an integer overflow\n(CVE-2007-1885). NOTE: as of 20070411, vector (3) might involve the\nimap_mail_compose function (CVE-2007-1825).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-424-1","https://www.cve.org/CVERecord?id=CVE-2007-0906"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-424-1"],"notices":[{"id":"USN-424-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"After a standard system upgrade you need to restart Apache or reboot\nyour computer to effect the necessary changes.","references":[],"published":"2007-02-22T01:42:17","description":"Multiple buffer overflows have been discovered in various PHP modules.\nIf a PHP application processes untrusted data with functions of the\nsession or zip module, or various string functions, a remote attacker\ncould exploit this to execute arbitrary code with the privileges of\nthe web server. (CVE-2007-0906)\n\nThe sapi_header_op() function had a buffer underflow that could be\nexploited to crash the PHP interpreter. (CVE-2007-0907)\n\nThe wddx unserialization handler did not correctly check for some\nbuffer boundaries and had an uninitialized variable. By unserializing\nuntrusted data, this could be exploited to expose memory regions that\nwere not meant to be accessible. Depending on the PHP application this\ncould lead to disclosure of potentially sensitive information.\n(CVE-2007-0908)\n\nOn 64 bit systems (the amd64 and sparc platforms), various print\nfunctions and the odbc_result_all() were susceptible to a format\nstring vulnerability. A remote attacker could exploit this to execute\narbitrary code with the privileges of the web server. (CVE-2007-0909)\n\nUnder certain circumstances it was possible to overwrite superglobal\nvariables (like the HTTP GET/POST arrays) with crafted session data.\n(CVE-2007-0910)\n\nWhen unserializing untrusted data on 64-bit platforms the\nzend_hash_init() function could be forced to enter an infinite loop,\nconsuming CPU resources, for a limited length of time, until the\nscript timeout alarm aborts the script. (CVE-2007-0988)","is_hidden":false,"release_packages":{"dapper":[{"name":"php5-cli","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"php5-common","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""},{"name":"php5-odbc","version":"5.1.2-1ubuntu3.5","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"php5-cli","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-common","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""},{"name":"php5-odbc","version":"5.0.5-2ubuntu1.7","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"php5-cli","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-cgi","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-common","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""},{"name":"php5-odbc","version":"5.1.6-1ubuntu2.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0906","CVE-2007-0907","CVE-2007-0908","CVE-2007-0909","CVE-2007-0910","CVE-2007-0988"]}]},{"id":"CVE-2007-0905","published":"2007-02-13T23:28:00","updated_at":"2025-07-17T16:40:44.808470+00:00","description":"\nPHP before 5.2.1 allows attackers to bypass safe_mode and open_basedir\nrestrictions via unspecified vectors in the session extension. NOTE: it is\npossible that this issue is a duplicate of CVE-2006-6383.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0905"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"5.2.0 only","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"5.2.0 only","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0903","published":"2007-02-13T20:28:00","updated_at":"2025-07-17T16:40:44.808470+00:00","description":"\nUnspecified vulnerability in the mod_roster_odbc module in ejabberd before\n1.1.3 has unknown impact and attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0903"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ejabberd","source":"https://ubuntu.com/security/cve?package=ejabberd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ejabberd","debian":"https://tracker.debian.org/pkg/ejabberd","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.1.2-5","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.1.2-5","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.2-5","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.1.2-5","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.2-5","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.1.2-5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0902","published":"2007-02-13T20:28:00","updated_at":"2025-07-17T16:40:42.080419+00:00","description":"\nUnspecified vulnerability in the \"Show debugging information\" feature in\nMoinMoin 1.5.7 allows remote attackers to obtain sensitive information.\nNOTE: the provenance of this information is unknown; the details are\nobtained solely from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-423-1","https://www.cve.org/CVERecord?id=CVE-2007-0902"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"moin","source":"https://ubuntu.com/security/cve?package=moin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moin","debian":"https://tracker.debian.org/pkg/moin","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.2-1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.3-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.3-1.1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-423-1"],"notices":[{"id":"USN-423-1","title":"MoinMoin vulnerabilities","summary":"MoinMoin vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-02-20T21:50:27","description":"A flaw was discovered in MoinMoin's debug reporting sanitizer which \ncould lead to a cross-site scripting attack. By tricking a user into \nviewing a crafted MoinMoin URL, an attacker could execute arbitrary \nJavaScript as the current MoinMoin user, possibly exposing the user's \nauthentication information for the domain where MoinMoin was hosted.\nOnly Ubuntu Breezy was vulnerable. (CVE-2007-0901)\n\nAn information leak was discovered in MoinMoin's debug reporting, which \ncould expose information about the versions of software running on the \nhost system. MoinMoin administrators can add \"show_traceback=0\" to\ntheir site configurations to disable debug tracebacks. (CVE-2007-0902)","is_hidden":false,"release_packages":{"dapper":[{"name":"python-moinmoin","version":"1.5.2-1ubuntu2.2","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"python-moinmoin","version":"1.3.4-6ubuntu1.5.10","is_source":false,"source_link":"","version_link":""},{"name":"moin","version":"1.2.4-1ubuntu2.2","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"python-moinmoin","version":"1.5.3-1ubuntu1.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0901","CVE-2007-0902"]}]},{"id":"CVE-2007-0901","published":"2007-02-13T20:28:00","updated_at":"2025-07-17T16:40:42.080419+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in Info pages in\nMoinMoin 1.5.7 allow remote attackers to inject arbitrary web script or\nHTML via the (1) hitcounts and (2) general parameters, different vectors\nthan CVE-2007-0857. NOTE: the provenance of this information is unknown;\nthe details are obtained solely from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-423-1","https://www.cve.org/CVERecord?id=CVE-2007-0901"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"moin","source":"https://ubuntu.com/security/cve?package=moin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moin","debian":"https://tracker.debian.org/pkg/moin","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-423-1"],"notices":[{"id":"USN-423-1","title":"MoinMoin vulnerabilities","summary":"MoinMoin vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-02-20T21:50:27","description":"A flaw was discovered in MoinMoin's debug reporting sanitizer which \ncould lead to a cross-site scripting attack. By tricking a user into \nviewing a crafted MoinMoin URL, an attacker could execute arbitrary \nJavaScript as the current MoinMoin user, possibly exposing the user's \nauthentication information for the domain where MoinMoin was hosted.\nOnly Ubuntu Breezy was vulnerable. (CVE-2007-0901)\n\nAn information leak was discovered in MoinMoin's debug reporting, which \ncould expose information about the versions of software running on the \nhost system. MoinMoin administrators can add \"show_traceback=0\" to\ntheir site configurations to disable debug tracebacks. (CVE-2007-0902)","is_hidden":false,"release_packages":{"dapper":[{"name":"python-moinmoin","version":"1.5.2-1ubuntu2.2","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"python-moinmoin","version":"1.3.4-6ubuntu1.5.10","is_source":false,"source_link":"","version_link":""},{"name":"moin","version":"1.2.4-1ubuntu2.2","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"python-moinmoin","version":"1.5.3-1ubuntu1.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0901","CVE-2007-0902"]}]},{"id":"CVE-2007-0896","published":"2007-02-13T11:28:00","updated_at":"2025-07-17T16:40:42.080419+00:00","description":"\nCross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and\n(2) Sage++ extensions for Firefox, allows remote attackers to inject\narbitrary web script or HTML via a \"