{"cves":[{"id":"CVE-2007-0262","published":"2007-01-16T23:28:00","updated_at":"2025-07-17T16:40:31.809691+00:00","description":"\nWordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that\nthe m parameter value has the string data type, which allows remote\nattackers to obtain sensitive information via an invalid m[] parameter, as\ndemonstrated by obtaining the path, and obtaining certain SQL information\nsuch as the table prefix.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0262"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.7","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0256","published":"2007-01-16T23:28:00","updated_at":"2025-07-17T16:40:29.668646+00:00","description":"\nVideoLAN VLC 0.8.6a allows remote attackers to cause a denial of service\n(application crash) via a crafted .wmv file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0256"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"vlc","source":"https://ubuntu.com/security/cve?package=vlc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vlc","debian":"https://tracker.debian.org/pkg/vlc","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.8.6.release.c-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.8.6.release.c-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.8.6.release.c-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.8.6.release.c-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.8.6.release.c-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0255","published":"2007-01-16T23:28:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nXINE 0.99.4 allows user-assisted remote attackers to cause a denial of\nservice (application crash) and possibly execute arbitrary code via a\ncertain M3U file that contains a long #EXTINF line and contains format\nstring specifiers in an invalid udp:// URI, possibly a variant of\nCVE-2007-0017.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"issue is unlisted on xine upstream website"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://xine.sourceforge.net/security","https://www.cve.org/CVERecord?id=CVE-2007-0255"],"bugs":[""],"patches":{"xine-ui":[]},"tags":{},"packages":[{"name":"xine-ui","source":"https://ubuntu.com/security/cve?package=xine-ui","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xine-ui","debian":"https://tracker.debian.org/pkg/xine-ui","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0254","published":"2007-01-16T23:28:00","updated_at":"2025-07-17T16:40:29.668646+00:00","description":"\nFormat string vulnerability in the errors_create_window function in\nerrors.c in xine-ui allows attackers to execute arbitrary code via unknown\nvectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0254"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"xine-ui","source":"https://ubuntu.com/security/cve?package=xine-ui","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xine-ui","debian":"https://tracker.debian.org/pkg/xine-ui","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.4+dfsg+cvs20061111-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0251","published":"2007-01-16T23:28:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger underflow in the DecodeGRE function in src/decode.c in Snort\n2.6.1.2 allows remote attackers to trigger dereferencing of certain memory\nlocations via crafted GRE packets, which may cause corruption of log files\nor writing of sensitive information into log files.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"according to http://www.securityfocus.com/bid/22004/solution,\nVersion 1.131 of 'src/decode.c', as of January 10, 2007 in the Snort CVS\nrepository, contains a fix to address this issue."},{"author":"fujitsu","note":"we never had the vulnerable release."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0251"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"snort","source":"https://ubuntu.com/security/cve?package=snort","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=snort","debian":"https://tracker.debian.org/pkg/snort","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-6931","published":"2007-01-16T23:28:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAlgorithmic complexity vulnerability in Snort before 2.6.1, during\npredicate evaluation in rule matching for certain rules, allows remote\nattackers to cause a denial of service (CPU consumption and detection\noutage) via crafted network traffic, aka a \"backtracking attack.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-6931"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"snort","source":"https://ubuntu.com/security/cve?package=snort","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=snort","debian":"https://tracker.debian.org/pkg/snort","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.7.0-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.7.0-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.7.0-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.7.0-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.7.0-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-5876","published":"2007-01-16T19:28:00","updated_at":"2025-07-17T16:40:01.755468+00:00","description":"\nThe soup_headers_parse function in soup-headers.c for libsoup HTTP library\nbefore 2.2.99 allows remote attackers to cause a denial of service (crash)\nvia malformed HTTP headers, probably involving missing fields or values.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-411-1","https://www.cve.org/CVERecord?id=CVE-2006-5876"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libsoup","source":"https://ubuntu.com/security/cve?package=libsoup","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsoup","debian":"https://tracker.debian.org/pkg/libsoup","statuses":[{"release_codename":"dapper","status":"released","description":"2.2.93-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.2.96-0ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.100","component":null,"pocket":"security"}]}],"notices_ids":["USN-411-1"],"notices":[{"id":"USN-411-1","title":"libsoup vulnerability","summary":"libsoup vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-01-23T22:31:37","description":"Roland Lezuo and Josselin Mouette discovered that the HTTP server code \nin libsoup did not correctly verify request headers. Remote attackers \ncould crash applications using libsoup by sending a crafted HTTP \nrequest, resulting in a denial of service.","is_hidden":false,"release_packages":{"dapper":[{"name":"libsoup2.2-8","version":"2.2.93-0ubuntu1.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"libsoup2.2-8","version":"2.2.6.1-0ubuntu1.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libsoup2.2-8","version":"2.2.96-0ubuntu2.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-5876"]}]},{"id":"CVE-2007-0248","published":"2007-01-16T18:28:00","updated_at":"2025-07-17T16:40:29.668646+00:00","description":"\nThe aclMatchExternal function in Squid before 2.6.STABLE7 allows remote\nattackers to cause a denial of service (crash) by causing an external_acl\nqueue overload, which triggers an infinite loop.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-414-1","https://www.cve.org/CVERecord?id=CVE-2007-0248"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"squid","source":"https://ubuntu.com/security/cve?package=squid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squid","debian":"https://tracker.debian.org/pkg/squid","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.1-3ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.5-4ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-414-1"],"notices":[{"id":"USN-414-1","title":"Squid vulnerabilities","summary":"Squid vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-01-25T00:08:54","description":"David Duncan Ross Palmer and Henrik Nordstrom discovered that squid \nincorrectly handled special characters in FTP URLs. Remote users with \naccess to squid could crash the server leading to a denial of service. \n(CVE-2007-0247)\n\nErick Dantas Rotole and Henrik Nordstrom discovered that squid could end \nup in an endless loop when exhausted of available external ACL helpers. \nRemote users with access to squid could cause CPU starvation, possibly \nleading to a denial of service. This does not affect a default Ubuntu \ninstallation, since external ACL helpers must be configured and used.\n(CVE-2007-0248)","is_hidden":false,"release_packages":{"dapper":[{"name":"squid","version":"2.5.12-4ubuntu2.2","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"squid","version":"2.6.1-3ubuntu1.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0247","CVE-2007-0248"]}]},{"id":"CVE-2007-0247","published":"2007-01-16T18:28:00","updated_at":"2025-07-17T16:40:29.668646+00:00","description":"\nsquid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to\ncause a denial of service (core dump) via crafted FTP directory listing\nresponses, possibly related to the (1) ftpListingFinish and (2)\nftpHtmlifyListEntry functions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-414-1","https://www.cve.org/CVERecord?id=CVE-2007-0247"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"squid","source":"https://ubuntu.com/security/cve?package=squid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squid","debian":"https://tracker.debian.org/pkg/squid","statuses":[{"release_codename":"dapper","status":"released","description":"2.5.12-4ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.1-3ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-414-1"],"notices":[{"id":"USN-414-1","title":"Squid vulnerabilities","summary":"Squid vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-01-25T00:08:54","description":"David Duncan Ross Palmer and Henrik Nordstrom discovered that squid \nincorrectly handled special characters in FTP URLs. Remote users with \naccess to squid could crash the server leading to a denial of service. \n(CVE-2007-0247)\n\nErick Dantas Rotole and Henrik Nordstrom discovered that squid could end \nup in an endless loop when exhausted of available external ACL helpers. \nRemote users with access to squid could cause CPU starvation, possibly \nleading to a denial of service. This does not affect a default Ubuntu \ninstallation, since external ACL helpers must be configured and used.\n(CVE-2007-0248)","is_hidden":false,"release_packages":{"dapper":[{"name":"squid","version":"2.5.12-4ubuntu2.2","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"squid","version":"2.6.1-3ubuntu1.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0247","CVE-2007-0248"]}]},{"id":"CVE-2007-0235","published":"2007-01-16T18:28:00","updated_at":"2025-07-17T16:40:28.122665+00:00","description":"\nStack-based buffer overflow in the glibtop_get_proc_map_s function in\nlibgtop before 2.14.6 (libgtop2) allows local users to cause a denial of\nservice (crash) and possibly execute arbitrary code via a process with a\nlong filename that is mapped in its address space, which triggers the\noverflow in gnome-system-monitor.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0235"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libgtop","source":"https://ubuntu.com/security/cve?package=libgtop","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgtop","debian":"https://tracker.debian.org/pkg/libgtop","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libgtop2","source":"https://ubuntu.com/security/cve?package=libgtop2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgtop2","debian":"https://tracker.debian.org/pkg/libgtop2","statuses":[{"release_codename":"dapper","status":"released","description":"2.14.1-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.14.4-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.14.8-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0233","published":"2007-01-13T02:28:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nwp-trackback.php in WordPress 2.0.6 and earlier does not properly unset\nvariables when the input data includes a numeric parameter with a value\nmatching an alphanumeric parameter's hash value, which allows remote\nattackers to execute arbitrary SQL commands via the tb_id parameter. NOTE:\nit could be argued that this vulnerability is due to a bug in the unset PHP\ncommand (CVE-2006-3017) and the proper fix should be in PHP; if so, then\nthis should not be treated as a vulnerability in WordPress.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0233"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.1.0-1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.1.0-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.1.0-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.1.0-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.1.0-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.1.0-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0227","published":"2007-01-13T02:28:00","updated_at":"2025-07-17T16:40:28.122665+00:00","description":"\nslocate 3.1 does not properly manage database entries that specify names of\nfiles in protected directories, which allows local users to obtain the\nnames of private files. NOTE: another researcher reports that the issue is\nnot present in slocate 2.7.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-425-1","https://www.cve.org/CVERecord?id=CVE-2007-0227"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"slocate","source":"https://ubuntu.com/security/cve?package=slocate","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=slocate","debian":"https://tracker.debian.org/pkg/slocate","statuses":[{"release_codename":"dapper","status":"released","description":"3.0.beta.r3-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.1-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-425-1"],"notices":[{"id":"USN-425-1","title":"slocate vulnerability","summary":"slocate vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-02-22T01:54:11","description":"A flaw was discovered in the permission checking code of slocate. When \nreporting matching files, locate would not correctly respect the parent \ndirectory's \"read\" bits. This could result in filenames being displayed \nwhen the file owner had expected them to remain hidden from other system \nusers.","is_hidden":false,"release_packages":{"dapper":[{"name":"slocate","version":"3.0.beta.r3-1ubuntu0.1","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"slocate","version":"3.1-1ubuntu0.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0227"]}]},{"id":"CVE-2006-6921","published":"2007-01-12T23:28:00","updated_at":"2025-07-17T16:40:18.021475+00:00","description":"\nUnspecified versions of the Linux kernel allow local users to cause a\ndenial of service (unrecoverable zombie process) via a program with certain\ninstructions that prevent init from properly reaping a child whose parent\nhas died.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-6921"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.20","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.20","debian":"https://tracker.debian.org/pkg/linux-source-2.6.20","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.22","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.22","debian":"https://tracker.debian.org/pkg/linux-source-2.6.22","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0204","published":"2007-01-11T11:28:00","updated_at":"2025-07-17T16:40:28.122665+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before\n2.9.2-rc1 allow remote attackers to inject arbitrary web script or HTML via\nunspecified vectors. NOTE: some of these details are obtained from third\nparty information.","ubuntu_description":"","notes":[{"author":"wgrant","note":"Fix backported in 4:2.9.1.1-2 (feisty)."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0204"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.9.2rc1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0203","published":"2007-01-11T11:28:00","updated_at":"2025-07-17T16:40:28.122665+00:00","description":"\nMultiple unspecified vulnerabilities in phpMyAdmin before 2.9.2-rc1 have\nunknown impact and attack vectors.","ubuntu_description":"","notes":[{"author":"wgrant","note":"Fix backported in 4:2.9.1.1-2 (feisty)."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0203"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.9.2rc1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0177","published":"2007-01-11T00:28:00","updated_at":"2025-07-17T16:40:28.122665+00:00","description":"\nCross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki\nbefore 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.3, and 1.9 before 1.9.0rc2,\nwhen wgUseAjax is enabled, allows remote attackers to inject arbitrary web\nscript or HTML via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0177"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0176","published":"2007-01-11T00:28:00","updated_at":"2025-07-17T16:40:28.122665+00:00","description":"\nCross-site scripting (XSS) vulnerability in search/advanced_search.php in\nGForge 4.5.11 allows remote attackers to inject arbitrary web script or\nHTML via the words parameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0176"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/gforge/+bug/186570"],"patches":{"gforge":["vendor: http://www.debian.org/security/2008/dsa-1475"]},"tags":{},"packages":[{"name":"gforge","source":"https://ubuntu.com/security/cve?package=gforge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gforge","debian":"https://tracker.debian.org/pkg/gforge","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0175","published":"2007-01-11T00:28:00","updated_at":"2025-07-17T16:40:28.122665+00:00","description":"\nCross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution\n1.8.6 allows remote attackers to inject arbitrary web script or HTML via\nscriptable attributes in the redirect_to parameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0175"],"bugs":["https://bugs.launchpad.net/bugs/227311"],"patches":{"b2evolution":["vendor: http://www.debian.org/security/2008/dsa-1568"]},"tags":{},"packages":[{"name":"b2evolution","source":"https://ubuntu.com/security/cve?package=b2evolution","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=b2evolution","debian":"https://tracker.debian.org/pkg/b2evolution","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.9.2-4","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"2.4.2-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2.4.2-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"2.4.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0160","published":"2007-01-10T00:28:00","updated_at":"2025-07-17T16:40:28.122665+00:00","description":"\nStack-based buffer overflow in the LiveJournal support (hooks/ljhook.cc) in\nCenterICQ 4.9.11 through 4.21.0, when using unofficial LiveJournal servers,\nallows remote attackers to cause a denial of service (crash) and possibly\nexecute arbitrary code by adding the victim as a friend and using long (1)\nusername and (2) real name strings.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0160"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"centericq","source":"https://ubuntu.com/security/cve?package=centericq","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=centericq","debian":"https://tracker.debian.org/pkg/centericq","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"4.21.0-17","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"centerim","source":"https://ubuntu.com/security/cve?package=centerim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=centerim","debian":"https://tracker.debian.org/pkg/centerim","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"4.21.0-17","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"4.21.0-17","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"4.21.0-17","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"4.21.0-17","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"4.21.0-17","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0159","published":"2007-01-10T00:28:00","updated_at":"2025-07-17T16:40:26.429283+00:00","description":"\nDirectory traversal vulnerability in the GeoIP_update_database_general\nfunction in libGeoIP/GeoIPUpdate.c in GeoIP 1.4.0 allows remote malicious\nupdate servers (possibly only update.maxmind.com) to overwrite arbitrary\nfiles via a .. (dot dot) in the database filename, which is returned by a\nrequest to app/update_getfilename.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-412-1","https://www.cve.org/CVERecord?id=CVE-2007-0159"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"geoip","source":"https://ubuntu.com/security/cve?package=geoip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=geoip","debian":"https://tracker.debian.org/pkg/geoip","statuses":[{"release_codename":"dapper","status":"released","description":"1.3.14-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.3.17-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.3.17-1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-412-1"],"notices":[{"id":"USN-412-1","title":"GeoIP vulnerability","summary":"GeoIP vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-01-24T01:30:00","description":"Dean Gaudet discovered that the GeoIP update tool did not validate the \nfilename responses from the update server. A malicious server, or \nmachine-in-the-middle system posing as a server, could write to arbitrary \nfiles with user privileges.","is_hidden":false,"release_packages":{"breezy":[{"name":"geoip-bin","version":"1.3.10-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"","version_link":""}],"dapper":[{"name":"geoip-bin","version":"1.3.14-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"","version_link":""}],"edgy":[{"name":"geoip-bin","version":"1.3.17-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0159"]}]}],"offset":76960,"limit":20,"total_results":79316}