{"cves":[{"id":"CVE-2007-0157","published":"2007-01-09T21:28:00","updated_at":"2025-07-17T16:40:26.429283+00:00","description":"\nArray index error in the uri_lookup function in the URI parser for neon\n0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote\nmalicious servers to cause a denial of service (crash) via a URI with\nnon-ASCII characters, which triggers a buffer under-read due to a type\nconversion error that generates a negative index.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0157"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"cadaver","source":"https://ubuntu.com/security/cve?package=cadaver","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cadaver","debian":"https://tracker.debian.org/pkg/cadaver","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.22.5-2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.22.5-2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.22.5-2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.22.5-2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.22.5-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"neon","source":"https://ubuntu.com/security/cve?package=neon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=neon","debian":"https://tracker.debian.org/pkg/neon","statuses":[{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"neon26","source":"https://ubuntu.com/security/cve?package=neon26","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=neon26","debian":"https://tracker.debian.org/pkg/neon26","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.26.3-1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.26.3-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.26.3-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.26.3-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.26.3-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.26.3-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0136","published":"2007-01-09T11:28:00","updated_at":"2025-07-17T16:40:26.429283+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in Drupal before\n4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary\nweb script or HTML via unspecified parameters in the (1) filter and (2)\nsystem modules. NOTE: some of these details are obtained from third party\ninformation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0136"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"drupal","source":"https://ubuntu.com/security/cve?package=drupal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal","debian":"https://tracker.debian.org/pkg/drupal","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.1-0ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0124","published":"2007-01-09T02:28:00","updated_at":"2025-07-17T16:40:26.429283+00:00","description":"\nUnspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5,\nwhen MySQL is used, allows remote authenticated users to cause a denial of\nservice by poisoning the page cache via unspecified vectors, which triggers\nerroneous 404 HTTP errors for pages that exist.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0124"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"drupal","source":"https://ubuntu.com/security/cve?package=drupal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal","debian":"https://tracker.debian.org/pkg/drupal","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.1-0ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0109","published":"2007-01-09T00:28:00","updated_at":"2025-07-17T16:40:26.429283+00:00","description":"\nwp-login.php in WordPress 2.0.5 and earlier displays different error\nmessages if a user exists or not, which allows remote attackers to obtain\nsensitive information and facilitates brute force attacks.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0109"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0107","published":"2007-01-09T00:28:00","updated_at":"2025-07-17T16:40:26.429283+00:00","description":"\nWordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate\ncharacter sets after escaping the SQL query, which allows remote attackers\nto bypass SQL injection protection schemes and execute arbitrary SQL\ncommands via multibyte charsets, as demonstrated using UTF-7.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0107"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0106","published":"2007-01-09T00:28:00","updated_at":"2025-07-17T16:40:26.429283+00:00","description":"\nCross-site scripting (XSS) vulnerability in the CSRF protection scheme in\nWordPress before 2.0.6 allows remote attackers to inject arbitrary web\nscript or HTML via a CSRF attack with an invalid token and quote characters\nor HTML tags in URL variable names, which are not properly handled when\nWordPress generates a new link to verify the request.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0106"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0104","published":"2007-01-09T00:28:00","updated_at":"2025-07-17T16:40:26.429283+00:00","description":"\nThe Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2,\n(b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products,\nallows remote attackers to have an unknown impact, possibly including\ndenial of service (infinite loop), arbitrary code execution, or memory\ncorruption, via a PDF file with a (1) crafted catalog dictionary or (2) a\ncrafted Pages attribute that references an invalid page tree node.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-410-1","https://ubuntu.com/security/notices/USN-410-2","https://www.cve.org/CVERecord?id=CVE-2007-0104"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kdegraphics","source":"https://ubuntu.com/security/cve?package=kdegraphics","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kdegraphics","debian":"https://tracker.debian.org/pkg/kdegraphics","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"koffice","source":"https://ubuntu.com/security/cve?package=koffice","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=koffice","debian":"https://tracker.debian.org/pkg/koffice","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0-0ubuntu9.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.2-0ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.6.2-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"poppler","source":"https://ubuntu.com/security/cve?package=poppler","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=poppler","debian":"https://tracker.debian.org/pkg/poppler","statuses":[{"release_codename":"dapper","status":"released","description":"0.5.1-0ubuntu7.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.5.4-0ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.5.4-0ubuntu8.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tetex-bin","source":"https://ubuntu.com/security/cve?package=tetex-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tetex-bin","debian":"https://tracker.debian.org/pkg/tetex-bin","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xpdf","source":"https://ubuntu.com/security/cve?package=xpdf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xpdf","debian":"https://tracker.debian.org/pkg/xpdf","statuses":[{"release_codename":"dapper","status":"released","description":"3.01-7ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.01-9ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.01-9ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-410-1","USN-410-2"],"notices":[{"id":"USN-410-1","title":"poppler vulnerability","summary":"poppler vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-01-19T00:47:57","description":"The poppler PDF loader library did not limit the recursion depth of\nthe page model tree. By tricking a user into opening a specially\ncrafter PDF file, this could be exploited to trigger an infinite loop\nand eventually crash an application that uses this library.\n\nkpdf in Ubuntu 5.10, and KOffice in all Ubuntu releases contains a\ncopy of this code and thus is affected as well.","is_hidden":false,"release_packages":{"dapper":[{"name":"libpoppler1","version":"0.5.1-0ubuntu7.1","is_source":false,"source_link":"","version_link":""},{"name":"kword","version":"1:1.5.0-0ubuntu9.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"kpdf","version":"4:3.4.3-0ubuntu2.6","is_source":false,"source_link":"","version_link":""},{"name":"kword","version":"1:1.4.1-0ubuntu7.5","is_source":false,"source_link":"","version_link":""},{"name":"libpoppler0c2","version":"0.4.2-0ubuntu6.8","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libpoppler1","version":"0.5.4-0ubuntu4.1","is_source":false,"source_link":"","version_link":""},{"name":"kword","version":"1:1.5.2-0ubuntu2.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0104"]},{"id":"USN-410-2","title":"teTeX vulnerability","summary":"teTeX vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-01-26T01:04:00","description":"USN-410-1 fixed vulnerabilities in the poppler PDF loader library. This \nupdate provides the corresponding updates for a copy of this code in \ntetex-bin in Ubuntu 5.10. Versions of tetex-bin after Ubuntu 5.10 use \npoppler directly and do not need a separate update.\n\nOriginal advisory details:\n\n The poppler PDF loader library did not limit the recursion depth of\n the page model tree. By tricking a user into opening a specially\n crafter PDF file, this could be exploited to trigger an infinite loop\n and eventually crash an application that uses this library.","is_hidden":false,"release_packages":{"breezy":[{"name":"tetex-bin","version":"2.0.2-30ubuntu3.6","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2007-0104"]}]},{"id":"CVE-2007-0103","published":"2007-01-09T00:28:00","updated_at":"2025-07-17T16:40:26.429283+00:00","description":"\nThe Adobe PDF specification 1.3, as implemented by Adobe Acrobat before\n8.0.0, allows remote attackers to have an unknown impact, possibly\nincluding denial of service (infinite loop), arbitrary code execution, or\nmemory corruption, via a PDF file with a (1) crafted catalog dictionary or\n(2) a crafted Pages attribute that references an invalid page tree node.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0103"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"9.1.0-7hardy1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0095","published":"2007-01-05T18:28:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nphpMyAdmin 2.9.1.1 allows remote attackers to obtain sensitive information\nvia a direct request for themes/darkblue_orange/layout.inc.php, which\nreveals the path in an error message.","ubuntu_description":"","notes":[{"author":"wgrant","note":"Path disclosure - probably shouldn't be worried."}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0095"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"4:2.9.1.1-1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"4:2.9.1.1-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"4:2.9.1.1-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"4:2.9.1.1-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"4:2.9.1.1-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"4:2.9.1.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.9.1.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0046","published":"2007-01-03T21:28:00","updated_at":"2025-07-17T16:40:26.429283+00:00","description":"\nDouble free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0,\nas used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute\narbitrary code by causing an error via a javascript: URI call to\ndocument.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request\nparameters.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0046"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"dapper","status":"released","description":"7.0.9-0.0.ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"7.0.9-0.0.ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0045","published":"2007-01-03T21:28:00","updated_at":"2025-07-17T16:40:24.719687+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader\nPlugin before 8.0.0, and possibly the plugin distributed with Adobe Reader\n7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla\nFirefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4\nbuild 770, and Opera 9.10.8679 on Windows allow remote attackers to inject\narbitrary JavaScript and conduct other attacks via a .pdf URL with a\njavascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX\nparameters, or (4) an arbitrarily named name=URI anchor identifier, aka\n\"Universal XSS (UXSS).\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0045"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"dapper","status":"released","description":"7.0.9-0.0.ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"7.0.9-0.0.ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"iceape","source":"https://ubuntu.com/security/cve?package=iceape","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=iceape","debian":"https://tracker.debian.org/pkg/iceape","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.1.4-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.8.0.10-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.8.0.10-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2007-0017","published":"2007-01-03T02:28:00","updated_at":"2025-07-17T16:40:24.719687+00:00","description":"\nMultiple format string vulnerabilities in (1) the cdio_log_handler function\nin modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and\nthe (2) cdio_log_handler and (3) vcd_log_handler functions in\nmodules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in\nVideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to\nexecute arbitrary code via format string specifiers in an invalid URI, as\ndemonstrated by a udp://-- URI in an M3U file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2007-0017"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"vlc","source":"https://ubuntu.com/security/cve?package=vlc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vlc","debian":"https://tracker.debian.org/pkg/vlc","statuses":[{"release_codename":"dapper","status":"released","description":"0.8.4.debian-1ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.8.6-svn20061012.debian-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.8.6.release-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-7232","published":"2006-12-31T05:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nsql_select.cc in MySQL 5.0.x before 5.0.32 and 5.1.x before 5.1.14 allows\nremote authenticated users to cause a denial of service (crash) via an\nEXPLAIN SELECT FROM on the INFORMATION_SCHEMA table, as originally\ndemonstrated using ORDER BY.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"DoS, but escalated to medium for customer"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-588-1","https://www.cve.org/CVERecord?id=CVE-2006-7232"],"bugs":["https://bugs.launchpad.net/ubuntu/gutsy/+source/mysql-dfsg-5.0/+bug/201009","https://bugs.launchpad.net/ubuntu/+source/mysql-dfsg-5.0/+bug/161127","https://bugs.launchpad.net/ubuntu/+bug/173641"],"patches":{"mysql-dfsg-5.0":[]},"tags":{},"packages":[{"name":"mysql-dfsg-5.0","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.0","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.0","statuses":[{"release_codename":"dapper","status":"released","description":"5.0.22-0ubuntu6.06.8","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.0.24a-9ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.32","component":null,"pocket":"security"}]}],"notices_ids":["USN-588-1"],"notices":[{"id":"USN-588-1","title":"MySQL vulnerabilities","summary":"MySQL vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2008-03-19T23:31:02.790688","description":"Masaaki Hirose discovered that MySQL could be made to dereference\na NULL pointer. An authenticated user could cause a denial of service\n(application crash) via an EXPLAIN SELECT FROM on the INFORMATION_SCHEMA\ntable. This issue only affects Ubuntu 6.06 and 6.10. (CVE-2006-7232)\n\nAlexander Nozdrin discovered that MySQL did not restore database access\nprivileges when returning from SQL SECURITY INVOKER stored routines. An\nauthenticated user could exploit this to gain privileges. This issue\ndoes not affect Ubuntu 7.10. (CVE-2007-2692)\n\nMartin Friebe discovered that MySQL did not properly update the DEFINER\nvalue of an altered view. An authenticated user could use CREATE SQL\nSECURITY DEFINER VIEW and ALTER VIEW statements to gain privileges.\n(CVE-2007-6303)\n\nLuigi Auriemma discovered that yaSSL as included in MySQL did not\nproperly validate its input. A remote attacker could send crafted\nrequests and cause a denial of service or possibly execute arbitrary\ncode. This issue did not affect Ubuntu 6.06 in the default installation.\n(CVE-2008-0226, CVE-2008-0227)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"mysql-dfsg-5.0","version":"5.0.45-1ubuntu3.3","description":"","is_source":true},{"name":"mysql-server-5.0","version":"5.0.45-1ubuntu3.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0/5.0.45-1ubuntu3.3"}],"dapper":[{"name":"mysql-dfsg-5.0","version":"5.0.22-0ubuntu6.06.8","description":"","is_source":true},{"name":"mysql-server-5.0","version":"5.0.22-0ubuntu6.06.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0/5.0.22-0ubuntu6.06.8"}],"feisty":[{"name":"mysql-dfsg-5.0","version":"5.0.38-0ubuntu1.4","description":"","is_source":true},{"name":"mysql-server-5.0","version":"5.0.38-0ubuntu1.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0/5.0.38-0ubuntu1.4"}],"edgy":[{"name":"mysql-dfsg-5.0","version":"5.0.24a-9ubuntu2.4","description":"","is_source":true},{"name":"mysql-server-5.0","version":"5.0.24a-9ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.0/5.0.24a-9ubuntu2.4"}]},"type":"USN","cves_ids":["CVE-2008-0226","CVE-2007-6303","CVE-2007-2692","CVE-2006-7232","CVE-2008-0227"]}]},{"id":"CVE-2006-6899","published":"2006-12-31T05:00:00","updated_at":"2025-07-17T16:40:18.021475+00:00","description":"\nhidd in BlueZ (bluez-utils) before 2.25 allows remote attackers to obtain\ncontrol of the (1) Mouse and (2) Keyboard Human Interface Device (HID) via\na certain configuration of two HID (PSM) endpoints, operating as a server,\naka HidAttack.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-413-1","https://www.cve.org/CVERecord?id=CVE-2006-6899"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"bluez-utils","source":"https://ubuntu.com/security/cve?package=bluez-utils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bluez-utils","debian":"https://tracker.debian.org/pkg/bluez-utils","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-413-1"],"notices":[{"id":"USN-413-1","title":"BlueZ vulnerability","summary":"BlueZ vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-01-24T02:28:49","description":"A flaw was discovered in the HID daemon of bluez-utils. A remote \nattacker could gain control of the mouse and keyboard if hidd was \nenabled. This does not affect a default Ubuntu installation, since hidd \nis normally disabled.","is_hidden":false,"release_packages":{"breezy":[{"name":"bluez-utils","version":"2.20-0ubuntu3.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-6899"]}]},{"id":"CVE-2006-6870","published":"2006-12-31T05:00:00","updated_at":"2025-07-17T16:40:18.021475+00:00","description":"\nThe consume_labels function in avahi-core/dns.c in Avahi before 0.6.16\nallows remote attackers to cause a denial of service (infinite loop) via a\ncrafted compressed DNS response with a label that points to itself.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-402-1","https://www.cve.org/CVERecord?id=CVE-2006-6870"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"avahi","source":"https://ubuntu.com/security/cve?package=avahi","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=avahi","debian":"https://tracker.debian.org/pkg/avahi","statuses":[{"release_codename":"dapper","status":"released","description":"0.6.10-0ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.6.13-2ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.6.16","component":null,"pocket":"security"}]}],"notices_ids":["USN-402-1"],"notices":[{"id":"USN-402-1","title":"Avahi vulnerability","summary":"Avahi vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-01-05T17:38:13","description":"A flaw was discovered in Avahi's handling of compressed DNS packets. If \na specially crafted reply were received over the network, the Avahi \ndaemon would go into an infinite loop, causing a denial of service.","is_hidden":false,"release_packages":{"dapper":[{"name":"avahi-daemon","version":"0.6.10-0ubuntu3.4","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"avahi-daemon","version":"0.5.2-1ubuntu1.4","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"avahi-daemon","version":"0.6.13-2ubuntu2.4","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-6870"]}]},{"id":"CVE-2006-6841","published":"2006-12-31T05:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCertain forms in phpBB before 2.0.22 lack session checks, which has unknown\nimpact and remote attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-6841"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/phpbb2/+bug/191201"],"patches":{"phpbb2":["vendor: http://www.debian.org/security/2008/dsa-1488"]},"tags":{},"packages":[{"name":"phpbb2","source":"https://ubuntu.com/security/cve?package=phpbb2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpbb2","debian":"https://tracker.debian.org/pkg/phpbb2","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.21-6","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.21-6","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.21-6","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.21-6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-6840","published":"2006-12-31T05:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in phpBB before 2.0.22 has unknown impact and\nremote attack vectors related to a \"negative start parameter.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-6840"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/phpbb2/+bug/191201"],"patches":{"phpbb2":["vendor: http://www.debian.org/security/2008/dsa-1488"]},"tags":{},"packages":[{"name":"phpbb2","source":"https://ubuntu.com/security/cve?package=phpbb2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpbb2","debian":"https://tracker.debian.org/pkg/phpbb2","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.21-6","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.21-6","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.21-6","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.21-6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-6839","published":"2006-12-31T05:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in phpBB before 2.0.22 has unknown impact and\nremote attack vectors related to \"criteria for 'bad' redirection targets.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-6839"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/phpbb2/+bug/191201"],"patches":{"phpbb2":["vendor: http://www.debian.org/security/2008/dsa-1488"]},"tags":{},"packages":[{"name":"phpbb2","source":"https://ubuntu.com/security/cve?package=phpbb2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpbb2","debian":"https://tracker.debian.org/pkg/phpbb2","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.21-6","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.21-6","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.21-6","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.21-6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-6144","published":"2006-12-31T05:00:00","updated_at":"2025-07-17T16:40:07.635160+00:00","description":"\nThe \"mechglue\" abstraction interface of the GSS-API library for Kerberos 5\n1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and\nother products that use this library, allows remote attackers to cause a\ndenial of service (crash) via unspecified vectors that cause mechglue to\nfree uninitialized pointers.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-6144"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-6143","published":"2006-12-31T05:00:00","updated_at":"2025-07-17T16:40:07.635160+00:00","description":"\nThe RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as\nused in Kerberos administration daemon (kadmind) and other products that\nuse this library, calls an uninitialized function pointer in freed memory,\nwhich allows remote attackers to cause a denial of service (crash) and\npossibly execute arbitrary code via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-408-1","https://www.cve.org/CVERecord?id=CVE-2006-6143"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.3-5ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.3-9ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.4-5ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-408-1"],"notices":[{"id":"USN-408-1","title":"krb5 vulnerability","summary":"krb5 vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2007-01-16T02:42:05","description":"The server-side portion of Kerberos' RPC library had a memory\nmanagement flaw which allowed users of that library to call a function\npointer located in unallocated memory. By doing specially crafted\ncalls to the kadmind server, a remote attacker could exploit this to\nexecute arbitrary code with root privileges on the target computer.","is_hidden":false,"release_packages":{"dapper":[{"name":"libkrb53","version":"1.4.3-5ubuntu0.2","is_source":false,"source_link":"","version_link":""},{"name":"libkadm55","version":"1.4.3-5ubuntu0.2","is_source":false,"source_link":"","version_link":""}],"edgy":[{"name":"libkrb53","version":"1.4.3-9ubuntu1.1","is_source":false,"source_link":"","version_link":""},{"name":"libkadm55","version":"1.4.3-9ubuntu1.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-6143"]}]}],"offset":76980,"limit":20,"total_results":79316}