{"cves":[{"id":"CVE-2006-3631","published":"2006-07-21T14:03:00","updated_at":"2025-07-17T16:39:21.661691+00:00","description":"\nUnspecified vulnerability in the SSH dissector in Wireshark (aka Ethereal)\n0.9.10 to 0.99.0 allows remote attackers to cause a denial of service\n(infinite loop) via unknown attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-3631"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-3630","published":"2006-07-21T14:03:00","updated_at":"2025-07-17T16:39:21.661691+00:00","description":"\nMultiple off-by-one errors in Wireshark (aka Ethereal) 0.9.7 to 0.99.0 have\nunknown impact and remote attack vectors via the (1) NCP NMAS and (2) NDPS\ndissectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-3630"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-3629","published":"2006-07-21T14:03:00","updated_at":"2025-07-17T16:39:21.661691+00:00","description":"\nUnspecified vulnerability in the MOUNT dissector in Wireshark (aka\nEthereal) 0.9.4 to 0.99.0 allows remote attackers to cause a denial of\nservice (memory consumption) via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-3629"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-3628","published":"2006-07-21T14:03:00","updated_at":"2025-07-17T16:39:21.661691+00:00","description":"\nMultiple format string vulnerabilities in Wireshark (aka Ethereal) 0.10.x\nto 0.99.0 allow remote attackers to cause a denial of service and possibly\nexecute arbitrary code via the (1) ANSI MAP, (2) Checkpoint FW-1, (3) MQ,\n(4) XML, and (5) NTP dissectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-3628"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-3627","published":"2006-07-21T14:03:00","updated_at":"2025-07-17T16:39:21.661691+00:00","description":"\nUnspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka\nEthereal) 0.10.11 to 0.99.0 allows remote attackers to cause a denial of\nservice (crash) via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-3627"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-3469","published":"2006-07-21T14:03:00","updated_at":"2025-07-17T16:39:18.362811+00:00","description":"\nFormat string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21\nand 5.0 before 1 April 2006 allows remote authenticated users to cause a\ndenial of service (crash) via a format string instead of a date as the\nfirst parameter to the date_format function, which is later used in a\nformatted print call to display the error message.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-321-1","https://www.cve.org/CVERecord?id=CVE-2006-3469"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mysql-dfsg","source":"https://ubuntu.com/security/cve?package=mysql-dfsg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg","debian":"https://tracker.debian.org/pkg/mysql-dfsg","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.0","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.0","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.0","statuses":[{"release_codename":"dapper","status":"released","description":"5.0.22-0ubuntu6.06.3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.0.24a-9ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.0.38-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-321-1"],"notices":[{"id":"USN-321-1","title":"mysql-dfsg-4.1 vulnerability","summary":"mysql-dfsg-4.1 vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2006-07-21T21:56:18","description":"Jean-David Maillefer discovered a format string bug in the\ndate_format() function's error reporting. By calling the function with\ninvalid arguments, an authenticated user could exploit this to crash\nthe server.","is_hidden":false,"release_packages":{"breezy":[{"name":"mysql-server-4.1","version":"4.1.12-1ubuntu3.7","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-3469"]}]},{"id":"CVE-2006-3468","published":"2006-07-21T14:03:00","updated_at":"2025-07-17T16:39:18.362811+00:00","description":"\nLinux kernel 2.6.x, when using both NFS and EXT3, allows remote attackers\nto cause a denial of service (file system panic) via a crafted UDP packet\nwith a V2 lookup procedure that specifies a bad file handle (inode number),\nwhich triggers an error and causes an exported directory to be remounted\nread-only.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-346-1","https://www.cve.org/CVERecord?id=CVE-2006-3468"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-29.58","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.40","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-346-1"],"notices":[{"id":"USN-346-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.","references":[],"published":"2006-09-15T02:44:33","description":"A Denial of service vulnerability was reported in iptables' SCTP\nconntrack module. On computers which use this iptables module, a\nremote attacker could expoit this to trigger a kernel crash.\n(CVE-2006-2934)\n\nA buffer overflow has been discovered in the dvd_read_bca() function.\nBy inserting a specially crafted DVD, USB stick, or similar\nautomatically mounted removable device, a local user could crash the\nmachine or potentially even execute arbitrary code with full root\nprivileges. (CVE-2006-2935)\n\nThe ftdi_sio driver for serial USB ports did not limit the amount of\npending data to be written. A local user could exploit this to drain\nall available kernel memory and thus render the system unusable.\n(CVE-2006-2936)\n\nJames McKenzie discovered a Denial of Service vulnerability in the NFS\ndriver. When exporting an ext3 file system over NFS, a remote attacker\ncould exploit this to trigger a file system panic by sending a\nspecially crafted UDP packet. (CVE-2006-3468)\n\nWei Wang of McAfee Avert Labs discovered a buffer overflow in the\nsctp_make_abort_user() function of iptables' SCTP module. On computers\nwhich use this module, a local attacker could expoit this to execute\narbitrary code with root privileges. (CVE-2006-3745)\n\nOlof Johansson discovered that the kernel did not disable the 'HID0'\nbit on PowerPC 970 processors so that the ATTN instruction was\nenabled. A local user could exploit this to crash the kernel. This\nflaw only affects the powerpc architecture. (CVE-2006-4093)\n\nThe UDF file system does not handle extends larger than 1 GB, but did\nnot check for this restriction on truncating files. A local user could\nexploit this to crash the kernel. (CVE-2006-4145)","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-image-2.6.15-26-hppa32-smp","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-powerpc64-smp","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-hppa64","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-386","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-amd64-xeon","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-amd64-server","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-amd64-k8","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-source-2.6.15","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-hppa64-smp","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-k7","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-server-bigiron","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-powerpc","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-mckinley-smp","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-amd64-generic","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-server","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-mckinley","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-itanium-smp","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-hppa32","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-686","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-itanium","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-powerpc-smp","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-sparc64","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-sparc64-smp","version":"2.6.15-26.47","is_source":false,"source_link":"","version_link":""}],"hoary":[{"name":"linux-patch-ubuntu-2.6.10","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-686","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-powerpc","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-itanium","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-power4-smp","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-sparc64-smp","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-hppa64-smp","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-power3-smp","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-hppa32-smp","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-386","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-hppa32","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-sparc64","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-hppa64","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-amd64-xeon","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-itanium-smp","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-powerpc-smp","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-k7-smp","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-power3","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-k7","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-power4","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-mckinley","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-686-smp","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-amd64-k8-smp","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-amd64-generic","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-amd64-k8","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-mckinley-smp","version":"2.6.10-34.23","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"linux-image-2.6.12-10-powerpc-smp","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-patch-ubuntu-2.6.12","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-hppa32","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-itanium-smp","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-sparc64","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-powerpc64-smp","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-hppa64-smp","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-amd64-generic","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-iseries-smp","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-k7-smp","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-amd64-xeon","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-itanium","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-hppa32-smp","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-powerpc","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-mckinley","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-sparc64-smp","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-hppa64","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-amd64-k8-smp","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-686","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-686-smp","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-k7","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-mckinley-smp","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-386","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-amd64-k8","version":"2.6.12-10.39","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2934","CVE-2006-2935","CVE-2006-2936","CVE-2006-3468","CVE-2006-3745","CVE-2006-4093","CVE-2006-4145"]}]},{"id":"CVE-2006-3467","published":"2006-07-21T00:00:00","updated_at":"2025-07-17T16:39:18.362811+00:00","description":"\nInteger overflow in FreeType before 2.2 allows remote attackers to cause a\ndenial of service (crash) and possibly execute arbitrary code via a crafted\nPCF file, as demonstrated by the Red Hat bad1.pcf test file, due to a\npartial fix of CVE-2006-1861.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-341-1","https://ubuntu.com/security/notices/USN-324-1","https://www.cve.org/CVERecord?id=CVE-2006-3467"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"freetype","source":"https://ubuntu.com/security/cve?package=freetype","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freetype","debian":"https://tracker.debian.org/pkg/freetype","statuses":[{"release_codename":"dapper","status":"released","description":"2.1.10-1ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.2.1-5ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.2.1-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.3.5-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.3.5-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.3.5-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.3.5-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.3.5-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.3.5-1","component":null,"pocket":"security"}]},{"name":"ia32-libs","source":"https://ubuntu.com/security/cve?package=ia32-libs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ia32-libs","debian":"https://tracker.debian.org/pkg/ia32-libs","statuses":[{"release_codename":"dapper","status":"released","description":"1.4ubuntu20","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"has 2.3.5-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libxfont","source":"https://ubuntu.com/security/cve?package=libxfont","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxfont","debian":"https://tracker.debian.org/pkg/libxfont","statuses":[{"release_codename":"dapper","status":"released","description":"1.0.0-0ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.2.0-0ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.2.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.2.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.2.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.2.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.2.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xorg","source":"https://ubuntu.com/security/cve?package=xorg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg","debian":"https://tracker.debian.org/pkg/xorg","statuses":[{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-341-1","USN-324-1"],"notices":[{"id":"USN-341-1","title":"libxfont vulnerability","summary":"libxfont vulnerability","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.","references":[],"published":"2006-09-07T06:23:18","description":"An integer overflow has been discovered in X.org's font handling\nlibrary. By using a specially crafted font file, this could be\nexploited to crash the X server or execute arbitrary code with root\nprivileges.","is_hidden":false,"release_packages":{"dapper":[{"name":"libxfont1","version":"1:1.0.0-0ubuntu3.1","is_source":false,"source_link":"","version_link":""}],"hoary":[{"name":"libfs6","version":"6.8.2-10.3","is_source":false,"source_link":"","version_link":""},{"name":"xserver-xorg","version":"6.8.2-10.3","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"libxfont1","version":"1:0.99.0+cvs.20050909-1.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-3467"]},{"id":"USN-324-1","title":"freetype vulnerability","summary":"freetype vulnerability","instructions":"After a standard system upgrade you need to restart your session to\neffect the necessary changes.","references":[],"published":"2006-07-28T00:27:12","description":"An integer overflow has been discovered in the FreeType library. By\ntricking a user into installing and/or opening a specially crafted\nfont file, these could be exploited to execute arbitrary code with the\nprivileges of that user.","is_hidden":false,"release_packages":{"dapper":[{"name":"libfreetype6","version":"2.1.10-1ubuntu2.2","is_source":false,"source_link":"","version_link":""}],"hoary":[{"name":"libfreetype6","version":"2.1.7-2.3ubuntu0.2","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"libfreetype6","version":"2.1.7-2.4ubuntu1.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-3467"]}]},{"id":"CVE-2006-3674","published":"2006-07-18T15:47:00","updated_at":"2025-07-17T16:39:23.454235+00:00","description":"\nnNetObject.cpp in Armagetron Advanced 2.8.2 and earlier allows remote\nattackers to cause a denial of service (CPU consumption) via a large number\nhandled by the id_req_handler function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-3674"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"armagetronad","source":"https://ubuntu.com/security/cve?package=armagetronad","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=armagetronad","debian":"https://tracker.debian.org/pkg/armagetronad","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-3673","published":"2006-07-18T15:47:00","updated_at":"2025-07-17T16:39:23.454235+00:00","description":"\nnNetObject.cpp in Armagetron Advanced 2.8.2 and earlier allows remote\nattackers to cause a denial of service (application crash) via a large\nowner value, which causes an assert error.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-3673"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"armagetronad","source":"https://ubuntu.com/security/cve?package=armagetronad","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=armagetronad","debian":"https://tracker.debian.org/pkg/armagetronad","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-3672","published":"2006-07-18T15:47:00","updated_at":"2025-07-17T16:39:23.454235+00:00","description":"\nKDE Konqueror 3.5.1 and earlier allows remote attackers to cause a denial\nof service (application crash) by calling the replaceChild method on a DOM\nobject, which triggers a null dereference, as demonstrated by calling\ndocument.replaceChild with a 0 (zero) argument.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-322-1","https://www.cve.org/CVERecord?id=CVE-2006-3672"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kdelibs","source":"https://ubuntu.com/security/cve?package=kdelibs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kdelibs","debian":"https://tracker.debian.org/pkg/kdelibs","statuses":[{"release_codename":"dapper","status":"released","description":"3.5.2-0ubuntu18.5","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.5.5-0ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.5.6-0ubuntu14.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-322-1"],"notices":[{"id":"USN-322-1","title":"Konqueror vulnerability","summary":"Konqueror vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.","references":[],"published":"2006-07-25T01:09:24","description":"A Denial of Service vulnerability has been reported in the replaceChild()\nmethod in KDE's DOM handler. A malicious remote web page could exploit\nthis to cause Konqueror to crash.","is_hidden":false,"release_packages":{"dapper":[{"name":"kdelibs","version":"4:3.5.2-0ubuntu18.1","is_source":false,"source_link":"","version_link":""}],"hoary":[{"name":"kdelibs","version":"4:3.4.0-0ubuntu3.6","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"kdelibs","version":"4:3.4.3-0ubuntu2.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-3672"]}]},{"id":"CVE-2006-3671","published":"2006-07-18T15:47:00","updated_at":"2025-07-17T16:39:23.454235+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in the communicate function\nin estmaster.c for Hyper Estraier before 1.3.3 allows remote attackers to\nperform unauthorized actions as other users via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-3671"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"hyperestraier","source":"https://ubuntu.com/security/cve?package=hyperestraier","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=hyperestraier","debian":"https://tracker.debian.org/pkg/hyperestraier","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.3.6-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.3.6-1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.3.6-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.3.6-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.3.6-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.3.6-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.3.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-3668","published":"2006-07-18T15:47:00","updated_at":"2025-07-17T16:39:21.661691+00:00","description":"\nHeap-based buffer overflow in the it_read_envelope function in Dynamic\nUniversal Music Bibliotheque (DUMB) 0.9.3 and earlier and current CVS as of\n20060716, including libdumb, allows user-assisted attackers to execute\narbitrary code via a \".it\" (Impulse Tracker) file with an envelope with a\nlarge number of nodes.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-3668"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libdumb","source":"https://ubuntu.com/security/cve?package=libdumb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libdumb","debian":"https://tracker.debian.org/pkg/libdumb","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.9.3-5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.9.3-5","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.9.3-5","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.9.3-5","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.9.3-5","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.9.3-5","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.9.3-5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-3665","published":"2006-07-18T15:47:00","updated_at":"2025-07-17T16:39:21.661691+00:00","description":"\nSquirrelMail 1.4.6 and earlier, with register_globals enabled, allows\nremote attackers to hijack cookies in src/redirect.php via unknown vectors.\n NOTE: while \"cookie theft\" is frequently associated with XSS, the vendor\ndisclosure is too vague to be certain of this.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-3665"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"squirrelmail","source":"https://ubuntu.com/security/cve?package=squirrelmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squirrelmail","debian":"https://tracker.debian.org/pkg/squirrelmail","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2:1.4.7-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2:1.4.7-1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2:1.4.7-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2:1.4.7-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2:1.4.7-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2:1.4.7-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2:1.4.7-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-3626","published":"2006-07-18T15:46:00","updated_at":"2025-07-17T16:39:21.661691+00:00","description":"\nRace condition in Linux kernel 2.6.17.4 and earlier allows local users to\ngain root privileges by using prctl with PR_SET_DUMPABLE in a way that\ncauses /proc/self/environ to become setuid root.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-319-2","https://ubuntu.com/security/notices/USN-319-1","https://ubuntu.com/security/notices/USN-319-1","https://www.cve.org/CVERecord?id=CVE-2006-3626"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-29.58","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.40","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-319-2","USN-319-1"],"notices":[{"id":"USN-319-2","title":"Linux kernel vulnerability","summary":"Linux kernel vulnerability","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.","references":[],"published":"2006-07-19T21:17:11","description":"USN-319-1 fixed a Linux kernel vulnerability in Ubuntu 6.06 LTS. This\nfollowup advisory provides the corresponding updates for Ubuntu 5.04\nand 5.10.\n\nFor reference, these are the details of the original USN:\n\n A race condition has been discovered in the file permission handling\n of the /proc file system. A local attacker could exploit this to\n execute arbitrary code with full root privileges.","is_hidden":false,"release_packages":{"hoary":[{"name":"linux-patch-ubuntu-2.6.10","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-686","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-powerpc","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-itanium","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-power4-smp","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-sparc64-smp","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-hppa64-smp","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-power3-smp","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-hppa32-smp","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-386","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-hppa32","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-sparc64","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-hppa64","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-amd64-xeon","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-itanium-smp","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-powerpc-smp","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-k7-smp","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-power3","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-k7","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-power4","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-mckinley","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-686-smp","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-amd64-k8-smp","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-amd64-generic","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-amd64-k8","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.10-6-mckinley-smp","version":"2.6.10-34.22","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"linux-image-2.6.12-10-powerpc-smp","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-patch-ubuntu-2.6.12","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-hppa32","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-itanium-smp","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-sparc64","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-powerpc64-smp","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-hppa64-smp","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-amd64-generic","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-iseries-smp","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-k7-smp","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-amd64-xeon","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-itanium","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-hppa32-smp","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-powerpc","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-mckinley","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-sparc64-smp","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-hppa64","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-amd64-k8-smp","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-686","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-686-smp","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-k7","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-mckinley-smp","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-386","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-amd64-k8","version":"2.6.12-10.36","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-3626"]},{"id":"USN-319-1","title":"Linux kernel vulnerability","summary":"Linux kernel vulnerability","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nThis flaw affects Ubuntu 5.04 and Ubuntu 5.10 as well; these releases\nwill be fixed shortly in a followup advisory.","references":[],"published":"2006-07-18T18:13:52","description":"A race condition has been discovered in the file permission handling\nof the /proc file system. A local attacker could exploit this to\nexecute arbitrary code with full root privileges.","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-image-2.6.15-26-hppa32-smp","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-powerpc64-smp","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-hppa64","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-386","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-amd64-xeon","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-amd64-server","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-amd64-k8","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-hppa64-smp","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-k7","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-server-bigiron","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-powerpc","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-mckinley-smp","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-amd64-generic","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-server","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-mckinley","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-itanium-smp","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-hppa32","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-686","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-itanium","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-powerpc-smp","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-sparc64","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.15-26-sparc64-smp","version":"2.6.15-26.45","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-3626","CVE-2006-3626"]}]},{"id":"CVE-2006-2450","published":"2006-07-18T15:40:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nauth.c in LibVNCServer 0.7.1 allows remote attackers to bypass\nauthentication via a request in which the client specifies an insecure\nsecurity type such as \"Type 1 - None\", which is accepted even if it is not\noffered by the server, a different issue than CVE-2006-2369.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-2450"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libvncserver","source":"https://ubuntu.com/security/cve?package=libvncserver","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvncserver","debian":"https://tracker.debian.org/pkg/libvncserver","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-3600","published":"2006-07-18T15:37:00","updated_at":"2025-07-17T16:39:19.843682+00:00","description":"\nMultiple stack-based buffer overflows in the LookupTRM::lookup function in\nlibtunepimp (TunePimp) 0.4.2 allow remote user-assisted attackers to cause\na denial of service (application crash) and possibly execute code via a\nlong (1) Album release date (MBE_ReleaseGetDate), (2) data, or (3) error\nstrings.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-3600"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libtunepimp","source":"https://ubuntu.com/security/cve?package=libtunepimp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libtunepimp","debian":"https://tracker.debian.org/pkg/libtunepimp","statuses":[{"release_codename":"dapper","status":"released","description":"0.3.0-9.1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.4.2-3ubuntu3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.4.2-3ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-3597","published":"2006-07-18T15:37:00","updated_at":"2025-07-17T16:39:19.843682+00:00","description":"\npasswd before 1:4.0.13 on Ubuntu 6.06 LTS leaves the root password blank\ninstead of locking it when the administrator selects the \"Go Back\" option\nafter the final \"Installation complete\" message and uses the main menu,\nwhich causes the password to be zeroed out in the installer's memory.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-3597"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"shadow","source":"https://ubuntu.com/security/cve?package=shadow","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=shadow","debian":"https://tracker.debian.org/pkg/shadow","statuses":[{"release_codename":"dapper","status":"released","description":"4.0.13-7ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-3588","published":"2006-07-13T21:05:00","updated_at":"2025-07-17T16:39:19.843682+00:00","description":"\nUnspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0\nallows remote attackers to cause a denial of service (browser crash) via a\nmalformed, compressed .swf file, a different issue than CVE-2006-3587.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-3588"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"7.0.68~ubuntu3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"9.0.48.0.0ubuntu1~7.04.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"7.0.68~ubuntu3","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"7.0.68~ubuntu3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"7.0.68~ubuntu3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"7.0.68~ubuntu3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"7.0.68~ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-3587","published":"2006-07-13T21:05:00","updated_at":"2025-07-17T16:39:19.843682+00:00","description":"\nUnspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0\nallows remote attackers to execute arbitrary commands via a malformed .swf\nfile that results in \"multiple improper memory access\" errors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-3587"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"7.0.68~ubuntu3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"9.0.48.0.0ubuntu1~7.04.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"7.0.68~ubuntu3","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"7.0.68~ubuntu3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"7.0.68~ubuntu3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"7.0.68~ubuntu3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"7.0.68~ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":77380,"limit":20,"total_results":79316}