{"cves":[{"id":"CVE-2006-0632","published":"2006-02-10T11:02:00","updated_at":"2025-07-17T16:37:41.472703+00:00","description":"\nThe gen_rand_string function in phpBB 2.0.19 uses insufficiently random\ndata (small value space) to create the activation key (\"validation ID\")\nthat is sent by e-mail when establishing a password, which makes it easier\nfor remote attackers to obtain the key and modify passwords for existing\naccounts or create new accounts.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0632"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"phpbb2","source":"https://ubuntu.com/security/cve?package=phpbb2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpbb2","debian":"https://tracker.debian.org/pkg/phpbb2","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.21-6","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.21-6","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.21-6","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.21-6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0612","published":"2006-02-09T00:02:00","updated_at":"2025-07-17T16:37:41.472703+00:00","description":"\nPowersave daemon before 0.10.15.2 allows local users to gain privileges\n(unauthorized access to an X session) via unspecified vectors. NOTE: the\nprovenance of this information is unknown; portions of the details are\nobtained from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0612"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"powersave","source":"https://ubuntu.com/security/cve?package=powersave","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=powersave","debian":"https://tracker.debian.org/pkg/powersave","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0582","published":"2006-02-08T01:02:00","updated_at":"2025-07-17T16:37:41.472703+00:00","description":"\nUnspecified vulnerability in rshd in Heimdal 0.6.x before 0.6.6 and 0.7.x\nbefore 0.7.2, when storing forwarded credentials, allows attackers to\noverwrite arbitrary files and change file ownership via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-247-1","https://www.cve.org/CVERecord?id=CVE-2006-0582"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"heimdal","source":"https://ubuntu.com/security/cve?package=heimdal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=heimdal","debian":"https://tracker.debian.org/pkg/heimdal","statuses":[{"release_codename":"dapper","status":"released","description":"0.7.1-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.7.1-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.7.1-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-247-1"],"notices":[{"id":"USN-247-1","title":"Heimdal vulnerability","summary":"Heimdal vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2006-02-11T18:35:38","description":"A privilege escalation flaw has been found in the heimdal rsh (remote\nshell) server. This allowed an authenticated attacker to overwrite\narbitrary files and gain ownership of them.\n\nPlease note that the heimdal-servers package is not officially\nsupported in Ubuntu (it is in the 'universe' component of the\narchive). However, this affects you if you use a customized version\nbuilt from the heimdal source package (which is supported).","is_hidden":false,"release_packages":{"hoary":[{"name":"heimdal-servers","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"heimdal-servers","version":"","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"heimdal-servers","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-0582"]}]},{"id":"CVE-2006-0579","published":"2006-02-08T01:02:00","updated_at":"2025-07-17T16:37:41.472703+00:00","description":"\nMultiple integer overflows in (1) the new_demux_packet function in\ndemuxer.h and (2) the demux_asf_read_packet function in demux_asf.c in\nMPlayer 1.0pre7try2 and earlier allow remote attackers to execute arbitrary\ncode via an ASF file with a large packet length value. NOTE: the provenance\nof this information is unknown; portions of the details are obtained from\nthird party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0579"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mplayer","source":"https://ubuntu.com/security/cve?package=mplayer","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mplayer","debian":"https://tracker.debian.org/pkg/mplayer","statuses":[{"release_codename":"dapper","status":"released","description":"0.99+1.0pre7try2+cvs20060117-0ubuntu8","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99+1.0pre7try2+cvs20060117-0ubuntu8","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.0~rc1-0ubuntu9.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0576","published":"2006-02-08T00:06:00","updated_at":"2025-07-17T16:37:41.472703+00:00","description":"\nUntrusted search path vulnerability in opcontrol in OProfile 0.9.1 and\nearlier allows local users to execute arbitrary commands via a modified\nPATH that references malicious (1) which or (2) dirname programs. NOTE:\nwhile opcontrol normally is not run setuid, a common configuration suggests\naccessing opcontrol using sudo. In such a context, this is a\nvulnerability.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0576"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"oprofile","source":"https://ubuntu.com/security/cve?package=oprofile","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oprofile","debian":"https://tracker.debian.org/pkg/oprofile","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"0.9.1-8ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.9.2-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.9.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0575","published":"2006-02-07T20:02:00","updated_at":"2025-07-17T16:37:41.472703+00:00","description":"\nconvert-fcrontab in Fcron 2.9.5 and 3.0.0 allows remote attackers to create\nor overwrite arbitrary files via \"..\" sequences and a symlink attack on the\ntemporary file that is used during conversion.","ubuntu_description":"","notes":[{"author":"fujitsu","note":"Vulnerable binary not in package."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0575"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"fcron","source":"https://ubuntu.com/security/cve?package=fcron","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fcron","debian":"https://tracker.debian.org/pkg/fcron","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0454","published":"2006-02-07T18:06:00","updated_at":"2025-07-17T16:37:38.570540+00:00","description":"\nLinux kernel before 2.6.15.3 down to 2.6.12, while constructing an ICMP\nresponse in icmp_send, does not properly handle when the ip_options_echo\nfunction in icmp.c fails, which allows remote attackers to cause a denial\nof service (crash) via vectors such as (1) record-route and (2) timestamp\nIP options with the needaddr bit set and a truncated value.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-250-1","https://www.cve.org/CVERecord?id=CVE-2006-0454"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-29.58","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.40","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-250-1"],"notices":[{"id":"USN-250-1","title":"Linux kernel vulnerability","summary":"Linux kernel vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2006-02-15T17:44:17","description":"Herbert Xu discovered a remote Denial of Service vulnerability in the\nICMP packet handler. In some situations a memory allocation was\nreleased twice, which led to memory corruption. A remote attacker\ncould exploit this to crash the machine.","is_hidden":false,"release_packages":{"breezy":[{"name":"linux-image-2.6.12-10-amd64-k8-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-686","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-amd64-generic","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-powerpc-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-patch-ubuntu-2.6.12","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-iseries-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-itanium-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-686-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-mckinley","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-amd64-xeon","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-k7","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-k7-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-mckinley-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-itanium","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-powerpc","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-amd64-k8","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-powerpc64-smp","version":"","is_source":false,"source_link":"","version_link":""},{"name":"linux-image-2.6.12-10-386","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-0454"]}]},{"id":"CVE-2006-0438","published":"2006-02-06T22:02:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when Link\nto off-site Avatar or bbcode (IMG) are enabled, allows remote attackers to\nperform unauthorized actions as a logged in user via a link or IMG tag in a\nuser profile, as demonstrated using links to (1) admin/admin_users.php and\n(2) modcp.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0438"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"phpbb2","source":"https://ubuntu.com/security/cve?package=phpbb2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpbb2","debian":"https://tracker.debian.org/pkg/phpbb2","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"2.0.22-3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"2.0.23+repack-4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.20","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0437","published":"2006-02-06T22:02:00","updated_at":"2025-07-17T16:37:38.570540+00:00","description":"\nCross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB\n2.0.19 allows remote attackers to inject arbitrary web script or HTML via\nJavascript events such as \"onmouseover\" in the (1) smile_url or (2)\nsmile_emotion parameters, which bypasses a check for \"<\" and \">\"\ncharacters.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0437"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"phpbb2","source":"https://ubuntu.com/security/cve?package=phpbb2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpbb2","debian":"https://tracker.debian.org/pkg/phpbb2","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.21-3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.21-3","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.21-3","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.21-3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.21-3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0539","published":"2006-02-04T02:02:00","updated_at":"2025-07-17T16:37:39.936119+00:00","description":"\nThe convert-fcrontab program in fcron 3.0.0 might allow local users to gain\nprivileges via a long command-line argument, which causes Linux glibc to\nreport heap memory corruption, possibly because a strcpy in the strdup2\nfunction can \"overwrite some data.\"","ubuntu_description":"","notes":[{"author":"fujitsu","note":"Not setuid, so not vulnerable."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0539"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"fcron","source":"https://ubuntu.com/security/cve?package=fcron","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fcron","debian":"https://tracker.debian.org/pkg/fcron","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0533","published":"2006-02-04T00:06:00","updated_at":"2025-07-17T16:37:39.936119+00:00","description":"\nCross-site scripting (XSS) vulnerability in webmailaging.cgi in cPanel\nallows remote attackers to inject arbitrary web script or HTML via the\nnumdays parameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0533"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"cpanel","source":"https://ubuntu.com/security/cve?package=cpanel","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cpanel","debian":"https://tracker.debian.org/pkg/cpanel","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0299","published":"2006-02-02T23:06:00","updated_at":"2025-07-17T16:37:35.706045+00:00","description":"\nThe E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5\nif running Javascript in mail, and SeaMonkey before 1.0 exposes the\ninternal \"AnyName\" object to external interfaces, which allows multiple\ncooperating domains to exchange information in violation of the same origin\nrestrictions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0299"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.0.6+0dfsg-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.0.6+1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0.13-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0.13-0ubuntu0.7.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0298","published":"2006-02-02T22:02:00","updated_at":"2025-07-17T16:37:35.706045+00:00","description":"\nThe XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0\nallows remote attackers to cause a denial of service (crash) and possibly\nread sensitive data via unknown attack vectors that trigger an\nout-of-bounds read.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0298"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.0.6+0dfsg-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.0.6+1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0.13-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0.13-0ubuntu0.7.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0297","published":"2006-02-02T22:02:00","updated_at":"2025-07-17T16:37:35.706045+00:00","description":"\nMultiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if\nJavascript is enabled in mail, and SeaMonkey before 1.0 might allow remote\nattackers to execute arbitrary code via the (1) EscapeAttributeValue in\njsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3)\nnsCanvasRenderingContext2D.cpp in Canvas.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0297"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.0.6+0dfsg-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.0.6+1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0.13-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0.13-0ubuntu0.7.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.8.0.5-4.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.8.0.5-4.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0296","published":"2006-02-02T20:06:00","updated_at":"2025-07-17T16:37:35.706045+00:00","description":"\nThe XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and\nSeaMonkey before 1.0 does not validate the attribute name, which allows\nremote attackers to execute arbitrary Javascript by injecting RDF data into\nthe user's localstore.rdf file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-276-1","https://ubuntu.com/security/notices/USN-271-1","https://ubuntu.com/security/notices/USN-275-1","https://www.cve.org/CVERecord?id=CVE-2006-0296"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.0.6+0dfsg-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.0.6+1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0.13-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0.13-0ubuntu0.7.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-275-1","USN-271-1","USN-276-1"],"notices":[{"id":"USN-275-1","title":"Mozilla vulnerabilities","summary":"Mozilla vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2006-04-28T06:42:37","description":"Web pages with extremely long titles caused subsequent launches of\nMozilla browser to hang for up to a few minutes, or caused Mozilla to\ncrash on computers with\tinsufficient memory. (CVE-2005-4134)\n\nIgor Bukanov discovered that the JavaScript engine did not properly\ndeclare some temporary variables. Under some rare circumstances, a\nmalicious website could exploit this to execute arbitrary code with\nthe privileges of the user. (CVE-2006-0292, CVE-2006-1742)\n\nThe function XULDocument.persist() did not sufficiently validate the\nnames of attributes. An attacker could exploit this to inject\narbitrary XML code into the file 'localstore.rdf', which is read and\nevaluated at startup. This could include JavaScript commands that\nwould be run with the user's privileges. (CVE-2006-0296)\n\nDue to a flaw in the HTML tag parser a specific sequence of HTML tags\ncaused memory corruption. A malicious web site could exploit this to\ncrash the browser or even execute arbitrary code with the user's\nprivileges. (CVE-2006-0748)\n\nAn invalid ordering of table-related tags caused Mozilla to use a\nnegative array index. A malicious website could exploit this to\nexecute arbitrary code with the privileges of the user.\n(CVE-2006-0749)\n\nGeorgi Guninski discovered that embedded XBL scripts of web sites\ncould escalate their (normally reduced) privileges to get full\nprivileges of the user if that page is viewed with \"Print Preview\".\n(CVE-2006-1727)\n\nThe crypto.generateCRMFRequest() function had a flaw which could be\nexploited to run arbitrary code with the user's privileges.\n(CVE-2006-1728)\n\nClaus Jørgensen and Jesse Ruderman discovered that a text input box\ncould be pre-filled with a filename and then turned into a file-upload\ncontrol with the contents intact. A malicious web site could exploit\nthis to read any local file the user has read privileges for.\n(CVE-2006-1729)\n\nAn integer overflow was detected in the handling of the CSS property\n\"letter-spacing\". A malicious web site could exploit this to run\narbitrary code with the user's privileges. (CVE-2006-1730)\n\nThe methods valueOf.call() and .valueOf.apply() returned an object\nwhose privileges were not properly confined to those of the caller,\nwhich made them vulnerable to cross-site scripting attacks. A\nmalicious web site could exploit this to modify the contents or steal\nconfidential data (such as passwords) from other opened web pages.\n(CVE-2006-1731) The window.controllers array variable (CVE-2006-1732)\nand event handlers (CVE-2006-1741) were vulnerable to a similar attack. \n\nThe privileged built-in XBL bindings were not fully protected from web\ncontent and could be accessed by calling valueOf.call() and\nvalueOf.apply() on a method of that binding. A malicious web site\ncould exploit this to run arbitrary JavaScript code with the user's\nprivileges. (CVE-2006-1733)\n\nIt was possible to use the Object.watch() method to access an internal\nfunction object (the \"clone parent\"). A malicious web site could\nexploit this to execute arbitrary JavaScript code with the user's\nprivileges. (CVE-2006-1734)\n\nBy calling the XBL.method.eval() method in a special way it was\npossible to create JavaScript functions that would get compiled with\nthe wrong privileges. A malicious web site could exploit this to\nexecute arbitrary JavaScript code with the user's privileges.\n(CVE-2006-1735)\n\nMichael Krax discovered that by layering a transparent image link to\nan executable on top of a visible (and presumably desirable) image a\nmalicious site could fool the user to right-click and choose \"Save\nimage as...\" from the context menu, which would download the\nexecutable instead of the image. (CVE-2006-1736)\n\nSeveral crashes have been fixed which could be triggered by web sites\nand involve memory corruption. These could potentially be exploited to\nexecute arbitrary code with the user's privileges. (CVE-2006-1737,\nCVE-2006-1738, CVE-2006-1739, CVE-2006-1790)\n\nIf the user has turned on the \"Entering secure site\" modal warning\ndialog, it was possible to spoof the browser's secure-site indicators\n(the lock icon and the gold URL field background) by first loading the\ntarget secure site in a pop-up window, then changing its location to a\ndifferent site, which retained the displayed secure-browsing\nindicators from the original site. (CVE-2006-1740)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-psm","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"mozilla-psm","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-psm","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-1736","CVE-2005-4134","CVE-2006-1729","CVE-2006-1740","CVE-2006-0292","CVE-2006-0296","CVE-2006-0748","CVE-2006-0749","CVE-2006-1727","CVE-2006-1728","CVE-2006-1730","CVE-2006-1731","CVE-2006-1732","CVE-2006-1733","CVE-2006-1734","CVE-2006-1735","CVE-2006-1737","CVE-2006-1738","CVE-2006-1739","CVE-2006-1741","CVE-2006-1742","CVE-2006-1790"]},{"id":"USN-271-1","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2006-04-20T00:32:19","description":"Web pages with extremely long titles caused subsequent launches of\nFirefox browser to hang for up to a few minutes, or caused Firefox to\ncrash on computers with\tinsufficient memory. (CVE-2005-4134)\n\nIgor Bukanov discovered that the JavaScript engine did not properly\ndeclare some temporary variables. Under some rare circumstances, a\nmalicious website could exploit this to execute arbitrary code with\nthe privileges of the user. (CVE-2006-0292, CVE-2006-1742)\n\nThe function XULDocument.persist() did not sufficiently validate the\nnames of attributes. An attacker could exploit this to inject\narbitrary XML code into the file 'localstore.rdf', which is read and\nevaluated at startup. This could include JavaScript commands that\nwould be run with the user's privileges. (CVE-2006-0296)\n\nDue to a flaw in the HTML tag parser a specific sequence of HTML tags\ncaused memory corruption. A malicious web site could exploit this to\ncrash the browser or even execute arbitrary code with the user's\nprivileges. (CVE-2006-0749)\n\nGeorgi Guninski discovered that embedded XBL scripts of web sites\ncould escalate their (normally reduced) privileges to get full\nprivileges of the user if that page is viewed with \"Print Preview\".\n(CVE-2006-1727)\n\nThe crypto.generateCRMFRequest() function had a flaw which could be\nexploited to run arbitrary code with the user's privileges.\n(CVE-2006-1728)\n\nClaus Jørgensen and Jesse Ruderman discovered that a text input box\ncould be pre-filled with a filename and then turned into a file-upload\ncontrol with the contents intact. A malicious web site could exploit\nthis to read any local file the user has read privileges for.\n(CVE-2006-1729)\n\nAn integer overflow was detected in the handling of the CSS property\n\"letter-spacing\". A malicious web site could exploit this to run\narbitrary code with the user's privileges. (CVE-2006-1730)\n\nThe methods valueOf.call() and .valueOf.apply() returned an object\nwhose privileges were not properly confined to those of the caller,\nwhich made them vulnerable to cross-site scripting attacks. A\nmalicious web site could exploit this to modify the contents or steal\nconfidential data (such as passwords) from other opened web pages.\n(CVE-2006-1731) The window.controllers array variable (CVE-2006-1732)\nand event handlers (CVE-2006-1741) were vulnerable to a similar attack. \n\nThe privileged built-in XBL bindings were not fully protected from web\ncontent and could be accessed by calling valueOf.call() and\nvalueOf.apply() on a method of that binding. A malicious web site\ncould exploit this to run arbitrary JavaScript code with the user's\nprivileges. (CVE-2006-1733)\n\nIt was possible to use the Object.watch() method to access an internal\nfunction object (the \"clone parent\"). A malicious web site could\nexploit this to execute arbitrary JavaScript code with the user's\nprivileges. (CVE-2006-1734)\n\nBy calling the XBL.method.eval() method in a special way it was\npossible to create JavaScript functions that would get compiled with\nthe wrong privileges. A malicious web site could exploit this to\nexecute arbitrary JavaScript code with the user's privileges.\n(CVE-2006-1735)\n\nMichael Krax discovered that by layering a transparent image link to\nan executable on top of a visible (and presumably desirable) image a\nmalicious site could fool the user to right-click and choose \"Save\nimage as...\" from the context menu, which would download the\nexecutable instead of the image. (CVE-2006-1736)\n\nSeveral crashes have been fixed which could be triggered by web sites\nand involve memory corruption. These could potentially be exploited to\nexecute arbitrary code with the user's privileges. (CVE-2006-1737,\nCVE-2006-1738, CVE-2006-1739, CVE-2006-1790)\n\nIf the user has turned on the \"Entering secure site\" modal warning\ndialog, it was possible to spoof the browser's secure-site indicators\n(the lock icon and the gold URL field background) by first loading the\ntarget secure site in a pop-up window, then changing its location to a\ndifferent site, which retained the displayed secure-browsing\nindicators from the original site. (CVE-2006-1740)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-firefox","version":"","is_source":false,"source_link":"","version_link":""},{"name":"firefox","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"mozilla-firefox","version":"","is_source":false,"source_link":"","version_link":""},{"name":"firefox","version":"","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-firefox","version":"","is_source":false,"source_link":"","version_link":""},{"name":"firefox","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-4134","CVE-2006-0292","CVE-2006-0296","CVE-2006-0749","CVE-2006-1727","CVE-2006-1728","CVE-2006-1729","CVE-2006-1730","CVE-2006-1731","CVE-2006-1732","CVE-2006-1733","CVE-2006-1734","CVE-2006-1735","CVE-2006-1736","CVE-2006-1737","CVE-2006-1738","CVE-2006-1739","CVE-2006-1740","CVE-2006-1741","CVE-2006-1742","CVE-2006-1790"]},{"id":"USN-276-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2006-05-03T18:44:54","description":"Igor Bukanov discovered that the JavaScript engine did not properly\ndeclare some temporary variables. Under some rare circumstances, a\nmalicious mail with embedded JavaScript could exploit this to execute\narbitrary code with the privileges of the user. (CVE-2006-0292,\nCVE-2006-1742)\n\nThe function XULDocument.persist() did not sufficiently validate the\nnames of attributes. An attacker could exploit this to inject\narbitrary XML code into the file 'localstore.rdf', which is read and\nevaluated at startup. This could include JavaScript commands that\nwould be run with the user's privileges. (CVE-2006-0296)\n\nDue to a flaw in the HTML tag parser a specific sequence of HTML tags\ncaused memory corruption. A malicious HTML email could exploit this to\ncrash the browser or even execute arbitrary code with the user's\nprivileges. (CVE-2006-0748)\n\nAn invalid ordering of table-related tags caused Thunderbird to use a\nnegative array index. A malicious HTML email could exploit this to\nexecute arbitrary code with the privileges of the user.\n(CVE-2006-0749)\n\nGeorgi Guninski discovered that forwarding mail in-line while using\nthe default HTML \"rich mail\" editor executed JavaScript embedded in\nthe email message. Forwarding mail in-line is not the default setting\nbut it is easily accessed through the \"Forward As\" menu item.\n(CVE-2006-0884)\n\nAs a privacy measure to prevent senders (primarily spammers) from\ntracking when email is read Thunderbird does not load remote content\nreferenced from an HTML mail message until a user tells it to do so.\nThis normally includes the content of frames and CSS files. It was\ndiscovered that it was possible to bypass this restriction by\nindirectly including remote content through an intermediate inline CSS\nscript or frame. (CVE-2006-1045)\n\nGeorgi Guninski discovered that embedded XBL scripts could escalate\ntheir (normally reduced) privileges to get full privileges of the user\nif the email is viewed with \"Print Preview\". (CVE-2006-1727)\n\nThe crypto.generateCRMFRequest() function had a flaw which could be\nexploited to run arbitrary code with the user's privileges.\n(CVE-2006-1728)\n\nAn integer overflow was detected in the handling of the CSS property\n\"letter-spacing\". A malicious HTML email could exploit this to run\narbitrary code with the user's privileges. (CVE-2006-1730)\n\nThe methods valueOf.call() and .valueOf.apply() returned an object\nwhose privileges were not properly confined to those of the caller,\nwhich made them vulnerable to cross-site scripting attacks. A\nmalicious email with embedded JavaScript code could exploit this to\nmodify the contents or steal confidential data (such as passwords)\nfrom other opened web pages. (CVE-2006-1731) The window.controllers\narray variable (CVE-2006-1732) and event handlers (CVE-2006-1741) were\nvulnerable to a similar attack.\n\nThe privileged built-in XBL bindings were not fully protected from web\ncontent and could be accessed by calling valueOf.call() and\nvalueOf.apply() on a method of that binding. A malicious email could\nexploit this to run arbitrary JavaScript code with the user's\nprivileges. (CVE-2006-1733)\n\nIt was possible to use the Object.watch() method to access an internal\nfunction object (the \"clone parent\"). A malicious email containing\nJavaScript code could exploit this to execute arbitrary code with the\nuser's privileges. (CVE-2006-1734)\n\nBy calling the XBL.method.eval() method in a special way it was\npossible to create JavaScript functions that would get compiled with\nthe wrong privileges. A malicious email could exploit this to execute\narbitrary JavaScript code with the user's privileges. (CVE-2006-1735)\n\nSeveral crashes have been fixed which could be triggered by specially\ncrafted HTML content and involve memory corruption. These could\npotentially be exploited to execute arbitrary code with the user's\nprivileges. (CVE-2006-1737, CVE-2006-1738, CVE-2006-1739,\nCVE-2006-1790)\n\nThe \"enigmail\" plugin has been updated to work with the new\nThunderbird and Mozilla versions.","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-thunderbird","version":"","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-thunderbird","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-1742","CVE-2006-1739","CVE-2006-1737","CVE-2006-1728","CVE-2006-0884","CVE-2006-1741","CVE-2006-0296","CVE-2006-0748","CVE-2006-1738","CVE-2006-1732","CVE-2006-1733","CVE-2006-1727","CVE-2006-1735","CVE-2006-1734","CVE-2006-0292","CVE-2006-1730","CVE-2006-1045","CVE-2006-1731","CVE-2006-1790","CVE-2006-0749"]}]},{"id":"CVE-2006-0295","published":"2006-02-02T20:06:00","updated_at":"2025-07-17T16:37:35.706045+00:00","description":"\nMozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and\nSeaMonkey before 1.0 might allow remote attackers to execute arbitrary code\nvia the QueryInterface method of the built-in Location and Navigator\nobjects, which leads to memory corruption.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0295"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.0.6+0dfsg-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.0.6+1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0.13-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0.13-0ubuntu0.7.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0294","published":"2006-02-02T20:06:00","updated_at":"2025-07-17T16:37:35.706045+00:00","description":"\nMozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in\nmail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary\ncode by changing an element's style from position:relative to\nposition:static, which causes Gecko to operate on freed memory.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0294"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.0.6+0dfsg-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.0.6+1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0.13-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0.13-0ubuntu0.7.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0293","published":"2006-02-02T20:06:00","updated_at":"2025-07-17T16:37:35.706045+00:00","description":"\nThe function allocation code (js_NewFunction in jsfun.c) in Firefox 1.5\nallows attackers to cause a denial of service (memory corruption) and\npossibly execute arbitrary code via user-defined methods that trigger\ngarbage collection in a way that operates on freed objects.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0293"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.0.6+0dfsg-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.0.6+1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0292","published":"2006-02-02T20:06:00","updated_at":"2025-07-17T16:37:33.412269+00:00","description":"\nThe Javascript interpreter (jsinterp.c) in Mozilla and Firefox before 1.5.1\ndoes not properly dereference objects, which allows remote attackers to\ncause a denial of service (crash) or execute arbitrary code via unknown\nattack vectors related to garbage collection.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-276-1","https://ubuntu.com/security/notices/USN-271-1","https://ubuntu.com/security/notices/USN-275-1","https://www.cve.org/CVERecord?id=CVE-2006-0292"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.0.6+0dfsg-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.0.6+1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0.13-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0.13-0ubuntu0.7.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-275-1","USN-271-1","USN-276-1"],"notices":[{"id":"USN-275-1","title":"Mozilla vulnerabilities","summary":"Mozilla vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2006-04-28T06:42:37","description":"Web pages with extremely long titles caused subsequent launches of\nMozilla browser to hang for up to a few minutes, or caused Mozilla to\ncrash on computers with\tinsufficient memory. (CVE-2005-4134)\n\nIgor Bukanov discovered that the JavaScript engine did not properly\ndeclare some temporary variables. Under some rare circumstances, a\nmalicious website could exploit this to execute arbitrary code with\nthe privileges of the user. (CVE-2006-0292, CVE-2006-1742)\n\nThe function XULDocument.persist() did not sufficiently validate the\nnames of attributes. An attacker could exploit this to inject\narbitrary XML code into the file 'localstore.rdf', which is read and\nevaluated at startup. This could include JavaScript commands that\nwould be run with the user's privileges. (CVE-2006-0296)\n\nDue to a flaw in the HTML tag parser a specific sequence of HTML tags\ncaused memory corruption. A malicious web site could exploit this to\ncrash the browser or even execute arbitrary code with the user's\nprivileges. (CVE-2006-0748)\n\nAn invalid ordering of table-related tags caused Mozilla to use a\nnegative array index. A malicious website could exploit this to\nexecute arbitrary code with the privileges of the user.\n(CVE-2006-0749)\n\nGeorgi Guninski discovered that embedded XBL scripts of web sites\ncould escalate their (normally reduced) privileges to get full\nprivileges of the user if that page is viewed with \"Print Preview\".\n(CVE-2006-1727)\n\nThe crypto.generateCRMFRequest() function had a flaw which could be\nexploited to run arbitrary code with the user's privileges.\n(CVE-2006-1728)\n\nClaus Jørgensen and Jesse Ruderman discovered that a text input box\ncould be pre-filled with a filename and then turned into a file-upload\ncontrol with the contents intact. A malicious web site could exploit\nthis to read any local file the user has read privileges for.\n(CVE-2006-1729)\n\nAn integer overflow was detected in the handling of the CSS property\n\"letter-spacing\". A malicious web site could exploit this to run\narbitrary code with the user's privileges. (CVE-2006-1730)\n\nThe methods valueOf.call() and .valueOf.apply() returned an object\nwhose privileges were not properly confined to those of the caller,\nwhich made them vulnerable to cross-site scripting attacks. A\nmalicious web site could exploit this to modify the contents or steal\nconfidential data (such as passwords) from other opened web pages.\n(CVE-2006-1731) The window.controllers array variable (CVE-2006-1732)\nand event handlers (CVE-2006-1741) were vulnerable to a similar attack. \n\nThe privileged built-in XBL bindings were not fully protected from web\ncontent and could be accessed by calling valueOf.call() and\nvalueOf.apply() on a method of that binding. A malicious web site\ncould exploit this to run arbitrary JavaScript code with the user's\nprivileges. (CVE-2006-1733)\n\nIt was possible to use the Object.watch() method to access an internal\nfunction object (the \"clone parent\"). A malicious web site could\nexploit this to execute arbitrary JavaScript code with the user's\nprivileges. (CVE-2006-1734)\n\nBy calling the XBL.method.eval() method in a special way it was\npossible to create JavaScript functions that would get compiled with\nthe wrong privileges. A malicious web site could exploit this to\nexecute arbitrary JavaScript code with the user's privileges.\n(CVE-2006-1735)\n\nMichael Krax discovered that by layering a transparent image link to\nan executable on top of a visible (and presumably desirable) image a\nmalicious site could fool the user to right-click and choose \"Save\nimage as...\" from the context menu, which would download the\nexecutable instead of the image. (CVE-2006-1736)\n\nSeveral crashes have been fixed which could be triggered by web sites\nand involve memory corruption. These could potentially be exploited to\nexecute arbitrary code with the user's privileges. (CVE-2006-1737,\nCVE-2006-1738, CVE-2006-1739, CVE-2006-1790)\n\nIf the user has turned on the \"Entering secure site\" modal warning\ndialog, it was possible to spoof the browser's secure-site indicators\n(the lock icon and the gold URL field background) by first loading the\ntarget secure site in a pop-up window, then changing its location to a\ndifferent site, which retained the displayed secure-browsing\nindicators from the original site. (CVE-2006-1740)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-psm","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"mozilla-psm","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-psm","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-1736","CVE-2005-4134","CVE-2006-1729","CVE-2006-1740","CVE-2006-0292","CVE-2006-0296","CVE-2006-0748","CVE-2006-0749","CVE-2006-1727","CVE-2006-1728","CVE-2006-1730","CVE-2006-1731","CVE-2006-1732","CVE-2006-1733","CVE-2006-1734","CVE-2006-1735","CVE-2006-1737","CVE-2006-1738","CVE-2006-1739","CVE-2006-1741","CVE-2006-1742","CVE-2006-1790"]},{"id":"USN-271-1","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2006-04-20T00:32:19","description":"Web pages with extremely long titles caused subsequent launches of\nFirefox browser to hang for up to a few minutes, or caused Firefox to\ncrash on computers with\tinsufficient memory. (CVE-2005-4134)\n\nIgor Bukanov discovered that the JavaScript engine did not properly\ndeclare some temporary variables. Under some rare circumstances, a\nmalicious website could exploit this to execute arbitrary code with\nthe privileges of the user. (CVE-2006-0292, CVE-2006-1742)\n\nThe function XULDocument.persist() did not sufficiently validate the\nnames of attributes. An attacker could exploit this to inject\narbitrary XML code into the file 'localstore.rdf', which is read and\nevaluated at startup. This could include JavaScript commands that\nwould be run with the user's privileges. (CVE-2006-0296)\n\nDue to a flaw in the HTML tag parser a specific sequence of HTML tags\ncaused memory corruption. A malicious web site could exploit this to\ncrash the browser or even execute arbitrary code with the user's\nprivileges. (CVE-2006-0749)\n\nGeorgi Guninski discovered that embedded XBL scripts of web sites\ncould escalate their (normally reduced) privileges to get full\nprivileges of the user if that page is viewed with \"Print Preview\".\n(CVE-2006-1727)\n\nThe crypto.generateCRMFRequest() function had a flaw which could be\nexploited to run arbitrary code with the user's privileges.\n(CVE-2006-1728)\n\nClaus Jørgensen and Jesse Ruderman discovered that a text input box\ncould be pre-filled with a filename and then turned into a file-upload\ncontrol with the contents intact. A malicious web site could exploit\nthis to read any local file the user has read privileges for.\n(CVE-2006-1729)\n\nAn integer overflow was detected in the handling of the CSS property\n\"letter-spacing\". A malicious web site could exploit this to run\narbitrary code with the user's privileges. (CVE-2006-1730)\n\nThe methods valueOf.call() and .valueOf.apply() returned an object\nwhose privileges were not properly confined to those of the caller,\nwhich made them vulnerable to cross-site scripting attacks. A\nmalicious web site could exploit this to modify the contents or steal\nconfidential data (such as passwords) from other opened web pages.\n(CVE-2006-1731) The window.controllers array variable (CVE-2006-1732)\nand event handlers (CVE-2006-1741) were vulnerable to a similar attack. \n\nThe privileged built-in XBL bindings were not fully protected from web\ncontent and could be accessed by calling valueOf.call() and\nvalueOf.apply() on a method of that binding. A malicious web site\ncould exploit this to run arbitrary JavaScript code with the user's\nprivileges. (CVE-2006-1733)\n\nIt was possible to use the Object.watch() method to access an internal\nfunction object (the \"clone parent\"). A malicious web site could\nexploit this to execute arbitrary JavaScript code with the user's\nprivileges. (CVE-2006-1734)\n\nBy calling the XBL.method.eval() method in a special way it was\npossible to create JavaScript functions that would get compiled with\nthe wrong privileges. A malicious web site could exploit this to\nexecute arbitrary JavaScript code with the user's privileges.\n(CVE-2006-1735)\n\nMichael Krax discovered that by layering a transparent image link to\nan executable on top of a visible (and presumably desirable) image a\nmalicious site could fool the user to right-click and choose \"Save\nimage as...\" from the context menu, which would download the\nexecutable instead of the image. (CVE-2006-1736)\n\nSeveral crashes have been fixed which could be triggered by web sites\nand involve memory corruption. These could potentially be exploited to\nexecute arbitrary code with the user's privileges. (CVE-2006-1737,\nCVE-2006-1738, CVE-2006-1739, CVE-2006-1790)\n\nIf the user has turned on the \"Entering secure site\" modal warning\ndialog, it was possible to spoof the browser's secure-site indicators\n(the lock icon and the gold URL field background) by first loading the\ntarget secure site in a pop-up window, then changing its location to a\ndifferent site, which retained the displayed secure-browsing\nindicators from the original site. (CVE-2006-1740)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-firefox","version":"","is_source":false,"source_link":"","version_link":""},{"name":"firefox","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"mozilla-firefox","version":"","is_source":false,"source_link":"","version_link":""},{"name":"firefox","version":"","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-firefox","version":"","is_source":false,"source_link":"","version_link":""},{"name":"firefox","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-4134","CVE-2006-0292","CVE-2006-0296","CVE-2006-0749","CVE-2006-1727","CVE-2006-1728","CVE-2006-1729","CVE-2006-1730","CVE-2006-1731","CVE-2006-1732","CVE-2006-1733","CVE-2006-1734","CVE-2006-1735","CVE-2006-1736","CVE-2006-1737","CVE-2006-1738","CVE-2006-1739","CVE-2006-1740","CVE-2006-1741","CVE-2006-1742","CVE-2006-1790"]},{"id":"USN-276-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2006-05-03T18:44:54","description":"Igor Bukanov discovered that the JavaScript engine did not properly\ndeclare some temporary variables. Under some rare circumstances, a\nmalicious mail with embedded JavaScript could exploit this to execute\narbitrary code with the privileges of the user. (CVE-2006-0292,\nCVE-2006-1742)\n\nThe function XULDocument.persist() did not sufficiently validate the\nnames of attributes. An attacker could exploit this to inject\narbitrary XML code into the file 'localstore.rdf', which is read and\nevaluated at startup. This could include JavaScript commands that\nwould be run with the user's privileges. (CVE-2006-0296)\n\nDue to a flaw in the HTML tag parser a specific sequence of HTML tags\ncaused memory corruption. A malicious HTML email could exploit this to\ncrash the browser or even execute arbitrary code with the user's\nprivileges. (CVE-2006-0748)\n\nAn invalid ordering of table-related tags caused Thunderbird to use a\nnegative array index. A malicious HTML email could exploit this to\nexecute arbitrary code with the privileges of the user.\n(CVE-2006-0749)\n\nGeorgi Guninski discovered that forwarding mail in-line while using\nthe default HTML \"rich mail\" editor executed JavaScript embedded in\nthe email message. Forwarding mail in-line is not the default setting\nbut it is easily accessed through the \"Forward As\" menu item.\n(CVE-2006-0884)\n\nAs a privacy measure to prevent senders (primarily spammers) from\ntracking when email is read Thunderbird does not load remote content\nreferenced from an HTML mail message until a user tells it to do so.\nThis normally includes the content of frames and CSS files. It was\ndiscovered that it was possible to bypass this restriction by\nindirectly including remote content through an intermediate inline CSS\nscript or frame. (CVE-2006-1045)\n\nGeorgi Guninski discovered that embedded XBL scripts could escalate\ntheir (normally reduced) privileges to get full privileges of the user\nif the email is viewed with \"Print Preview\". (CVE-2006-1727)\n\nThe crypto.generateCRMFRequest() function had a flaw which could be\nexploited to run arbitrary code with the user's privileges.\n(CVE-2006-1728)\n\nAn integer overflow was detected in the handling of the CSS property\n\"letter-spacing\". A malicious HTML email could exploit this to run\narbitrary code with the user's privileges. (CVE-2006-1730)\n\nThe methods valueOf.call() and .valueOf.apply() returned an object\nwhose privileges were not properly confined to those of the caller,\nwhich made them vulnerable to cross-site scripting attacks. A\nmalicious email with embedded JavaScript code could exploit this to\nmodify the contents or steal confidential data (such as passwords)\nfrom other opened web pages. (CVE-2006-1731) The window.controllers\narray variable (CVE-2006-1732) and event handlers (CVE-2006-1741) were\nvulnerable to a similar attack.\n\nThe privileged built-in XBL bindings were not fully protected from web\ncontent and could be accessed by calling valueOf.call() and\nvalueOf.apply() on a method of that binding. A malicious email could\nexploit this to run arbitrary JavaScript code with the user's\nprivileges. (CVE-2006-1733)\n\nIt was possible to use the Object.watch() method to access an internal\nfunction object (the \"clone parent\"). A malicious email containing\nJavaScript code could exploit this to execute arbitrary code with the\nuser's privileges. (CVE-2006-1734)\n\nBy calling the XBL.method.eval() method in a special way it was\npossible to create JavaScript functions that would get compiled with\nthe wrong privileges. A malicious email could exploit this to execute\narbitrary JavaScript code with the user's privileges. (CVE-2006-1735)\n\nSeveral crashes have been fixed which could be triggered by specially\ncrafted HTML content and involve memory corruption. These could\npotentially be exploited to execute arbitrary code with the user's\nprivileges. (CVE-2006-1737, CVE-2006-1738, CVE-2006-1739,\nCVE-2006-1790)\n\nThe \"enigmail\" plugin has been updated to work with the new\nThunderbird and Mozilla versions.","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-thunderbird","version":"","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-thunderbird","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-1742","CVE-2006-1739","CVE-2006-1737","CVE-2006-1728","CVE-2006-0884","CVE-2006-1741","CVE-2006-0296","CVE-2006-0748","CVE-2006-1738","CVE-2006-1732","CVE-2006-1733","CVE-2006-1727","CVE-2006-1735","CVE-2006-1734","CVE-2006-0292","CVE-2006-1730","CVE-2006-1045","CVE-2006-1731","CVE-2006-1790","CVE-2006-0749"]}]},{"id":"CVE-2006-0528","published":"2006-02-02T11:02:00","updated_at":"2025-07-17T16:37:39.936119+00:00","description":"\nThe cairo library (libcairo), as used in GNOME Evolution and possibly other\nproducts, allows remote attackers to cause a denial of service (persistent\nclient crash) via an attached text file that contains \"Content-Disposition:\ninline\" in the header, and a very long line in the body, which causes the\nclient to repeatedly crash until the e-mail message is manually removed,\npossibly due to a buffer overflow, as demonstrated using an XML attachment.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-265-1","https://www.cve.org/CVERecord?id=CVE-2006-0528"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"evolution","source":"https://ubuntu.com/security/cve?package=evolution","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=evolution","debian":"https://tracker.debian.org/pkg/evolution","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libcairo","source":"https://ubuntu.com/security/cve?package=libcairo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libcairo","debian":"https://tracker.debian.org/pkg/libcairo","statuses":[{"release_codename":"dapper","status":"released","description":"1.0.4-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-265-1"],"notices":[{"id":"USN-265-1","title":"cairo/Evolution library vulnerability","summary":"cairo/Evolution library vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2006-03-23T22:44:35","description":"When rendering glyphs, the cairo graphics rendering library did not\ncheck the maximum length of character strings. A request to display\nan excessively long string with cairo caused a program crash due to an\nX library error.\n\nMike Davis discovered that this could be turned into a Denial of\nService attack in Evolution. An email with an attachment with very\nlong lines caused Evolution to crash repeatedly until that email was\nmanually removed from the mail folder.\n\nThis only affects Ubuntu 5.10. Previous Ubuntu releases did not use\nlibcairo for text rendering.","is_hidden":false,"release_packages":{"breezy":[{"name":"libcairo2","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-0528"]}]}],"offset":77820,"limit":20,"total_results":79316}