{"cves":[{"id":"CVE-2006-0353","published":"2006-01-22T19:03:00","updated_at":"2025-07-17T16:37:37.170185+00:00","description":"\nunix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the\nrandomness generator, which allows local users to cause a denial of service\nby truncating the seed file, which prevents the server from starting, or\nobtain sensitive seed information that could be used to crack keys.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0353"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"lsh-utils","source":"https://ubuntu.com/security/cve?package=lsh-utils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lsh-utils","debian":"https://tracker.debian.org/pkg/lsh-utils","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.1cdbs-4","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.1cdbs-4","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.1cdbs-4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0351","published":"2006-01-21T01:03:00","updated_at":"2025-07-17T16:37:37.170185+00:00","description":"\nUnspecified \"critical denial-of-service vulnerability\" in MyDNS before\n1.1.0 has unknown impact and attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0351"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mydns","source":"https://ubuntu.com/security/cve?package=mydns","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mydns","debian":"https://tracker.debian.org/pkg/mydns","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.1.0-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.1.0-6ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.1.0-8","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0347","published":"2006-01-21T01:03:00","updated_at":"2025-07-17T16:37:37.170185+00:00","description":"\nDirectory traversal vulnerability in ELOG before 2.6.1 allows remote\nattackers to access arbitrary files outside of the elog directory via \"../\"\n(dot dot) sequences in the URL.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0347"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"elog","source":"https://ubuntu.com/security/cve?package=elog","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=elog","debian":"https://tracker.debian.org/pkg/elog","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.1+r1642-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.1+r1642-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.1+r1642-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0327","published":"2006-01-21T00:03:00","updated_at":"2025-07-17T16:37:37.170185+00:00","description":"\nTYPO3 3.7.1 allows remote attackers to obtain sensitive information via a\ndirect request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which\ncauses them to incorrectly define a variable and reveal the path in an\nerror message when a require function call fails.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0327"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"typo3-src","source":"https://ubuntu.com/security/cve?package=typo3-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=typo3-src","debian":"https://tracker.debian.org/pkg/typo3-src","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"4.0.4+debian-2","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"4.0.4+debian-2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"4.0.4+debian-2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"4.0.4+debian-2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"4.0.4+debian-2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"4.0.4+debian-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0045","published":"2006-01-20T21:03:00","updated_at":"2025-07-17T16:37:26.984010+00:00","description":"\ncrawl before 4.0.0 does not securely call programs when saving and loading\ngames, which allows local users to gain privileges.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0045"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"crawl","source":"https://ubuntu.com/security/cve?package=crawl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=crawl","debian":"https://tracker.debian.org/pkg/crawl","statuses":[{"release_codename":"dapper","status":"released","description":"4.0.0beta26-7","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"4.0.0beta26-7","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"4.0.0beta26-7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0019","published":"2006-01-20T21:03:00","updated_at":"2025-07-17T16:37:25.695466+00:00","description":"\nHeap-based buffer overflow in the encodeURI and decodeURI functions in the\nkjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote\nattackers to execute arbitrary code via a crafted, UTF-8 encoded URI.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-245-1","https://www.cve.org/CVERecord?id=CVE-2006-0019"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kdelibs","source":"https://ubuntu.com/security/cve?package=kdelibs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kdelibs","debian":"https://tracker.debian.org/pkg/kdelibs","statuses":[{"release_codename":"dapper","status":"released","description":"3.5.2-0ubuntu18.5","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.5.5-0ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.5.6-0ubuntu14.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-245-1"],"notices":[{"id":"USN-245-1","title":"KDE library vulnerability","summary":"KDE library vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2006-01-20T20:24:49","description":"Maksim Orlovich discovered that kjs, the Javascript interpreter engine\nused by Konqueror and other parts of KDE, did not sufficiently verify\nthe validity of UTF-8 encoded URIs. Specially crafted URIs could\ntrigger a buffer overflow. By tricking an user into visiting a\nweb site with malicious JavaScript code, a remote attacker could\nexploit this to execute arbitrary code with user privileges.","is_hidden":false,"release_packages":{"hoary":[{"name":"kdelibs4c2","version":"","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"kdelibs4c2","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-0019"]}]},{"id":"CVE-2006-0322","published":"2006-01-19T21:03:00","updated_at":"2025-07-17T16:37:37.170185+00:00","description":"\nUnspecified vulnerability the edit comment formatting functionality in\nMediaWiki 1.5.x before 1.5.6 and 1.4.x before 1.4.14 allows attackers to\ncause a denial of service (infinite loop) via \"certain malformed links.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0322"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.14-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.14-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.14-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.4.14-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0044","published":"2006-01-18T01:51:00","updated_at":"2025-07-17T16:37:26.984010+00:00","description":"\nUnspecified vulnerability in context.py in Albatross web application\ntoolkit before 1.33 allows remote attackers to execute arbitrary commands\nvia unspecified vectors involving template files and the \"handling of\nsubmitted form fields\".","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0044"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"albatross","source":"https://ubuntu.com/security/cve?package=albatross","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=albatross","debian":"https://tracker.debian.org/pkg/albatross","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0236","published":"2006-01-18T01:07:00","updated_at":"2025-07-17T16:37:33.412269+00:00","description":"\nGUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6,\nand 1.0.7 allows user-assisted attackers to execute arbitrary code via an\nattachment with a filename containing a large number of spaces ending with\na dangerous extension that is not displayed by Thunderbird, along with an\ninconsistent Content-Type header, which could be used to trick a user into\ndownloading dangerous content by dragging or saving the attachment.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0236"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0208","published":"2006-01-13T23:03:00","updated_at":"2025-07-17T16:37:33.412269+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1,\nwhen display_errors and html_errors are on, allow remote attackers to\ninject arbitrary web script or HTML via inputs to PHP applications that are\nnot filtered when they are included in the resulting error message.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-261-1","https://www.cve.org/CVERecord?id=CVE-2006-0208"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"released","description":"4.4.2-1build1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"4.4.2-1build1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-261-1"],"notices":[{"id":"USN-261-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2006-03-10T23:52:12","description":"Stefan Esser discovered that the 'session' module did not sufficiently\nverify the validity of the user-supplied session ID. A remote attacker\ncould exploit this to insert arbitrary HTTP headers into the response\nsent by the PHP application, which could lead to HTTP Response\nSplitting (forging of arbitrary responses on behalf the PHP\napplication) and Cross Site Scripting (XSS) (execution of arbitrary\nweb script code in the client's browser) attacks. (CVE-2006-0207)\n\nPHP applications were also vulnerable to several Cross Site Scripting\n(XSS) flaws if the options 'display_errors' and 'html_errors' were\nenabled. Please note that enabling 'html_errors' is not recommended\nfor production systems. (CVE-2006-0208)","is_hidden":false,"release_packages":{"hoary":[{"name":"libapache2-mod-php4","version":"","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"libapache2-mod-php4","version":"","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"libapache2-mod-php4","version":"","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-0207","CVE-2006-0208"]}]},{"id":"CVE-2006-0207","published":"2006-01-13T23:03:00","updated_at":"2025-07-17T16:37:33.412269+00:00","description":"\nMultiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote\nattackers to inject arbitrary HTTP headers via a crafted Set-Cookie header,\nrelated to the (1) session extension (aka ext/session) and the (2) header\nfunction.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-261-1","https://www.cve.org/CVERecord?id=CVE-2006-0207"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"released","description":"4.4.2-1build1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"4.4.2-1build1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-261-1"],"notices":[{"id":"USN-261-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2006-03-10T23:52:12","description":"Stefan Esser discovered that the 'session' module did not sufficiently\nverify the validity of the user-supplied session ID. A remote attacker\ncould exploit this to insert arbitrary HTTP headers into the response\nsent by the PHP application, which could lead to HTTP Response\nSplitting (forging of arbitrary responses on behalf the PHP\napplication) and Cross Site Scripting (XSS) (execution of arbitrary\nweb script code in the client's browser) attacks. (CVE-2006-0207)\n\nPHP applications were also vulnerable to several Cross Site Scripting\n(XSS) flaws if the options 'display_errors' and 'html_errors' were\nenabled. Please note that enabling 'html_errors' is not recommended\nfor production systems. (CVE-2006-0208)","is_hidden":false,"release_packages":{"hoary":[{"name":"libapache2-mod-php4","version":"","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"libapache2-mod-php4","version":"","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"libapache2-mod-php4","version":"","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-php5","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-0207","CVE-2006-0208"]}]},{"id":"CVE-2006-0200","published":"2006-01-13T23:03:00","updated_at":"2025-07-17T16:37:33.412269+00:00","description":"\nFormat string vulnerability in the error-reporting feature in the mysqli\nextension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute\narbitrary code via format string specifiers in MySQL error messages.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0200"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.1.6-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.1-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0176","published":"2006-01-11T21:03:00","updated_at":"2025-07-17T16:37:33.412269+00:00","description":"\nBuffer overflow in certain functions in src/fileio.c and src/unix/fileio.c\nin xmame before 11 January 2006 may allow local users to gain privileges\nvia a long (1) -lang, (2) -ctrlr, (3) -pb, or (4) -rec argument on many\noperating systems, and via a long (5) -jdev argument on Ubuntu Linux.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0176"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"xmame","source":"https://ubuntu.com/security/cve?package=xmame","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xmame","debian":"https://tracker.debian.org/pkg/xmame","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.106-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.106-1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.106-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.106-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.106-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.106-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.106-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0055","published":"2006-01-11T21:03:00","updated_at":"2025-07-17T16:37:28.520824+00:00","description":"\nThe ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable\nfilenames and does not confirm which file is being written, which allows\nlocal users to overwrite arbitrary files via a symlink attack when ee\ninvokes ispell.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0055"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ee","source":"https://ubuntu.com/security/cve?package=ee","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ee","debian":"https://tracker.debian.org/pkg/ee","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"1:1.4.2-5","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1:1.4.2-5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1:1.4.2-5","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1:1.4.2-5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0035","published":"2006-01-11T21:03:00","updated_at":"2025-07-17T16:37:25.695466+00:00","description":"\nThe netlink_rcv_skb function in af_netlink.c in Linux kernel 2.6.14 and\n2.6.15 allows local users to cause a denial of service (infinite loop) via\na nlmsg_len field of 0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0035"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-29.58","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.40","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0162","published":"2006-01-10T19:03:00","updated_at":"2025-07-17T16:37:29.978631+00:00","description":"\nHeap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV)\nbefore 0.88 allows remote attackers to cause a denial of service (crash)\nand possibly execute arbitrary code via crafted UPX files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0162"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0151","published":"2006-01-09T23:03:00","updated_at":"2025-07-17T16:37:29.978631+00:00","description":"\nsudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment\nvariable, which allows limited local users to gain privileges via a Python\nscript, a variant of CVE-2005-4158.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0151"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sudo","source":"https://ubuntu.com/security/cve?package=sudo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sudo","debian":"https://tracker.debian.org/pkg/sudo","statuses":[{"release_codename":"dapper","status":"released","description":"1.6.8p12-1ubuntu6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.6.8p12-1ubuntu6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.6.8p12-1ubuntu6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0150","published":"2006-01-09T23:03:00","updated_at":"2025-07-17T16:37:29.978631+00:00","description":"\nMultiple format string vulnerabilities in the auth_ldap_log_reason function\nin Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute\narbitrary code via various vectors, including the username.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0150"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libapache-auth-ldap","source":"https://ubuntu.com/security/cve?package=libapache-auth-ldap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libapache-auth-ldap","debian":"https://tracker.debian.org/pkg/libapache-auth-ldap","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0147","published":"2006-01-09T23:03:00","updated_at":"2025-07-17T16:37:29.978631+00:00","description":"\nDynamic code evaluation vulnerability in tests/tmssql.php test script in\nADOdb for PHP before 4.70, as used in multiple products including (1)\nMantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat,\npossibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to\nexecute arbitrary PHP functions via the do parameter, which is saved in a\nvariable that is then executed as a function, as demonstrated using\nphpinfo.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0147"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libphp-adodb","source":"https://ubuntu.com/security/cve?package=libphp-adodb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libphp-adodb","debian":"https://tracker.debian.org/pkg/libphp-adodb","statuses":[{"release_codename":"dapper","status":"released","description":"4.72-0.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"4.72-0.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"4.72-0.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"4.72-0.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0146","published":"2006-01-09T23:03:00","updated_at":"2025-07-17T16:37:29.978631+00:00","description":"\nThe server.php test script in ADOdb for PHP before 4.70, as used in\nmultiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4)\nCacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez,\nwhen the MySQL root password is empty, allows remote attackers to execute\narbitrary SQL commands via the sql parameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0146"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libphp-adodb","source":"https://ubuntu.com/security/cve?package=libphp-adodb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libphp-adodb","debian":"https://tracker.debian.org/pkg/libphp-adodb","statuses":[{"release_codename":"dapper","status":"released","description":"4.72-0.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"4.72-0.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"4.72-0.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"4.72-0.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":77860,"limit":20,"total_results":79316}