{"cves":[{"id":"CVE-2005-3245","published":"2005-10-27T10:02:00","updated_at":"2025-07-17T16:36:44.535968+00:00","description":"\nUnspecified vulnerability in the ONC RPC dissector in Ethereal 0.10.3 to\n0.10.12, when the \"Dissect unknown RPC program numbers\" option is enabled,\nallows remote attackers to cause a denial of service (memory consumption).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-3245"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"released","description":"0.99.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-3244","published":"2005-10-27T10:02:00","updated_at":"2025-07-17T16:36:44.535968+00:00","description":"\nThe BER dissector in Ethereal 0.10.3 to 0.10.12 allows remote attackers to\ncause a denial of service (infinite loop) via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-3244"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"released","description":"0.99.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-3243","published":"2005-10-27T10:02:00","updated_at":"2025-07-17T16:36:44.535968+00:00","description":"\nMultiple buffer overflows in Ethereal 0.10.12 and earlier might allow\nremote attackers to execute arbitrary code via unknown vectors in the (1)\nSLIMP3 and (2) AgentX dissector.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-3243"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"released","description":"0.99.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-3242","published":"2005-10-27T10:02:00","updated_at":"2025-07-17T16:36:44.535968+00:00","description":"\nEthereal 0.10.12 and earlier allows remote attackers to cause a denial of\nservice (crash) via unknown vectors in (1) the IrDA dissector and (2) the\nSMB dissector when SMB transaction payload reassembly is enabled.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-3242"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"released","description":"0.99.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-3241","published":"2005-10-27T10:02:00","updated_at":"2025-07-17T16:36:44.535968+00:00","description":"\nMultiple vulnerabilities in Ethereal 0.10.12 and earlier allow remote\nattackers to cause a denial of service (memory consumption) via unspecified\nvectors in the (1) ISAKMP, (2) FC-FCS, (3) RSVP, and (4) ISIS LSP\ndissector.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-3241"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"0.99.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-3088","published":"2005-10-27T10:02:00","updated_at":"2025-07-17T16:36:36.151208+00:00","description":"\nfetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.5.2 creates\nconfiguration files with insecure world-readable permissions, which allows\nlocal users to obtain sensitive information such as passwords.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-215-1","https://www.cve.org/CVERecord?id=CVE-2005-3088"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"fetchmail","source":"https://ubuntu.com/security/cve?package=fetchmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fetchmail","debian":"https://tracker.debian.org/pkg/fetchmail","statuses":[{"release_codename":"dapper","status":"released","description":"6.3.2-2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"6.3.4-1ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"6.3.6-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-215-1"],"notices":[{"id":"USN-215-1","title":"fetchmailconf vulnerability","summary":"fetchmailconf vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-11-08T01:26:25","description":"Thomas Wolff and Miloslav Trmac discovered a race condition in the\nfetchmailconf program. The output configuration file was initially\ncreated with insecure permissions, and secure permissions were applied\nafter writing the configuration into the file. During this time, the\nfile was world readable on a standard system (unless the user manually\ntightened his umask setting), which could expose email passwords to\nlocal users.","is_hidden":false,"release_packages":{"hoary":[{"name":"fetchmailconf","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"fetchmailconf","version":"","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"fetchmailconf","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-3088"]}]},{"id":"CVE-2005-3310","published":"2005-10-26T01:02:00","updated_at":"2025-07-17T16:36:48.159771+00:00","description":"\nInterpretation conflict in phpBB 2.0.17, with remote avatars and avatar\nuploading enabled, allows remote authenticated users to inject arbitrary\nweb script or HTML via an HTML file with a GIF or JPEG file extension,\nwhich causes the HTML to be executed by a victim who views the file in\nInternet Explorer, which renders malformed image types as HTML, enabling\ncross-site scripting (XSS) attacks. NOTE: it could be argued that this\nvulnerability is due to a design flaw in Internet Explorer (CVE-2005-3312)\nand the proper fix should be in that browser; if so, then this should not\nbe treated as a vulnerability in phpBB.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-3310"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"phpbb2","source":"https://ubuntu.com/security/cve?package=phpbb2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpbb2","debian":"https://tracker.debian.org/pkg/phpbb2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.18-2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.18-2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.18-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2708","published":"2005-10-25T18:02:00","updated_at":"2025-07-17T16:36:25.196327+00:00","description":"\nThe search_binary_handler function in exec.c in Linux 2.4 kernel on 64-bit\nx86 architectures does not check a return code for a particular function\ncall when virtual memory is low, which allows local users to cause a denial\nof service (panic), as demonstrated by running a process using the bash\nulimit -v command.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2708"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2970","published":"2005-10-25T17:06:00","updated_at":"2025-07-17T16:36:32.239428+00:00","description":"\nMemory leak in the worker MPM (worker.c) for Apache 2, in certain\ncircumstances, allows remote attackers to cause a denial of service (memory\nconsumption) via aborted connections, which prevents the memory for the\ntransaction pool from being reused for other connections.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-225-1","https://www.cve.org/CVERecord?id=CVE-2005-2970"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-225-1"],"notices":[{"id":"USN-225-1","title":"Apache 2 vulnerability","summary":"Apache 2 vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-12-07T01:35:15","description":"A memory leak was found in the Apache 2 'worker' module in the\nhandling of aborted TCP connections. By repeatedly triggering this\nsituation, a remote attacker could drain all available memory, which\neventually led to a Denial of Service.","is_hidden":false,"release_packages":{"hoary":[{"name":"apache2-mpm-worker","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"apache2-mpm-worker","version":"","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"apache2-mpm-worker","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-2970"]}]},{"id":"CVE-2005-2100","published":"2005-10-25T17:06:00","updated_at":"2025-07-17T16:35:58.627320+00:00","description":"\nThe rw_vm function in usercopy.c in the 4GB split patch for the Linux\nkernel in Red Hat Enterprise Linux 4 does not perform proper bounds\nchecking, which allows local users to cause a denial of service (crash).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2100"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.12","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.12","debian":"https://tracker.debian.org/pkg/linux-source-2.6.12","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2959","published":"2005-10-25T16:02:00","updated_at":"2025-07-17T16:36:30.739788+00:00","description":"\nIncomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local\nusers to gain privileges via the (1) SHELLOPTS and (2) PS4 environment\nvariables before executing a bash script on behalf of another user, which\nare not cleared even though other variables are.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-213-1","https://www.cve.org/CVERecord?id=CVE-2005-2959"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sudo","source":"https://ubuntu.com/security/cve?package=sudo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sudo","debian":"https://tracker.debian.org/pkg/sudo","statuses":[{"release_codename":"dapper","status":"released","description":"1.6.8p12-1ubuntu6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.6.8p12-1ubuntu6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.6.8p12-1ubuntu6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-213-1"],"notices":[{"id":"USN-213-1","title":"sudo vulnerability","summary":"sudo vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-10-28T22:44:09","description":"Tavis Ormandy discovered a privilege escalation vulnerability in sudo.\nOn executing shell scripts with sudo, the \"P4\" and \"SHELLOPTS\"\nenvironment variables were not cleaned properly. If sudo is set up to\ngrant limited sudo privileges to normal users this could be exploited\nto run arbitrary commands as the target user.\n\nUpdated packags for Ubuntu 4.10:","is_hidden":false,"release_packages":{"hoary":[{"name":"sudo","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"sudo","version":"","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"sudo","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-2959"]}]},{"id":"CVE-2005-2958","published":"2005-10-25T16:02:00","updated_at":"2025-07-17T16:36:30.739788+00:00","description":"\nMultiple format string vulnerabilities in the GNOME Data Access library for\nGNOME2 (libgda2) 1.2.1 and earlier allow attackers to execute arbitrary\ncode.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-212-1","https://www.cve.org/CVERecord?id=CVE-2005-2958"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libgda2","source":"https://ubuntu.com/security/cve?package=libgda2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgda2","debian":"https://tracker.debian.org/pkg/libgda2","statuses":[{"release_codename":"dapper","status":"released","description":"1.2.2-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.2.2-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.2.2-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libgda3","source":"https://ubuntu.com/security/cve?package=libgda3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgda3","debian":"https://tracker.debian.org/pkg/libgda3","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-212-1"],"notices":[{"id":"USN-212-1","title":"libgda2 vulnerability","summary":"libgda2 vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-10-28T22:38:04","description":"Steve Kemp discovered two format string vulnerabilities in the logging\nhandler of the Gnome database access library. Depending on the\napplication that uses the library, this could have been exploited to\nexecute arbitrary code with the permission of the user running the\napplication.","is_hidden":false,"release_packages":{"hoary":[{"name":"libgda2-3","version":"","is_source":false,"source_link":"","version_link":""},{"name":"libgda2-1","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"libgda2-3","version":"","is_source":false,"source_link":"","version_link":""},{"name":"libgda2-1","version":"","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"libgda2-3","version":"","is_source":false,"source_link":"","version_link":""},{"name":"libgda2-1","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-2958"]}]},{"id":"CVE-2005-3302","published":"2005-10-24T10:02:00","updated_at":"2025-07-17T16:36:48.159771+00:00","description":"\nEval injection vulnerability in bvh_import.py in Blender 2.36 allows\nattackers to execute arbitrary Python code via a hierarchy element in a\n.bvh file, which is supplied to an eval function call.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-3302"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"blender","source":"https://ubuntu.com/security/cve?package=blender","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=blender","debian":"https://tracker.debian.org/pkg/blender","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-3301","published":"2005-10-24T10:02:00","updated_at":"2025-07-17T16:36:48.159771+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before\n2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via\ncertain arguments to (1) left.php, (2) queryframe.php, or (3)\nserver_databases.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-3301"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"dapper","status":"released","description":"2.8.0.3-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.8.0.3-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.8.0.3-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-3300","published":"2005-10-23T21:02:00","updated_at":"2025-07-17T16:36:48.159771+00:00","description":"\nThe register_globals emulation layer in grab_globals.php for phpMyAdmin\nbefore 2.6.4-pl3 does not perform safety checks on values in the _FILES\narray for uploaded files, which allows remote attackers to include\narbitrary files by using direct requests to library scripts that do not use\ngrab_globals.php, then modifying certain configuration values for the\ntheme.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-3300"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"dapper","status":"released","description":"2.8.0.3-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.8.0.3-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.8.0.3-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-3299","published":"2005-10-23T21:02:00","updated_at":"2025-07-17T16:36:48.159771+00:00","description":"\nPHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin\n2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the\n$__redirect parameter, possibly involving the subform array.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-3299"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"dapper","status":"released","description":"2.8.0.3-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.8.0.3-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.8.0.3-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-3278","published":"2005-10-23T10:02:00","updated_at":"2025-07-17T16:36:48.159771+00:00","description":"\nInteger overflow in the openpsfile function in gsinterf.c for Jan Kybic\nBitMap Viewer (BMV) 1.2 allows local users to execute arbitrary code via a\nPostScript (PS) file containing a large number of pages value, which leads\nto a resultant buffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-3278"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"bmv","source":"https://ubuntu.com/security/cve?package=bmv","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bmv","debian":"https://tracker.debian.org/pkg/bmv","statuses":[{"release_codename":"dapper","status":"released","description":"1.2-18","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.2-18","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.2-18","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2972","published":"2005-10-23T10:02:00","updated_at":"2025-07-17T16:36:34.052637+00:00","description":"\nMultiple stack-based buffer overflows in the RTF import feature in AbiWord\nbefore 2.2.11 allow user-assisted attackers to execute arbitrary code via\nan RTF file with long identifiers, which are not properly handled in the\n(1) ParseLevelText, (2) getCharsInsideBrace, (3) HandleLists, (4) or (5)\nHandleAbiLists functions in ie_imp_RTF.cpp, a different vulnerability than\nCVE-2005-2964.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-203-1","https://www.cve.org/CVERecord?id=CVE-2005-2972"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"abiword","source":"https://ubuntu.com/security/cve?package=abiword","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=abiword","debian":"https://tracker.debian.org/pkg/abiword","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-203-1"],"notices":[{"id":"USN-203-1","title":"Abiword vulnerabilities","summary":"Abiword vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-10-13T23:51:36","description":"Chris Evans discovered several buffer overflows in the RTF import\nmodule of AbiWord. By tricking a user into opening an RTF file with\nspecially crafted long identifiers, an attacker could exploit this to\nexecute arbitrary code with the privileges of the AbiWord user.","is_hidden":false,"release_packages":{"hoary":[{"name":"abiword","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"abiword","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-2972"]}]},{"id":"CVE-2005-3276","published":"2005-10-21T01:02:00","updated_at":"2025-07-17T16:36:48.159771+00:00","description":"\nThe sys_get_thread_area function in process.c in Linux 2.6 before 2.6.12.4\nand 2.6.13 does not clear a data structure before copying it to userspace,\nwhich might allow a user process to obtain sensitive information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-219-1","https://www.cve.org/CVERecord?id=CVE-2005-3276"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.12","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.12","debian":"https://tracker.debian.org/pkg/linux-source-2.6.12","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-219-1"],"notices":[{"id":"USN-219-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-11-22T21:34:21","description":"","is_hidden":false,"release_packages":{},"type":"USN","cves_ids":["CVE-2005-3180","CVE-2005-3274","CVE-2005-3271","CVE-2005-3055","CVE-2005-2709","CVE-2005-3276","CVE-2005-3273","CVE-2005-2973","CVE-2005-3272","CVE-2005-3275"]}]},{"id":"CVE-2005-3275","published":"2005-10-21T01:02:00","updated_at":"2025-07-17T16:36:48.159771+00:00","description":"\nThe NAT code (1) ip_nat_proto_tcp.c and (2) ip_nat_proto_udp.c in Linux\nkernel 2.6 before 2.6.13 and 2.4 before 2.4.32-rc1 incorrectly declares a\nvariable to be static, which allows remote attackers to cause a denial of\nservice (memory corruption) by causing two packets for the same protocol to\nbe NATed at the same time, which leads to memory corruption.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-219-1","https://www.cve.org/CVERecord?id=CVE-2005-3275"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.12","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.12","debian":"https://tracker.debian.org/pkg/linux-source-2.6.12","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-219-1"],"notices":[{"id":"USN-219-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-11-22T21:34:21","description":"","is_hidden":false,"release_packages":{},"type":"USN","cves_ids":["CVE-2005-3180","CVE-2005-3274","CVE-2005-3271","CVE-2005-3055","CVE-2005-2709","CVE-2005-3276","CVE-2005-3273","CVE-2005-2973","CVE-2005-3272","CVE-2005-3275"]}]}],"offset":78140,"limit":20,"total_results":79316}