{"cves":[{"id":"CVE-2005-2261","published":"2005-07-13T04:00:00","updated_at":"2025-07-17T16:36:05.666555+00:00","description":"\nFirefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9,\nNetscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has\nbeen disabled, which makes it easier for remote attackers to bypass such\nprotection.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-155-1","https://ubuntu.com/security/notices/USN-157-1","https://ubuntu.com/security/notices/USN-149-3","https://ubuntu.com/security/notices/USN-149-1","https://www.cve.org/CVERecord?id=CVE-2005-2261"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mozilla","source":"https://ubuntu.com/security/cve?package=mozilla","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozilla","debian":"https://tracker.debian.org/pkg/mozilla","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"1.7.12-1.1ubuntu2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.7.12-1.1ubuntu2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0.13-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0.13-0ubuntu0.7.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-155-1","USN-157-1","USN-149-3","USN-149-1"],"notices":[{"id":"USN-155-1","title":"Mozilla vulnerabilities","summary":"Mozilla vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-07-27T04:34:26","description":"Secunia.com reported that one of the recent security patches in\nFirefox reintroduced the frame injection patch that was originally\nknown as CAN-2004-0718. This allowed a malicious web site to spoof the\ncontents of other web sites. (CAN-2005-1937)\n\nIt was discovered that a malicious website could inject arbitrary\nscripts into a target site by loading it into a frame and navigating\nback to a previous Javascript URL that contained an eval() call. This\ncould be used to steal cookies or other confidential data from the\ntarget site. (MFSA 2005-42)\n\nMichael Krax, Georgi Guninski, and L. David Baron found that the\nsecurity checks that prevent script injection could be bypassed by\nwrapping a javascript: url in another pseudo-protocol like\n\"view-source:\" or \"jar:\". (CAN-2005-1531)\n\nA variant of the attack described in CAN-2005-1160 (see USN-124-1) was\ndiscovered. Additional checks were added to make sure Javascript eval\nand script objects are run with the privileges of the context that\ncreated them, not the potentially elevated privilege of the context\ncalling them. (CAN-2005-1532)\n\nIn several places the browser user interface did not correctly\ndistinguish between true user events, such as mouse clicks or\nkeystrokes, and synthetic events genenerated by web content. This\ncould be exploited by malicious web sites to generate e. g. mouse clicks\nthat install malicious plugins. Synthetic events are now prevented\nfrom reaching the browser UI entirely. (CAN-2005-2260)\n\nScripts in XBL controls from web content continued to be run even when\nJavascript was disabled. This could be combined with most script-based\nexploits to attack people running vulnerable versions who thought\ndisabling Javascript would protect them. (CAN-2005-2261)\n\nMatthew Mastracci discovered a flaw in the addons installation\nlauncher. By forcing a page navigation immediately after calling the\ninstall method a callback function could end up running in the context\nof the new page selected by the attacker. This callback script could\nsteal data from the new page such as cookies or passwords, or perform\nactions on the user's behalf such as make a purchase if the user is\nalready logged into the target site. However, the default settings\nallow only http://addons.mozilla.org to bring up this install dialog.\nThis could only be exploited if users have added untrustworthy sites\nto the installation allowlist, and if a malicious site can convince\nyou to install from their site. (CAN-2005-2263)\n\nThe function for version comparison in the addons installer did not\nproperly verify the type of its argument. By passing specially crafted\nJavascript objects to it, a malicious web site could crash the browser\nand possibly even execute arbitrary code with the privilege of the\nuser account Firefox runs in. (CAN-2005-2265)\n\nA child frame can call top.focus() even if the framing page comes from\na different origin and has overridden the focus() routine. Andreas\nSandblad discovered that the call is made in the context of the child\nframe. This could be exploited to steal cookies and passwords from the\nframed page, or take actions on behalf of a signed-in user. However,\nweb sites with above properties are not very common. (CAN-2005-2266)\n\nAlerts and prompts created by scripts in web pages were presented with\nthe generic title [Javascript Application] which sometimes made it\ndifficult to know which site created them. A malicious page could\nexploit this by causing a prompt to appear in front of a trusted site\nin an attempt to extract information such as passwords from the user.\nIn the fixed version these prompts contain the hostname of the page\nwhich created it. (CAN-2005-2268)\n\nThe XHTML DOM node handler did not take namespaces into account when\nverifying node types based on their names. For example, an XHTML\ndocument could contain an <IMG> tag with malicious contents, which\nwould then be processed as the standard trusted HTML <img> tag. By\ntricking an user to view malicious web sites, this could be exploited\nto execute attacker-specified code with the full privileges of the\nuser. (CAN-2005-2269)\n\nIt was discovered that some objects were not created appropriately.\nThis allowed malicious web content scripts to trace back the creation\nchain until they found a privileged object and execute code with\nhigher privileges than allowed by the current site. (CAN-2005-2270)\n\nThe update for Ubuntu 4.10 (Warty Warthog) also fixes several\nvulnerabilities which are not present in the Ubuntu 5.04 version. Some\nof them could be exploited to execute arbitrary code with full user\nprivileges if the user visited a malicious web site. (MFSA-2005-01 to\nMFSA-2005-41; please see the following web site for details:\nhttp://www.mozilla.org/projects/security/known-vulnerabilities.html). We\napologize for the huge delay of this update; we changed our update\nstrategy for Mozilla products to make sure that such long delays will\nnot happen again.","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-browser","version":"","is_source":false,"is_visible":true,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"","is_source":false,"is_visible":true,"source_link":"","version_link":""}],"warty":[{"name":"mozilla-browser","version":"","is_source":false,"is_visible":true,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"","is_source":false,"is_visible":true,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-2266","CVE-2005-2261","CVE-2005-2260","CVE-2005-1532","CVE-2005-1937","CVE-2005-2270","CVE-2005-2268","CVE-2005-1531","CVE-2005-2265","CVE-2005-2263","CVE-2005-2269"]},{"id":"USN-157-1","title":"Mozilla Thunderbird vulnerabilities","summary":"Mozilla Thunderbird vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-08-01T17:47:42","description":"Vladimir V. Perepelitsa discovered a bug in Thunderbird's handling of anonymous\nfunctions during regular expression string replacement. A malicious HTML email\ncould exploit this to capture a random block of client memory. (CAN-2005-0989)\n\nGeorgi Guninski discovered that the types of certain XPInstall related\nJavaScript objects were not sufficiently validated when they were called. This\ncould be exploited by malicious HTML email content to crash Thunderbird or even\nexecute arbitrary code with the privileges of the user. (CAN-2005-1159) \n\nThunderbird did not properly verify the values of XML DOM nodes.  By tricking\nthe user to perform a common action like clicking on a link or opening the\ncontext menu, a malicious HTML email could exploit this to execute arbitrary\nJavaScript code with the full privileges of the user. (CAN-2005-1160)\n\nA variant of the attack described in CAN-2005-1160 (see USN-124-1) was\ndiscovered. Additional checks were added to make sure Javascript eval and\nscript objects are run with the privileges of the context that created them,\nnot the potentially elevated privilege of the context calling them.\n(CAN-2005-1532)\n\nScripts in XBL controls from web content continued to be run even when\nJavascript was disabled. This could be combined with most script-based exploits\nto attack people running vulnerable versions who thought disabling Javascript\nwould protect them. (CAN-2005-2261)\n\nThe function for version comparison in the addons installer did not properly\nverify the type of its argument. By passing specially crafted Javascript\nobjects to it, a malicious web site could crash Thunderbird and possibly even\nexecute arbitrary code with the privilege of the user account Thunderbird runs\nin. (CAN-2005-2265)\n\nThe XHTML DOM node handler did not take namespaces into account when verifying\nnode types based on their names. For example, an XHTML email could contain an\n<IMG> tag with malicious contents, which would then be processed as the\nstandard trusted HTML <img> tag. By tricking an user to view a malicious email,\nthis could be exploited to execute attacker-specified code with the full\nprivileges of the user. (CAN-2005-2269) \n\nIt was discovered that some objects were not created appropriately.  This\nallowed malicious web content scripts to trace back the creation chain until\nthey found a privileged object and execute code with higher privileges than\nallowed by the current site. (CAN-2005-2270) \n\nJavier Fernández-Sanguino Peña discovered that the run-mozilla.sh script\ncreated temporary files in an unsafe way when running with 'debugging' enabled.\nThis could allow a symlink attack to create or overwrite arbitrary files with\nthe privileges of the user invoking the program.\n(CAN-2005-2353)\n\nThe update for Ubuntu 4.10 (Warty Warthog) also fixes several less\ncritical vulnerabilities which are not present in the Ubuntu 5.04\nversion. (MFSA-2005-02 to MFSA-2005-30; please see the following web\nsite for details:\nhttp://www.mozilla.org/projects/security/known-vulnerabilities.html).\nWe apologize for the huge delay of this update; we changed our update\nstrategy for Mozilla products to make sure that such long delays will\nnot happen again.","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-thunderbird","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-thunderbird-enigmail","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"mozilla-thunderbird","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-thunderbird-enigmail","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-2353","CVE-2005-1159","CVE-2005-0989","CVE-2005-1160","CVE-2005-1532","CVE-2005-2261","CVE-2005-2265","CVE-2005-2269","CVE-2005-2270"]},{"id":"USN-149-3","title":"Ubuntu 4.10 update for Firefox vulnerabilities","summary":"Ubuntu 4.10 update for Firefox vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-07-28T19:16:31","description":"USN-149-1 fixed some vulnerabilities in the Ubuntu 5.04 (Hoary\nHedgehog) version of Firefox. The version shipped with Ubuntu 4.10\n(Warty Warthog) is also vulnerable to these flaws, so it needs to be\nupgraded as well. Please see\n\n  http://www.ubuntulinux.org/support/documentation/usn/usn-149-1\n\nfor the original advisory.\n\nThis update also fixes several older vulnerabilities; Some of them\ncould be exploited to execute arbitrary code with full user privileges\nif the user visited a malicious web site. (MFSA-2005-01 to\nMFSA-2005-44; please see the following web site for details:\nhttp://www.mozilla.org/projects/security/known-vulnerabilities.html)","is_hidden":false,"release_packages":{"warty":[{"name":"mozilla-firefox","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-es","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-ja","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-ca","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-uk","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-de","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-nb","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-it","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-tr","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-fr","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-pl","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-1156","CVE-2004-1381","CVE-2005-0141","CVE-2005-0142","CVE-2005-0143","CVE-2005-0144","CVE-2005-0145","CVE-2005-0146","CVE-2005-0147","CVE-2005-0150","CVE-2005-0230","CVE-2005-0231","CVE-2005-0232","CVE-2005-0233","CVE-2005-0255","CVE-2005-0399","CVE-2005-0401","CVE-2005-0402","CVE-2005-0578","CVE-2005-0584","CVE-2005-0585","CVE-2005-0586","CVE-2005-0587","CVE-2005-0588","CVE-2005-0589","CVE-2005-0590","CVE-2005-0591","CVE-2005-0592","CVE-2005-0593","CVE-2005-0752","CVE-2005-0989","CVE-2005-1153","CVE-2005-1154","CVE-2005-1155","CVE-2005-1156","CVE-2005-1157","CVE-2005-1158","CVE-2005-1159","CVE-2005-1160","CVE-2005-1531","CVE-2005-1532","CVE-2005-1937","CVE-2005-2260","CVE-2005-2261","CVE-2005-2262","CVE-2005-2263","CVE-2005-2264","CVE-2005-2265","CVE-2005-2266","CVE-2005-2267","CVE-2005-2268","CVE-2005-2269","CVE-2005-2270"]},{"id":"USN-149-1","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-07-21T16:13:51","description":"Secunia.com reported that one of the recent security patches in\nFirefox reintroduced the frame injection patch that was originally\nknown as CAN-2004-0718. This allowed a malicious web site to spoof the\ncontents of other web sites. (CAN-2005-1937)\n\nIn several places the browser user interface did not correctly\ndistinguish between true user events, such as mouse clicks or\nkeystrokes, and synthetic events genenerated by web content. This\ncould be exploited by malicious web sites to generate e. g. mouse\nclicks that install malicious plugins. Synthetic events are now\nprevented from reaching the browser UI entirely. (CAN-2005-2260)\n\nScripts in XBL controls from web content continued to be run even when\nJavascript was disabled. This could be combined with most script-based\nexploits to attack people running vulnerable versions who thought\ndisabling Javascript would protect them. (CAN-2005-2261)\n\nMatthew Mastracci discovered a flaw in the addons installation\nlauncher. By forcing a page navigation immediately after calling the\ninstall method a callback function could end up running in the context\nof the new page selected by the attacker. This callback script could\nsteal data from the new page such as cookies or passwords, or perform\nactions on the user's behalf such as make a purchase if the user is\nalready logged into the target site. However, the default settings\nallow only http://addons.mozilla.org to bring up this install dialog.\nThis could only be exploited if users have added untrustworthy sites\nto the installation allowlist, and if a malicious site can convince\nyou to install from their site. (CAN-2005-2263)\n\nKohei Yoshino discovered a Javascript injection vulnerability in the\nsidebar. Sites can use the _search target to open links in the Firefox\nsidebar. A missing security check allowed the sidebar to inject\n\"data:\" URLs containing scripts into any page open in the browser.\nThis could be used to steal cookies, passwords or other sensitive\ndata. (CAN-2005-2264)\n\nThe function for version comparison in the addons installer did not\nproperly verify the type of its argument. By passing specially crafted\nJavascript objects to it, a malicious web site could crash the browser\nand possibly even execute arbitrary code with the privilege of the\nuser account Firefox runs in. (CAN-2005-2265)\n\nA child frame can call top.focus() even if the framing page comes from\na different origin and has overridden the focus() routine. Andreas\nSandblad discovered that the call is made in the context of the child\nframe. This could be exploited to steal cookies and passwords from the\nframed page, or take actions on behalf of a signed-in user. However,\nweb sites with above properties are not very common. (CAN-2005-2266)\n\nSeveral media players, for example Flash and QuickTime, support\nscripted content with the ability to open URLs in the default browser.\nThe default behavior for Firefox was to replace the currently open\nbrowser window's content with the externally opened content. Michael\nKrax discovered that if the external URL was a javascript: URL it\nwould run as if it came from the site that served the previous\ncontent, which could be used to steal sensitive information such as\nlogin cookies or passwords. If the media player content first caused a\nprivileged chrome: url to load then the subsequent javascript: url\ncould execute arbitrary code. (CAN-2005-2267)\n\nAlerts and prompts created by scripts in web pages were presented with\nthe generic title [JavaScript Application] which sometimes made it\ndifficult to know which site created them. A malicious page could\nexploit this by causing a prompt to appear in front of a trusted site\nin an attempt to extract information such as passwords from the user.\nIn the fixed version these prompts contain the hostname of the page\nwhich created it. (CAN-2005-2268)\n\nThe XHTML DOM node handler did not take namespaces into account when\nverifying node types based on their names. For example, an XHTML\ndocument could contain an <IMG> tag with malicious contents, which\nwould then be processed as the standard trusted HTML <img> tag. By\ntricking an user to view malicious web sites, this could be exploited\nto execute attacker-specified code with the full privileges of the\nuser. (CAN-2005-2269)\n\nIt was discovered that some objects were not created appropriately.\nThis allowed malicious web content scripts to trace back the creation\nchain until they found a privileged object and execute code with\nhigher privileges than allowed by the current site.  (CAN-2005-2270)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-firefox","version":"","is_source":false,"is_visible":true,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-1937","CVE-2005-2260","CVE-2005-2261","CVE-2005-2263","CVE-2005-2264","CVE-2005-2265","CVE-2005-2266","CVE-2005-2267","CVE-2005-2268","CVE-2005-2269","CVE-2005-2270"]}]},{"id":"CVE-2005-2260","published":"2005-07-13T04:00:00","updated_at":"2025-07-17T16:36:05.666555+00:00","description":"\nThe browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9,\nand Netscape 8.0.2 and 7.2 does not properly distinguish between\nuser-generated events and untrusted synthetic events, which makes it easier\nfor remote attackers to perform dangerous actions that normally could only\nbe performed manually by the user.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-155-1","https://ubuntu.com/security/notices/USN-149-3","https://ubuntu.com/security/notices/USN-149-1","https://www.cve.org/CVERecord?id=CVE-2005-2260"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mozilla","source":"https://ubuntu.com/security/cve?package=mozilla","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozilla","debian":"https://tracker.debian.org/pkg/mozilla","statuses":[{"release_codename":"dapper","status":"released","description":"1.7.12-1.1ubuntu2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.7.12-1.1ubuntu2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-155-1","USN-149-3","USN-149-1"],"notices":[{"id":"USN-155-1","title":"Mozilla vulnerabilities","summary":"Mozilla vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-07-27T04:34:26","description":"Secunia.com reported that one of the recent security patches in\nFirefox reintroduced the frame injection patch that was originally\nknown as CAN-2004-0718. This allowed a malicious web site to spoof the\ncontents of other web sites. (CAN-2005-1937)\n\nIt was discovered that a malicious website could inject arbitrary\nscripts into a target site by loading it into a frame and navigating\nback to a previous Javascript URL that contained an eval() call. This\ncould be used to steal cookies or other confidential data from the\ntarget site. (MFSA 2005-42)\n\nMichael Krax, Georgi Guninski, and L. David Baron found that the\nsecurity checks that prevent script injection could be bypassed by\nwrapping a javascript: url in another pseudo-protocol like\n\"view-source:\" or \"jar:\". (CAN-2005-1531)\n\nA variant of the attack described in CAN-2005-1160 (see USN-124-1) was\ndiscovered. Additional checks were added to make sure Javascript eval\nand script objects are run with the privileges of the context that\ncreated them, not the potentially elevated privilege of the context\ncalling them. (CAN-2005-1532)\n\nIn several places the browser user interface did not correctly\ndistinguish between true user events, such as mouse clicks or\nkeystrokes, and synthetic events genenerated by web content. This\ncould be exploited by malicious web sites to generate e. g. mouse clicks\nthat install malicious plugins. Synthetic events are now prevented\nfrom reaching the browser UI entirely. (CAN-2005-2260)\n\nScripts in XBL controls from web content continued to be run even when\nJavascript was disabled. This could be combined with most script-based\nexploits to attack people running vulnerable versions who thought\ndisabling Javascript would protect them. (CAN-2005-2261)\n\nMatthew Mastracci discovered a flaw in the addons installation\nlauncher. By forcing a page navigation immediately after calling the\ninstall method a callback function could end up running in the context\nof the new page selected by the attacker. This callback script could\nsteal data from the new page such as cookies or passwords, or perform\nactions on the user's behalf such as make a purchase if the user is\nalready logged into the target site. However, the default settings\nallow only http://addons.mozilla.org to bring up this install dialog.\nThis could only be exploited if users have added untrustworthy sites\nto the installation allowlist, and if a malicious site can convince\nyou to install from their site. (CAN-2005-2263)\n\nThe function for version comparison in the addons installer did not\nproperly verify the type of its argument. By passing specially crafted\nJavascript objects to it, a malicious web site could crash the browser\nand possibly even execute arbitrary code with the privilege of the\nuser account Firefox runs in. (CAN-2005-2265)\n\nA child frame can call top.focus() even if the framing page comes from\na different origin and has overridden the focus() routine. Andreas\nSandblad discovered that the call is made in the context of the child\nframe. This could be exploited to steal cookies and passwords from the\nframed page, or take actions on behalf of a signed-in user. However,\nweb sites with above properties are not very common. (CAN-2005-2266)\n\nAlerts and prompts created by scripts in web pages were presented with\nthe generic title [Javascript Application] which sometimes made it\ndifficult to know which site created them. A malicious page could\nexploit this by causing a prompt to appear in front of a trusted site\nin an attempt to extract information such as passwords from the user.\nIn the fixed version these prompts contain the hostname of the page\nwhich created it. (CAN-2005-2268)\n\nThe XHTML DOM node handler did not take namespaces into account when\nverifying node types based on their names. For example, an XHTML\ndocument could contain an <IMG> tag with malicious contents, which\nwould then be processed as the standard trusted HTML <img> tag. By\ntricking an user to view malicious web sites, this could be exploited\nto execute attacker-specified code with the full privileges of the\nuser. (CAN-2005-2269)\n\nIt was discovered that some objects were not created appropriately.\nThis allowed malicious web content scripts to trace back the creation\nchain until they found a privileged object and execute code with\nhigher privileges than allowed by the current site. (CAN-2005-2270)\n\nThe update for Ubuntu 4.10 (Warty Warthog) also fixes several\nvulnerabilities which are not present in the Ubuntu 5.04 version. Some\nof them could be exploited to execute arbitrary code with full user\nprivileges if the user visited a malicious web site. (MFSA-2005-01 to\nMFSA-2005-41; please see the following web site for details:\nhttp://www.mozilla.org/projects/security/known-vulnerabilities.html). We\napologize for the huge delay of this update; we changed our update\nstrategy for Mozilla products to make sure that such long delays will\nnot happen again.","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-browser","version":"","is_source":false,"is_visible":true,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"","is_source":false,"is_visible":true,"source_link":"","version_link":""}],"warty":[{"name":"mozilla-browser","version":"","is_source":false,"is_visible":true,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"","is_source":false,"is_visible":true,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-2266","CVE-2005-2261","CVE-2005-2260","CVE-2005-1532","CVE-2005-1937","CVE-2005-2270","CVE-2005-2268","CVE-2005-1531","CVE-2005-2265","CVE-2005-2263","CVE-2005-2269"]},{"id":"USN-149-3","title":"Ubuntu 4.10 update for Firefox vulnerabilities","summary":"Ubuntu 4.10 update for Firefox vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-07-28T19:16:31","description":"USN-149-1 fixed some vulnerabilities in the Ubuntu 5.04 (Hoary\nHedgehog) version of Firefox. The version shipped with Ubuntu 4.10\n(Warty Warthog) is also vulnerable to these flaws, so it needs to be\nupgraded as well. Please see\n\n  http://www.ubuntulinux.org/support/documentation/usn/usn-149-1\n\nfor the original advisory.\n\nThis update also fixes several older vulnerabilities; Some of them\ncould be exploited to execute arbitrary code with full user privileges\nif the user visited a malicious web site. (MFSA-2005-01 to\nMFSA-2005-44; please see the following web site for details:\nhttp://www.mozilla.org/projects/security/known-vulnerabilities.html)","is_hidden":false,"release_packages":{"warty":[{"name":"mozilla-firefox","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-es","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-ja","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-ca","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-uk","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-de","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-nb","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-it","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-tr","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-fr","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-pl","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-1156","CVE-2004-1381","CVE-2005-0141","CVE-2005-0142","CVE-2005-0143","CVE-2005-0144","CVE-2005-0145","CVE-2005-0146","CVE-2005-0147","CVE-2005-0150","CVE-2005-0230","CVE-2005-0231","CVE-2005-0232","CVE-2005-0233","CVE-2005-0255","CVE-2005-0399","CVE-2005-0401","CVE-2005-0402","CVE-2005-0578","CVE-2005-0584","CVE-2005-0585","CVE-2005-0586","CVE-2005-0587","CVE-2005-0588","CVE-2005-0589","CVE-2005-0590","CVE-2005-0591","CVE-2005-0592","CVE-2005-0593","CVE-2005-0752","CVE-2005-0989","CVE-2005-1153","CVE-2005-1154","CVE-2005-1155","CVE-2005-1156","CVE-2005-1157","CVE-2005-1158","CVE-2005-1159","CVE-2005-1160","CVE-2005-1531","CVE-2005-1532","CVE-2005-1937","CVE-2005-2260","CVE-2005-2261","CVE-2005-2262","CVE-2005-2263","CVE-2005-2264","CVE-2005-2265","CVE-2005-2266","CVE-2005-2267","CVE-2005-2268","CVE-2005-2269","CVE-2005-2270"]},{"id":"USN-149-1","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-07-21T16:13:51","description":"Secunia.com reported that one of the recent security patches in\nFirefox reintroduced the frame injection patch that was originally\nknown as CAN-2004-0718. This allowed a malicious web site to spoof the\ncontents of other web sites. (CAN-2005-1937)\n\nIn several places the browser user interface did not correctly\ndistinguish between true user events, such as mouse clicks or\nkeystrokes, and synthetic events genenerated by web content. This\ncould be exploited by malicious web sites to generate e. g. mouse\nclicks that install malicious plugins. Synthetic events are now\nprevented from reaching the browser UI entirely. (CAN-2005-2260)\n\nScripts in XBL controls from web content continued to be run even when\nJavascript was disabled. This could be combined with most script-based\nexploits to attack people running vulnerable versions who thought\ndisabling Javascript would protect them. (CAN-2005-2261)\n\nMatthew Mastracci discovered a flaw in the addons installation\nlauncher. By forcing a page navigation immediately after calling the\ninstall method a callback function could end up running in the context\nof the new page selected by the attacker. This callback script could\nsteal data from the new page such as cookies or passwords, or perform\nactions on the user's behalf such as make a purchase if the user is\nalready logged into the target site. However, the default settings\nallow only http://addons.mozilla.org to bring up this install dialog.\nThis could only be exploited if users have added untrustworthy sites\nto the installation allowlist, and if a malicious site can convince\nyou to install from their site. (CAN-2005-2263)\n\nKohei Yoshino discovered a Javascript injection vulnerability in the\nsidebar. Sites can use the _search target to open links in the Firefox\nsidebar. A missing security check allowed the sidebar to inject\n\"data:\" URLs containing scripts into any page open in the browser.\nThis could be used to steal cookies, passwords or other sensitive\ndata. (CAN-2005-2264)\n\nThe function for version comparison in the addons installer did not\nproperly verify the type of its argument. By passing specially crafted\nJavascript objects to it, a malicious web site could crash the browser\nand possibly even execute arbitrary code with the privilege of the\nuser account Firefox runs in. (CAN-2005-2265)\n\nA child frame can call top.focus() even if the framing page comes from\na different origin and has overridden the focus() routine. Andreas\nSandblad discovered that the call is made in the context of the child\nframe. This could be exploited to steal cookies and passwords from the\nframed page, or take actions on behalf of a signed-in user. However,\nweb sites with above properties are not very common. (CAN-2005-2266)\n\nSeveral media players, for example Flash and QuickTime, support\nscripted content with the ability to open URLs in the default browser.\nThe default behavior for Firefox was to replace the currently open\nbrowser window's content with the externally opened content. Michael\nKrax discovered that if the external URL was a javascript: URL it\nwould run as if it came from the site that served the previous\ncontent, which could be used to steal sensitive information such as\nlogin cookies or passwords. If the media player content first caused a\nprivileged chrome: url to load then the subsequent javascript: url\ncould execute arbitrary code. (CAN-2005-2267)\n\nAlerts and prompts created by scripts in web pages were presented with\nthe generic title [JavaScript Application] which sometimes made it\ndifficult to know which site created them. A malicious page could\nexploit this by causing a prompt to appear in front of a trusted site\nin an attempt to extract information such as passwords from the user.\nIn the fixed version these prompts contain the hostname of the page\nwhich created it. (CAN-2005-2268)\n\nThe XHTML DOM node handler did not take namespaces into account when\nverifying node types based on their names. For example, an XHTML\ndocument could contain an <IMG> tag with malicious contents, which\nwould then be processed as the standard trusted HTML <img> tag. By\ntricking an user to view malicious web sites, this could be exploited\nto execute attacker-specified code with the full privileges of the\nuser. (CAN-2005-2269)\n\nIt was discovered that some objects were not created appropriately.\nThis allowed malicious web content scripts to trace back the creation\nchain until they found a privileged object and execute code with\nhigher privileges than allowed by the current site.  (CAN-2005-2270)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-firefox","version":"","is_source":false,"is_visible":true,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-1937","CVE-2005-2260","CVE-2005-2261","CVE-2005-2263","CVE-2005-2264","CVE-2005-2265","CVE-2005-2266","CVE-2005-2267","CVE-2005-2268","CVE-2005-2269","CVE-2005-2270"]}]},{"id":"CVE-2005-2256","published":"2005-07-13T04:00:00","updated_at":"2025-07-17T16:36:05.666555+00:00","description":"\nEncoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows\nremote attackers to access arbitrary files via \"%2e%2e%2f\" (encoded dot\ndot) sequences in the formLanguage parameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2256"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"phppgadmin","source":"https://ubuntu.com/security/cve?package=phppgadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=phppgadmin","debian":"https://tracker.debian.org/pkg/phppgadmin","statuses":[{"release_codename":"dapper","status":"released","description":"4.0.1-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"4.0.1-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"4.0.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2250","published":"2005-07-13T04:00:00","updated_at":"2025-07-17T16:36:05.666555+00:00","description":"\nBuffer overflow in Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and\n3.2.0 allows remote attackers to execute arbitrary code via a long filename\nin an OBEX file share.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2250"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"affix","source":"https://ubuntu.com/security/cve?package=affix","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=affix","debian":"https://tracker.debian.org/pkg/affix","statuses":[{"release_codename":"dapper","status":"released","description":"2.1.2-3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.1.2-3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.1.2-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2095","published":"2005-07-13T04:00:00","updated_at":"2025-07-17T16:35:58.627320+00:00","description":"\noptions_identities.php in SquirrelMail 1.4.4 and earlier uses the extract\nfunction to process the $_POST variable, which allows remote attackers to\nmodify or read the preferences of other users, conduct cross-site scripting\nXSS) attacks, and write arbitrary files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2095"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"squirrelmail","source":"https://ubuntu.com/security/cve?package=squirrelmail","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=squirrelmail","debian":"https://tracker.debian.org/pkg/squirrelmail","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.6-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.8-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.9a-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2247","published":"2005-07-12T04:00:00","updated_at":"2025-07-17T16:36:05.666555+00:00","description":"\nMultiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact\nand attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2247"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2240","published":"2005-07-12T04:00:00","updated_at":"2025-07-17T16:36:05.666555+00:00","description":"\nxpvm.tcl in xpvm 1.2.5 allows local users to overwrite arbitrary files via\na symlink attack on the xpvm.trace.$user temporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2240"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"xpvm","source":"https://ubuntu.com/security/cve?package=xpvm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xpvm","debian":"https://tracker.debian.org/pkg/xpvm","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2239","published":"2005-07-12T04:00:00","updated_at":"2025-07-17T16:36:05.666555+00:00","description":"\noftpd 0.3.7 allows remote attackers to cause a denial of service via a USER\ncommand with a large number of null (\\0) characters.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2239"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"oftpd","source":"https://ubuntu.com/security/cve?package=oftpd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=oftpd","debian":"https://tracker.debian.org/pkg/oftpd","statuses":[{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2231","published":"2005-07-12T04:00:00","updated_at":"2025-07-17T16:36:05.666555+00:00","description":"\nHigh Availability Linux Project Heartbeat 1.2.3 allows local users to\noverwrite arbitrary files via a symlink attack on temporary files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-165-1","https://www.cve.org/CVERecord?id=CVE-2005-2231"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"heartbeat","source":"https://ubuntu.com/security/cve?package=heartbeat","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=heartbeat","debian":"https://tracker.debian.org/pkg/heartbeat","statuses":[{"release_codename":"dapper","status":"released","description":"1.2.4-2ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.2.4-14build1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.2.4-14build1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"heartbeat-2","source":"https://ubuntu.com/security/cve?package=heartbeat-2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=heartbeat-2","debian":"https://tracker.debian.org/pkg/heartbeat-2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.2-5","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.2-5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.2-5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-165-1"],"notices":[{"id":"USN-165-1","title":"heartbeat vulnerability","summary":"heartbeat vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-08-11T22:13:20","description":"Eric Romang discovered that heartbeat created temporary files in an\ninsecure manner. This could allow a symlink attack to create or\noverwrite arbitrary files with root privileges as soon as heartbeat is\nstarted.","is_hidden":false,"release_packages":{"hoary":[{"name":"heartbeat","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"heartbeat","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-2231"]}]},{"id":"CVE-2005-2230","published":"2005-07-12T04:00:00","updated_at":"2025-07-17T16:36:05.666555+00:00","description":"\nElectronic Mail Operator (elmo) 1.3.2-r1 and earlier creates the elmostats\ntemporary file insecurely, which allows local users to overwrite arbitrary\nfiles.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2230"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"elmo","source":"https://ubuntu.com/security/cve?package=elmo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=elmo","debian":"https://tracker.debian.org/pkg/elmo","statuses":[{"release_codename":"dapper","status":"released","description":"1.3.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.3.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.3.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2214","published":"2005-07-11T04:00:00","updated_at":"2025-07-17T16:36:03.904437+00:00","description":"\napt-setup in Debian GNU/Linux installs the apt.conf file with insecure\npermissions, which allows local users to obtain sensitive information such\nas passwords.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2214"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"base-config","source":"https://ubuntu.com/security/cve?package=base-config","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=base-config","debian":"https://tracker.debian.org/pkg/base-config","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2177","published":"2005-07-11T04:00:00","updated_at":"2025-07-17T16:36:03.904437+00:00","description":"\nNet-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when\nnet-snmp is using stream sockets such as TCP, allows remote attackers to\ncause a denial of service (daemon hang and CPU consumption) via a TCP\npacket of length 1, which triggers an infinite loop.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-190-1","https://ubuntu.com/security/notices/USN-190-2","https://www.cve.org/CVERecord?id=CVE-2005-2177"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"net-snmp","source":"https://ubuntu.com/security/cve?package=net-snmp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=net-snmp","debian":"https://tracker.debian.org/pkg/net-snmp","statuses":[{"release_codename":"dapper","status":"released","description":"5.2.1.2-4ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.2.2-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.2.2-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-190-1","USN-190-2"],"notices":[{"id":"USN-190-1","title":"SNMP vulnerability","summary":"SNMP vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-09-30T01:58:07","description":"A remote Denial of Service has been discovered in the SMNP (Simple\nNetwork Management Protocol) library. If a SNMP agent uses TCP sockets\nfor communication, a malicious SNMP server could exploit this to crash\nthe agent. Please note that by default SNMP uses UDP sockets.","is_hidden":false,"release_packages":{"hoary":[{"name":"snmpd","version":"","is_source":false,"source_link":"","version_link":""},{"name":"libsnmp5","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"snmpd","version":"","is_source":false,"source_link":"","version_link":""},{"name":"libsnmp5","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-2177"]},{"id":"USN-190-2","title":"ucs-snmp vulnerability","summary":"ucs-snmp vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-11-21T20:07:43","description":"USN-190-1 fixed a vulnerability in the net-snmp library. It was\ndiscovered that the same problem also affects the ucs-snmp\nimplementation (which is used by the Cyrus email server).\n\nOriginal advisory:\n\n  A remote Denial of Service has been discovered in the SMNP (Simple\n  Network Management Protocol) library. If a SNMP agent uses TCP sockets\n  for communication, a malicious SNMP server could exploit this to crash\n  the agent. Please note that by default SNMP uses UDP sockets.","is_hidden":false,"release_packages":{"hoary":[{"name":"libsnmp4.2","version":"","is_source":false,"source_link":"","version_link":""}],"warty":[{"name":"libsnmp4.2","version":"","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"libsnmp4.2","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-2177"]}]},{"id":"CVE-2005-2170","published":"2005-07-11T04:00:00","updated_at":"2025-07-17T16:36:03.904437+00:00","description":"\nThe LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows\nremote attackers to cause a denial of service (process exit and connection\nloss) by connecting to LCF and ending the connection without sending any\ndata.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2170"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"helix-player","source":"https://ubuntu.com/security/cve?package=helix-player","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=helix-player","debian":"https://tracker.debian.org/pkg/helix-player","statuses":[{"release_codename":"dapper","status":"released","description":"1.0.6-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.0.6-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.0.6-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-1848","published":"2005-07-11T04:00:00","updated_at":"2025-07-17T16:35:50.194894+00:00","description":"\nThe dhcpcd DHCP client before 1.3.22 allows remote attackers to cause a\ndenial of service (daemon crash) via unknown vectors that cause an\nout-of-bounds memory read.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-1848"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"dhcpcd","source":"https://ubuntu.com/security/cve?package=dhcpcd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dhcpcd","debian":"https://tracker.debian.org/pkg/dhcpcd","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-1768","published":"2005-07-11T04:00:00","updated_at":"2025-07-17T16:35:50.194894+00:00","description":"\nRace condition in the ia32 compatibility code for the execve system call in\nLinux kernel 2.4 before 2.4.31 and 2.6 before 2.6.6 allows local users to\ncause a denial of service (kernel panic) and possibly execute arbitrary\ncode via a concurrent thread that increments a pointer count after the\nnargs function has counted the pointers, but before the count is copied\nfrom user space to kernel space, which leads to a buffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-1768"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kernel-source-2.4.27","source":"https://ubuntu.com/security/cve?package=kernel-source-2.4.27","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kernel-source-2.4.27","debian":"https://tracker.debian.org/pkg/kernel-source-2.4.27","statuses":[{"release_codename":"dapper","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2174","published":"2005-07-08T04:00:00","updated_at":"2025-07-17T16:36:03.904437+00:00","description":"\nBugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1\ninserts a bug into the database before it is marked private, which\nintroduces a race condition and allows attackers to access information\nabout the bug via buglist.cgi before MySQL replication is complete.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2174"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2173","published":"2005-07-08T04:00:00","updated_at":"2025-07-17T16:36:03.904437+00:00","description":"\nThe Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1\nand 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the\ngiven bug or attachment ID, which allows users to change flags on arbitrary\nbugs and obtain a bug summary via process_bug.cgi.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2173"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2161","published":"2005-07-06T04:00:00","updated_at":"2025-07-17T16:36:03.904437+00:00","description":"\nCross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote\nattackers to inject arbitrary web script or HTML via nested [url] tags.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2161"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"phpbb2","source":"https://ubuntu.com/security/cve?package=phpbb2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=phpbb2","debian":"https://tracker.debian.org/pkg/phpbb2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.18-2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.18-2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.18-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-2151","published":"2005-07-06T04:00:00","updated_at":"2025-07-17T16:36:03.904437+00:00","description":"\nspf.c in Courier Mail Server does not properly handle DNS failures when\nlooking up Sender Policy Framework (SPF) records, which could allow\nattackers to cause memory corruption.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-174-1","https://www.cve.org/CVERecord?id=CVE-2005-2151"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"courier","source":"https://ubuntu.com/security/cve?package=courier","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=courier","debian":"https://tracker.debian.org/pkg/courier","statuses":[{"release_codename":"dapper","status":"released","description":"0.47-13ubuntu5.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.53.2-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.53.2-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-174-1"],"notices":[{"id":"USN-174-1","title":"courier vulnerability","summary":"courier vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-08-26T22:54:47","description":"A Denial of Service vulnerability has been discovered in the Courier\nmail server. Due to a flawed status code check, failed DNS (domain\nname service) queries for SPF (sender policy framework) were not\nhandled properly and could lead to memory corruption. A malicious DNS\nserver could exploit this to crash the Courier server.\n\nHowever, SPF is not enabled by default, so you are only vulnerable if\nyou explicitly enabled it.\n\nThe Ubuntu 4.10 version of courier is not affected by this.","is_hidden":false,"release_packages":{"hoary":[{"name":"courier-base","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-2151"]}]},{"id":"CVE-2005-2149","published":"2005-07-06T04:00:00","updated_at":"2025-07-17T16:36:03.904437+00:00","description":"\nconfig.php in Cacti 0.8.6e and earlier allows remote attackers to set the\nno_http_headers switch, then modify session information to gain privileges\nand disable the use of addslashes to conduct SQL injection attacks.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-2149"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"cacti","source":"https://ubuntu.com/security/cve?package=cacti","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cacti","debian":"https://tracker.debian.org/pkg/cacti","statuses":[{"release_codename":"dapper","status":"released","description":"0.8.6h-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.8.6h-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.8.6i-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":78400,"limit":20,"total_results":79316}