{"cves":[{"id":"CVE-2005-0146","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:48.773814+00:00","description":"\nFirefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to\nobtain sensitive data from the clipboard via Javascript that generates a\nmiddle-click event on systems for which a middle-click performs a paste\noperation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-149-3","https://www.cve.org/CVERecord?id=CVE-2005-0146"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mozilla","source":"https://ubuntu.com/security/cve?package=mozilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla","debian":"https://tracker.debian.org/pkg/mozilla","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-149-3"],"notices":[{"id":"USN-149-3","title":"Ubuntu 4.10 update for Firefox vulnerabilities","summary":"Ubuntu 4.10 update for Firefox vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-07-28T19:16:31","description":"USN-149-1 fixed some vulnerabilities in the Ubuntu 5.04 (Hoary\nHedgehog) version of Firefox. The version shipped with Ubuntu 4.10\n(Warty Warthog) is also vulnerable to these flaws, so it needs to be\nupgraded as well. Please see\n\n http://www.ubuntulinux.org/support/documentation/usn/usn-149-1\n\nfor the original advisory.\n\nThis update also fixes several older vulnerabilities; Some of them\ncould be exploited to execute arbitrary code with full user privileges\nif the user visited a malicious web site. (MFSA-2005-01 to\nMFSA-2005-44; please see the following web site for details:\nhttp://www.mozilla.org/projects/security/known-vulnerabilities.html)","is_hidden":false,"release_packages":{"warty":[{"name":"mozilla-firefox","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-es","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-ja","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-ca","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-uk","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-de","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-nb","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-it","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-tr","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-fr","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-pl","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-1156","CVE-2004-1381","CVE-2005-0141","CVE-2005-0142","CVE-2005-0143","CVE-2005-0144","CVE-2005-0145","CVE-2005-0146","CVE-2005-0147","CVE-2005-0150","CVE-2005-0230","CVE-2005-0231","CVE-2005-0232","CVE-2005-0233","CVE-2005-0255","CVE-2005-0399","CVE-2005-0401","CVE-2005-0402","CVE-2005-0578","CVE-2005-0584","CVE-2005-0585","CVE-2005-0586","CVE-2005-0587","CVE-2005-0588","CVE-2005-0589","CVE-2005-0590","CVE-2005-0591","CVE-2005-0592","CVE-2005-0593","CVE-2005-0752","CVE-2005-0989","CVE-2005-1153","CVE-2005-1154","CVE-2005-1155","CVE-2005-1156","CVE-2005-1157","CVE-2005-1158","CVE-2005-1159","CVE-2005-1160","CVE-2005-1531","CVE-2005-1532","CVE-2005-1937","CVE-2005-2260","CVE-2005-2261","CVE-2005-2262","CVE-2005-2263","CVE-2005-2264","CVE-2005-2265","CVE-2005-2266","CVE-2005-2267","CVE-2005-2268","CVE-2005-2269","CVE-2005-2270"]}]},{"id":"CVE-2005-0144","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:48.773814+00:00","description":"\nFirefox before 1.0 and Mozilla before 1.7.5 display the secure site lock\nicon when a view-source: URL references a secure SSL site while an insecure\npage is being loaded, which could facilitate phishing attacks.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-149-3","https://www.cve.org/CVERecord?id=CVE-2005-0144"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mozilla","source":"https://ubuntu.com/security/cve?package=mozilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla","debian":"https://tracker.debian.org/pkg/mozilla","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-149-3"],"notices":[{"id":"USN-149-3","title":"Ubuntu 4.10 update for Firefox vulnerabilities","summary":"Ubuntu 4.10 update for Firefox vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-07-28T19:16:31","description":"USN-149-1 fixed some vulnerabilities in the Ubuntu 5.04 (Hoary\nHedgehog) version of Firefox. The version shipped with Ubuntu 4.10\n(Warty Warthog) is also vulnerable to these flaws, so it needs to be\nupgraded as well. Please see\n\n http://www.ubuntulinux.org/support/documentation/usn/usn-149-1\n\nfor the original advisory.\n\nThis update also fixes several older vulnerabilities; Some of them\ncould be exploited to execute arbitrary code with full user privileges\nif the user visited a malicious web site. (MFSA-2005-01 to\nMFSA-2005-44; please see the following web site for details:\nhttp://www.mozilla.org/projects/security/known-vulnerabilities.html)","is_hidden":false,"release_packages":{"warty":[{"name":"mozilla-firefox","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-es","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-ja","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-ca","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-uk","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-de","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-nb","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-it","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-tr","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-fr","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-pl","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-1156","CVE-2004-1381","CVE-2005-0141","CVE-2005-0142","CVE-2005-0143","CVE-2005-0144","CVE-2005-0145","CVE-2005-0146","CVE-2005-0147","CVE-2005-0150","CVE-2005-0230","CVE-2005-0231","CVE-2005-0232","CVE-2005-0233","CVE-2005-0255","CVE-2005-0399","CVE-2005-0401","CVE-2005-0402","CVE-2005-0578","CVE-2005-0584","CVE-2005-0585","CVE-2005-0586","CVE-2005-0587","CVE-2005-0588","CVE-2005-0589","CVE-2005-0590","CVE-2005-0591","CVE-2005-0592","CVE-2005-0593","CVE-2005-0752","CVE-2005-0989","CVE-2005-1153","CVE-2005-1154","CVE-2005-1155","CVE-2005-1156","CVE-2005-1157","CVE-2005-1158","CVE-2005-1159","CVE-2005-1160","CVE-2005-1531","CVE-2005-1532","CVE-2005-1937","CVE-2005-2260","CVE-2005-2261","CVE-2005-2262","CVE-2005-2263","CVE-2005-2264","CVE-2005-2265","CVE-2005-2266","CVE-2005-2267","CVE-2005-2268","CVE-2005-2269","CVE-2005-2270"]}]},{"id":"CVE-2005-0142","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:47.212312+00:00","description":"\nFirefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7\nbefore 1.7.5 save temporary files with world-readable permissions, which\nallows local users to read certain web content or attachments that belong\nto other users, e.g. content that is managed by helper applications such as\nPDF.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-149-3","https://www.cve.org/CVERecord?id=CVE-2005-0142"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mozilla","source":"https://ubuntu.com/security/cve?package=mozilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla","debian":"https://tracker.debian.org/pkg/mozilla","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-149-3"],"notices":[{"id":"USN-149-3","title":"Ubuntu 4.10 update for Firefox vulnerabilities","summary":"Ubuntu 4.10 update for Firefox vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-07-28T19:16:31","description":"USN-149-1 fixed some vulnerabilities in the Ubuntu 5.04 (Hoary\nHedgehog) version of Firefox. The version shipped with Ubuntu 4.10\n(Warty Warthog) is also vulnerable to these flaws, so it needs to be\nupgraded as well. Please see\n\n http://www.ubuntulinux.org/support/documentation/usn/usn-149-1\n\nfor the original advisory.\n\nThis update also fixes several older vulnerabilities; Some of them\ncould be exploited to execute arbitrary code with full user privileges\nif the user visited a malicious web site. (MFSA-2005-01 to\nMFSA-2005-44; please see the following web site for details:\nhttp://www.mozilla.org/projects/security/known-vulnerabilities.html)","is_hidden":false,"release_packages":{"warty":[{"name":"mozilla-firefox","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-es","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-ja","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-ca","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-uk","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-de","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-nb","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-it","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-tr","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-fr","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-pl","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-1156","CVE-2004-1381","CVE-2005-0141","CVE-2005-0142","CVE-2005-0143","CVE-2005-0144","CVE-2005-0145","CVE-2005-0146","CVE-2005-0147","CVE-2005-0150","CVE-2005-0230","CVE-2005-0231","CVE-2005-0232","CVE-2005-0233","CVE-2005-0255","CVE-2005-0399","CVE-2005-0401","CVE-2005-0402","CVE-2005-0578","CVE-2005-0584","CVE-2005-0585","CVE-2005-0586","CVE-2005-0587","CVE-2005-0588","CVE-2005-0589","CVE-2005-0590","CVE-2005-0591","CVE-2005-0592","CVE-2005-0593","CVE-2005-0752","CVE-2005-0989","CVE-2005-1153","CVE-2005-1154","CVE-2005-1155","CVE-2005-1156","CVE-2005-1157","CVE-2005-1158","CVE-2005-1159","CVE-2005-1160","CVE-2005-1531","CVE-2005-1532","CVE-2005-1937","CVE-2005-2260","CVE-2005-2261","CVE-2005-2262","CVE-2005-2263","CVE-2005-2264","CVE-2005-2265","CVE-2005-2266","CVE-2005-2267","CVE-2005-2268","CVE-2005-2269","CVE-2005-2270"]}]},{"id":"CVE-2005-0141","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:47.212312+00:00","description":"\nFirefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load\nlocal files via links \"with a custom getter and toString method\" that are\nmiddle-clicked by the user to be opened in a new tab.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-149-3","https://www.cve.org/CVERecord?id=CVE-2005-0141"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mozilla","source":"https://ubuntu.com/security/cve?package=mozilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla","debian":"https://tracker.debian.org/pkg/mozilla","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-149-3"],"notices":[{"id":"USN-149-3","title":"Ubuntu 4.10 update for Firefox vulnerabilities","summary":"Ubuntu 4.10 update for Firefox vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-07-28T19:16:31","description":"USN-149-1 fixed some vulnerabilities in the Ubuntu 5.04 (Hoary\nHedgehog) version of Firefox. The version shipped with Ubuntu 4.10\n(Warty Warthog) is also vulnerable to these flaws, so it needs to be\nupgraded as well. Please see\n\n http://www.ubuntulinux.org/support/documentation/usn/usn-149-1\n\nfor the original advisory.\n\nThis update also fixes several older vulnerabilities; Some of them\ncould be exploited to execute arbitrary code with full user privileges\nif the user visited a malicious web site. (MFSA-2005-01 to\nMFSA-2005-44; please see the following web site for details:\nhttp://www.mozilla.org/projects/security/known-vulnerabilities.html)","is_hidden":false,"release_packages":{"warty":[{"name":"mozilla-firefox","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-es","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-ja","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-ca","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-uk","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-de","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-nb","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-it","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-tr","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-fr","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-pl","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-1156","CVE-2004-1381","CVE-2005-0141","CVE-2005-0142","CVE-2005-0143","CVE-2005-0144","CVE-2005-0145","CVE-2005-0146","CVE-2005-0147","CVE-2005-0150","CVE-2005-0230","CVE-2005-0231","CVE-2005-0232","CVE-2005-0233","CVE-2005-0255","CVE-2005-0399","CVE-2005-0401","CVE-2005-0402","CVE-2005-0578","CVE-2005-0584","CVE-2005-0585","CVE-2005-0586","CVE-2005-0587","CVE-2005-0588","CVE-2005-0589","CVE-2005-0590","CVE-2005-0591","CVE-2005-0592","CVE-2005-0593","CVE-2005-0752","CVE-2005-0989","CVE-2005-1153","CVE-2005-1154","CVE-2005-1155","CVE-2005-1156","CVE-2005-1157","CVE-2005-1158","CVE-2005-1159","CVE-2005-1160","CVE-2005-1531","CVE-2005-1532","CVE-2005-1937","CVE-2005-2260","CVE-2005-2261","CVE-2005-2262","CVE-2005-2263","CVE-2005-2264","CVE-2005-2265","CVE-2005-2266","CVE-2005-2267","CVE-2005-2268","CVE-2005-2269","CVE-2005-2270"]}]},{"id":"CVE-2005-0137","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:47.212312+00:00","description":"\nLinux kernel 2.6 on Itanium (ia64) architectures allows local users to\ncause a denial of service via a \"missing Itanium syscall table entry.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0137"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kernel-source-2.4.27","source":"https://ubuntu.com/security/cve?package=kernel-source-2.4.27","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kernel-source-2.4.27","debian":"https://tracker.debian.org/pkg/kernel-source-2.4.27","statuses":[{"release_codename":"dapper","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-0135","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:47.212312+00:00","description":"\nThe unw_unwind_to_user function in unwind.c on Itanium (ia64) architectures\nin Linux kernel 2.6 allows local users to cause a denial of service (system\ncrash).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0135"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-29.58","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.40","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-0133","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:47.212312+00:00","description":"\nClamAV 0.80 and earlier allows remote attackers to cause a denial of\nservice (clamd daemon crash) via a ZIP file with malformed headers.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0133"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"dapper","status":"released","description":"0.88.2-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.88.4-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.90.2-0ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-0089","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:43.979966+00:00","description":"\nThe SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and\n2.4, when used by XML-RPC servers that use the register_instance method to\nregister an object without a _dispatch method, allows remote attackers to\nread or modify globals of the associated module, and possibly execute\narbitrary code, via dotted attributes.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-73-1","https://www.cve.org/CVERecord?id=CVE-2005-0089"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"python2.2","source":"https://ubuntu.com/security/cve?package=python2.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.2","debian":"https://tracker.debian.org/pkg/python2.2","statuses":[{"release_codename":"dapper","status":"released","description":"2.2.3dfsg-4","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python2.3","source":"https://ubuntu.com/security/cve?package=python2.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.3","debian":"https://tracker.debian.org/pkg/python2.3","statuses":[{"release_codename":"dapper","status":"released","description":"2.3.5-9ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python2.4","source":"https://ubuntu.com/security/cve?package=python2.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.4","debian":"https://tracker.debian.org/pkg/python2.4","statuses":[{"release_codename":"dapper","status":"released","description":"2.4.3-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.4.4~c1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.4.4~c1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python2.5","source":"https://ubuntu.com/security/cve?package=python2.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.5","debian":"https://tracker.debian.org/pkg/python2.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.5-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.5-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-73-1"],"notices":[{"id":"USN-73-1","title":"Python vulnerability","summary":"Python vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-02-04T01:18:26","description":"The Python developers discovered a flaw in the SimpleXMLRPCServer\nmodule. Python XML-RPC servers that used the register_instance()\nmethod to register an object, but do not have a _dispatch() method,\nallowed remote users to access or change function internals using the\nim_* and func_* attributes.","is_hidden":false,"release_packages":{"warty":[{"name":"python2.3","version":"","is_source":false,"source_link":"","version_link":""},{"name":"python2.2","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-0089"]}]},{"id":"CVE-2005-0088","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:43.979966+00:00","description":"\nThe publisher handler for mod_python 2.7.8 and earlier allows remote\nattackers to obtain access to restricted objects via a crafted URL.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-80-1","https://www.cve.org/CVERecord?id=CVE-2005-0088"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libapache-mod-python","source":"https://ubuntu.com/security/cve?package=libapache-mod-python","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libapache-mod-python","debian":"https://tracker.debian.org/pkg/libapache-mod-python","statuses":[{"release_codename":"dapper","status":"released","description":"2.7.10-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.7.10-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.7.10-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libapache2-mod-python","source":"https://ubuntu.com/security/cve?package=libapache2-mod-python","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libapache2-mod-python","debian":"https://tracker.debian.org/pkg/libapache2-mod-python","statuses":[{"release_codename":"dapper","status":"released","description":"3.1.4-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.2.8-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.2.8-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-80-1"],"notices":[{"id":"USN-80-1","title":"mod_python vulnerability","summary":"mod_python vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-02-11T18:41:39","description":"Graham Dumpleton discovered an information disclosure in the\n\"publisher\" handle of mod_python. By requesting a carefully crafted\nURL for a published module page, anybody can obtain extra information\nabout internal variables, objects, and other information which is not\nintended to be visible.","is_hidden":false,"release_packages":{"warty":[{"name":"libapache2-mod-python2.3","version":"","is_source":false,"source_link":"","version_link":""},{"name":"libapache2-mod-python2.2","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-0088"]}]},{"id":"CVE-2005-0084","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:42.165154+00:00","description":"\nBuffer overflow in the X11 dissector in Ethereal 0.8.10 through 0.10.8\nallows remote attackers to execute arbitrary code via a crafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0084"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"released","description":"0.99.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-0080","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:42.165154+00:00","description":"\nThe 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10\ndisplays a different error message depending on whether the e-mail address\nis subscribed to a private list, which allows remote attackers to determine\nthe list membership for a given e-mail address.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0080"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mailman","source":"https://ubuntu.com/security/cve?package=mailman","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mailman","debian":"https://tracker.debian.org/pkg/mailman","statuses":[{"release_codename":"dapper","status":"released","description":"2.1.5-9ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.1.8-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.1.8-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-0079","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:42.165154+00:00","description":"\nBuffer overflow in xtrlock 2.0 allows local users to cause a denial of\nservice (application crash) and hijack the desktop session.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0079"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"xtrlock","source":"https://ubuntu.com/security/cve?package=xtrlock","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xtrlock","debian":"https://tracker.debian.org/pkg/xtrlock","statuses":[{"release_codename":"dapper","status":"released","description":"2.0-11","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0-11","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0-11","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-0077","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:42.165154+00:00","description":"\nThe DBI library (libdbi-perl) for Perl allows local users to overwrite\narbitrary files via a symlink attack on a temporary PID file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-70-1","https://www.cve.org/CVERecord?id=CVE-2005-0077"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libdbi-perl","source":"https://ubuntu.com/security/cve?package=libdbi-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libdbi-perl","debian":"https://tracker.debian.org/pkg/libdbi-perl","statuses":[{"release_codename":"dapper","status":"released","description":"1.50-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.50-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.50-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-70-1"],"notices":[{"id":"USN-70-1","title":"Perl DBI module vulnerability","summary":"Perl DBI module vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-01-26T01:45:27","description":"Javier Fernández-Sanguino Peña from the Debian Security Audit Project\ndiscovered that the module DBI::ProxyServer in Perl's DBI library\ncreated a PID file in an insecure manner. This could allow a symbolic\nlink attack to create or overwrite arbitrary files with the privileges\nof the user invoking a program using this module (like 'dbiproxy').\n\nNow the module does not create a such a PID file by default.","is_hidden":false,"release_packages":{"warty":[{"name":"libdbi-perl","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-0077"]}]},{"id":"CVE-2005-0076","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:42.165154+00:00","description":"\nMultiple buffer overflows in the XView library 3.2 may allow local users to\nexecute arbitrary code via setuid applications that use the library.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0076"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"xview","source":"https://ubuntu.com/security/cve?package=xview","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xview","debian":"https://tracker.debian.org/pkg/xview","statuses":[{"release_codename":"dapper","status":"released","description":"3.2p1.4-21","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.2p1.4-21","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.2p1.4-21","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-0073","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:42.165154+00:00","description":"\nBuffer overflow in queue.c in a support script for sympa 3.3.3, when\nrunning setuid, allows local users to execute arbitrary code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0073"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sympa","source":"https://ubuntu.com/security/cve?package=sympa","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sympa","debian":"https://tracker.debian.org/pkg/sympa","statuses":[{"release_codename":"dapper","status":"released","description":"4.1.5-7","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"4.1.5-7","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"4.1.5-7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-0071","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:40.489355+00:00","description":"\nvdr before 1.2.6 does not securely create files, which allows attackers to\noverwrite arbitrary files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0071"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"vdr","source":"https://ubuntu.com/security/cve?package=vdr","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vdr","debian":"https://tracker.debian.org/pkg/vdr","statuses":[{"release_codename":"dapper","status":"released","description":"1.3.37-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.3.37-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.3.37-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-0070","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:40.489355+00:00","description":"\nSynaesthesia 2.1 and earlier, and possibly other versions, when installed\nsetuid root, does not drop privileges before processing configuration and\nmixer files, which allows local users to read arbitrary files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0070"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"synaesthesia","source":"https://ubuntu.com/security/cve?package=synaesthesia","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=synaesthesia","debian":"https://tracker.debian.org/pkg/synaesthesia","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-0064","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:40.489355+00:00","description":"\nBuffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for\nxpdf 3.00 and earlier allows remote attackers to execute arbitrary code via\na PDF file with a large /Encrypt /Length keyLength value.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-64-1","https://www.cve.org/CVERecord?id=CVE-2005-0064"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"cupsys","source":"https://ubuntu.com/security/cve?package=cupsys","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cupsys","debian":"https://tracker.debian.org/pkg/cupsys","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gpdf","source":"https://ubuntu.com/security/cve?package=gpdf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpdf","debian":"https://tracker.debian.org/pkg/gpdf","statuses":[{"release_codename":"dapper","status":"released","description":"2.10.0-2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.10.0-2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"kdegraphics","source":"https://ubuntu.com/security/cve?package=kdegraphics","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kdegraphics","debian":"https://tracker.debian.org/pkg/kdegraphics","statuses":[{"release_codename":"dapper","status":"released","description":"3.5.2-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.5.2-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.5.2-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"koffice","source":"https://ubuntu.com/security/cve?package=koffice","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=koffice","debian":"https://tracker.debian.org/pkg/koffice","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0-0ubuntu9.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.2-0ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.6.2-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libextractor","source":"https://ubuntu.com/security/cve?package=libextractor","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libextractor","debian":"https://tracker.debian.org/pkg/libextractor","statuses":[{"release_codename":"dapper","status":"released","description":"0.5.14-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.5.14-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.5.14-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"pdftohtml","source":"https://ubuntu.com/security/cve?package=pdftohtml","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pdftohtml","debian":"https://tracker.debian.org/pkg/pdftohtml","statuses":[{"release_codename":"dapper","status":"released","description":"0.36-13","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.36-13","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.36-13","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tetex-bin","source":"https://ubuntu.com/security/cve?package=tetex-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tetex-bin","debian":"https://tracker.debian.org/pkg/tetex-bin","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xpdf","source":"https://ubuntu.com/security/cve?package=xpdf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xpdf","debian":"https://tracker.debian.org/pkg/xpdf","statuses":[{"release_codename":"dapper","status":"released","description":"3.01-7ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.01-9ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.01-9ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-64-1"],"notices":[{"id":"USN-64-1","title":"xpdf, CUPS vulnerabilities","summary":"xpdf, CUPS vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-01-19T20:00:53","description":"A buffer overflow has been found in the xpdf viewer. An insufficient\ninput validation of the encryption key length could be exploited by an\nattacker providing a specially crafted PDF file which, when processed\nby xpdf, could result in abnormal program termination or the execution\nof attacker supplied program code with the user's privileges.\n\nThe Common UNIX Printing System (CUPS) uses the same code to print PDF\nfiles. In this case, this bug could be exploited to gain the\nprivileges of the CUPS print server (by default, user cupsys).","is_hidden":false,"release_packages":{"warty":[{"name":"cupsys","version":"","is_source":false,"source_link":"","version_link":""},{"name":"libcupsys2-gnutls10","version":"","is_source":false,"source_link":"","version_link":""},{"name":"xpdf-utils","version":"","is_source":false,"source_link":"","version_link":""},{"name":"xpdf-reader","version":"","is_source":false,"source_link":"","version_link":""},{"name":"libcupsimage2","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-0064"]}]},{"id":"CVE-2005-0034","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:40.489355+00:00","description":"\nAn \"incorrect assumption\" in the authvalidated validator function in BIND\n9.3.0, when DNSSEC is enabled, allows remote attackers to cause a denial of\nservice (named server exit) via crafted DNS packets that cause an internal\nconsistency test (self-check) to fail.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0034"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"bind9","source":"https://ubuntu.com/security/cve?package=bind9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bind9","debian":"https://tracker.debian.org/pkg/bind9","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-0033","published":"2005-05-02T04:00:00","updated_at":"2025-07-17T16:34:40.489355+00:00","description":"\nBuffer overflow in the code for recursion and glue fetching in BIND 8.4.4\nand 8.4.5 allows remote attackers to cause a denial of service (crash) via\nqueries that trigger the overflow in the q_usedns array that tracks\nnameservers and addresses.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0033"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"bind","source":"https://ubuntu.com/security/cve?package=bind","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bind","debian":"https://tracker.debian.org/pkg/bind","statuses":[{"release_codename":"dapper","status":"released","description":"8.4.6-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"8.4.6-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"8.4.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":78720,"limit":20,"total_results":79316}