{"cves":[{"id":"CVE-2004-0803","published":"2004-12-23T05:00:00","updated_at":"2025-07-17T16:34:02.653171+00:00","description":"\nMultiple vulnerabilities in the RLE (run length encoding) decoders for\nlibtiff 3.6.1 and earlier, related to buffer overflows and integer\noverflows, allow remote attackers to execute arbitrary code via TIFF files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0803"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"dapper","status":"released","description":"3.7.4-1ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.8.2-6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.8.2-6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0749","published":"2004-12-23T05:00:00","updated_at":"2025-07-17T16:33:59.019750+00:00","description":"\nThe mod_authz_svn module in Subversion 1.0.7 and earlier does not properly\nrestrict access to all metadata on unreadable paths, which could allow\nremote attackers to gain sensitive information via (1) svn log -v, (2) svn\npropget, or (3) svn blame, and other commands that follow renames.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0749"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"subversion","source":"https://ubuntu.com/security/cve?package=subversion","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=subversion","debian":"https://tracker.debian.org/pkg/subversion","statuses":[{"release_codename":"dapper","status":"released","description":"1.3.1-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.3.1-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.3.1-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0685","published":"2004-12-23T05:00:00","updated_at":"2025-07-17T16:33:57.609302+00:00","description":"\nCertain USB drivers in the Linux 2.4 kernel use the copy_to_user function\non uninitialized structures, which could allow local users to obtain\nsensitive information by reading memory that was not cleared from previous\nusage.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0685"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kernel-source-2.4.27","source":"https://ubuntu.com/security/cve?package=kernel-source-2.4.27","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kernel-source-2.4.27","debian":"https://tracker.debian.org/pkg/kernel-source-2.4.27","statuses":[{"release_codename":"dapper","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0564","published":"2004-12-23T05:00:00","updated_at":"2025-07-17T16:33:54.800190+00:00","description":"\nRoaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid\nroot contrary to its design, allows local users to overwrite arbitrary\nfiles. NOTE: the developer has publicly disputed the claim that this is a\nvulnerability because pppoe \"is NOT designed to run setuid-root.\"\nTherefore this identifier applies *only* to those configurations and\ninstallations under which pppoe is run setuid root despite the developer's\nwarnings.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0564"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"rp-pppoe","source":"https://ubuntu.com/security/cve?package=rp-pppoe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rp-pppoe","debian":"https://tracker.debian.org/pkg/rp-pppoe","statuses":[{"release_codename":"dapper","status":"released","description":"3.5-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.5-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.5-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0563","published":"2004-12-23T05:00:00","updated_at":"2025-07-17T16:33:54.800190+00:00","description":"\nThe tspc.conf configuration file in freenet6 before 0.9.6 and before 1.0 on\nDebian Linux has world readable permissions, which could allow local users\nto gain sensitive information, such as a username and password.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0563"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"tspc","source":"https://ubuntu.com/security/cve?package=tspc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tspc","debian":"https://tracker.debian.org/pkg/tspc","statuses":[{"release_codename":"dapper","status":"released","description":"2.1.1-6ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.1.1-6ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.1.1-6ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2001-1413","published":"2004-12-23T05:00:00","updated_at":"2025-07-17T16:33:18.700823+00:00","description":"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2001-1413"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ncompress","source":"https://ubuntu.com/security/cve?package=ncompress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ncompress","debian":"https://tracker.debian.org/pkg/ncompress","statuses":[{"release_codename":"dapper","status":"released","description":"4.2.4-15","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0452","published":"2004-12-21T05:00:00","updated_at":"2025-07-17T16:33:51.092101+00:00","description":"\nRace condition in the rmtree function in the File::Path module in Perl\n5.6.1 and 5.8.4 sets read/write permissions for the world, which allows\nlocal users to delete arbitrary files and directories, and possibly read\nfiles and directories, via a symlink attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-44-1","https://www.cve.org/CVERecord?id=CVE-2004-0452"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"perl","source":"https://ubuntu.com/security/cve?package=perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=perl","debian":"https://tracker.debian.org/pkg/perl","statuses":[{"release_codename":"dapper","status":"released","description":"5.8.7-10ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.8.7-10ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.8.7-10ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-44-1"],"notices":[{"id":"USN-44-1","title":"perl information leak","summary":"perl information leak","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-12-21T19:27:13","description":"A race condition and possible information leak has been discovered in\nPerl's File::Path::rmtree(). This function changes the permission of\nfiles and directories before removing them to avoid problems with\nwrong permissions. However, they were made readable and writable not\nonly for the owner, but for the entire world, which opened a race\ncondition and a possible information leak (if the actual removal of a\nfile/directory failed for some reason).","is_hidden":false,"release_packages":{"warty":[{"name":"perl-modules","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0452"]}]},{"id":"CVE-2004-1335","published":"2004-12-15T05:00:00","updated_at":"2025-07-17T16:34:30.572469+00:00","description":"\nMemory leak in the ip_options_get function in the Linux kernel before\n2.6.10 allows local users to cause a denial of service (memory consumption)\nby repeatedly calling the ip_cmsg_send function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-1335"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kernel-source-2.4.27","source":"https://ubuntu.com/security/cve?package=kernel-source-2.4.27","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kernel-source-2.4.27","debian":"https://tracker.debian.org/pkg/kernel-source-2.4.27","statuses":[{"release_codename":"dapper","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-1333","published":"2004-12-15T05:00:00","updated_at":"2025-07-17T16:34:30.572469+00:00","description":"\nInteger overflow in the vc_resize function in the Linux kernel 2.4 and 2.6\nbefore 2.6.10 allows local users to cause a denial of service (kernel\ncrash) via a short new screen value, which leads to a buffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-1333"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kernel-source-2.4.27","source":"https://ubuntu.com/security/cve?package=kernel-source-2.4.27","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kernel-source-2.4.27","debian":"https://tracker.debian.org/pkg/kernel-source-2.4.27","statuses":[{"release_codename":"dapper","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-29.58","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.40","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-1145","published":"2004-12-15T05:00:00","updated_at":"2025-07-17T16:34:24.659145+00:00","description":"\nMultiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow\naccess to restricted Java classes via JavaScript and (2) do not properly\nrestrict access to certain Java classes from the Java applet, which allows\nremote attackers to bypass sandbox restrictions and read or write arbitrary\nfiles.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-1145"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kdelibs","source":"https://ubuntu.com/security/cve?package=kdelibs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kdelibs","debian":"https://tracker.debian.org/pkg/kdelibs","statuses":[{"release_codename":"dapper","status":"released","description":"3.5.2-0ubuntu18.5","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.5.5-0ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.5.6-0ubuntu14.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-1142","published":"2004-12-15T05:00:00","updated_at":"2025-07-17T16:34:24.659145+00:00","description":"\nEthereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of\nservice (CPU consumption) via a certain malformed SMB packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-1142"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"0.99.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-1139","published":"2004-12-15T05:00:00","updated_at":"2025-07-17T16:34:24.659145+00:00","description":"\nUnknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through\n0.10.7 allows remote attackers to cause a denial of service (application\ncrash).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-1139"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ethereal","source":"https://ubuntu.com/security/cve?package=ethereal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ethereal","debian":"https://tracker.debian.org/pkg/ethereal","statuses":[{"release_codename":"dapper","status":"released","description":"0.99.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.99.3a-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0623","published":"2004-12-06T05:00:00","updated_at":"2025-07-17T16:33:56.181005+00:00","description":"\nFormat string vulnerability in misc.c in GNU GNATS 4.00 may allow remote\nattackers to execute arbitrary code via format string specifiers in a\nstring that gets logged by syslog.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0623"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gnats","source":"https://ubuntu.com/security/cve?package=gnats","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnats","debian":"https://tracker.debian.org/pkg/gnats","statuses":[{"release_codename":"dapper","status":"released","description":"4.1.0-0","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"4.1.0-0","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"4.1.0-0","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0565","published":"2004-12-06T05:00:00","updated_at":"2025-07-17T16:33:54.800190+00:00","description":"\nFloating point information leak in the context switch code for Linux 2.4.x\nonly checks the MFH bit but does not verify the FPH owner, which allows\nlocal users to read register values of other processes by setting the MFH\nbit.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0565"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kernel-source-2.4.27","source":"https://ubuntu.com/security/cve?package=kernel-source-2.4.27","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kernel-source-2.4.27","debian":"https://tracker.debian.org/pkg/kernel-source-2.4.27","statuses":[{"release_codename":"dapper","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0497","published":"2004-12-06T05:00:00","updated_at":"2025-07-17T16:33:52.996207+00:00","description":"\nUnknown vulnerability in Linux kernel 2.x may allow local users to modify\nthe group ID of files, such as NFS exported files in kernel 2.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0497"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kernel-source-2.4.27","source":"https://ubuntu.com/security/cve?package=kernel-source-2.4.27","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kernel-source-2.4.27","debian":"https://tracker.debian.org/pkg/kernel-source-2.4.27","statuses":[{"release_codename":"dapper","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0455","published":"2004-12-06T05:00:00","updated_at":"2025-07-17T16:33:51.092101+00:00","description":"\nBuffer overflow in cgi.c in www-sql before 0.5.7 allows local users to\nexecute arbitrary code via a web page that is processed by www-sql.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0455"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"www-sql","source":"https://ubuntu.com/security/cve?package=www-sql","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=www-sql","debian":"https://tracker.debian.org/pkg/www-sql","statuses":[{"release_codename":"dapper","status":"released","description":"0.5.7-19ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.5.7-19ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.5.7-19ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0454","published":"2004-12-06T05:00:00","updated_at":"2025-07-17T16:33:51.092101+00:00","description":"\nBuffer overflow in the msg function for rlpr daemon (rlprd) 2.04 allows\nlocal users to execute arbitrary code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0454"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"rlpr","source":"https://ubuntu.com/security/cve?package=rlpr","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rlpr","debian":"https://tracker.debian.org/pkg/rlpr","statuses":[{"release_codename":"dapper","status":"released","description":"2.05-3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.05-3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.05-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0395","published":"2004-12-06T05:00:00","updated_at":"2025-07-17T16:33:46.356464+00:00","description":"\nThe xatitv program in the gatos package does not properly drop root\nprivileges when the configuration file does not exist, which allows local\nusers to execute arbitrary commands via shell metacharacters in a system\ncall.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0395"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gatos","source":"https://ubuntu.com/security/cve?package=gatos","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gatos","debian":"https://tracker.debian.org/pkg/gatos","statuses":[{"release_codename":"dapper","status":"released","description":"0.0.5-16ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.0.5-16ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.0.5-16ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0393","published":"2004-12-06T05:00:00","updated_at":"2025-07-17T16:33:46.356464+00:00","description":"\nFormat string vulnerability in the msg function for rlpr daemon (rlprd)\n2.0.4 allows remote attackers to execute arbitrary code via format string\nspecifiers in a buffer that can not be resolved, which is provided to the\nsyslog function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0393"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"rlpr","source":"https://ubuntu.com/security/cve?package=rlpr","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rlpr","debian":"https://tracker.debian.org/pkg/rlpr","statuses":[{"release_codename":"dapper","status":"released","description":"2.05-3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.05-3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.05-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2002-1581","published":"2004-12-06T05:00:00","updated_at":"2025-07-17T16:33:20.402911+00:00","description":"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2002-1581"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mailreader","source":"https://ubuntu.com/security/cve?package=mailreader","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mailreader","debian":"https://tracker.debian.org/pkg/mailreader","statuses":[{"release_codename":"dapper","status":"released","description":"2.3.36-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.3.36-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.3.36-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":79040,"limit":20,"total_results":79316}