{"cves":[{"id":"CVE-2004-0793","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:34:02.653171+00:00","description":"\nThe calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root\nprivileges when executed with the -a flag, which allows attackers to\nexecute arbitrary commands via a calendar event file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0793"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"bsdmainutils","source":"https://ubuntu.com/security/cve?package=bsdmainutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bsdmainutils","debian":"https://tracker.debian.org/pkg/bsdmainutils","statuses":[{"release_codename":"dapper","status":"released","description":"6.1.2ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"6.1.2ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"6.1.2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0792","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:34:02.653171+00:00","description":"\nDirectory traversal vulnerability in the sanitize_path function in util.c\nfor rsync 2.6.2 and earlier, when chroot is disabled, allows attackers to\nread or write certain files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0792"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"rsync","source":"https://ubuntu.com/security/cve?package=rsync","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rsync","debian":"https://tracker.debian.org/pkg/rsync","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.6-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.8-2ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.9-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0788","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:34:02.653171+00:00","description":"\nInteger overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22\nand (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of\nservice (application crash) via a crafted ICO file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0788"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gdk-pixbuf","source":"https://ubuntu.com/security/cve?package=gdk-pixbuf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gdk-pixbuf","debian":"https://tracker.debian.org/pkg/gdk-pixbuf","statuses":[{"release_codename":"dapper","status":"released","description":"0.22.0-11","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.22.0-11","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.22.0-11","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gtk+2.0","source":"https://ubuntu.com/security/cve?package=gtk+2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gtk+2.0","debian":"https://tracker.debian.org/pkg/gtk+2.0","statuses":[{"release_codename":"dapper","status":"released","description":"2.8.20-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.10.6-0ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.10.11-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0786","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:34:00.669632+00:00","description":"\nThe IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and\nearlier allow remote attackers to cause a denial of service (child process\ncrash) via a certain URI, as demonstrated using the Codenomicon HTTP Test\nTool.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0786"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.55-4ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.55-4ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.2.3-3.2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0785","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:34:00.669632+00:00","description":"\nMultiple buffer overflows in Gaim before 0.82 allow remote attackers to\ncause a denial of service and possibly execute arbitrary code via (1) Rich\nText Format (RTF) messages, (2) a long hostname for the local system as\nobtained from DNS, or (3) a long URL that is not properly handled by the\nURL decoder.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0785"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gaim","source":"https://ubuntu.com/security/cve?package=gaim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gaim","debian":"https://tracker.debian.org/pkg/gaim","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0+1.5.1cvs20051015-1ubuntu10","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0+1.5.1cvs20051015-1ubuntu10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0+1.5.1cvs20051015-1ubuntu10","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0783","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:34:00.669632+00:00","description":"\nStack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM\nimage decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before\n0.22, may allow remote attackers to execute arbitrary code via a certain\ncolor string. NOTE: this identifier is ONLY for gtk+. It was incorrectly\nreferenced in an advisory for a different issue (CVE-2004-0688).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0783"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gtk+2.0","source":"https://ubuntu.com/security/cve?package=gtk+2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gtk+2.0","debian":"https://tracker.debian.org/pkg/gtk+2.0","statuses":[{"release_codename":"dapper","status":"released","description":"2.8.20-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.10.6-0ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.10.11-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0782","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:34:00.669632+00:00","description":"\nInteger overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image\ndecoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22,\nallows remote attackers to execute arbitrary code via certain n_col and cpp\nvalues that enable a heap-based buffer overflow. NOTE: this identifier is\nONLY for gtk+. It was incorrectly referenced in an advisory for a\ndifferent issue (CVE-2004-0687).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0782"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gdk-pixbuf","source":"https://ubuntu.com/security/cve?package=gdk-pixbuf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gdk-pixbuf","debian":"https://tracker.debian.org/pkg/gdk-pixbuf","statuses":[{"release_codename":"dapper","status":"released","description":"0.22.0-11","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.22.0-11","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.22.0-11","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gtk+2.0","source":"https://ubuntu.com/security/cve?package=gtk+2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gtk+2.0","debian":"https://tracker.debian.org/pkg/gtk+2.0","statuses":[{"release_codename":"dapper","status":"released","description":"2.8.20-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.10.6-0ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.10.11-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0781","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:34:00.669632+00:00","description":"\nCross-site scripting (XSS) vulnerability in list.cgi in the Icecast\ninternal web server (icecast-server) 1.3.12 and earlier allows remote\nattackers to inject arbitrary web script via the UserAgent parameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0781"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"icecast-server","source":"https://ubuntu.com/security/cve?package=icecast-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=icecast-server","debian":"https://tracker.debian.org/pkg/icecast-server","statuses":[{"release_codename":"dapper","status":"released","description":"1.3.12-14","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.3.12-14","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.3.12-14","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0772","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:34:00.669632+00:00","description":"\nDouble free vulnerabilities in error handling code in krb524d for MIT\nKerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute\narbitrary code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0772"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"1.4.3-5ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.3-9ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.4-5ubuntu3.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0768","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:34:00.669632+00:00","description":"\nlibpng 1.2.5 and earlier does not properly calculate certain buffer\noffsets, which could allow remote attackers to execute arbitrary code via a\nbuffer overflow attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0768"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libpng","source":"https://ubuntu.com/security/cve?package=libpng","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpng","debian":"https://tracker.debian.org/pkg/libpng","statuses":[{"release_codename":"dapper","status":"released","description":"1.2.8rel-5ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.2.8rel-5.1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.2.15~beta5-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libpng3","source":"https://ubuntu.com/security/cve?package=libpng3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpng3","debian":"https://tracker.debian.org/pkg/libpng3","statuses":[{"release_codename":"dapper","status":"released","description":"1.2.8rel-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.2.8rel-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0755","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:34:00.669632+00:00","description":"\nThe FileStore capability in CGI::Session for Ruby before 1.8.1, and\npossibly PStore, creates files with insecure permissions, which can allow\nlocal users to steal session information and hijack sessions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0755"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ruby1.6","source":"https://ubuntu.com/security/cve?package=ruby1.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.6","debian":"https://tracker.debian.org/pkg/ruby1.6","statuses":[{"release_codename":"dapper","status":"released","description":"1.6.8-13ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"ruby1.8","source":"https://ubuntu.com/security/cve?package=ruby1.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.8","debian":"https://tracker.debian.org/pkg/ruby1.8","statuses":[{"release_codename":"dapper","status":"released","description":"1.8.4-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.8.4-5ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.8.5-4ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0754","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:33:59.019750+00:00","description":"\nInteger overflow in Gaim before 0.82 allows remote attackers to cause a\ndenial of service and possibly execute arbitrary code via the size variable\nin Groupware server messages.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0754"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gaim","source":"https://ubuntu.com/security/cve?package=gaim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gaim","debian":"https://tracker.debian.org/pkg/gaim","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0+1.5.1cvs20051015-1ubuntu10","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0+1.5.1cvs20051015-1ubuntu10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0+1.5.1cvs20051015-1ubuntu10","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0753","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:33:59.019750+00:00","description":"\nThe BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before\n2.2.4 allows remote attackers to cause a denial of service (infinite loop)\nvia a crafted BMP file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0753"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gdk-pixbuf","source":"https://ubuntu.com/security/cve?package=gdk-pixbuf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gdk-pixbuf","debian":"https://tracker.debian.org/pkg/gdk-pixbuf","statuses":[{"release_codename":"dapper","status":"released","description":"0.22.0-11","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.22.0-11","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.22.0-11","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0752","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:33:59.019750+00:00","description":"\nOpenOffice (OOo) 1.1.2 creates predictable directory names with insecure\npermissions during startup, which may allow local users to read or list\nfiles of other users.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0752"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"openoffice.org","source":"https://ubuntu.com/security/cve?package=openoffice.org","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openoffice.org","debian":"https://tracker.debian.org/pkg/openoffice.org","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.2-2ubuntu12.4","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.4-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.2.0-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openoffice.org-l10n","source":"https://ubuntu.com/security/cve?package=openoffice.org-l10n","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openoffice.org-l10n","debian":"https://tracker.debian.org/pkg/openoffice.org-l10n","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.2-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.2-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.2-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0751","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:33:59.019750+00:00","description":"\nThe char_buffer_read function in the mod_ssl module for Apache 2.x, when\nusing reverse proxying to an SSL server, allows remote attackers to cause a\ndenial of service (segmentation fault).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0751"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.55-4ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.55-4ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.2.3-3.2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0748","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:33:59.019750+00:00","description":"\nmod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a\ndenial of service (CPU consumption) by aborting an SSL connection in a way\nthat causes an Apache child process to enter an infinite loop.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0748"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.55-4ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.55-4ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.2.3-3.2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0747","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:33:59.019750+00:00","description":"\nBuffer overflow in Apache 2.0.50 and earlier allows local users to gain\napache privileges via a .htaccess file that causes the overflow during\nexpansion of environment variables.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0747"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.55-4ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.55-4ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.2.3-3.2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0688","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:33:57.609302+00:00","description":"\nMultiple integer overflows in (1) the xpmParseColors function in parse.c,\n(2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5)\nParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to\nexecute arbitrary code via a malformed XPM image file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-27-1","https://www.cve.org/CVERecord?id=CVE-2004-0688"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"lesstif1-1","source":"https://ubuntu.com/security/cve?package=lesstif1-1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lesstif1-1","debian":"https://tracker.debian.org/pkg/lesstif1-1","statuses":[{"release_codename":"dapper","status":"released","description":"0.93.94-12","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.93.94-12","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lesstif2","source":"https://ubuntu.com/security/cve?package=lesstif2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lesstif2","debian":"https://tracker.debian.org/pkg/lesstif2","statuses":[{"release_codename":"dapper","status":"released","description":"0.94.4-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.94.4-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.94.4-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openmotif","source":"https://ubuntu.com/security/cve?package=openmotif","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openmotif","debian":"https://tracker.debian.org/pkg/openmotif","statuses":[{"release_codename":"dapper","status":"released","description":"2.2.3-1.2ubuntu2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.2.3-1.2ubuntu2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.2.3-1.2ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xorg","source":"https://ubuntu.com/security/cve?package=xorg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg","debian":"https://tracker.debian.org/pkg/xorg","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-27-1"],"notices":[{"id":"USN-27-1","title":"libxpm4 vulnerability","summary":"libxpm4 vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-11-18T00:51:07","description":"Chris Evans discovered several stack overflows in the versions of\nlibXpm shipped by X.Org, XFree86, and LessTif. These overflows\nwere fixed in the Warty development tree before its release.\nMathieu Herrb of OpenBSD subsequently discovered that the original\npatch was insufficient to address these overflows, and thus the\nversion of libxpm4 shipped with Warty is still vulnerable to the\noriginal overflows.\n\nThese overflows do not allow privilege escalation through the X\nserver; the overflows are in a client-side library, allowing\narbitrary code execution with the privileges of the user\nviewing a malicious pixmap.","is_hidden":false,"release_packages":{"warty":[{"name":"libxpm4","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0688","CVE-2004-0687"]}]},{"id":"CVE-2004-0687","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:33:57.609302+00:00","description":"\nMultiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2)\nParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm\nbefore 6.8.1 allow remote attackers to execute arbitrary code via a\nmalformed XPM image file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-27-1","https://www.cve.org/CVERecord?id=CVE-2004-0687"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"openmotif","source":"https://ubuntu.com/security/cve?package=openmotif","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openmotif","debian":"https://tracker.debian.org/pkg/openmotif","statuses":[{"release_codename":"dapper","status":"released","description":"2.2.3-1.2ubuntu2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.2.3-1.2ubuntu2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.2.3-1.2ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xorg","source":"https://ubuntu.com/security/cve?package=xorg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg","debian":"https://tracker.debian.org/pkg/xorg","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-27-1"],"notices":[{"id":"USN-27-1","title":"libxpm4 vulnerability","summary":"libxpm4 vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-11-18T00:51:07","description":"Chris Evans discovered several stack overflows in the versions of\nlibXpm shipped by X.Org, XFree86, and LessTif. These overflows\nwere fixed in the Warty development tree before its release.\nMathieu Herrb of OpenBSD subsequently discovered that the original\npatch was insufficient to address these overflows, and thus the\nversion of libxpm4 shipped with Warty is still vulnerable to the\noriginal overflows.\n\nThese overflows do not allow privilege escalation through the X\nserver; the overflows are in a client-side library, allowing\narbitrary code execution with the privileges of the user\nviewing a malicious pixmap.","is_hidden":false,"release_packages":{"warty":[{"name":"libxpm4","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0688","CVE-2004-0687"]}]},{"id":"CVE-2004-0559","published":"2004-10-20T04:00:00","updated_at":"2025-07-17T16:33:54.800190+00:00","description":"\nThe maketemp.pl script in Usermin 1.070 and 1.080 allows local users to\noverwrite arbitrary files at install time via a symlink attack on the\n/tmp/.usermin directory.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0559"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"usermin","source":"https://ubuntu.com/security/cve?package=usermin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=usermin","debian":"https://tracker.debian.org/pkg/usermin","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":79080,"limit":20,"total_results":79316}