{"cves":[{"id":"CVE-2004-1617","published":"2004-10-18T04:00:00","updated_at":"2025-07-17T16:34:33.860335+00:00","description":"\nLynx, lynx-ssl, and lynx-cur before 2.8.6dev.8 allow remote attackers to\ncause a denial of service (infinite loop) via a web page or HTML email that\ncontains invalid HTML including (1) a TEXTAREA tag with a large COLS value\nand (2) a large tag name in an element that is not terminated, as\ndemonstrated by mangleme. NOTE: a followup suggests that the relevant\ntrigger for this issue is the large COLS value.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-1617"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"lynx","source":"https://ubuntu.com/security/cve?package=lynx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lynx","debian":"https://tracker.debian.org/pkg/lynx","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.8.5-2ubuntu4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-0373","published":"2004-10-07T04:00:00","updated_at":"2025-07-17T16:34:58.875538+00:00","description":"\nBuffer overflow in digestmd5.c CVS release 1.170 (also referred to as\ndigestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not\nin any official releases, allows remote attackers to execute arbitrary\ncode.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0373"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"cyrus-sasl2","source":"https://ubuntu.com/security/cve?package=cyrus-sasl2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cyrus-sasl2","debian":"https://tracker.debian.org/pkg/cyrus-sasl2","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0745","published":"2004-09-28T04:00:00","updated_at":"2025-07-17T16:33:59.019750+00:00","description":"\nLHA 1.14 and earlier allows attackers to execute arbitrary commands via a\ndirectory with shell metacharacters in its name.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0745"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"lha","source":"https://ubuntu.com/security/cve?package=lha","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lha","debian":"https://tracker.debian.org/pkg/lha","statuses":[{"release_codename":"dapper","status":"released","description":"1.14i-10","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.14i-10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.14i-10","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0693","published":"2004-09-28T04:00:00","updated_at":"2025-07-17T16:33:57.609302+00:00","description":"\nThe GIF parser in the QT library (qt3) before 3.3.3 allows remote attackers\nto cause a denial of service (application crash) via a malformed image file\nthat triggers a null dereference, a different vulnerability than\nCVE-2004-0692.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0693"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"qt-x11-free","source":"https://ubuntu.com/security/cve?package=qt-x11-free","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qt-x11-free","debian":"https://tracker.debian.org/pkg/qt-x11-free","statuses":[{"release_codename":"dapper","status":"released","description":"3.3.6-1ubuntu6.4","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.3.6-3ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.3.8really3.3.7-0ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0692","published":"2004-09-28T04:00:00","updated_at":"2025-07-17T16:33:57.609302+00:00","description":"\nThe XPM parser in the QT library (qt3) before 3.3.3 allows remote attackers\nto cause a denial of service (application crash) via a malformed image file\nthat triggers a null dereference, a different vulnerability than\nCVE-2004-0693.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0692"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"qt-x11-free","source":"https://ubuntu.com/security/cve?package=qt-x11-free","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qt-x11-free","debian":"https://tracker.debian.org/pkg/qt-x11-free","statuses":[{"release_codename":"dapper","status":"released","description":"3.3.6-1ubuntu6.4","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.3.6-3ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.3.8really3.3.7-0ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0691","published":"2004-09-28T04:00:00","updated_at":"2025-07-17T16:33:57.609302+00:00","description":"\nHeap-based buffer overflow in the BMP image format parser for the QT\nlibrary (qt3) before 3.3.3 allows remote attackers to cause a denial of\nservice (application crash) and possibly execute arbitrary code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0691"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"qt-x11-free","source":"https://ubuntu.com/security/cve?package=qt-x11-free","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qt-x11-free","debian":"https://tracker.debian.org/pkg/qt-x11-free","statuses":[{"release_codename":"dapper","status":"released","description":"3.3.6-1ubuntu6.4","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.3.6-3ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.3.8really3.3.7-0ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0644","published":"2004-09-28T04:00:00","updated_at":"2025-07-17T16:33:56.181005+00:00","description":"\nThe asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos\n5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of\nservice (infinite loop) via a certain BER encoding.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0644"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.3-5ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.3-9ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.4-5ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0643","published":"2004-09-28T04:00:00","updated_at":"2025-07-17T16:33:56.181005+00:00","description":"\nDouble free vulnerability in the krb5_rd_cred function for MIT Kerberos 5\n(krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0643"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.3-5ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.3-9ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.4-5ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0642","published":"2004-09-28T04:00:00","updated_at":"2025-07-17T16:33:56.181005+00:00","description":"\nDouble free vulnerabilities in the error handling code for ASN.1 decoders\nin the (1) Key Distribution Center (KDC) library and (2) client library for\nMIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to\nexecute arbitrary code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0642"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.3-5ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.3-9ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.4-5ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0558","published":"2004-09-28T04:00:00","updated_at":"2025-07-17T16:33:54.800190+00:00","description":"\nThe Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21\nallows remote attackers to cause a denial of service (service hang) via a\ncertain UDP packet to the IPP port.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0558"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"cupsys","source":"https://ubuntu.com/security/cve?package=cupsys","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cupsys","debian":"https://tracker.debian.org/pkg/cupsys","statuses":[{"release_codename":"dapper","status":"released","description":"1.2.0-0ubuntu5","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.2.0-0ubuntu5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.2.0-0ubuntu5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0500","published":"2004-09-28T04:00:00","updated_at":"2025-07-17T16:33:52.996207+00:00","description":"\nBuffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for\nGaim before 0.82 allows remote attackers to cause a denial of service and\npossibly execute arbitrary code via MSNSLP protocol messages that are not\nproperly handled in a strncpy call.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0500"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gaim","source":"https://ubuntu.com/security/cve?package=gaim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gaim","debian":"https://tracker.debian.org/pkg/gaim","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0+1.5.1cvs20051015-1ubuntu10","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0+1.5.1cvs20051015-1ubuntu10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0+1.5.1cvs20051015-1ubuntu10","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0458","published":"2004-09-28T04:00:00","updated_at":"2025-07-17T16:33:51.092101+00:00","description":"\nmah-jong before 1.6.2 allows remote attackers to cause a denial of service\n(server crash) via a missing argument, which triggers a null pointer\ndereference.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0458"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mah-jong","source":"https://ubuntu.com/security/cve?package=mah-jong","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mah-jong","debian":"https://tracker.debian.org/pkg/mah-jong","statuses":[{"release_codename":"dapper","status":"released","description":"1.6.3-2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.6.3-2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.6.3-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0457","published":"2004-09-28T04:00:00","updated_at":"2025-07-17T16:33:51.092101+00:00","description":"\nThe mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp\nmethod from the mysql-server package, allows local users to overwrite\narbitrary files via a symlink attack on temporary files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0457"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mysql-dfsg","source":"https://ubuntu.com/security/cve?package=mysql-dfsg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg","debian":"https://tracker.debian.org/pkg/mysql-dfsg","statuses":[{"release_codename":"dapper","status":"released","description":"4.0.24-10ubuntu2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"4.0.24-10ubuntu2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-4.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-4.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-4.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-4.1","statuses":[{"release_codename":"dapper","status":"released","description":"4.1.15-1ubuntu5","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"4.1.15-1ubuntu5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.0","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.0","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.0","statuses":[{"release_codename":"dapper","status":"released","description":"5.0.22-0ubuntu6.06.3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.0.24a-9ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.0.38-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0408","published":"2004-09-28T04:00:00","updated_at":"2025-07-17T16:33:48.003589+00:00","description":"\nBuffer overflow in the child_service function in the ident2 ident daemon\nallows remote attackers to execute arbitrary code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0408"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"ident2","source":"https://ubuntu.com/security/cve?package=ident2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ident2","debian":"https://tracker.debian.org/pkg/ident2","statuses":[{"release_codename":"dapper","status":"released","description":"1.05-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.05-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.05-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0827","published":"2004-09-16T04:00:00","updated_at":"2025-07-17T16:34:04.450695+00:00","description":"\nMultiple buffer overflows in the ImageMagick graphics library 5.x before\n5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of\nservice (application crash) and possibly execute arbitrary code via\nmalformed (1) AVI, (2) BMP, or (3) DIB files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-35-1","https://www.cve.org/CVERecord?id=CVE-2004-0827"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"dapper","status":"released","description":"6.2.4.5-0.6ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"6.2.4.5.dfsg1-0.10ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"6.2.4.5.dfsg1-0.14ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-35-1"],"notices":[{"id":"USN-35-1","title":"imagemagick vulnerabilities","summary":"imagemagick vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-12-01T06:29:50","description":"Markus Meissner discovered several potential buffer overflows in some\nimage decoding functions of ImageMagick. Decoding a malicious BMP or\nDIB image or AVI video might result in execution of arbitrary code\nwith the user's privileges.\n\nSince imagemagick can be used in custom printing systems, this also\nmight lead to privilege escalation (execute code with the printer\nspooler's privileges). However, Ubuntu's standard printing system does\nnot use imagemagick, thus there is no risk of privilege escalation in\na standard installation.","is_hidden":false,"release_packages":{"warty":[{"name":"libmagick6","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0827"]}]},{"id":"CVE-2004-0809","published":"2004-09-16T04:00:00","updated_at":"2025-07-17T16:34:04.450695+00:00","description":"\nThe mod_dav module in Apache 2.0.50 and earlier allows remote attackers to\ncause a denial of service (child process crash) via a certain sequence of\nLOCK requests for a location that allows WebDAV authoring access.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0809"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.55-4ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.55-4ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.2.3-3.2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libapache-mod-dav","source":"https://ubuntu.com/security/cve?package=libapache-mod-dav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libapache-mod-dav","debian":"https://tracker.debian.org/pkg/libapache-mod-dav","statuses":[{"release_codename":"feisty","status":"released","description":"1.0.3-10","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"1.0.3-10","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.0.3-10","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0801","published":"2004-09-16T04:00:00","updated_at":"2025-07-17T16:34:02.653171+00:00","description":"\nUnknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local\nusers or remote attackers with access to CUPS to execute arbitrary\ncommands.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0801"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"foomatic-filters","source":"https://ubuntu.com/security/cve?package=foomatic-filters","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=foomatic-filters","debian":"https://tracker.debian.org/pkg/foomatic-filters","statuses":[{"release_codename":"dapper","status":"released","description":"3.0.2-20060318-2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.0.2-20060318-2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.0.2-20060318-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0807","published":"2004-09-13T04:00:00","updated_at":"2025-07-17T16:34:04.450695+00:00","description":"\nSamba 3.0.6 and earlier allows remote attackers to cause a denial of\nservice (infinite loop and memory exhaustion) via certain malformed\nrequests that cause new processes to be spawned and enter an infinite loop.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0807"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"samba","source":"https://ubuntu.com/security/cve?package=samba","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba","debian":"https://tracker.debian.org/pkg/samba","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-1735","published":"2004-08-21T04:00:00","updated_at":"2025-07-17T16:34:33.860335+00:00","description":"\nCross-site scripting (XSS) vulnerability in the create list option in Sympa\n4.1.x and earlier allows remote authenticated users to inject arbitrary web\nscript or HTML via the description field.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-1735"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sympa","source":"https://ubuntu.com/security/cve?package=sympa","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sympa","debian":"https://tracker.debian.org/pkg/sympa","statuses":[{"release_codename":"dapper","status":"released","description":"4.1.5-7","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"4.1.5-7","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"4.1.5-7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0769","published":"2004-08-18T04:00:00","updated_at":"2025-07-17T16:34:00.669632+00:00","description":"\nBuffer overflow in LHA allows remote attackers to execute arbitrary code\nvia long pathnames in LHarc format 2 headers for a .LHZ archive, as\noriginally demonstrated using the \"x\" option but also exploitable through\n\"l\" and \"v\", and fixed in header.c, a different issue than CVE-2004-0771.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0769"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"lha","source":"https://ubuntu.com/security/cve?package=lha","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lha","debian":"https://tracker.debian.org/pkg/lha","statuses":[{"release_codename":"dapper","status":"released","description":"1.14i-10","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.14i-10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.14i-10","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":79100,"limit":20,"total_results":79316}