{"cves":[{"id":"CVE-2004-0557","published":"2004-08-06T04:00:00","updated_at":"2025-07-17T16:33:54.800190+00:00","description":"\nMultiple buffer overflows in the st_wavstartread function in wav.c for\nSound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to\nexecute arbitrary code via certain WAV file header fields.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0557"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"sox","source":"https://ubuntu.com/security/cve?package=sox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sox","debian":"https://tracker.debian.org/pkg/sox","statuses":[{"release_codename":"dapper","status":"released","description":"12.17.9-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"12.17.9-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"12.17.9-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0554","published":"2004-08-06T04:00:00","updated_at":"2025-07-17T16:33:52.996207+00:00","description":"\nLinux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial\nof service (system crash), possibly via an infinite loop that triggers a\nsignal handler with a certain sequence of fsave and frstor instructions, as\noriginally demonstrated using a \"crash.c\" program.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0554"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kernel-image-2.4.27-i386","source":"https://ubuntu.com/security/cve?package=kernel-image-2.4.27-i386","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kernel-image-2.4.27-i386","debian":"https://tracker.debian.org/pkg/kernel-image-2.4.27-i386","statuses":[{"release_codename":"dapper","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"kernel-source-2.4.27","source":"https://ubuntu.com/security/cve?package=kernel-source-2.4.27","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kernel-source-2.4.27","debian":"https://tracker.debian.org/pkg/kernel-source-2.4.27","statuses":[{"release_codename":"dapper","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0541","published":"2004-08-06T04:00:00","updated_at":"2025-07-17T16:33:52.996207+00:00","description":"\nBuffer overflow in the ntlm_check_auth (NTLM authentication) function for\nSquid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers\nenabled, allows remote attackers to execute arbitrary code via a long\npassword (\"pass\" variable).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0541"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"squid","source":"https://ubuntu.com/security/cve?package=squid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squid","debian":"https://tracker.debian.org/pkg/squid","statuses":[{"release_codename":"dapper","status":"released","description":"2.5.12-4ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.1-3ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.5-4ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0536","published":"2004-08-06T04:00:00","updated_at":"2025-07-17T16:33:52.996207+00:00","description":"\nFormat string vulnerability in Tripwire commercial 4.0.1 and earlier,\nincluding 2.4, and open source 2.3.1 and earlier, allows local users to\ngain privileges via format string specifiers in a file name, which is used\nin the generation of an email report.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0536"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"tripwire","source":"https://ubuntu.com/security/cve?package=tripwire","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tripwire","debian":"https://tracker.debian.org/pkg/tripwire","statuses":[{"release_codename":"dapper","status":"released","description":"2.3.1.2.0-6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.3.1.2.0-6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.3.1.2.0-6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0535","published":"2004-08-06T04:00:00","updated_at":"2025-07-17T16:33:52.996207+00:00","description":"\nThe e1000 driver for Linux kernel 2.4.26 and earlier does not properly\ninitialize memory before using it, which allows local users to read\nportions of kernel memory. NOTE: this issue was originally incorrectly\nreported as a \"buffer overflow\" by some sources.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0535"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kernel-source-2.4.27","source":"https://ubuntu.com/security/cve?package=kernel-source-2.4.27","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kernel-source-2.4.27","debian":"https://tracker.debian.org/pkg/kernel-source-2.4.27","statuses":[{"release_codename":"dapper","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0495","published":"2004-08-06T04:00:00","updated_at":"2025-07-17T16:33:52.996207+00:00","description":"\nMultiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local\nusers to gain privileges or access kernel memory, as found by the Sparse\nsource code checking tool.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0495"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kernel-source-2.4.27","source":"https://ubuntu.com/security/cve?package=kernel-source-2.4.27","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kernel-source-2.4.27","debian":"https://tracker.debian.org/pkg/kernel-source-2.4.27","statuses":[{"release_codename":"dapper","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.4.27-12","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0493","published":"2004-08-06T04:00:00","updated_at":"2025-07-17T16:33:51.092101+00:00","description":"\nThe ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote\nattackers to cause a denial of service (memory exhaustion), and possibly an\ninteger signedness error leading to a heap-based buffer overflow on 64 bit\nsystems, via long header lines with large numbers of space or tab\ncharacters.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0493"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.55-4ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.55-4ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.2.3-3.2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0492","published":"2004-08-06T04:00:00","updated_at":"2025-07-17T16:33:51.092101+00:00","description":"\nHeap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25\nto 1.3.31 allows remote attackers to cause a denial of service (process\ncrash) and possibly execute arbitrary code via a negative Content-Length\nHTTP header field, which causes a large amount of data to be copied.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0492"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"apache","source":"https://ubuntu.com/security/cve?package=apache","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache","debian":"https://tracker.debian.org/pkg/apache","statuses":[{"release_codename":"dapper","status":"released","description":"1.3.34-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.3.34-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.3.34-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0418","published":"2004-08-06T04:00:00","updated_at":"2025-07-17T16:33:49.528524+00:00","description":"\nserve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does\nnot properly handle empty data lines, which may allow remote attackers to\nperform an \"out-of-bounds\" write for a single byte to execute arbitrary\ncode or modify critical program data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0418"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"cvs","source":"https://ubuntu.com/security/cve?package=cvs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cvs","debian":"https://tracker.debian.org/pkg/cvs","statuses":[{"release_codename":"dapper","status":"released","description":"1.12.9-17","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.12.9-17","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.12.9-17","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0417","published":"2004-08-06T04:00:00","updated_at":"2025-07-17T16:33:49.528524+00:00","description":"\nInteger overflow in the \"Max-dotdot\" CVS protocol command\n(serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through\n1.11.16, may allow remote attackers to cause a server crash, which could\ncause temporary data to remain undeleted and consume disk space.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0417"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"cvs","source":"https://ubuntu.com/security/cve?package=cvs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cvs","debian":"https://tracker.debian.org/pkg/cvs","statuses":[{"release_codename":"dapper","status":"released","description":"1.12.9-17","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.12.9-17","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.12.9-17","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0416","published":"2004-08-06T04:00:00","updated_at":"2025-07-17T16:33:49.528524+00:00","description":"\nDouble free vulnerability for the error_prog_name string in CVS 1.12.x\nthrough 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to\nexecute arbitrary code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0416"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"cvs","source":"https://ubuntu.com/security/cve?package=cvs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cvs","debian":"https://tracker.debian.org/pkg/cvs","statuses":[{"release_codename":"dapper","status":"released","description":"1.12.9-17","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.12.9-17","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.12.9-17","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0414","published":"2004-08-06T04:00:00","updated_at":"2025-07-17T16:33:49.528524+00:00","description":"\nCVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly\nhandle malformed \"Entry\" lines, which prevents a NULL terminator from being\nused and may lead to a denial of service (crash), modification of critical\nprogram data, or arbitrary code execution.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0414"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"cvs","source":"https://ubuntu.com/security/cve?package=cvs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cvs","debian":"https://tracker.debian.org/pkg/cvs","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"1.12.9-17","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.12.9-17","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.12.9-17","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0413","published":"2004-08-06T04:00:00","updated_at":"2025-07-17T16:33:49.528524+00:00","description":"\nlibsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://,\n(2) svn+ssh://, and (3) other svn protocol URL strings, which allows remote\nattackers to cause a denial of service (memory consumption) and possibly\nexecute arbitrary code via an integer overflow that leads to a heap-based\nbuffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0413"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"subversion","source":"https://ubuntu.com/security/cve?package=subversion","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=subversion","debian":"https://tracker.debian.org/pkg/subversion","statuses":[{"release_codename":"dapper","status":"released","description":"1.3.1-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.3.1-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.3.1-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0718","published":"2004-07-27T04:00:00","updated_at":"2025-07-17T16:33:59.019750+00:00","description":"\nThe (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape\n7.1 web browsers do not properly prevent a frame in one domain from\ninjecting content into a frame that belongs to another domain, which\nfacilitates web site spoofing and other attacks, aka the frame injection\nvulnerability.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0718"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.0.6+0dfsg-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.0.6+1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0707","published":"2004-07-27T04:00:00","updated_at":"2025-07-17T16:33:59.019750+00:00","description":"\nSQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before\n2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to\ngrant membership to any group to execute arbitrary SQL.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0707"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"released","description":"2.20-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.20-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.20-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0705","published":"2004-07-27T04:00:00","updated_at":"2025-07-17T16:33:57.609302+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in (1)\neditcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4)\neditproducts.cgi, (5) editusers.cgi, and (6) editversions.cgi in Bugzilla\n2.16.x before 2.16.6, and 2.18 before 2.18rc1, allow remote attackers to\nexecute arbitrary JavaScript as other users via a URL parameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0705"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"released","description":"2.20-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.20-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.20-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0704","published":"2004-07-27T04:00:00","updated_at":"2025-07-17T16:33:57.609302+00:00","description":"\nUnknown vulnerability in (1) duplicates.cgi and (2) buglist.cgi in Bugzilla\n2.16.x before 2.16.6, 2.18 before 2.18rc1, when configured to hide\nproducts, allows remote attackers to view hidden products.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0704"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"released","description":"2.20-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.20-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.20-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0700","published":"2004-07-27T04:00:00","updated_at":"2025-07-17T16:33:57.609302+00:00","description":"\nFormat string vulnerability in the mod_proxy hook functions function in\nssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may\nallow remote attackers to execute arbitrary messages via format string\nspecifiers in certain log messages for HTTPS that are handled by the\nssl_log function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0700"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libapache-mod-ssl","source":"https://ubuntu.com/security/cve?package=libapache-mod-ssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libapache-mod-ssl","debian":"https://tracker.debian.org/pkg/libapache-mod-ssl","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0488","published":"2004-07-07T04:00:00","updated_at":"2025-07-17T16:33:51.092101+00:00","description":"\nStack-based buffer overflow in the ssl_util_uuencode_binary function in\nssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the\nissuing CA, may allow remote attackers to execute arbitrary code via a\nclient certificate with a long subject DN.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0488"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.55-4ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.55-4ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.2.3-3.2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0472","published":"2004-07-07T04:00:00","updated_at":"2025-08-04T19:18:33.183189+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none.\nReason: This candidate is a reservation duplicate of CVE-2004-0434. Notes:\nAll CVE users should reference CVE-2004-0434 instead of this candidate.\nAll references and descriptions in this candidate have been removed to\nprevent accidental usage","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0472"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"heimdal","source":"https://ubuntu.com/security/cve?package=heimdal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=heimdal","debian":"https://tracker.debian.org/pkg/heimdal","statuses":[{"release_codename":"dapper","status":"released","description":"0.7.1-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.7.1-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.7.1-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":79140,"limit":20,"total_results":79316}