<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from osv_ubuntu</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:26:48 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2010-4001</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2010-4001</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: gromacs, Ubuntu:Pro:18.04:LTS: gromacs, Ubuntu:20.04:LTS: gromacs, Ubuntu:22.04:LTS: gromacs, Ubuntu:24.04:LTS: gromacs&lt;/p&gt;
&lt;p&gt;** DISPUTED ** GMXRC.bash in Gromacs 4.5.1 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.  NOTE: CVE disputes this issue because the GMXLDLIB value is always added to the beginning of LD_LIBRARY_PATH at a later point in the script.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: gromacs, Ubuntu:Pro:18.04:LTS: gromacs, Ubuntu:20.04:LTS: gromacs, Ubuntu:22.04:LTS: gromacs, Ubuntu:24.04:LTS: gromacs&lt;/p&gt;
&lt;p&gt;** DISPUTED ** GMXRC.bash in Gromacs 4.5.1 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.  NOTE: CVE disputes this issue because the GMXLDLIB value is always added to the beginning of LD_LIBRARY_PATH at a later point in the script.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2010-4001</guid>
      <pubDate>Sat, 06 Nov 2010 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2011-4898</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2011-4898</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: wordpress, Ubuntu:Pro:18.04:LTS: wordpress, Ubuntu:20.04:LTS: wordpress, Ubuntu:22.04:LTS: wordpress, Ubuntu:24.04:LTS: wordpress&lt;/p&gt;
&lt;p&gt;** DISPUTED ** wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, which makes it easier for remote attackers to conduct brute-force attacks via a series of requests with different uname and pwd parameters. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether providing intentionally vague error messages during installation would be reasonable from a usability perspective.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: wordpress, Ubuntu:Pro:18.04:LTS: wordpress, Ubuntu:20.04:LTS: wordpress, Ubuntu:22.04:LTS: wordpress, Ubuntu:24.04:LTS: wordpress&lt;/p&gt;
&lt;p&gt;** DISPUTED ** wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, which makes it easier for remote attackers to conduct brute-force attacks via a series of requests with different uname and pwd parameters. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether providing intentionally vague error messages during installation would be reasonable from a usability perspective.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2011-4898</guid>
      <pubDate>Mon, 30 Jan 2012 17:55:00 +0000</pubDate>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2011-4899</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2011-4899</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: wordpress, Ubuntu:Pro:18.04:LTS: wordpress, Ubuntu:20.04:LTS: wordpress, Ubuntu:22.04:LTS: wordpress, Ubuntu:24.04:LTS: wordpress&lt;/p&gt;
&lt;p&gt;** DISPUTED ** wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database service is appropriate, which allows remote attackers to configure an arbitrary database via the dbhost and dbname parameters, and subsequently conduct static code injection and cross-site scripting (XSS) attacks via (1) an HTTP request or (2) a MySQL query.  NOTE: the vendor disputes the significance of this issue; however, remote code execution makes the issue important in many realistic environments.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: wordpress, Ubuntu:Pro:18.04:LTS: wordpress, Ubuntu:20.04:LTS: wordpress, Ubuntu:22.04:LTS: wordpress, Ubuntu:24.04:LTS: wordpress&lt;/p&gt;
&lt;p&gt;** DISPUTED ** wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database service is appropriate, which allows remote attackers to configure an arbitrary database via the dbhost and dbname parameters, and subsequently conduct static code injection and cross-site scripting (XSS) attacks via (1) an HTTP request or (2) a MySQL query.  NOTE: the vendor disputes the significance of this issue; however, remote code execution makes the issue important in many realistic environments.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2011-4899</guid>
      <pubDate>Mon, 30 Jan 2012 17:55:00 +0000</pubDate>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2012-0782</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2012-0782</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: wordpress, Ubuntu:Pro:18.04:LTS: wordpress, Ubuntu:20.04:LTS: wordpress, Ubuntu:22.04:LTS: wordpress, Ubuntu:24.04:LTS: wordpress&lt;/p&gt;
&lt;p&gt;** DISPUTED ** Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dbhost, (2) dbname, or (3) uname parameter. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether this specific XSS scenario has security relevance.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: wordpress, Ubuntu:Pro:18.04:LTS: wordpress, Ubuntu:20.04:LTS: wordpress, Ubuntu:22.04:LTS: wordpress, Ubuntu:24.04:LTS: wordpress&lt;/p&gt;
&lt;p&gt;** DISPUTED ** Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dbhost, (2) dbname, or (3) uname parameter. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether this specific XSS scenario has security relevance.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2012-0782</guid>
      <pubDate>Mon, 30 Jan 2012 17:55:00 +0000</pubDate>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2012-0937</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2012-0937</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: wordpress, Ubuntu:Pro:18.04:LTS: wordpress, Ubuntu:20.04:LTS: wordpress, Ubuntu:22.04:LTS: wordpress, Ubuntu:24.04:LTS: wordpress&lt;/p&gt;
&lt;p&gt;** DISPUTED ** wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external MySQL database servers, which allows remote attackers to use WordPress as a proxy for brute-force attacks or denial of service attacks via the dbhost parameter, a different vulnerability than CVE-2011-4898. NOTE: the vendor disputes the significance of this issue because an incomplete WordPress installation might be present on the network for only a short time.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: wordpress, Ubuntu:Pro:18.04:LTS: wordpress, Ubuntu:20.04:LTS: wordpress, Ubuntu:22.04:LTS: wordpress, Ubuntu:24.04:LTS: wordpress&lt;/p&gt;
&lt;p&gt;** DISPUTED ** wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external MySQL database servers, which allows remote attackers to use WordPress as a proxy for brute-force attacks or denial of service attacks via the dbhost parameter, a different vulnerability than CVE-2011-4898. NOTE: the vendor disputes the significance of this issue because an incomplete WordPress installation might be present on the network for only a short time.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2012-0937</guid>
      <pubDate>Mon, 30 Jan 2012 17:55:00 +0000</pubDate>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2012-5855</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2012-5855</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: vlc&lt;/p&gt;
&lt;p&gt;The SHAddToRecentDocs function in VideoLAN VLC media player 2.0.4 and earlier might allow user-assisted attackers to cause a denial of service (crash) via a crafted file name that triggers an incorrect string-length calculation when the file is added to VLC.  NOTE: it is not clear whether this issue crosses privilege boundaries or whether it can be exploited without user interaction.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: vlc&lt;/p&gt;
&lt;p&gt;The SHAddToRecentDocs function in VideoLAN VLC media player 2.0.4 and earlier might allow user-assisted attackers to cause a denial of service (crash) via a crafted file name that triggers an incorrect string-length calculation when the file is added to VLC.  NOTE: it is not clear whether this issue crosses privilege boundaries or whether it can be exploited without user interaction.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2012-5855</guid>
      <pubDate>Wed, 10 Jul 2013 19:55:00 +0000</pubDate>
    </item>
    <item>
      <title>UBUNTU-CVE-2014-3621</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-3621</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: keystone&lt;/p&gt;
&lt;p&gt;The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by &amp;#34;$(admin_token)&amp;#34; in the publicurl endpoint field.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: keystone&lt;/p&gt;
&lt;p&gt;The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by &amp;#34;$(admin_token)&amp;#34; in the publicurl endpoint field.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-3621</guid>
      <pubDate>Thu, 02 Oct 2014 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>UBUNTU-CVE-2015-1329</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-1329</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: oxide-qt&lt;/p&gt;
&lt;p&gt;Use-after-free vulnerability in oxide::qt::URLRequestDelegatedJob in oxide-qt in Ubuntu 15.04 and 14.04 LTS might allow remote attackers to execute arbitrary code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: oxide-qt&lt;/p&gt;
&lt;p&gt;Use-after-free vulnerability in oxide::qt::URLRequestDelegatedJob in oxide-qt in Ubuntu 15.04 and 14.04 LTS might allow remote attackers to execute arbitrary code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2015-1329</guid>
      <pubDate>Tue, 04 Aug 2015 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2016-7919</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-7919</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: moodle, Ubuntu:Pro:18.04:LTS: moodle&lt;/p&gt;
&lt;p&gt;** DISPUTED ** Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a &amp;#34;SQL Injection&amp;#34; issue affecting the Administration panel function in the installation process component.  NOTE: the vendor disputes the relevance of this report, noting that &amp;#34;the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields.&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: moodle, Ubuntu:Pro:18.04:LTS: moodle&lt;/p&gt;
&lt;p&gt;** DISPUTED ** Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a &amp;#34;SQL Injection&amp;#34; issue affecting the Administration panel function in the installation process component.  NOTE: the vendor disputes the relevance of this report, noting that &amp;#34;the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields.&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-7919</guid>
      <pubDate>Fri, 28 Oct 2016 15:59:00 +0000</pubDate>
    </item>
    <item>
      <title>UBUNTU-CVE-2014-3498</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-3498</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ansible&lt;/p&gt;
&lt;p&gt;The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ansible&lt;/p&gt;
&lt;p&gt;The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-3498</guid>
      <pubDate>Thu, 08 Jun 2017 18:29:00 +0000</pubDate>
    </item>
  </channel>
</rss>
