{"cves":[{"id":"CVE-2024-28575","published":"2024-03-20T06:15:00","updated_at":"2025-07-11T07:57:54.647589+00:00","description":"\nBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909]\nallows a local attacker to cause a denial of service (DoS) via the\nopj_j2k_read_mct() function when reading images in J2K format.","ubuntu_description":"","notes":[{"author":"juliaphoebe","note":"Patch code not available upstream as of 2025-01-16"}],"codename":null,"priority":"medium","cvss3":6.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909","https://www.cve.org/CVERecord?id=CVE-2024-28575"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068461"],"patches":{"freeimage":[]},"tags":{},"packages":[{"name":"freeimage","source":"https://ubuntu.com/security/cve?package=freeimage","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freeimage","debian":"https://tracker.debian.org/pkg/freeimage","statuses":[{"release_codename":"xenial","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-28574","published":"2024-03-20T06:15:00","updated_at":"2025-07-11T07:57:54.647589+00:00","description":"\nBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909]\nallows a local attacker to cause a denial of service (DoS) via the\nopj_j2k_copy_default_tcp_and_create_tcd() function when reading images in\nJ2K format.","ubuntu_description":"","notes":[{"author":"juliaphoebe","note":"Patch code not available upstream as of 2025-01-16"}],"codename":null,"priority":"medium","cvss3":6.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909","https://www.cve.org/CVERecord?id=CVE-2024-28574"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068461"],"patches":{"freeimage":[]},"tags":{},"packages":[{"name":"freeimage","source":"https://ubuntu.com/security/cve?package=freeimage","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freeimage","debian":"https://tracker.debian.org/pkg/freeimage","statuses":[{"release_codename":"xenial","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-28573","published":"2024-03-20T06:15:00","updated_at":"2025-07-11T07:57:54.647589+00:00","description":"\nBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909]\nallows a local attacker to cause a denial of service (DoS) via the\njpeg_read_exif_profile() function when reading images in JPEG format.","ubuntu_description":"","notes":[{"author":"juliaphoebe","note":"Patch code not available upstream as of 2025-01-16"}],"codename":null,"priority":"medium","cvss3":6.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909","https://www.cve.org/CVERecord?id=CVE-2024-28573"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068461"],"patches":{"freeimage":[]},"tags":{},"packages":[{"name":"freeimage","source":"https://ubuntu.com/security/cve?package=freeimage","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freeimage","debian":"https://tracker.debian.org/pkg/freeimage","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-28572","published":"2024-03-20T06:15:00","updated_at":"2025-07-11T07:57:54.647589+00:00","description":"\nBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909]\nallows a local attacker to cause a denial of service (DoS) via the\nFreeImage_SetTagValue() function when reading images in JPEG format.","ubuntu_description":"","notes":[{"author":"juliaphoebe","note":"Patch code not available upstream as of 2025-01-16"}],"codename":null,"priority":"medium","cvss3":6.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909","https://www.cve.org/CVERecord?id=CVE-2024-28572"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068461"],"patches":{"freeimage":[]},"tags":{},"packages":[{"name":"freeimage","source":"https://ubuntu.com/security/cve?package=freeimage","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freeimage","debian":"https://tracker.debian.org/pkg/freeimage","statuses":[{"release_codename":"xenial","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-28571","published":"2024-03-20T06:15:00","updated_at":"2025-07-11T07:57:54.647589+00:00","description":"\nBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909]\nallows a local attacker to cause a denial of service (DoS) via the\nfill_input_buffer() function when reading images in JPEG format.","ubuntu_description":"","notes":[{"author":"juliaphoebe","note":"Patch code not available upstream as of 2025-01-16"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909","https://www.cve.org/CVERecord?id=CVE-2024-28571"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068461"],"patches":{"freeimage":[]},"tags":{},"packages":[{"name":"freeimage","source":"https://ubuntu.com/security/cve?package=freeimage","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freeimage","debian":"https://tracker.debian.org/pkg/freeimage","statuses":[{"release_codename":"xenial","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-28570","published":"2024-03-20T06:15:00","updated_at":"2025-07-11T07:57:54.647589+00:00","description":"\nBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909]\nallows a local attacker to cause a denial of service (DoS) via the\nprocessMakerNote() function when reading images in JPEG format.","ubuntu_description":"","notes":[{"author":"juliaphoebe","note":"Patch code not available upstream as of 2025-01-15"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909","https://www.cve.org/CVERecord?id=CVE-2024-28570"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068461"],"patches":{"freeimage":[]},"tags":{},"packages":[{"name":"freeimage","source":"https://ubuntu.com/security/cve?package=freeimage","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freeimage","debian":"https://tracker.debian.org/pkg/freeimage","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was deferred [2025-01-15]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"deferred","description":"2025-01-15","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2025-01-15","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2025-01-15","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2025-01-15","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"2025-01-15","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"2025-01-15","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was deferred [2025-01-15]","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"2025-01-15","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred [2025-01-15]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-28569","published":"2024-03-20T06:15:00","updated_at":"2025-07-11T07:57:54.647589+00:00","description":"\nBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909]\nallows a local attacker to execute arbitrary code via the\nImf_2_2::Xdr::read() function when reading images in EXR format.","ubuntu_description":"","notes":[{"author":"juliaphoebe","note":"Patch code not available upstream as of 2025-01-16"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909","https://www.cve.org/CVERecord?id=CVE-2024-28569"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068461"],"patches":{"freeimage":[]},"tags":{},"packages":[{"name":"freeimage","source":"https://ubuntu.com/security/cve?package=freeimage","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freeimage","debian":"https://tracker.debian.org/pkg/freeimage","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-28568","published":"2024-03-20T06:15:00","updated_at":"2025-07-11T07:57:54.647589+00:00","description":"\nBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909]\nallows a local attacker to cause a denial of service (DoS) via the\nread_iptc_profile() function when reading images in TIFF format.","ubuntu_description":"","notes":[{"author":"juliaphoebe","note":"Patch code not available upstream as of 2025-01-16"}],"codename":null,"priority":"medium","cvss3":6.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909","https://www.cve.org/CVERecord?id=CVE-2024-28568"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068461"],"patches":{"freeimage":[]},"tags":{},"packages":[{"name":"freeimage","source":"https://ubuntu.com/security/cve?package=freeimage","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freeimage","debian":"https://tracker.debian.org/pkg/freeimage","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-28567","published":"2024-03-20T06:15:00","updated_at":"2025-07-11T07:57:52.768418+00:00","description":"\nBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909]\nallows a local attacker to cause a denial of service (DoS) via the\nFreeImage_CreateICCProfile() function when reading images in TIFF format.","ubuntu_description":"","notes":[{"author":"juliaphoebe","note":"Patch code not available upstream as of 2025-01-16"}],"codename":null,"priority":"medium","cvss3":6.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909","https://www.cve.org/CVERecord?id=CVE-2024-28567"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068461"],"patches":{"freeimage":[]},"tags":{},"packages":[{"name":"freeimage","source":"https://ubuntu.com/security/cve?package=freeimage","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freeimage","debian":"https://tracker.debian.org/pkg/freeimage","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-28566","published":"2024-03-20T06:15:00","updated_at":"2025-07-11T07:57:52.768418+00:00","description":"\nBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909]\nallows a local attacker to execute arbitrary code via the AssignPixel()\nfunction when reading images in TIFF format.","ubuntu_description":"","notes":[{"author":"juliaphoebe","note":"Patch code not available upstream as of 2025-01-15"}],"codename":null,"priority":"medium","cvss3":8.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.4,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909","https://www.cve.org/CVERecord?id=CVE-2024-28566"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068461"],"patches":{"freeimage":[]},"tags":{},"packages":[{"name":"freeimage","source":"https://ubuntu.com/security/cve?package=freeimage","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freeimage","debian":"https://tracker.debian.org/pkg/freeimage","statuses":[{"release_codename":"xenial","status":"deferred","description":"2025-01-15","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was deferred [2025-01-15]","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2025-01-15","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2025-01-15","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2025-01-15","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"2025-01-15","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"2025-01-15","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was deferred [2025-01-15]","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred [2025-01-15]","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"2025-01-15","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-28565","published":"2024-03-20T06:15:00","updated_at":"2025-07-11T07:57:52.768418+00:00","description":"\nBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909]\nallows a local attacker to cause a denial of service (DoS) via the\npsdParser::ReadImageData() function when reading images in PSD format.","ubuntu_description":"","notes":[{"author":"juliaphoebe","note":"Patch code not available upstream as of 2025-01-16"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909","https://www.cve.org/CVERecord?id=CVE-2024-28565"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068461"],"patches":{"freeimage":[]},"tags":{},"packages":[{"name":"freeimage","source":"https://ubuntu.com/security/cve?package=freeimage","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freeimage","debian":"https://tracker.debian.org/pkg/freeimage","statuses":[{"release_codename":"xenial","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-28564","published":"2024-03-20T06:15:00","updated_at":"2025-07-11T07:57:52.768418+00:00","description":"\nBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909]\nallows a local attacker to cause a denial of service (DoS) via the\nImf_2_2::CharPtrIO::readChars() function when reading images in EXR format.","ubuntu_description":"","notes":[{"author":"juliaphoebe","note":"Patch code not available upstream as of 2025-01-16"}],"codename":null,"priority":"medium","cvss3":6.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909","https://www.cve.org/CVERecord?id=CVE-2024-28564"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068461"],"patches":{"freeimage":[]},"tags":{},"packages":[{"name":"freeimage","source":"https://ubuntu.com/security/cve?package=freeimage","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freeimage","debian":"https://tracker.debian.org/pkg/freeimage","statuses":[{"release_codename":"xenial","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-28563","published":"2024-03-20T06:15:00","updated_at":"2025-07-11T07:57:52.768418+00:00","description":"\nBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909]\nallows a local attacker to cause a denial of service (DoS) via the\nImf_2_2::DwaCompressor::Classifier::Classifier() function when reading\nimages in EXR format.","ubuntu_description":"","notes":[{"author":"juliaphoebe","note":"Patch code not available upstream as of 2025-01-16"}],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909","https://www.cve.org/CVERecord?id=CVE-2024-28563"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068461"],"patches":{"freeimage":[]},"tags":{},"packages":[{"name":"freeimage","source":"https://ubuntu.com/security/cve?package=freeimage","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freeimage","debian":"https://tracker.debian.org/pkg/freeimage","statuses":[{"release_codename":"xenial","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-28562","published":"2024-03-20T06:15:00","updated_at":"2025-07-11T07:57:52.768418+00:00","description":"\nBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909]\nallows a local attacker to execute arbitrary code via the\nImf_2_2::copyIntoFrameBuffer() component when reading images in EXR format.","ubuntu_description":"","notes":[{"author":"juliaphoebe","note":"Patch code not available upstream as of 2025-01-16"}],"codename":null,"priority":"medium","cvss3":6.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909","https://www.cve.org/CVERecord?id=CVE-2024-28562"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068461"],"patches":{"freeimage":[]},"tags":{},"packages":[{"name":"freeimage","source":"https://ubuntu.com/security/cve?package=freeimage","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freeimage","debian":"https://tracker.debian.org/pkg/freeimage","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred [2025-01-16]","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"2025-01-16","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-22258","published":"2024-03-20T04:15:00","updated_at":"2025-08-04T18:57:43.357033+00:00","description":"\nSpring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 -\n1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade\nAttack for Confidential Clients.\nSpecifically, an application is vulnerable when a Confidential Client uses\nPKCE for the Authorization Code Grant.\nAn application is not vulnerable when a Public Client uses PKCE for the\nAuthorization Code Grant.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://spring.io/security/cve-2024-22258","https://www.cve.org/CVERecord?id=CVE-2024-22258"],"bugs":[""],"patches":{"spring":[]},"tags":{},"packages":[{"name":"spring","source":"https://ubuntu.com/security/cve?package=spring","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=spring","debian":"https://tracker.debian.org/pkg/spring","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-2631","published":"2024-03-20T00:00:00","updated_at":"2025-08-26T00:22:43.314858+00:00","description":"\nInappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58\nallowed a remote attacker to perform UI spoofing via a crafted HTML page.\n(Chromium security severity: Low)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2024-2631"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-2630","published":"2024-03-20T00:00:00","updated_at":"2025-08-26T00:22:43.314858+00:00","description":"\nInappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58\nallowed a remote attacker to leak cross-origin data via a crafted HTML\npage. (Chromium security severity: Medium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2024-2630"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-2629","published":"2024-03-20T00:00:00","updated_at":"2025-08-26T00:22:43.314858+00:00","description":"\nIncorrect security UI in iOS in Google Chrome prior to 123.0.6312.58\nallowed a remote attacker to perform UI spoofing via a crafted HTML page.\n(Chromium security severity: Medium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2024-2629"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-2628","published":"2024-03-20T00:00:00","updated_at":"2025-08-26T00:22:43.314858+00:00","description":"\nInappropriate implementation in Downloads in Google Chrome prior to\n123.0.6312.58 allowed a remote attacker to perform UI spoofing via a\ncrafted URL. (Chromium security severity: Medium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2024-2628"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-2627","published":"2024-03-20T00:00:00","updated_at":"2025-08-26T00:22:43.314858+00:00","description":"\nUse after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a\nremote attacker to potentially exploit heap corruption via a crafted HTML\npage. (Chromium security severity: Medium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2024-2627"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":31300,"limit":20,"total_results":79316}