{"cves":[{"id":"CVE-2023-2203","published":"2023-05-17T22:15:00","updated_at":"2025-08-26T00:08:18.197591+00:00","description":"\nA flaw was found in the WebKitGTK package. An improper input validation\nissue may lead to a use-after-free vulnerability. This flaw allows\nattackers with network access to pass specially crafted web content files,\ncausing a denial of service or arbitrary code execution. This CVE exists\nbecause of a CVE-2023-28205 security regression for the WebKitGTK package\nin Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"},{"author":"mdeslaur","note":"This CVE is specific to Red Hat's webkitgtk package, Ubuntu is\nnot vulnerable to this issue."}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2023-2203"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=2188543"],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"wpewebkit":[]},"tags":{},"packages":[{"name":"wpewebkit","source":"https://ubuntu.com/security/cve?package=wpewebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wpewebkit","debian":"https://tracker.debian.org/pkg/wpewebkit","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: RHEL-specific backport regression","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was deferred","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was deferred","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-26044","published":"2023-05-17T18:15:00","updated_at":"2026-02-09T05:51:21.041577+00:00","description":"\nreact/http is an event-driven, streaming HTTP client and server\nimplementation for ReactPHP. Previous versions of ReactPHP's HTTP server\ncomponent contain a potential DoS vulnerability that can cause high CPU\nload when processing large HTTP request bodies. This vulnerability has\nlittle to no impact on the default configuration, but can be exploited when\nexplicitly using the RequestBodyBufferMiddleware with very large settings.\nThis might lead to consuming large amounts of CPU time for processing\nrequests and significantly delay or slow down the processing of legitimate\nuser requests. This issue has been addressed in release 1.9.0. Users are\nadvised to upgrade. Users unable to upgrade may keep the request body\nlimited using RequestBodyBufferMiddleware with a sensible value which\nshould mitigate the issue. An infrastructure or DevOps workaround could be\nto place a reverse proxy in front of the ReactPHP HTTP server to filter out\nany excessive HTTP request bodies.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/reactphp/http/security/advisories/GHSA-95x4-j7vc-h8mf","https://github.com/reactphp/http/commit/b3594f7936b92f9fc2d5f9e84dc01bdb95a72167 (v1.9.0)","https://github.com/reactphp/http/commit/9681f764b80c45ebfb5fe2ea7da5bd3babfcdcfd","https://www.cve.org/CVERecord?id=CVE-2023-26044"],"bugs":[""],"patches":{"php-react-http":["upstream: https://github.com/reactphp/http/commit/b3594f7936b92f9fc2d5f9e84dc01bdb95a72167","upstream: https://github.com/reactphp/http/commit/9681f764b80c45ebfb5fe2ea7da5bd3babfcdcfd"]},"tags":{},"packages":[{"name":"php-react-http","source":"https://ubuntu.com/security/cve?package=php-react-http","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-react-http","debian":"https://tracker.debian.org/pkg/php-react-http","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.0","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-22348","published":"2023-05-17T16:15:00","updated_at":"2025-08-26T18:00:49.174200+00:00","description":"\nImproper Authorization in RestAPI in Checkmk GmbH's Checkmk versions\n<2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary\nhost_configs.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2023-22348"],"bugs":[""],"patches":{"check-mk":[]},"tags":{},"packages":[{"name":"check-mk","source":"https://ubuntu.com/security/cve?package=check-mk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=check-mk","debian":"https://tracker.debian.org/pkg/check-mk","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-31725","published":"2023-05-17T15:15:00","updated_at":"2025-07-11T07:54:42.365078+00:00","description":"\nyasm 1.3.0.55.g101bc was discovered to contain a heap-use-after-free via\nthe function expand_mmac_params at yasm/modules/preprocs/nasm/nasm-pp.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/yasm/yasm/issues/221","https://github.com/DaisyPo/fuzzing-vulncollect/tree/main/yasm/heap-use-after-free/nasm-pp.c:3878%20in%20expand_mmac_params","https://www.cve.org/CVERecord?id=CVE-2023-31725"],"bugs":[""],"patches":{"yasm":[]},"tags":{},"packages":[{"name":"yasm","source":"https://ubuntu.com/security/cve?package=yasm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=yasm","debian":"https://tracker.debian.org/pkg/yasm","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-31724","published":"2023-05-17T15:15:00","updated_at":"2025-07-11T07:54:42.365078+00:00","description":"\nyasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via\nthe function do_directive at /nasm/nasm-pp.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/yasm/yasm/issues/222","https://github.com/DaisyPo/fuzzing-vulncollect/tree/main/yasm/SEGV/nasm-pp.c:3570%20in%20do_directive","https://www.cve.org/CVERecord?id=CVE-2023-31724"],"bugs":[""],"patches":{"yasm":[]},"tags":{},"packages":[{"name":"yasm","source":"https://ubuntu.com/security/cve?package=yasm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=yasm","debian":"https://tracker.debian.org/pkg/yasm","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-31723","published":"2023-05-17T15:15:00","updated_at":"2025-07-11T07:54:42.365078+00:00","description":"\nyasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via\nthe function expand_mmac_params at /nasm/nasm-pp.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/DaisyPo/fuzzing-vulncollect/blob/main/yasm/SEGV/nasm-pp.c:4008%20in%20expand_mmac_params/README.md","https://github.com/yasm/yasm/issues/220","https://www.cve.org/CVERecord?id=CVE-2023-31723"],"bugs":[""],"patches":{"yasm":[]},"tags":{},"packages":[{"name":"yasm","source":"https://ubuntu.com/security/cve?package=yasm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=yasm","debian":"https://tracker.debian.org/pkg/yasm","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-31722","published":"2023-05-17T14:15:00","updated_at":"2026-05-13T13:34:37.299426+00:00","description":"\nThere exists a heap buffer overflow in nasm 2.16.02rc1 (GitHub commit:\nb952891).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://bugzilla.nasm.us/show_bug.cgi?id=3392857#c1","https://www.cve.org/CVERecord?id=CVE-2023-31722","https://ubuntu.com/security/notices/USN-8248-1"],"bugs":[""],"patches":{"nasm":["upstream: https://repo.or.cz/nasm/nasm2.git/commit/e39b856bdeec852e9b078dd9b7cad74caee618b4"]},"tags":{},"packages":[{"name":"nasm","source":"https://ubuntu.com/security/cve?package=nasm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nasm","debian":"https://tracker.debian.org/pkg/nasm","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.01-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred [2025-09-11]","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.16.01-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"2.15.05-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"}]}],"notices_ids":["USN-8248-1"],"notices":[{"id":"USN-8248-1","title":"NASM vulnerabilities","summary":"Several security issues were fixed in NASM.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-05-07T13:00:13.762448","description":"Daisy Chen discovered that NASM was vulnerable to a heap buffer overflow\nwhen handling certain input. An attacker could possibly use this issue\nto cause NASM to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2023-31722)\n\nIt was discovered that NASM incorrectly handled memory allocation.\nAn attacker could possibly use this issue to cause NASM to use\nexcessive resources, leading to a denial of service. This issue\nonly affected Ubuntu 24.04 LTS. (CVE-2021-33452, CVE-2021-33450)","is_hidden":false,"release_packages":{"jammy":[{"name":"nasm","version":"2.15.05-1ubuntu0.1~esm1","description":"Netwide Assembler","is_source":true},{"name":"nasm","version":"2.15.05-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nasm","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"nasm","version":"2.16.01-1ubuntu0.1~esm1","description":"Netwide Assembler","is_source":true},{"name":"nasm","version":"2.16.01-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nasm","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2021-33450","CVE-2021-33452","CVE-2023-31722"]}]},{"id":"CVE-2023-31208","published":"2023-05-17T09:15:00","updated_at":"2025-08-26T17:30:42.131611+00:00","description":"\nImproper neutralization of livestatus command delimiters in the RestAPI in\nCheckmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary\nlivestatus command execution for authorized users.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2023-31208"],"bugs":[""],"patches":{"check-mk":[]},"tags":{},"packages":[{"name":"check-mk","source":"https://ubuntu.com/security/cve?package=check-mk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=check-mk","debian":"https://tracker.debian.org/pkg/check-mk","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-2745","published":"2023-05-17T09:15:00","updated_at":"2025-08-26T17:55:01.509607+00:00","description":"\nWordPress Core is vulnerable to Directory Traversal in versions up to, and\nincluding, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated\nattackers to access and load arbitrary translation files. In cases where an\nattacker is able to upload a crafted translation file onto the site, such\nas via an upload form, this could be also used to perform a Cross-Site\nScripting attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://core.trac.wordpress.org/changeset?old=55765&new=55765","https://wordpress.org/news/2023/05/wordpress-6-2-1-maintenance-security-release/","https://www.cve.org/CVERecord?id=CVE-2023-2745"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1036296"],"patches":{"wordpress":[]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.2.1+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.4.3+dfsg1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.4.3+dfsg1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"6.4.3+dfsg1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"6.4.3+dfsg1-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-28322","published":"2023-05-17T06:00:00","updated_at":"2025-08-18T17:21:41.482928+00:00","description":"\nAn information disclosure vulnerability exists in curl > 8;` which calls the\n`system` command with the operand `cmdline`. `cmdline` contains multiple\nuser controlled, unsanitized values. As a result an attacker with network\naccess to the hosted print server can exploit this vulnerability to inject\nsystem commands which are executed in the context of the running server.\nThis issue has been addressed in commit `8f2740357` and is expected to be\nbundled in the next release. Users are advised to upgrade when possible and\nto restrict access to network printers in the meantime.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-6083-1","https://ubuntu.com/security/notices/USN-6083-2","https://www.cve.org/CVERecord?id=CVE-2023-24805"],"bugs":["https://github.com/OpenPrinting/cups-filters/security/advisories/GHSA-gpxc-v2m8-fr3x"],"patches":{"cups-filters":["upstream: https://github.com/OpenPrinting/cups-filters/commit/8f274035756c04efeb77eb654e9d4c4447287d65"]},"tags":{},"packages":[{"name":"cups-filters","source":"https://ubuntu.com/security/cve?package=cups-filters","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cups-filters","debian":"https://tracker.debian.org/pkg/cups-filters","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.8.3-2ubuntu3.5+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"bionic","status":"released","description":"1.20.2-0ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.27.4-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.28.15-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"1.28.16-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"2.0~rc1-0ubuntu1.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-6083-1","USN-6083-2"],"notices":[{"id":"USN-6083-1","title":"cups-filters vulnerability","summary":"cups-filters could be made to crash or run programs if it received\nspecially crafted network traffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-05-17T14:31:21.350172","description":"It was discovered that cups-filters incorrectly handled the beh CUPS\nbackend. A remote attacker could possibly use this issue to cause the\nbackend to stop responding or to execute arbitrary code.\n","is_hidden":false,"release_packages":{"kinetic":[{"name":"cups-filters","version":"1.28.16-1ubuntu0.2","description":"OpenPrinting CUPS Filters","is_source":true},{"name":"libfontembed-dev","version":"1.28.16-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.28.16-1ubuntu0.2","pocket":"security"},{"name":"libfontembed1","version":"1.28.16-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.28.16-1ubuntu0.2","pocket":"security"},{"name":"libcupsfilters-dev","version":"1.28.16-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.28.16-1ubuntu0.2","pocket":"security"},{"name":"cups-filters","version":"1.28.16-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.28.16-1ubuntu0.2","pocket":"security"},{"name":"cups-browsed","version":"1.28.16-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.28.16-1ubuntu0.2","pocket":"security"},{"name":"cups-filters-core-drivers","version":"1.28.16-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.28.16-1ubuntu0.2","pocket":"security"},{"name":"libcupsfilters1","version":"1.28.16-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.28.16-1ubuntu0.2","pocket":"security"}],"jammy":[{"name":"cups-filters","version":"1.28.15-0ubuntu1.2","description":"OpenPrinting CUPS Filters","is_source":true},{"name":"libfontembed-dev","version":"1.28.15-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.28.15-0ubuntu1.2","pocket":"security"},{"name":"libfontembed1","version":"1.28.15-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.28.15-0ubuntu1.2","pocket":"security"},{"name":"libcupsfilters-dev","version":"1.28.15-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.28.15-0ubuntu1.2","pocket":"security"},{"name":"cups-filters","version":"1.28.15-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.28.15-0ubuntu1.2","pocket":"security"},{"name":"cups-browsed","version":"1.28.15-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.28.15-0ubuntu1.2","pocket":"security"},{"name":"cups-filters-core-drivers","version":"1.28.15-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.28.15-0ubuntu1.2","pocket":"security"},{"name":"libcupsfilters1","version":"1.28.15-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.28.15-0ubuntu1.2","pocket":"security"}],"focal":[{"name":"cups-filters","version":"1.27.4-1ubuntu0.2","description":"OpenPrinting CUPS Filters","is_source":true},{"name":"libfontembed-dev","version":"1.27.4-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.27.4-1ubuntu0.2","pocket":"security"},{"name":"libfontembed1","version":"1.27.4-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.27.4-1ubuntu0.2","pocket":"security"},{"name":"libcupsfilters-dev","version":"1.27.4-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.27.4-1ubuntu0.2","pocket":"security"},{"name":"cups-filters","version":"1.27.4-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.27.4-1ubuntu0.2","pocket":"security"},{"name":"cups-browsed","version":"1.27.4-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.27.4-1ubuntu0.2","pocket":"security"},{"name":"cups-filters-core-drivers","version":"1.27.4-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.27.4-1ubuntu0.2","pocket":"security"},{"name":"libcupsfilters1","version":"1.27.4-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.27.4-1ubuntu0.2","pocket":"security"}],"bionic":[{"name":"cups-filters","version":"1.20.2-0ubuntu3.3","description":"OpenPrinting CUPS Filters","is_source":true},{"name":"libfontembed-dev","version":"1.20.2-0ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.20.2-0ubuntu3.3","pocket":"security"},{"name":"libfontembed1","version":"1.20.2-0ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.20.2-0ubuntu3.3","pocket":"security"},{"name":"libcupsfilters-dev","version":"1.20.2-0ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.20.2-0ubuntu3.3","pocket":"security"},{"name":"cups-filters","version":"1.20.2-0ubuntu3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.20.2-0ubuntu3.3","pocket":"security"},{"name":"cups-browsed","version":"1.20.2-0ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.20.2-0ubuntu3.3","pocket":"security"},{"name":"cups-filters-core-drivers","version":"1.20.2-0ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.20.2-0ubuntu3.3","pocket":"security"},{"name":"libcupsfilters1","version":"1.20.2-0ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.20.2-0ubuntu3.3","pocket":"security"}],"lunar":[{"name":"cups-filters","version":"2.0~rc1-0ubuntu1.2","description":"OpenPrinting CUPS Filters","is_source":true},{"name":"cups-filters-core-drivers","version":"2.0~rc1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/2.0~rc1-0ubuntu1.2","pocket":"security"},{"name":"cups-filters","version":"2.0~rc1-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/2.0~rc1-0ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2023-24805"]},{"id":"USN-6083-2","title":"cups-filters vulnerability","summary":"cups-filters could be made to crash or run programs if it received\nspecially crafted network traffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-06-19T13:33:27.784581","description":"USN-6083-1 fixed a vulnerability in cups-filters. This update provides\nthe corresponding update for Ubuntu 16.04 LTS.\n\nOriginal advisory details:\n\n It was discovered that cups-filters incorrectly handled the beh CUPS\n backend. A remote attacker could possibly use this issue to cause the\n backend to stop responding or to execute arbitrary code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"cups-filters","version":"1.8.3-2ubuntu3.5+esm1","description":"OpenPrinting CUPS Filters","is_source":true},{"name":"libfontembed-dev","version":"1.8.3-2ubuntu3.5+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":null,"pocket":"esm-infra"},{"name":"libfontembed1","version":"1.8.3-2ubuntu3.5+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":null,"pocket":"esm-infra"},{"name":"libcupsfilters-dev","version":"1.8.3-2ubuntu3.5+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":null,"pocket":"esm-infra"},{"name":"cups-filters","version":"1.8.3-2ubuntu3.5+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":null,"pocket":"esm-infra"},{"name":"cups-browsed","version":"1.8.3-2ubuntu3.5+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":null,"pocket":"esm-infra"},{"name":"cups-filters-core-drivers","version":"1.8.3-2ubuntu3.5+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":null,"pocket":"esm-infra"},{"name":"libcupsfilters1","version":"1.8.3-2ubuntu3.5+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2023-24805"]}]},{"id":"CVE-2023-2295","published":"2023-05-17T00:00:00","updated_at":"2025-07-11T07:54:00.516169+00:00","description":"\nA vulnerability was found in the libreswan library. This security issue\noccurs when an IKEv1 Aggressive Mode packet is received with only\nunacceptable crypto algorithms, and the response packet is not sent with a\nzero responder SPI. When a subsequent packet is received where the sender\nreuses the libreswan responder SPI as its own initiator SPI, the pluto\ndaemon state machine crashes. No remote code execution is possible. This\nCVE exists because of a CVE-2023-30570 security regression for libreswan\npackage in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://rhn.redhat.com/errata/RHSA-2023-3107.html","https://www.cve.org/CVERecord?id=CVE-2023-2295"],"bugs":[""],"patches":{"libreswan":[]},"tags":{},"packages":[{"name":"libreswan","source":"https://ubuntu.com/security/cve?package=libreswan","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libreswan","debian":"https://tracker.debian.org/pkg/libreswan","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-27131","published":"2023-05-16T20:15:00","updated_at":"2025-08-04T19:35:28.917495+00:00","description":"\nMoodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS)\ndue to the improper input sanitization on the \"Additional HTML Section\" via\n\"Header and Footer\" parameter in /admin/settings.php. This vulnerability is\nleading an attacker to steal admin and all user account cookies by storing\nthe malicious XSS payload in Header and Footer. NOTE: this is disputed by\nthe vendor because the \"Additional HTML Section\" for \"Header and Footer\"\ncan only be supplied by an administrator, who is intentionally allowed to\nenter unsanitized input (e.g., site-specific JavaScript).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/p4nk4jv/CVEs-Assigned/blob/master/Moodle-3.10.1-CVE-2021-27131.md","https://github.com/moodle/moodle","https://www.cve.org/CVERecord?id=CVE-2021-27131"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"disputed","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"disputed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-2726","published":"2023-05-16T19:15:00","updated_at":"2025-08-26T00:10:20.629440+00:00","description":"\nInappropriate implementation in WebApp Installs in Google Chrome prior to\n113.0.5672.126 allowed an attacker who convinced a user to install a\nmalicious web app to bypass install dialog via a crafted HTML page.\n(Chromium security severity: Medium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://crbug.com/1442018","https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop_16.html","https://www.cve.org/CVERecord?id=CVE-2023-2726"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-2725","published":"2023-05-16T19:15:00","updated_at":"2025-08-26T00:10:20.629440+00:00","description":"\nUse after free in Guest View in Google Chrome prior to 113.0.5672.126\nallowed an attacker who convinced a user to install a malicious extension\nto potentially exploit heap corruption via a crafted HTML page. (Chromium\nsecurity severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop_16.html","https://crbug.com/1442516","https://www.cve.org/CVERecord?id=CVE-2023-2725"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":34660,"limit":20,"total_results":79316}