{"cves":[{"id":"CVE-2021-40540","published":"2021-09-07T02:15:00","updated_at":"2025-08-26T12:35:04.126447+00:00","description":"\nulfius_uri_logger in Ulfius HTTP Framework before 2.7.4 omits con_info\ninitialization and a con_info->request NULL check for certain malformed\nHTTP requests.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/babelouest/ulfius/commit/c83f564c184a27145e07c274b305cabe943bbfaa","https://github.com/babelouest/ulfius/compare/v2.7.3...v2.7.4","https://www.cve.org/CVERecord?id=CVE-2021-40540"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=993851"],"patches":{"ulfius":[]},"tags":{},"packages":[{"name":"ulfius","source":"https://ubuntu.com/security/cve?package=ulfius","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ulfius","debian":"https://tracker.debian.org/pkg/ulfius","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.1-2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.7.10-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.7.10-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.7.10-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.7.10-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.7.10-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.7.10-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.7.10-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-40530","published":"2021-09-06T19:15:00","updated_at":"2025-07-11T07:48:12.318391+00:00","description":"\nThe ElGamal implementation in Crypto++ through 8.5 allows plaintext\nrecovery because, during interaction between two cryptographic libraries, a\ncertain dangerous combination of the prime defined by the receiver's public\nkey, the generator defined by the receiver's public key, and the sender's\nephemeral exponents can lead to a cross-configuration attack against\nOpenPGP.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://eprint.iacr.org/2021/923","https://github.com/weidai11/cryptopp/issues/1059","https://ibm.github.io/system-security-research-updates/2021/07/20/insecurity-elgamal-pt1","https://ibm.github.io/system-security-research-updates/2021/09/06/insecurity-elgamal-pt2","https://www.cve.org/CVERecord?id=CVE-2021-40530"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=993841"],"patches":{"libcrypto++":[]},"tags":{},"packages":[{"name":"libcrypto++","source":"https://ubuntu.com/security/cve?package=libcrypto++","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libcrypto++","debian":"https://tracker.debian.org/pkg/libcrypto++","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-40529","published":"2021-09-06T19:15:00","updated_at":"2025-08-26T12:35:04.126447+00:00","description":"\nThe ElGamal implementation in Botan through 2.18.1, as used in Thunderbird\nand other products, allows plaintext recovery because, during interaction\nbetween two cryptographic libraries, a certain dangerous combination of the\nprime defined by the receiver's public key, the generator defined by the\nreceiver's public key, and the sender's ephemeral exponents can lead to a\ncross-configuration attack against OpenPGP.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://eprint.iacr.org/2021/923","https://github.com/randombit/botan/pull/2790","https://ibm.github.io/system-security-research-updates/2021/07/20/insecurity-elgamal-pt1","https://ibm.github.io/system-security-research-updates/2021/09/06/insecurity-elgamal-pt2","https://www.cve.org/CVERecord?id=CVE-2021-40529"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=993840"],"patches":{"botan":[],"botan1.10":[]},"tags":{},"packages":[{"name":"botan","source":"https://ubuntu.com/security/cve?package=botan","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=botan","debian":"https://tracker.debian.org/pkg/botan","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.18.1+dfsg-3","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.19.2+dfsg-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.19.2+dfsg-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.19.2+dfsg-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.19.2+dfsg-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.19.2+dfsg-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.19.2+dfsg-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"botan1.10","source":"https://ubuntu.com/security/cve?package=botan1.10","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=botan1.10","debian":"https://tracker.debian.org/pkg/botan1.10","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-40528","published":"2021-09-06T19:15:00","updated_at":"2025-08-18T17:16:54.367489+00:00","description":"\nThe ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext\nrecovery because, during interaction between two cryptographic libraries, a\ncertain dangerous combination of the prime defined by the receiver's public\nkey, the generator defined by the receiver's public key, and the sender's\nephemeral exponents can lead to a cross-configuration attack against\nOpenPGP.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"The commits below reference CVE-2021-33560, but they appear to\nactually be for this CVE, which was issued later. The original\nCVE was switched later on to the exponent blinding issue\ninstead."}],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://eprint.iacr.org/2021/923","https://ibm.github.io/system-security-research-updates/2021/07/20/insecurity-elgamal-pt1","https://ibm.github.io/system-security-research-updates/2021/09/06/insecurity-elgamal-pt2","https://ubuntu.com/security/notices/USN-5080-1","https://ubuntu.com/security/notices/USN-5080-2","https://www.cve.org/CVERecord?id=CVE-2021-40528"],"bugs":["https://dev.gnupg.org/T5328"],"patches":{"libgcrypt20":["upstream: https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=3462280f2e23e16adf3ed5176e0f2413d8861320","upstream: https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=707c3c5c511ee70ad0e39ec613471f665305fbea"]},"tags":{},"packages":[{"name":"libgcrypt20","source":"https://ubuntu.com/security/cve?package=libgcrypt20","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libgcrypt20","debian":"https://tracker.debian.org/pkg/libgcrypt20","statuses":[{"release_codename":"impish","status":"released","description":"1.8.7-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.8.7-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.4-2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.8.1-4ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.8.5-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"1.8.7-2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.6.5-2ubuntu0.6+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"kinetic","status":"released","description":"1.8.7-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"1.8.7-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"1.8.7-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.8.7-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"1.8.7-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.8.7-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"1.8.7-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.8.7-5ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":["USN-5080-1","USN-5080-2"],"notices":[{"id":"USN-5080-1","title":"Libgcrypt vulnerabilities","summary":"Libgcrypt could be made to expose sensitive information.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-09-16T11:12:40.177384","description":"It was discovered that Libgcrypt incorrectly handled ElGamal encryption. An\nattacker could possibly use this issue to recover sensitive information.\n","is_hidden":false,"release_packages":{"hirsute":[{"name":"libgcrypt20","version":"1.8.7-2ubuntu2.1","description":"LGPL Crypto library","is_source":true},{"name":"libgcrypt20","version":"1.8.7-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.8.7-2ubuntu2.1","pocket":"security"},{"name":"libgcrypt-mingw-w64-dev","version":"1.8.7-2ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.8.7-2ubuntu2.1","pocket":"security"},{"name":"libgcrypt20-doc","version":"1.8.7-2ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.8.7-2ubuntu2.1","pocket":"security"},{"name":"libgcrypt20-dev","version":"1.8.7-2ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.8.7-2ubuntu2.1","pocket":"security"}],"focal":[{"name":"libgcrypt20","version":"1.8.5-5ubuntu1.1","description":"LGPL Crypto library","is_source":true},{"name":"libgcrypt20","version":"1.8.5-5ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.8.5-5ubuntu1.1","pocket":"security"},{"name":"libgcrypt-mingw-w64-dev","version":"1.8.5-5ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.8.5-5ubuntu1.1","pocket":"security"},{"name":"libgcrypt20-doc","version":"1.8.5-5ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.8.5-5ubuntu1.1","pocket":"security"},{"name":"libgcrypt20-dev","version":"1.8.5-5ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.8.5-5ubuntu1.1","pocket":"security"}],"bionic":[{"name":"libgcrypt20","version":"1.8.1-4ubuntu1.3","description":"LGPL Crypto library","is_source":true},{"name":"libgcrypt20","version":"1.8.1-4ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.8.1-4ubuntu1.3","pocket":"security"},{"name":"libgcrypt-mingw-w64-dev","version":"1.8.1-4ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.8.1-4ubuntu1.3","pocket":"security"},{"name":"libgcrypt11-dev","version":"1.5.4-3+really1.8.1-4ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.8.1-4ubuntu1.3","pocket":"security"},{"name":"libgcrypt20-doc","version":"1.8.1-4ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.8.1-4ubuntu1.3","pocket":"security"},{"name":"libgcrypt20-dev","version":"1.8.1-4ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.8.1-4ubuntu1.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-33560","CVE-2021-40528"]},{"id":"USN-5080-2","title":"Libgcrypt vulnerabilities","summary":"Libgcrypt could be made to expose sensitive information.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-09-16T16:07:21.304965","description":"USN-5080-1 fixed several vulnerabilities in Libgcrypt. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that Libgcrypt incorrectly handled ElGamal encryption. An\n attacker could possibly use this issue to recover sensitive information.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"libgcrypt20","version":"1.6.5-2ubuntu0.6+esm1","description":"LGPL Crypto library","is_source":true},{"name":"libgcrypt11-dev","version":"1.5.4-3+really1.6.5-2ubuntu0.6+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":null,"pocket":"esm-infra"},{"name":"libgcrypt20","version":"1.6.5-2ubuntu0.6+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":null,"pocket":"esm-infra"},{"name":"libgcrypt20-dev","version":"1.6.5-2ubuntu0.6+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":null,"pocket":"esm-infra"},{"name":"libgcrypt20-doc","version":"1.6.5-2ubuntu0.6+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2021-33560","CVE-2021-40528"]}]},{"id":"CVE-2021-36096","published":"2021-09-06T15:15:00","updated_at":"2025-08-26T12:33:09.976663+00:00","description":"\nGenerated Support Bundles contains private S/MIME and PGP keys if\ncontaining folder is not hidden. This issue affects: OTRS AG ((OTRS))\nCommunity Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS\n7.0.x version 7.0.28 and prior versions; 8.0.x version 8.0.15 and prior\nversions.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://otrs.com/release-notes/otrs-security-advisory-2021-10/","https://www.cve.org/CVERecord?id=CVE-2021-36096"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=993846"],"patches":{"otrs2":[]},"tags":{},"packages":[{"name":"otrs2","source":"https://ubuntu.com/security/cve?package=otrs2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=otrs2","debian":"https://tracker.debian.org/pkg/otrs2","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-36095","published":"2021-09-06T14:15:00","updated_at":"2025-08-26T12:33:09.976663+00:00","description":"\nMalicious attacker is able to find out valid user logins by using the \"lost\npassword\" feature. This issue affects: OTRS AG ((OTRS)) Community Edition\nversion 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and\nprior versions.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://otrs.com/release-notes/otrs-security-advisory-2021-18/","https://www.cve.org/CVERecord?id=CVE-2021-36095"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=993846"],"patches":{"otrs2":[]},"tags":{},"packages":[{"name":"otrs2","source":"https://ubuntu.com/security/cve?package=otrs2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=otrs2","debian":"https://tracker.debian.org/pkg/otrs2","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-36094","published":"2021-09-06T14:15:00","updated_at":"2025-08-26T12:33:09.976663+00:00","description":"\nIt's possible to craft a request for appointment edit screen, which could\nlead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community\nEdition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version\n7.0.28 and prior versions.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.7,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://otrs.com/release-notes/otrs-security-advisory-2021-17/","https://www.cve.org/CVERecord?id=CVE-2021-36094"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=993846"],"patches":{"otrs2":[]},"tags":{},"packages":[{"name":"otrs2","source":"https://ubuntu.com/security/cve?package=otrs2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=otrs2","debian":"https://tracker.debian.org/pkg/otrs2","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-36093","published":"2021-09-06T14:15:00","updated_at":"2025-08-26T12:33:09.976663+00:00","description":"\nIt's possible to create an email which can be stuck while being processed\nby PostMaster filters, causing DoS. This issue affects: OTRS AG ((OTRS))\nCommunity Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS\n7.0.x version 7.0.28 and prior versions; 8.0.x version 8.0.15 and prior\nversions.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://otrs.com/release-notes/otrs-security-advisory-2021-16/","https://www.cve.org/CVERecord?id=CVE-2021-36093"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=993846"],"patches":{"otrs2":[]},"tags":{},"packages":[{"name":"otrs2","source":"https://ubuntu.com/security/cve?package=otrs2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=otrs2","debian":"https://tracker.debian.org/pkg/otrs2","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-3770","published":"2021-09-06T12:15:00","updated_at":"2025-08-25T23:39:02.449122+00:00","description":"\nvim is vulnerable to Heap-based Buffer Overflow","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://huntr.dev/bounties/016ad2f2-07c1-4d14-a8ce-6eed10729365/","https://github.com/vim/vim/commit/b7081e135a16091c93f6f5f7525a5c58fb7ca9f9","https://github.com/vim/vim/commit/2ddb89f8a94425cda1e5491efc80c1ccccb6e08e","https://huntr.dev/bounties/016ad2f2-07c1-4d14-a8ce-6eed10729365","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J2CJLY3CF55I2ULG2X4ENXLSXAXYW5J4/","https://ubuntu.com/security/notices/USN-5093-1","https://www.cve.org/CVERecord?id=CVE-2021-3770"],"bugs":[""],"patches":{"vim":["upstream: https://github.com/vim/vim/commit/b7081e135a16091c93f6f5f7525a5c58fb7ca9f9","upstream: https://github.com/vim/vim/commit/2ddb89f8a94425cda1e5491efc80c1ccccb6e08e"]},"tags":{},"packages":[{"name":"vim","source":"https://ubuntu.com/security/cve?package=vim","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=vim","debian":"https://tracker.debian.org/pkg/vim","statuses":[{"release_codename":"hirsute","status":"released","description":"2:8.2.2434-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"v8.2.3403","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"2:8.2.2434-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2:8.1.2269-1ubuntu5.3","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2:8.2.2434-3ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":["USN-5093-1"],"notices":[{"id":"USN-5093-1","title":"Vim vulnerabilities","summary":"Several security issues were fixed in Vim.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-09-28T10:46:15.110218","description":"Brian Carpenter discovered that vim incorrectly handled memory\nwhen opening certain files. If a user was tricked into opening\na specially crafted file, a remote attacker could crash the\napplication, leading to a denial of service, or possibly execute\narbitrary code with user privileges. This issue only affected\nUbuntu 20.04 LTS and Ubuntu 21.04. (CVE-2021-3770)\n\nBrian Carpenter discovered that vim incorrectly handled memory\nwhen opening certain files. If a user was tricked into opening\na specially crafted file, a remote attacker could crash the\napplication, leading to a denial of service, or possibly execute\narbitrary code with user privileges. (CVE-2021-3778)\n\nDhiraj Mishra discovered that vim incorrectly handled memory\nwhen opening certain files. If a user was tricked into opening\na specially crafted file, a remote attacker could crash the\napplication, leading to a denial of service, or possibly execute\narbitrary code with user privileges. (CVE-2021-3796)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"vim","version":"2:8.0.1453-1ubuntu1.6","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.0.1453-1ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.0.1453-1ubuntu1.6","pocket":"security"},{"name":"vim-athena","version":"2:8.0.1453-1ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.0.1453-1ubuntu1.6","pocket":"security"},{"name":"vim-common","version":"2:8.0.1453-1ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.0.1453-1ubuntu1.6","pocket":"security"},{"name":"vim-doc","version":"2:8.0.1453-1ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.0.1453-1ubuntu1.6","pocket":"security"},{"name":"vim-gnome","version":"2:8.0.1453-1ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.0.1453-1ubuntu1.6","pocket":"security"},{"name":"vim-gtk","version":"2:8.0.1453-1ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.0.1453-1ubuntu1.6","pocket":"security"},{"name":"vim-gtk3","version":"2:8.0.1453-1ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.0.1453-1ubuntu1.6","pocket":"security"},{"name":"vim-gui-common","version":"2:8.0.1453-1ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.0.1453-1ubuntu1.6","pocket":"security"},{"name":"vim-nox","version":"2:8.0.1453-1ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.0.1453-1ubuntu1.6","pocket":"security"},{"name":"vim-runtime","version":"2:8.0.1453-1ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.0.1453-1ubuntu1.6","pocket":"security"},{"name":"vim-tiny","version":"2:8.0.1453-1ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.0.1453-1ubuntu1.6","pocket":"security"},{"name":"xxd","version":"2:8.0.1453-1ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.0.1453-1ubuntu1.6","pocket":"security"}],"focal":[{"name":"vim","version":"2:8.1.2269-1ubuntu5.3","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.1.2269-1ubuntu5.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.3","pocket":"security"},{"name":"vim-athena","version":"2:8.1.2269-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.3","pocket":"security"},{"name":"vim-common","version":"2:8.1.2269-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.3","pocket":"security"},{"name":"vim-doc","version":"2:8.1.2269-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.3","pocket":"security"},{"name":"vim-gtk","version":"2:8.1.2269-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.3","pocket":"security"},{"name":"vim-gtk3","version":"2:8.1.2269-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.3","pocket":"security"},{"name":"vim-gui-common","version":"2:8.1.2269-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.3","pocket":"security"},{"name":"vim-nox","version":"2:8.1.2269-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.3","pocket":"security"},{"name":"vim-runtime","version":"2:8.1.2269-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.3","pocket":"security"},{"name":"vim-tiny","version":"2:8.1.2269-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.3","pocket":"security"},{"name":"xxd","version":"2:8.1.2269-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.3","pocket":"security"}],"hirsute":[{"name":"vim","version":"2:8.2.2434-1ubuntu1.1","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.2.2434-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.2434-1ubuntu1.1","pocket":"security"},{"name":"vim-athena","version":"2:8.2.2434-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.2434-1ubuntu1.1","pocket":"security"},{"name":"vim-common","version":"2:8.2.2434-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.2434-1ubuntu1.1","pocket":"security"},{"name":"vim-doc","version":"2:8.2.2434-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.2434-1ubuntu1.1","pocket":"security"},{"name":"vim-gtk","version":"2:8.2.2434-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.2434-1ubuntu1.1","pocket":"security"},{"name":"vim-gtk3","version":"2:8.2.2434-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.2434-1ubuntu1.1","pocket":"security"},{"name":"vim-gui-common","version":"2:8.2.2434-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.2434-1ubuntu1.1","pocket":"security"},{"name":"vim-nox","version":"2:8.2.2434-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.2434-1ubuntu1.1","pocket":"security"},{"name":"vim-runtime","version":"2:8.2.2434-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.2434-1ubuntu1.1","pocket":"security"},{"name":"vim-tiny","version":"2:8.2.2434-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.2434-1ubuntu1.1","pocket":"security"},{"name":"xxd","version":"2:8.2.2434-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.2434-1ubuntu1.1","pocket":"security"}],"trusty":[{"name":"vim","version":"2:7.4.052-1ubuntu3.1+esm3","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:7.4.052-1ubuntu3.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena","version":"2:7.4.052-1ubuntu3.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-common","version":"2:7.4.052-1ubuntu3.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-doc","version":"2:7.4.052-1ubuntu3.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome","version":"2:7.4.052-1ubuntu3.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk","version":"2:7.4.052-1ubuntu3.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gui-common","version":"2:7.4.052-1ubuntu3.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-lesstif","version":"2:7.4.052-1ubuntu3.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox","version":"2:7.4.052-1ubuntu3.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-runtime","version":"2:7.4.052-1ubuntu3.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-tiny","version":"2:7.4.052-1ubuntu3.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"vim","version":"2:7.4.1689-3ubuntu1.5+esm2","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:7.4.1689-3ubuntu1.5+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena","version":"2:7.4.1689-3ubuntu1.5+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena-py2","version":"2:7.4.1689-3ubuntu1.5+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-common","version":"2:7.4.1689-3ubuntu1.5+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-doc","version":"2:7.4.1689-3ubuntu1.5+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome","version":"2:7.4.1689-3ubuntu1.5+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome-py2","version":"2:7.4.1689-3ubuntu1.5+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk","version":"2:7.4.1689-3ubuntu1.5+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk-py2","version":"2:7.4.1689-3ubuntu1.5+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk3","version":"2:7.4.1689-3ubuntu1.5+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk3-py2","version":"2:7.4.1689-3ubuntu1.5+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gui-common","version":"2:7.4.1689-3ubuntu1.5+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox","version":"2:7.4.1689-3ubuntu1.5+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox-py2","version":"2:7.4.1689-3ubuntu1.5+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-runtime","version":"2:7.4.1689-3ubuntu1.5+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-tiny","version":"2:7.4.1689-3ubuntu1.5+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2021-3796","CVE-2021-3778","CVE-2021-3770"]}]},{"id":"CVE-2021-25737","published":"2021-09-06T12:15:00","updated_at":"2025-07-11T07:46:28.820189+00:00","description":"\nA security issue was discovered in Kubernetes where a user may be able to\nredirect pod traffic to private networks on a Node. Kubernetes already\nprevents creation of Endpoint IPs in the localhost or link-local range, but\nthe same validation was not performed on EndpointSlice IPs.","ubuntu_description":"","notes":[{"author":"leosilva","note":"kubernates is in fact a kubernetes installer\nthat calls snap, not the package it self."}],"codename":null,"priority":"medium","cvss3":2.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.openwall.com/lists/oss-security/2021/05/18/4","https://www.cve.org/CVERecord?id=CVE-2021-25737"],"bugs":[""],"patches":{"kubernetes":[]},"tags":{},"packages":[{"name":"kubernetes","source":"https://ubuntu.com/security/cve?package=kubernetes","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kubernetes","debian":"https://tracker.debian.org/pkg/kubernetes","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-25735","published":"2021-09-06T12:15:00","updated_at":"2025-07-11T07:46:28.820189+00:00","description":"\nA security issue was discovered in kube-apiserver that could allow node\nupdates to bypass a Validating Admission Webhook. Clusters are only\naffected by this vulnerability if they run a Validating Admission Webhook\nfor Nodes that denies admission based at least partially on the old state\nof the Node object. Validating Admission Webhook does not observe some\nprevious fields.","ubuntu_description":"","notes":[{"author":"leosilva","note":"kubernates is in fact a kubernetes installer\nthat calls snap, not the package it self."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.openwall.com/lists/oss-security/2021/04/14/1","https://github.com/kubernetes/kubernetes/issues/100096","https://www.cve.org/CVERecord?id=CVE-2021-25735"],"bugs":[""],"patches":{"kubernetes":[]},"tags":{},"packages":[{"name":"kubernetes","source":"https://ubuntu.com/security/cve?package=kubernetes","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kubernetes","debian":"https://tracker.debian.org/pkg/kubernetes","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-40524","published":"2021-09-05T19:15:00","updated_at":"2025-07-11T07:48:12.318391+00:00","description":"\nIn Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in\nthe server allows attackers to upload files of unbounded size, which may\nlead to denial of service or a server hang. This occurs because a certain\ngreater-than-zero test does not anticipate an initial -1 value. (Versions\n1.0.23 through 1.0.49 are affected.)","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/jedisct1/pure-ftpd/pull/158","https://www.cve.org/CVERecord?id=CVE-2021-40524"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=993810"],"patches":{"pure-ftpd":[]},"tags":{},"packages":[{"name":"pure-ftpd","source":"https://ubuntu.com/security/cve?package=pure-ftpd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=pure-ftpd","debian":"https://tracker.debian.org/pkg/pure-ftpd","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-40516","published":"2021-09-05T18:15:00","updated_at":"2025-08-25T23:41:17.365043+00:00","description":"\nWeeChat before 3.2.1 allows remote attackers to cause a denial of service\n(crash) via a crafted WebSocket frame that trigger an out-of-bounds read in\nplugins/relay/relay-websocket.c in the Relay plugin.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/weechat/weechat/commit/8b1331f98de1714bae15a9ca2e2b393ba49d735b","https://weechat.org/doc/security/","https://ubuntu.com/security/notices/USN-5258-1","https://www.cve.org/CVERecord?id=CVE-2021-40516"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=993803"],"patches":{"weechat":[]},"tags":{},"packages":[{"name":"weechat","source":"https://ubuntu.com/security/cve?package=weechat","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=weechat","debian":"https://tracker.debian.org/pkg/weechat","statuses":[{"release_codename":"impish","status":"not-affected","description":"3.2.1-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"3.2.1-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"3.2.1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.9.1-1ubuntu1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"2.8-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"xenial","status":"released","description":"1.4-2ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.1-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.2.1-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.2.1-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.2.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"3.2.1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.2.1-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5258-1"],"notices":[{"id":"USN-5258-1","title":"WeeChat vulnerabilities","summary":"Several security issues were fixed in WeeChat.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-02-04T16:38:24.988878","description":"Stuart Nevans Locke discovered that WeeChat's relay plugin insecurely handled\nmalformed websocket frames. A remote attacker in control of a server\ncould possibly use this issue to cause denial of service in a client.\n(CVE-2021-40516)\n\nStuart Nevans Locke discovered that WeeChat insecurely handled certain\nIRC messages. A remote attacker in control of a server could possibly use\nthis issue to cause denial of service in a client. This issue only affected\nUbuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2020-9760)\n\nStuart Nevans Locke discovered that WeeChat insecurely handled certain\nIRC messages. A remote unauthenticated attacker could possibly use these\nissues to cause denial of service in a client. These issues only affected\nUbuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2020-9759, CVE-2020-8955)\n\nJoseph Bisch discovered that WeeChat's logger incorrectly handled certain\nmemory operations when handling log file names. A remote attacker could possibly\nuse this issue to cause denial of service in a client. This issue only\naffected Ubuntu 16.04 ESM. (CVE-2017-14727)\n","is_hidden":false,"release_packages":{"focal":[{"name":"weechat","version":"2.8-1ubuntu0.1~esm1","description":"Fast, light and extensible chat client (metapackage)","is_source":true},{"name":"weechat-python","version":"2.8-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-dev","version":"2.8-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-plugins","version":"2.8-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-guile","version":"2.8-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-core","version":"2.8-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-tcl","version":"2.8-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-ruby","version":"2.8-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-curses","version":"2.8-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-doc","version":"2.8-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-php","version":"2.8-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-perl","version":"2.8-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat","version":"2.8-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-lua","version":"2.8-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-headless","version":"2.8-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"weechat","version":"1.9.1-1ubuntu1+esm1","description":"Fast, light and extensible chat client (metapackage)","is_source":true},{"name":"weechat-dev","version":"1.9.1-1ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-core","version":"1.9.1-1ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-curses","version":"1.9.1-1ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-doc","version":"1.9.1-1ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-plugins","version":"1.9.1-1ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat","version":"1.9.1-1ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"weechat","version":"1.4-2ubuntu0.1+esm1","description":"Fast, light and extensible chat client","is_source":true},{"name":"weechat-dev","version":"1.4-2ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-core","version":"1.4-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-curses","version":"1.4-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-doc","version":"1.4-2ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat-plugins","version":"1.4-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"},{"name":"weechat","version":"1.4-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/weechat","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2020-9760","CVE-2021-40516","CVE-2020-9759","CVE-2020-8955","CVE-2017-14727"]}]},{"id":"CVE-2021-30624","published":"2021-09-03T20:15:00","updated_at":"2025-08-25T23:36:03.521048+00:00","description":"\nChromium: CVE-2021-30624 Use after free in Autofill","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2021-30624"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"93.0.4577.63","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"93.0.4577.63-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-30623","published":"2021-09-03T20:15:00","updated_at":"2025-08-25T23:36:03.521048+00:00","description":"\nChromium: CVE-2021-30623 Use after free in Bookmarks","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2021-30623"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"93.0.4577.63","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"93.0.4577.63-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-30622","published":"2021-09-03T20:15:00","updated_at":"2025-08-25T23:36:03.521048+00:00","description":"\nChromium: CVE-2021-30622 Use after free in WebApp Installs","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2021-30622"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"93.0.4577.63","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"93.0.4577.63-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-30621","published":"2021-09-03T20:15:00","updated_at":"2025-08-25T23:36:03.521048+00:00","description":"\nChromium: CVE-2021-30621 UI Spoofing in Autofill","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2021-30621"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"released","description":"93.0.4577.63-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"93.0.4577.63","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-30620","published":"2021-09-03T20:15:00","updated_at":"2025-08-25T23:36:03.521048+00:00","description":"\nChromium: CVE-2021-30620 Insufficient policy enforcement in Blink","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2021-30620"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"released","description":"93.0.4577.63-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"93.0.4577.63","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-30619","published":"2021-09-03T20:15:00","updated_at":"2025-08-25T23:36:03.521048+00:00","description":"\nChromium: CVE-2021-30619 UI Spoofing in Autofill","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2021-30619"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"93.0.4577.63","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"93.0.4577.63-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-30618","published":"2021-09-03T20:15:00","updated_at":"2025-08-25T23:36:03.521048+00:00","description":"\nChromium: CVE-2021-30618 Inappropriate implementation in DevTools","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2021-30618"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"93.0.4577.63","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"93.0.4577.63-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":41300,"limit":20,"total_results":79316}