{"cves":[{"id":"CVE-2006-3100","published":"2019-11-06T03:15:00","updated_at":"2025-07-17T16:39:05.252305+00:00","description":"\ntermpkg 3.3 suffers from buffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-3100"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"termpkg","source":"https://ubuntu.com/security/cve?package=termpkg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=termpkg","debian":"https://tracker.debian.org/pkg/termpkg","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.3-7","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.3-7","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"3.3-7","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.3-7","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.3-7","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.3-7","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.3-7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0062","published":"2019-11-06T03:15:00","updated_at":"2025-07-17T16:37:28.520824+00:00","description":"\nxlockmore 5.13 allows potential xlock bypass when FVWM switches to the same\nvirtual desktop as a new Gaim window.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0062"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"xlockmore","source":"https://ubuntu.com/security/cve?package=xlockmore","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xlockmore","debian":"https://tracker.debian.org/pkg/xlockmore","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.22-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.22-1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.22-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.22-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"5.22-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"5.22-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"5.22-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-0061","published":"2019-11-06T02:15:00","updated_at":"2025-07-17T16:37:28.520824+00:00","description":"\nxlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the\nunderlying xsession. This allows unauthorized users access to the X\nsession.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-0061"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"xlockmore","source":"https://ubuntu.com/security/cve?package=xlockmore","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xlockmore","debian":"https://tracker.debian.org/pkg/xlockmore","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.22-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.22-1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.22-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.22-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"5.22-1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"5.22-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"5.22-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1460","published":"2019-11-05T23:15:00","updated_at":"2025-08-25T20:10:40.439115+00:00","description":"\nWebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock\nwhen anonymous blocks are renderblocks.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://trac.webkit.org/changeset/81648","http://trac.webkit.org/changeset/81748","https://bugs.chromium.org/p/chromium/issues/detail?id=76784","https://www.cve.org/CVERecord?id=CVE-2011-1460"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1459","published":"2019-11-05T23:15:00","updated_at":"2025-08-25T20:10:40.439115+00:00","description":"\nThe WebKit::WebPluginContainerImpl::handleEvent function in Google Chrome\nbefore Blink M11 allows an attacker to cause a denial of service (crash)\nvia the htmlpluginelement.cpp plugin.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://trac.webkit.org/changeset/81795","http://trac.webkit.org/changeset/81891","https://bugs.chromium.org/p/chromium/issues/detail?id=76474","https://www.cve.org/CVERecord?id=CVE-2011-1459"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-5068","published":"2019-11-05T22:15:00","updated_at":"2025-08-25T23:12:10.044981+00:00","description":"\nAn exploitable shared memory permissions vulnerability exists in the\nfunctionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can\naccess the shared memory without any specific permissions to trigger this\nvulnerability.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"mesa and its build dependencies have been updated for the HWE\nstack in bionic, so to fix this there will require no-change rebuilds\nin the security pocket for libdrm, libclc, wayland, and\nllvm-toolchain-9."}],"codename":null,"priority":"medium","cvss3":4.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://talosintelligence.com/vulnerability_reports/TALOS-2019-0857","https://lists.freedesktop.org/pipermail/mesa-dev/2019-October/223704.html","https://ubuntu.com/security/notices/USN-4271-1","https://www.cve.org/CVERecord?id=CVE-2019-5068"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=944298"],"patches":{"mesa":["upstream: https://cgit.freedesktop.org/mesa/mesa/commit/?id=02c3dad0f3b4d26e0faa5cc51d06bc50d693dcdc"]},"tags":{},"packages":[{"name":"mesa","source":"https://ubuntu.com/security/cve?package=mesa","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mesa","debian":"https://tracker.debian.org/pkg/mesa","statuses":[{"release_codename":"bionic","status":"released","description":"19.2.8-0ubuntu0~18.04.2","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"19.2.8-0ubuntu0~19.10.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"19.2.6-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-4271-1"],"notices":[{"id":"USN-4271-1","title":"Mesa vulnerability","summary":"Mesa could be made to expose sensitive information.\n","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2020-02-06T13:10:55.305107","description":"Tim Brown discovered that Mesa incorrectly handled shared memory\npermissions. A local attacker could use this issue to obtain and possibly\nalter sensitive information belonging to another user.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"mesa","version":"19.2.8-0ubuntu0~18.04.2","description":"free implementation of the EGL API","is_source":true},{"name":"libd3dadapter9-mesa","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"libd3dadapter9-mesa-dev","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"libegl-mesa0","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"libegl1-mesa","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"libegl1-mesa-dev","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"libgbm-dev","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"libgbm1","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"libgl1-mesa-dev","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"libgl1-mesa-dri","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"libgl1-mesa-glx","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"libglapi-mesa","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"libgles2-mesa","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"libgles2-mesa-dev","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"libglx-mesa0","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"libosmesa6","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"libosmesa6-dev","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"libwayland-egl1-mesa","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"libxatracker-dev","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"libxatracker2","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"mesa-common-dev","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"mesa-opencl-icd","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"mesa-va-drivers","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"mesa-vdpau-drivers","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"},{"name":"mesa-vulkan-drivers","version":"19.2.8-0ubuntu0~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~18.04.2","pocket":"security"}],"eoan":[{"name":"mesa","version":"19.2.8-0ubuntu0~19.10.2","description":"free implementation of the EGL API","is_source":true},{"name":"libd3dadapter9-mesa","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"libd3dadapter9-mesa-dev","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"libegl-mesa0","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"libegl1-mesa","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"libegl1-mesa-dev","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"libgbm-dev","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"libgbm1","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"libgl1-mesa-dev","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"libgl1-mesa-dri","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"libgl1-mesa-glx","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"libglapi-mesa","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"libgles2-mesa","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"libgles2-mesa-dev","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"libglx-mesa0","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"libosmesa6","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"libosmesa6-dev","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"libwayland-egl1-mesa","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"libxatracker-dev","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"libxatracker2","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"mesa-common-dev","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"mesa-opencl-icd","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"mesa-va-drivers","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"mesa-vdpau-drivers","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"},{"name":"mesa-vulkan-drivers","version":"19.2.8-0ubuntu0~19.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mesa","version_link":"https://launchpad.net/ubuntu/+source/mesa/19.2.8-0ubuntu0~19.10.2"}]},"type":"USN","cves_ids":["CVE-2019-5068"]}]},{"id":"CVE-2016-4983","published":"2019-11-05T22:15:00","updated_at":"2025-08-25T22:04:33.551308+00:00","description":"\nA postinstall script in the dovecot rpm allows local users to read the\ncontents of newly created SSL/TLS key files.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"RedHat specific"}],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.3,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2016-4983"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-4983"],"patches":{"dovecot":[]},"tags":{},"packages":[{"name":"dovecot","source":"https://ubuntu.com/security/cve?package=dovecot","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dovecot","debian":"https://tracker.debian.org/pkg/dovecot","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5123","published":"2019-11-05T22:15:00","updated_at":"2025-08-25T20:58:20.130304+00:00","description":"\nThe mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses\ninsecure DNS querying and authenticity checks which allows attackers to\nperform man-in-the-middle attacks.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"This will probably require some ecosystem changes in the Python world\nto support authenticated PIP downloads."}],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/08/21/18","https://www.cve.org/CVERecord?id=CVE-2013-5123"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/python-pip/+bug/1418592"],"patches":{"python-pip":[]},"tags":{},"packages":[{"name":"python-pip","source":"https://ubuntu.com/security/cve?package=python-pip","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=python-pip","debian":"https://tracker.debian.org/pkg/python-pip","statuses":[{"release_codename":"vivid","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.5.4-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.1-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"8.1.1-2ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1135","published":"2019-11-05T21:15:00","updated_at":"2025-08-25T20:09:42.339524+00:00","description":"\nCross-Site Scripting (XSS) in Xinha, as included in the Serendipity package\nbefore 1.5.5, allows remote attackers to execute arbitrary code in\nplugins/ExtendedFileManager/manager.php and\nplugins/ImageManager/manager.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://secunia.com/advisories/40669/","https://www.cve.org/CVERecord?id=CVE-2011-1135"],"bugs":[""],"patches":{"serendipity":[],"openacs":[],"dotlrn":[]},"tags":{},"packages":[{"name":"dotlrn","source":"https://ubuntu.com/security/cve?package=dotlrn","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dotlrn","debian":"https://tracker.debian.org/pkg/dotlrn","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.5.0+dfsg-2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.0+dfsg-2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"openacs","source":"https://ubuntu.com/security/cve?package=openacs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openacs","debian":"https://tracker.debian.org/pkg/openacs","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"serendipity","source":"https://ubuntu.com/security/cve?package=serendipity","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=serendipity","debian":"https://tracker.debian.org/pkg/serendipity","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1134","published":"2019-11-05T21:15:00","updated_at":"2025-08-25T20:09:42.339524+00:00","description":"\nCross-Site Scripting (XSS) in Xinha, as included in the Serendipity package\nbefore 1.5.5, allows remote attackers to execute arbitrary code in the\nimage manager.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://secunia.com/advisories/40669/","https://www.cve.org/CVERecord?id=CVE-2011-1134"],"bugs":[""],"patches":{"serendipity":[],"openacs":[],"dotlrn":[]},"tags":{},"packages":[{"name":"dotlrn","source":"https://ubuntu.com/security/cve?package=dotlrn","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dotlrn","debian":"https://tracker.debian.org/pkg/dotlrn","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.5.0+dfsg-2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.0+dfsg-2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"openacs","source":"https://ubuntu.com/security/cve?package=openacs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openacs","debian":"https://tracker.debian.org/pkg/openacs","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"serendipity","source":"https://ubuntu.com/security/cve?package=serendipity","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=serendipity","debian":"https://tracker.debian.org/pkg/serendipity","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1133","published":"2019-11-05T21:15:00","updated_at":"2025-08-25T20:09:42.339524+00:00","description":"\nCross-Site Scripting (XSS) in Xinha, as included in the Serendipity package\nbefore 1.5.5, allows remote attackers to execute arbitrary code via\nplugins/ExtendedFileManager/backend.php.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per Debian, openacs <not-affected> (PHP bindings not used)\ndotlrn <not-affected> (PHP bindings not used)"}],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://secunia.com/advisories/40669/","https://www.cve.org/CVERecord?id=CVE-2011-1133"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=611661"],"patches":{"serendipity":[],"openacs":[],"dotlrn":[]},"tags":{},"packages":[{"name":"dotlrn","source":"https://ubuntu.com/security/cve?package=dotlrn","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dotlrn","debian":"https://tracker.debian.org/pkg/dotlrn","statuses":[{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.5.0+dfsg-2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.0+dfsg-2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"openacs","source":"https://ubuntu.com/security/cve?package=openacs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openacs","debian":"https://tracker.debian.org/pkg/openacs","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"serendipity","source":"https://ubuntu.com/security/cve?package=serendipity","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=serendipity","debian":"https://tracker.debian.org/pkg/serendipity","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3674","published":"2019-11-05T20:15:00","updated_at":"2025-08-25T20:01:21.651490+00:00","description":"\nTYPO3 before 4.4.1 allows XSS in the frontend search box.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3674"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590719"],"patches":{"typo3-src":[]},"tags":{},"packages":[{"name":"typo3-src","source":"https://ubuntu.com/security/cve?package=typo3-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=typo3-src","debian":"https://tracker.debian.org/pkg/typo3-src","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"4.3.9+dfsg1-1+squeeze1build0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.3.5-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3673","published":"2019-11-05T20:15:00","updated_at":"2025-08-25T20:01:21.651490+00:00","description":"\nTYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows\ninformation disclosure in the mail header of the HTML mailing API.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3673"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590719"],"patches":{"typo3-src":[]},"tags":{},"packages":[{"name":"typo3-src","source":"https://ubuntu.com/security/cve?package=typo3-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=typo3-src","debian":"https://tracker.debian.org/pkg/typo3-src","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"4.3.9+dfsg1-1+squeeze1build0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.3.5-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3672","published":"2019-11-05T20:15:00","updated_at":"2025-08-25T20:01:21.651490+00:00","description":"\nTYPO3 before 4.3.4 and 4.4.x before 4.4.1 allows XSS in the textarea view\nhelper in an extbase extension.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3672"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590719"],"patches":{"typo3-src":[]},"tags":{},"packages":[{"name":"typo3-src","source":"https://ubuntu.com/security/cve?package=typo3-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=typo3-src","debian":"https://tracker.debian.org/pkg/typo3-src","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"4.3.9+dfsg1-1+squeeze1build0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.3.5-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3671","published":"2019-11-05T20:15:00","updated_at":"2025-08-25T20:01:21.651490+00:00","description":"\nTYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x\nbefore 4.4.1 is open to a session fixation attack which allows remote\nattackers to hijack a victim's session.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3671"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590719"],"patches":{"typo3-src":[]},"tags":{},"packages":[{"name":"typo3-src","source":"https://ubuntu.com/security/cve?package=typo3-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=typo3-src","debian":"https://tracker.debian.org/pkg/typo3-src","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"4.3.9+dfsg1-1+squeeze1build0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.3.5-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3670","published":"2019-11-05T20:15:00","updated_at":"2025-08-25T20:01:21.651490+00:00","description":"\nTYPO3 before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness\nduring generation of a hash with the \"forgot password\" function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3670"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590719"],"patches":{"typo3-src":[]},"tags":{},"packages":[{"name":"typo3-src","source":"https://ubuntu.com/security/cve?package=typo3-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=typo3-src","debian":"https://tracker.debian.org/pkg/typo3-src","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"4.3.9+dfsg1-1+squeeze1build0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.3.5-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6275","published":"2019-11-05T19:15:00","updated_at":"2025-08-25T21:00:57.864402+00:00","description":"\nMultiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier\nin basic.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-6275"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=727669"],"patches":{"ingo1":[],"php-horde-ingo":[]},"tags":{},"packages":[{"name":"ingo1","source":"https://ubuntu.com/security/cve?package=ingo1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ingo1","debian":"https://tracker.debian.org/pkg/ingo1","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"php-horde-ingo","source":"https://ubuntu.com/security/cve?package=php-horde-ingo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=php-horde-ingo","debian":"https://tracker.debian.org/pkg/php-horde-ingo","statuses":[{"release_codename":"vivid","status":"not-affected","description":"3.1.3-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1.3-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.1.3-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.1.3-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.1.3-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.1.3-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"3.1.3-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.1.3-1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5661","published":"2019-11-05T19:15:00","updated_at":"2025-08-25T20:58:59.535902+00:00","description":"\nCache Poisoning issue exists in DNS Response Rate Limiting.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"This appears to be about the tradeoff of providing service to\nclients and preventing the massive DDoS attacks using high-speed DNS\nservers. This seems like an unfixable issue."}],"codename":null,"priority":"negligible","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.isc.org/blogs/cache-poisoning-gets-a-second-wind-from-rrl-probably-not/","https://www.cve.org/CVERecord?id=CVE-2013-5661"],"bugs":[""],"patches":{"bind9":[]},"tags":{},"packages":[{"name":"bind9","source":"https://ubuntu.com/security/cve?package=bind9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=bind9","debian":"https://tracker.debian.org/pkg/bind9","statuses":[{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"see Notes","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6461","published":"2019-11-05T15:15:00","updated_at":"2025-08-25T21:03:36.513791+00:00","description":"\nNokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing\nto apply limits","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"this is for JRuby only"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://groups.google.com/forum/#!topic/ruby-security-ann/DeJpjTAg1FA","https://www.cve.org/CVERecord?id=CVE-2013-6461"],"bugs":[""],"patches":{"ruby-nokogiri":[],"libnokogiri-ruby":[]},"tags":{},"packages":[{"name":"libnokogiri-ruby","source":"https://ubuntu.com/security/cve?package=libnokogiri-ruby","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libnokogiri-ruby","debian":"https://tracker.debian.org/pkg/libnokogiri-ruby","statuses":[{"release_codename":"lucid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"ruby-nokogiri","source":"https://ubuntu.com/security/cve?package=ruby-nokogiri","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-nokogiri","debian":"https://tracker.debian.org/pkg/ruby-nokogiri","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6460","published":"2019-11-05T15:15:00","updated_at":"2025-08-25T21:03:36.513791+00:00","description":"\nNokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML\ndocuments","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"this is for JRuby only"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://groups.google.com/forum/#!topic/ruby-security-ann/DeJpjTAg1FA","https://www.cve.org/CVERecord?id=CVE-2013-6460"],"bugs":[""],"patches":{"ruby-nokogiri":[],"libnokogiri-ruby":[]},"tags":{},"packages":[{"name":"libnokogiri-ruby","source":"https://ubuntu.com/security/cve?package=libnokogiri-ruby","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libnokogiri-ruby","debian":"https://tracker.debian.org/pkg/libnokogiri-ruby","statuses":[{"release_codename":"lucid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"ruby-nokogiri","source":"https://ubuntu.com/security/cve?package=ruby-nokogiri","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-nokogiri","debian":"https://tracker.debian.org/pkg/ruby-nokogiri","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":47840,"limit":20,"total_results":79316}