{"cves":[{"id":"CVE-2018-16068","published":"2019-01-09T19:29:00","updated_at":"2025-08-25T22:48:35.851266+00:00","description":"\nMissing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a\nremote attacker to potentially perform a sandbox escape via a crafted HTML\npage.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.6,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://chromereleases.googleblog.com/2018/09/stable-channel-update-for-desktop.html","https://www.cve.org/CVERecord?id=CVE-2018-16068"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"released","description":"69.0.3497.81-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"69.0.3497.81-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"69.0.3497.81","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"69.0.3497.81-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no longer updated]","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [Ubuntu touch end-of-life]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-16067","published":"2019-01-09T19:29:00","updated_at":"2025-08-25T22:48:35.851266+00:00","description":"\nA use after free in WebAudio in Google Chrome prior to 69.0.3497.81 allowed\na remote attacker to potentially exploit heap corruption via a crafted HTML\npage.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://chromereleases.googleblog.com/2018/09/stable-channel-update-for-desktop.html","https://www.cve.org/CVERecord?id=CVE-2018-16067"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"released","description":"69.0.3497.81-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"69.0.3497.81-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"69.0.3497.81","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"69.0.3497.81-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no longer updated]","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [Ubuntu touch end-of-life]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-16066","published":"2019-01-09T19:29:00","updated_at":"2025-08-25T22:48:35.851266+00:00","description":"\nA use after free in Blink in Google Chrome prior to 69.0.3497.81 allowed a\nremote attacker to potentially exploit heap corruption via a crafted HTML\npage.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://chromereleases.googleblog.com/2018/09/stable-channel-update-for-desktop.html","https://www.cve.org/CVERecord?id=CVE-2018-16066"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"released","description":"69.0.3497.81-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"69.0.3497.81-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"69.0.3497.81","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"69.0.3497.81-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no longer updated]","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [Ubuntu touch end-of-life]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-16065","published":"2019-01-09T19:29:00","updated_at":"2025-08-25T22:48:35.851266+00:00","description":"\nA Javascript reentrancy issues that caused a use-after-free in V8 in Google\nChrome prior to 69.0.3497.81 allowed a remote attacker to execute arbitrary\ncode inside a sandbox via a crafted HTML page.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://chromereleases.googleblog.com/2018/09/stable-channel-update-for-desktop.html","https://www.cve.org/CVERecord?id=CVE-2018-16065"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"released","description":"69.0.3497.81-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"69.0.3497.81-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"69.0.3497.81","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"69.0.3497.81-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no longer updated]","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [Ubuntu touch end-of-life]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15428","published":"2019-01-09T19:29:00","updated_at":"2025-08-25T22:27:05.484993+00:00","description":"\nInsufficient data validation in V8 builtins string generator could lead to\nout of bounds read and write access in V8 in Google Chrome prior to\n62.0.3202.94 and allowed a remote attacker to execute arbitrary code inside\na sandbox via a crafted HTML page.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://chromereleases.googleblog.com/2017/11/stable-channel-update-for-desktop_13.html","https://crbug.com/782145","https://www.cve.org/CVERecord?id=CVE-2017-15428"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"not-affected","description":"74.0.3729.169-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"74.0.3729.169-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"74.0.3729.169-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"63.0.3239.84-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"74.0.3729.169-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was ignored [no longer updated]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15405","published":"2019-01-09T19:29:00","updated_at":"2025-08-25T22:26:55.375375+00:00","description":"\nInappropriate symlink handling and a race condition in the stateful\nrecovery feature implementation could lead to a persistance established by\na malicious code running with root privileges in cryptohomed in Google\nChrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to\nexecute arbitrary code via a crafted HTML page.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://chromereleases.googleblog.com/2017/10/stable-channel-updates-for-chrome-os.html","https://crbug.com/766276","https://www.cve.org/CVERecord?id=CVE-2017-15405"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was ignored [no longer updated]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15404","published":"2019-01-09T19:29:00","updated_at":"2025-08-25T22:26:55.375375+00:00","description":"\nAn ability to process crash dumps under root privileges and inappropriate\nsymlinks handling could lead to a local privilege escalation in Crash\nReporting in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a\nlocal attacker to perform privilege escalation via a crafted HTML page.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://chromereleases.googleblog.com/2017/10/stable-channel-updates-for-chrome-os.html","https://crbug.com/766275","https://www.cve.org/CVERecord?id=CVE-2017-15404"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was ignored [no longer updated]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15403","published":"2019-01-09T19:29:00","updated_at":"2025-08-25T22:26:55.375375+00:00","description":"\nInsufficient data validation in crosh could lead to a command injection\nunder chronos privileges in Networking in Google Chrome on Chrome OS prior\nto 61.0.3163.113 allowed a local attacker to execute arbitrary code via a\ncrafted HTML page.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"chrome os specific"}],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://chromereleases.googleblog.com/2017/10/stable-channel-updates-for-chrome-os.html","https://crbug.com/766271","https://www.cve.org/CVERecord?id=CVE-2017-15403"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was ignored [no longer updated]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15402","published":"2019-01-09T19:29:00","updated_at":"2025-08-25T22:26:55.375375+00:00","description":"\nUsing an ID that can be controlled by a compromised renderer which allows\nany frame to overwrite the page_state of any other frame in the same\nprocess in Navigation in Google Chrome on Chrome OS prior to 62.0.3202.74\nallowed a remote attacker who had compromised the renderer process to\npotentially perform a sandbox escape via a crafted HTML page.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"chrome os specific"}],"codename":null,"priority":"medium","cvss3":9.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.6,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-chrome-os_27.html","https://crbug.com/766262","https://www.cve.org/CVERecord?id=CVE-2017-15402"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was ignored [no longer updated]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15401","published":"2019-01-09T19:29:00","updated_at":"2025-08-25T22:26:55.375375+00:00","description":"\nA memory corruption bug in WebAssembly could lead to out of bounds read and\nwrite through V8 in WebAssembly in Google Chrome prior to 62.0.3202.62\nallowed a remote attacker to execute arbitrary code inside a sandbox via a\ncrafted HTML page.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-chrome-os_27.html","https://crbug.com/766260","https://www.cve.org/CVERecord?id=CVE-2017-15401"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-10403","published":"2019-01-09T19:29:00","updated_at":"2025-08-25T21:53:25.358643+00:00","description":"\nInsufficient data validation on image data in PDFium in Google Chrome prior\nto 51.0.2704.63 allowed a remote attacker to perform an out of bounds\nmemory read via a crafted PDF file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://chromereleases.googleblog.com/2016/05/stable-channel-update_25.html","https://crbug.com/602046","https://www.cve.org/CVERecord?id=CVE-2016-10403"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"not-affected","description":"51.0.2704.63-1~deb8u1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"51.0.2704.63-1~deb8u1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"51.0.2704.63-1~deb8u1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"51.0.2704.63-1~deb8u1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was ignored [no longer updated]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-0542","published":"2019-01-09T15:29:00","updated_at":"2025-08-25T23:00:31.735404+00:00","description":"\nA remote code execution vulnerability exists in Xterm.js when the component\nmishandles special characters, aka \"Xterm Remote Code Execution\nVulnerability.\" This affects xterm.js.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/xtermjs/xterm.js/releases","https://www.cve.org/CVERecord?id=CVE-2019-0542"],"bugs":[""],"patches":{"node-xterm":[]},"tags":{},"packages":[{"name":"node-xterm","source":"https://ubuntu.com/security/cve?package=node-xterm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=node-xterm","debian":"https://tracker.debian.org/pkg/node-xterm","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-20677","published":"2019-01-09T05:29:00","updated_at":"2025-07-11T07:40:54.095539+00:00","description":"\nIn Bootstrap before 3.4.0, XSS is possible in the affix configuration\ntarget property.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/","https://github.com/twbs/bootstrap/issues/27045","https://github.com/twbs/bootstrap/issues/27915#issuecomment-452140906","https://github.com/twbs/bootstrap/issues/27915#issuecomment-452196628","https://github.com/twbs/bootstrap/pull/27047","https://www.cve.org/CVERecord?id=CVE-2018-20677"],"bugs":[""],"patches":{"twitter-bootstrap":[],"twitter-bootstrap3":[],"twitter-bootstrap4":[]},"tags":{},"packages":[{"name":"twitter-bootstrap","source":"https://ubuntu.com/security/cve?package=twitter-bootstrap","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=twitter-bootstrap","debian":"https://tracker.debian.org/pkg/twitter-bootstrap","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"twitter-bootstrap3","source":"https://ubuntu.com/security/cve?package=twitter-bootstrap3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=twitter-bootstrap3","debian":"https://tracker.debian.org/pkg/twitter-bootstrap3","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"}]},{"name":"twitter-bootstrap4","source":"https://ubuntu.com/security/cve?package=twitter-bootstrap4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=twitter-bootstrap4","debian":"https://tracker.debian.org/pkg/twitter-bootstrap4","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-20676","published":"2019-01-09T05:29:00","updated_at":"2025-07-11T07:40:54.095539+00:00","description":"\nIn Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport\nattribute.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/","https://github.com/twbs/bootstrap/issues/27044","https://github.com/twbs/bootstrap/issues/27915#issuecomment-452140906","https://github.com/twbs/bootstrap/issues/27915#issuecomment-452196628","https://github.com/twbs/bootstrap/pull/27047","https://www.cve.org/CVERecord?id=CVE-2018-20676"],"bugs":[""],"patches":{"twitter-bootstrap":[],"twitter-bootstrap3":[],"twitter-bootstrap4":[]},"tags":{},"packages":[{"name":"twitter-bootstrap","source":"https://ubuntu.com/security/cve?package=twitter-bootstrap","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=twitter-bootstrap","debian":"https://tracker.debian.org/pkg/twitter-bootstrap","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"twitter-bootstrap3","source":"https://ubuntu.com/security/cve?package=twitter-bootstrap3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=twitter-bootstrap3","debian":"https://tracker.debian.org/pkg/twitter-bootstrap3","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.4.0+dfsg-1","component":null,"pocket":"security"}]},{"name":"twitter-bootstrap4","source":"https://ubuntu.com/security/cve?package=twitter-bootstrap4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=twitter-bootstrap4","debian":"https://tracker.debian.org/pkg/twitter-bootstrap4","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-10735","published":"2019-01-09T05:29:00","updated_at":"2025-08-26T11:53:50.029867+00:00","description":"\nIn Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is\npossible in the data-target attribute, a different vulnerability than\nCVE-2018-14041.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/","https://github.com/twbs/bootstrap/issues/20184","https://github.com/twbs/bootstrap/issues/27915#issuecomment-452140906","https://github.com/twbs/bootstrap/pull/23679","https://github.com/twbs/bootstrap/pull/23687","https://github.com/twbs/bootstrap/pull/26460","https://www.cve.org/CVERecord?id=CVE-2016-10735"],"bugs":[""],"patches":{"twitter-bootstrap":[],"twitter-bootstrap3":[],"twitter-bootstrap4":[]},"tags":{},"packages":[{"name":"twitter-bootstrap3","source":"https://ubuntu.com/security/cve?package=twitter-bootstrap3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=twitter-bootstrap3","debian":"https://tracker.debian.org/pkg/twitter-bootstrap3","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.4.0","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.4.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.4.0+dfsg-1","component":null,"pocket":"security"}]},{"name":"twitter-bootstrap","source":"https://ubuntu.com/security/cve?package=twitter-bootstrap","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=twitter-bootstrap","debian":"https://tracker.debian.org/pkg/twitter-bootstrap","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"twitter-bootstrap4","source":"https://ubuntu.com/security/cve?package=twitter-bootstrap4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=twitter-bootstrap4","debian":"https://tracker.debian.org/pkg/twitter-bootstrap4","statuses":[{"release_codename":"impish","status":"not-affected","description":"4.0.0","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.0.0","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.0.0","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.0.0","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.0.0","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.0.0","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.0.0","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.0.0","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.0.0","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.0.0","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.0.0","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.0.0","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.0.0","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.0.0","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.0.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-5882","published":"2019-01-09T00:00:00","updated_at":"2025-08-25T23:13:36.525368+00:00","description":"\nIrssi 1.1.x before 1.1.2 has a use after free when hidden lines are expired\nfrom the scroll buffer.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://irssi.org/security/irssi_sa_2019_01.txt","https://github.com/irssi/irssi/pull/948","https://irssi.org/NEWS/#v1-1-2","https://ubuntu.com/security/notices/USN-3862-1","https://www.cve.org/CVERecord?id=CVE-2019-5882"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=918865"],"patches":{"irssi":["upstream: https://github.com/irssi/irssi//commit/8684ccb45c267fdeaaa779fce9323047aa5a9e38"]},"tags":{},"packages":[{"name":"irssi","source":"https://ubuntu.com/security/cve?package=irssi","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=irssi","debian":"https://tracker.debian.org/pkg/irssi","statuses":[{"release_codename":"trusty","status":"released","description":"0.8.15-5ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.5-1ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1.1.1-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.2-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.8.19-1ubuntu1.8","component":null,"pocket":"security"}]}],"notices_ids":["USN-3862-1"],"notices":[{"id":"USN-3862-1","title":"Irssi vulnerability","summary":"Irssi could be made to crash or execute arbitrary code if it\nreceived a specially crafted input.\n","instructions":"After a standard system update you need to restart Irssi to make all the necessary changes.\n","references":[],"published":"2019-01-17T12:47:01.471039","description":"It was discovered that Irssi incorrectly handled certain inputs.\nAn attacker could possibly use this issue to cause a denial of service\nor to execute arbitrary code.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"irssi","version":"1.0.5-1ubuntu4.1","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"1.0.5-1ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/1.0.5-1ubuntu4.1","pocket":"security"},{"name":"irssi-dev","version":"1.0.5-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/1.0.5-1ubuntu4.1","pocket":"security"}],"cosmic":[{"name":"irssi","version":"1.1.1-1ubuntu1.1","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"1.1.1-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/1.1.1-1ubuntu1.1"},{"name":"irssi-dev","version":"1.1.1-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/1.1.1-1ubuntu1.1"}],"trusty":[{"name":"irssi","version":"0.8.15-5ubuntu3.6","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.15-5ubuntu3.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.15-5ubuntu3.6","pocket":"security"},{"name":"irssi-dev","version":"0.8.15-5ubuntu3.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.15-5ubuntu3.6","pocket":"security"}],"xenial":[{"name":"irssi","version":"0.8.19-1ubuntu1.8","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.19-1ubuntu1.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu1.8","pocket":"security"},{"name":"irssi-dev","version":"0.8.19-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu1.8","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-5882"]}]},{"id":"CVE-2019-5747","published":"2019-01-09T00:00:00","updated_at":"2025-08-25T23:12:30.746887+00:00","description":"\nAn issue was discovered in BusyBox through 1.30.0. An out of bounds read in\nudhcp components (consumed by the DHCP client, server, and/or relay) might\nallow a remote attacker to leak sensitive information from the stack by\nsending a crafted DHCP message. This is related to assurance of a 4-byte\nlength when decoding DHCP_SUBNET. NOTE: this issue exists because of an\nincomplete fix for CVE-2018-20679.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3935-1","https://www.cve.org/CVERecord?id=CVE-2019-5747"],"bugs":["https://bugs.busybox.net/show_bug.cgi?id=11506"],"patches":{"busybox":["upstream: https://git.busybox.net/busybox/commit/?id=74d9f1ba37010face4bd1449df4d60dd84450b06"]},"tags":{},"packages":[{"name":"busybox","source":"https://ubuntu.com/security/cve?package=busybox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=busybox","debian":"https://tracker.debian.org/pkg/busybox","statuses":[{"release_codename":"hirsute","status":"released","description":"1:1.27.2-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1:1.27.2-2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1:1.27.2-2ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"1:1.27.2-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"1:1.27.2-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:1.27.2-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"1:1.27.2-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:1.21.0-1ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.30.1-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:1.22.0-15ubuntu1.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-3935-1"],"notices":[{"id":"USN-3935-1","title":"BusyBox vulnerabilities","summary":"Several security issues were fixed in BusyBox.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-04-03T11:59:48.636617","description":"Tyler Hicks discovered that BusyBox incorrectly handled symlinks inside tar\narchives. If a user or automated system were tricked into processing a\nspecially crafted tar archive, a remote attacker could overwrite arbitrary\nfiles outside of the current directory. This issue only affected Ubuntu\n14.04 LTS and Ubuntu 16.04 LTS. (CVE-2011-5325)\n\nMathias Krause discovered that BusyBox incorrectly handled kernel module\nloading restrictions. A local attacker could possibly use this issue to\nbypass intended restrictions. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2014-9645)\n\nIt was discovered that BusyBox incorrectly handled certain ZIP archives. If\na user or automated system were tricked into processing a specially crafted\nZIP archive, a remote attacker could cause BusyBox to crash, leading to a\ndenial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu\n16.04 LTS. (CVE-2015-9261)\n\nNico Golde discovered that the BusyBox DHCP client incorrectly handled\ncertain malformed domain names. A remote attacker could possibly use this\nissue to cause the DHCP client to crash, leading to a denial of service.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2016-2147)\n\nNico Golde discovered that the BusyBox DHCP client incorrectly handled\ncertain 6RD options. A remote attacker could use this issue to cause the\nDHCP client to crash, leading to a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04\nLTS. (CVE-2016-2148)\n\nIt was discovered that BusyBox incorrectly handled certain bzip2 archives.\nIf a user or automated system were tricked into processing a specially\ncrafted bzip2 archive, a remote attacker could cause BusyBox to crash,\nleading to a denial of service, or possibly execute arbitrary code. This\nissue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2017-15873)\n\nIt was discovered that BusyBox incorrectly handled tab completion. A local\nattacker could possibly use this issue to execute arbitrary code. This\nissue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2017-16544)\n\nIt was discovered that the BusyBox wget utility incorrectly handled certain\nresponses. A remote attacker could use this issue to cause BusyBox to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2018-1000517)\n\nIt was discovered that the BusyBox DHCP utilities incorrectly handled\ncertain memory operations. A remote attacker could possibly use this issue\nto access sensitive information. (CVE-2018-20679, CVE-2019-5747)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"busybox","version":"1:1.27.2-2ubuntu3.2","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"busybox-static","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"busybox-udeb","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"udhcpc","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"udhcpd","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"}],"cosmic":[{"name":"busybox","version":"1:1.27.2-2ubuntu4.1","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"busybox-initramfs","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"busybox-static","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"busybox-syslogd","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"busybox-udeb","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"udhcpc","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"udhcpd","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"}],"trusty":[{"name":"busybox","version":"1:1.21.0-1ubuntu1.4","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"busybox-static","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"busybox-udeb","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"udhcpc","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"udhcpd","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"}],"xenial":[{"name":"busybox","version":"1:1.22.0-15ubuntu1.4","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"busybox-static","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"busybox-udeb","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"udhcpc","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"udhcpd","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2011-5325","CVE-2014-9645","CVE-2015-9261","CVE-2016-2147","CVE-2016-2148","CVE-2017-15873","CVE-2017-16544","CVE-2018-1000517","CVE-2018-20679","CVE-2019-5747"]}]},{"id":"CVE-2018-20679","published":"2019-01-09T00:00:00","updated_at":"2025-08-25T22:53:02.610254+00:00","description":"\nAn issue was discovered in BusyBox before 1.30.0. An out of bounds read in\nudhcp components (consumed by the DHCP server, client, and relay) allows a\nremote attacker to leak sensitive information from the stack by sending a\ncrafted DHCP message. This is related to verification in udhcp_get_option()\nin networking/udhcp/common.c that 4-byte options are indeed 4 bytes.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"this fix is incomplete, see CVE-2019-5747"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://busybox.net/news.html","https://ubuntu.com/security/notices/USN-3935-1","https://www.cve.org/CVERecord?id=CVE-2018-20679"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=918846","https://bugs.busybox.net/show_bug.cgi?id=11506"],"patches":{"busybox":["upstream: https://git.busybox.net/busybox/commit/?id=6d3b4bb24da9a07c263f3c1acf8df85382ff562c"]},"tags":{},"packages":[{"name":"busybox","source":"https://ubuntu.com/security/cve?package=busybox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=busybox","debian":"https://tracker.debian.org/pkg/busybox","statuses":[{"release_codename":"hirsute","status":"released","description":"1:1.27.2-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1:1.27.2-2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1:1.27.2-2ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"1:1.27.2-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"1:1.27.2-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:1.27.2-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"1:1.27.2-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:1.21.0-1ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.30.1-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:1.22.0-15ubuntu1.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-3935-1"],"notices":[{"id":"USN-3935-1","title":"BusyBox vulnerabilities","summary":"Several security issues were fixed in BusyBox.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-04-03T11:59:48.636617","description":"Tyler Hicks discovered that BusyBox incorrectly handled symlinks inside tar\narchives. If a user or automated system were tricked into processing a\nspecially crafted tar archive, a remote attacker could overwrite arbitrary\nfiles outside of the current directory. This issue only affected Ubuntu\n14.04 LTS and Ubuntu 16.04 LTS. (CVE-2011-5325)\n\nMathias Krause discovered that BusyBox incorrectly handled kernel module\nloading restrictions. A local attacker could possibly use this issue to\nbypass intended restrictions. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2014-9645)\n\nIt was discovered that BusyBox incorrectly handled certain ZIP archives. If\na user or automated system were tricked into processing a specially crafted\nZIP archive, a remote attacker could cause BusyBox to crash, leading to a\ndenial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu\n16.04 LTS. (CVE-2015-9261)\n\nNico Golde discovered that the BusyBox DHCP client incorrectly handled\ncertain malformed domain names. A remote attacker could possibly use this\nissue to cause the DHCP client to crash, leading to a denial of service.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2016-2147)\n\nNico Golde discovered that the BusyBox DHCP client incorrectly handled\ncertain 6RD options. A remote attacker could use this issue to cause the\nDHCP client to crash, leading to a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04\nLTS. (CVE-2016-2148)\n\nIt was discovered that BusyBox incorrectly handled certain bzip2 archives.\nIf a user or automated system were tricked into processing a specially\ncrafted bzip2 archive, a remote attacker could cause BusyBox to crash,\nleading to a denial of service, or possibly execute arbitrary code. This\nissue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2017-15873)\n\nIt was discovered that BusyBox incorrectly handled tab completion. A local\nattacker could possibly use this issue to execute arbitrary code. This\nissue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2017-16544)\n\nIt was discovered that the BusyBox wget utility incorrectly handled certain\nresponses. A remote attacker could use this issue to cause BusyBox to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2018-1000517)\n\nIt was discovered that the BusyBox DHCP utilities incorrectly handled\ncertain memory operations. A remote attacker could possibly use this issue\nto access sensitive information. (CVE-2018-20679, CVE-2019-5747)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"busybox","version":"1:1.27.2-2ubuntu3.2","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"busybox-static","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"busybox-udeb","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"udhcpc","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"udhcpd","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"}],"cosmic":[{"name":"busybox","version":"1:1.27.2-2ubuntu4.1","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"busybox-initramfs","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"busybox-static","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"busybox-syslogd","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"busybox-udeb","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"udhcpc","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"udhcpd","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"}],"trusty":[{"name":"busybox","version":"1:1.21.0-1ubuntu1.4","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"busybox-static","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"busybox-udeb","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"udhcpc","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"udhcpd","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"}],"xenial":[{"name":"busybox","version":"1:1.22.0-15ubuntu1.4","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"busybox-static","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"busybox-udeb","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"udhcpc","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"udhcpd","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2011-5325","CVE-2014-9645","CVE-2015-9261","CVE-2016-2147","CVE-2016-2148","CVE-2017-15873","CVE-2017-16544","CVE-2018-1000517","CVE-2018-20679","CVE-2019-5747"]}]},{"id":"CVE-2019-5721","published":"2019-01-08T23:29:00","updated_at":"2025-08-25T23:12:30.746887+00:00","description":"\nIn Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was\naddressed in epan/dissectors/packet-enip.c by changing the\nmemory-management approach so that a use-after-free is avoided.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14470","https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=1c66174ec7aa19e2ddc79178cf59f15a654fc4fe","https://www.wireshark.org/security/wnpa-sec-2019-05.html","https://www.cve.org/CVERecord?id=CVE-2019-5721"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"bionic","status":"not-affected","description":"2.6.5-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.6.5-1~ubuntu18.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"2.6.5-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"2.6.5","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.6.5-1~ubuntu16.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-5719","published":"2019-01-08T23:29:00","updated_at":"2025-08-25T23:12:30.746887+00:00","description":"\nIn Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could\ncrash. This was addressed in epan/dissectors/packet-isakmp.c by properly\nhandling the case of a missing decryption data block.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=15374","https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=b5b02f2a9b8772d8814096f86c60a32889d61f2c","https://www.wireshark.org/security/wnpa-sec-2019-04.html","https://www.cve.org/CVERecord?id=CVE-2019-5719"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"bionic","status":"released","description":"2.6.6-1~ubuntu18.04.0","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"2.6.6-1~ubuntu18.10.0","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.6-1~ubuntu14.04.0","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.6-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.6-1~ubuntu16.04.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":50700,"limit":20,"total_results":79316}