{"cves":[{"id":"CVE-2018-14404","published":"2018-07-19T00:00:00","updated_at":"2025-08-25T22:47:24.264562+00:00","description":"\nA NULL pointer dereference vulnerability exists in the\nxpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing\nan invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case.\nApplications processing untrusted XSL format inputs with the use of the\nlibxml2 library may be vulnerable to a denial of service attack due to a\ncrash of the application.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3739-1","https://ubuntu.com/security/notices/USN-3739-2","https://www.cve.org/CVERecord?id=CVE-2018-14404"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=901817","https://gitlab.gnome.org/GNOME/libxml2/issues/10","https://bugzilla.redhat.com/show_bug.cgi?id=1595985"],"patches":{"libxml2":["other: https://gitlab.gnome.org/GNOME/libxml2/commit/a436374994c47b12d5de1b8b1d191a098fa23594"]},"tags":{},"packages":[{"name":"libxml2","source":"https://ubuntu.com/security/cve?package=libxml2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxml2","debian":"https://tracker.debian.org/pkg/libxml2","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.9.4+dfsg1-6.1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.9.1+dfsg1-3ubuntu4.13","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.9.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.9.3+dfsg1-1ubuntu0.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-3739-2","USN-3739-1"],"notices":[{"id":"USN-3739-2","title":"libxml2 vulnerabilities","summary":"Several security issues were fixed in libxml2.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-08-14T19:58:51.962343","description":"USN-3739-1 fixed a vulnerability in libxml2. This update provides\nthe corresponding update for Ubuntu 12.04.\n\nOriginal advisory details:\n\n Matias Brutti discovered that libxml2 incorrectly handled certain XML files.\n An attacker could possibly use this issue to expose sensitive information.\n (CVE-2016-9318)\n\n It was discovered that libxml2 incorrectly handled certain files.\n An attacker could possibly use this issue to cause a denial of service.\n (CVE-2018-14404)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libxml2","version":"2.7.8.dfsg-5.1ubuntu4.21","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.7.8.dfsg-5.1ubuntu4.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.7.8.dfsg-5.1ubuntu4.21"},{"name":"libxml2-utils","version":"2.7.8.dfsg-5.1ubuntu4.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.7.8.dfsg-5.1ubuntu4.21"},{"name":"python-libxml2","version":"2.7.8.dfsg-5.1ubuntu4.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.7.8.dfsg-5.1ubuntu4.21"}]},"type":"USN","cves_ids":["CVE-2016-9318","CVE-2018-14404"]},{"id":"USN-3739-1","title":"libxml2 vulnerabilities","summary":"Several security issues were fixed in libxml2.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-08-14T17:28:27.853893","description":"Matias Brutti discovered that libxml2 incorrectly handled certain XML files.\nAn attacker could possibly use this issue to expose sensitive information.\n(CVE-2016-9318)\n\nIt was discovered that libxml2 incorrectly handled certain files.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 18.04 LTS. (CVE-2017-16932)\n\nIt was discovered that libxml2 incorrectly handled certain files.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2017-18258, CVE-2018-14404, CVE-2018-14567)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"libxml2","version":"2.9.4+dfsg1-6.1ubuntu1.2","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.9.4+dfsg1-6.1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.4+dfsg1-6.1ubuntu1.2","pocket":"security"},{"name":"libxml2-dev","version":"2.9.4+dfsg1-6.1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.4+dfsg1-6.1ubuntu1.2","pocket":"security"},{"name":"libxml2-doc","version":"2.9.4+dfsg1-6.1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.4+dfsg1-6.1ubuntu1.2","pocket":"security"},{"name":"libxml2-udeb","version":"2.9.4+dfsg1-6.1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.4+dfsg1-6.1ubuntu1.2","pocket":"security"},{"name":"libxml2-utils","version":"2.9.4+dfsg1-6.1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.4+dfsg1-6.1ubuntu1.2","pocket":"security"},{"name":"python-libxml2","version":"2.9.4+dfsg1-6.1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.4+dfsg1-6.1ubuntu1.2","pocket":"security"},{"name":"python3-libxml2","version":"2.9.4+dfsg1-6.1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.4+dfsg1-6.1ubuntu1.2","pocket":"security"}],"trusty":[{"name":"libxml2","version":"2.9.1+dfsg1-3ubuntu4.13","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.9.1+dfsg1-3ubuntu4.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.13","pocket":"security"},{"name":"libxml2-dev","version":"2.9.1+dfsg1-3ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.13","pocket":"security"},{"name":"libxml2-doc","version":"2.9.1+dfsg1-3ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.13","pocket":"security"},{"name":"libxml2-udeb","version":"2.9.1+dfsg1-3ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.13","pocket":"security"},{"name":"libxml2-utils","version":"2.9.1+dfsg1-3ubuntu4.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.13","pocket":"security"},{"name":"python-libxml2","version":"2.9.1+dfsg1-3ubuntu4.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.13","pocket":"security"}],"xenial":[{"name":"libxml2","version":"2.9.3+dfsg1-1ubuntu0.6","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.9.3+dfsg1-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.3+dfsg1-1ubuntu0.6","pocket":"security"},{"name":"libxml2-dev","version":"2.9.3+dfsg1-1ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.3+dfsg1-1ubuntu0.6","pocket":"security"},{"name":"libxml2-doc","version":"2.9.3+dfsg1-1ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.3+dfsg1-1ubuntu0.6","pocket":"security"},{"name":"libxml2-udeb","version":"2.9.3+dfsg1-1ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.3+dfsg1-1ubuntu0.6","pocket":"security"},{"name":"libxml2-utils","version":"2.9.3+dfsg1-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.3+dfsg1-1ubuntu0.6","pocket":"security"},{"name":"python-libxml2","version":"2.9.3+dfsg1-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.3+dfsg1-1ubuntu0.6","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-9318","CVE-2017-16932","CVE-2017-18258","CVE-2018-14404","CVE-2018-14567"]}]},{"id":"CVE-2018-12911","published":"2018-07-19T00:00:00","updated_at":"2025-08-25T22:46:41.256838+00:00","description":"\nWebKitGTK+ 2.20.3 has an off-by-one error, with a resultant out-of-bounds\nwrite, in the get_simple_globs functions in\nThirdParty/xdgmime/src/xdgmimecache.c and\nThirdParty/xdgmime/src/xdgmimeglob.c.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://webkitgtk.org/security/WSA-2018-0006.html","https://ubuntu.com/security/notices/USN-3743-1","https://www.cve.org/CVERecord?id=CVE-2018-12911"],"bugs":["https://bugs.webkit.org/show_bug.cgi?id=186554"],"patches":{"webkitgtk":[],"webkit2gtk":["upstream: https://trac.webkit.org/changeset/233404/webkit"],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"qtwebkit":[]},"tags":{},"packages":[{"name":"qtwebkit","source":"https://ubuntu.com/security/cve?package=qtwebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit","debian":"https://tracker.debian.org/pkg/qtwebkit","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"impish","status":"not-affected","description":"2.20.5-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.20.5-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.20.5-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.20.5-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.20.5-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.20.5-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.20.5-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.20.5-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.20.5-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.20.5-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.20.5-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.20.4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.20.5-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.20.5-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.20.5-1","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-3743-1"],"notices":[{"id":"USN-3743-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany, to make all the necessary changes.\n","references":[],"published":"2018-08-16T12:57:54.779603","description":"A large number of security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"webkit2gtk","version":"2.20.5-0ubuntu0.18.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.20.5-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.5-0ubuntu0.18.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.20.5-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.5-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.20.5-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.5-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.20.5-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.5-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.20.5-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.5-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.20.5-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.5-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.20.5-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.5-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.20.5-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.5-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.20.5-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.5-0ubuntu0.18.04.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.20.5-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.5-0ubuntu0.18.04.1","pocket":"security"}],"xenial":[{"name":"webkit2gtk","version":"2.20.5-0ubuntu0.16.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.20.5-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.5-0ubuntu0.16.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.20.5-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.5-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.20.5-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.5-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.20.5-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.5-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.20.5-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.5-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.20.5-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.5-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.20.5-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.5-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.20.5-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.5-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.20.5-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.5-0ubuntu0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-12911","CVE-2018-4246","CVE-2018-4261","CVE-2018-4262","CVE-2018-4263","CVE-2018-4264","CVE-2018-4265","CVE-2018-4266","CVE-2018-4267","CVE-2018-4270","CVE-2018-4272","CVE-2018-4273","CVE-2018-4278","CVE-2018-4284"]}]},{"id":"CVE-2017-7481","published":"2018-07-19T00:00:00","updated_at":"2025-08-25T22:37:43.981148+00:00","description":"\nAnsible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark\nlookup-plugin results as unsafe. If an attacker could control the results\nof lookup() calls, they could inject Unicode strings to be parsed by the\njinja2 templating system, resulting in code execution. By default, the\njinja2 templating language is now marked as 'unsafe' and is not evaluated.","ubuntu_description":"","notes":[{"author":"john-breton","note":"Vulnerable code introduced in version 2.0"}],"codename":null,"priority":"low","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4072-1","https://www.cve.org/CVERecord?id=CVE-2017-7481"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1450018"],"patches":{"ansible":["upstream: https://github.com/ansible/ansible/commit/ed56f51f185a1ffd7ea57130d260098686fcc7c2"]},"tags":{},"packages":[{"name":"ansible","source":"https://ubuntu.com/security/cve?package=ansible","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ansible","debian":"https://tracker.debian.org/pkg/ansible","statuses":[{"release_codename":"impish","status":"not-affected","description":"2.6.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.6.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.6.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.6.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.6.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.5.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.6.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.6.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.6.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.6.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.6.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.3.1.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.0.0.2-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.6.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.6.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.6.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-4072-1"],"notices":[{"id":"USN-4072-1","title":"Ansible vulnerabilities","summary":"Several security issues were fixed in Ansible.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-07-24T23:07:07.510996","description":"It was discovered that Ansible failed to properly handle sensitive information.\nA local attacker could use those vulnerabilities to extract them.\n(CVE-2017-7481)\n(CVE-2018-10855)\n(CVE-2018-16837)\n(CVE-2018-16876)\n(CVE-2019-10156)\n\nIt was discovered that Ansible could load configuration files from the current\nworking directory containing crafted commands. An attacker could run arbitrary\ncode as result.\n(CVE-2018-10874)\n(CVE-2018-10875)\n\nIt was discovered that Ansible fetch module had a path traversal vulnerability.\nA local attacker could copy and overwrite files outside of the specified\ndestination.\n(CVE-2019-3828)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"ansible","version":"2.5.1+dfsg-1ubuntu0.1","description":"Configuration management, deployment, and task execution system","is_source":true},{"name":"ansible","version":"2.5.1+dfsg-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ansible","version_link":"https://launchpad.net/ubuntu/+source/ansible/2.5.1+dfsg-1ubuntu0.1","pocket":"security"}],"disco":[{"name":"ansible","version":"2.7.8+dfsg-1ubuntu0.19.04.1","description":"Configuration management, deployment, and task execution system","is_source":true},{"name":"ansible","version":"2.7.8+dfsg-1ubuntu0.19.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ansible","version_link":"https://launchpad.net/ubuntu/+source/ansible/2.7.8+dfsg-1ubuntu0.19.04.1"},{"name":"ansible-doc","version":"2.7.8+dfsg-1ubuntu0.19.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ansible","version_link":"https://launchpad.net/ubuntu/+source/ansible/2.7.8+dfsg-1ubuntu0.19.04.1"}],"xenial":[{"name":"ansible","version":"2.0.0.2-2ubuntu1.3","description":"Configuration management, deployment, and task execution system","is_source":true},{"name":"ansible","version":"2.0.0.2-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ansible","version_link":"https://launchpad.net/ubuntu/+source/ansible/2.0.0.2-2ubuntu1.3","pocket":"security"},{"name":"ansible-fireball","version":"2.0.0.2-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ansible","version_link":"https://launchpad.net/ubuntu/+source/ansible/2.0.0.2-2ubuntu1.3","pocket":"security"},{"name":"ansible-node-fireball","version":"2.0.0.2-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ansible","version_link":"https://launchpad.net/ubuntu/+source/ansible/2.0.0.2-2ubuntu1.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-7481","CVE-2018-10855","CVE-2018-10874","CVE-2018-10875","CVE-2018-16837","CVE-2018-16876","CVE-2019-10156","CVE-2019-3828"]}]},{"id":"CVE-2018-14364","published":"2018-07-18T19:29:00","updated_at":"2025-08-25T22:47:15.111315+00:00","description":"\nGitLab Community and Enterprise Edition before 10.7.7, 10.8.x before\n10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access\nand resultant remote code execution via the GitLab projects import\ncomponent.","ubuntu_description":"","notes":[{"author":"msalvatore","note":"Affects GitLab CE/EE 8.9.0 and later."}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://about.gitlab.com/2018/07/17/critical-security-release-gitlab-11-dot-0-dot-4-released/","https://www.cve.org/CVERecord?id=CVE-2018-14364"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=904026"],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-8011","published":"2018-07-18T14:29:00","updated_at":"2025-08-25T22:59:28.004322+00:00","description":"\nBy specially crafting HTTP requests, the mod_md challenge handler would\ndereference a NULL pointer and cause the child process to segfault. This\ncould be used to DoS the server. Fixed in Apache HTTP Server 2.4.34\n(Affected 2.4.33).","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"only affects 2.4.33"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2018/07/18/2","https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2018-8011","https://www.cve.org/CVERecord?id=CVE-2018-8011"],"bugs":[""],"patches":{"apache2":[]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"artful","status":"not-affected","description":"2.4.27-2ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.4.29-1ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"2.4.7-1ubuntu4.20","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.34","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.18-2ubuntu3.9","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-3091","published":"2018-07-18T13:29:00","updated_at":"2025-07-11T07:41:16.188036+00:00","description":"\nVulnerability in the Oracle VM VirtualBox component of Oracle\nVirtualization (subcomponent: Core). The supported version that is affected\nis Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated\nattacker with logon to the infrastructure where Oracle VM VirtualBox\nexecutes to compromise Oracle VM VirtualBox. Successful attacks require\nhuman interaction from a person other than the attacker and while the\nvulnerability is in Oracle VM VirtualBox, attacks may significantly impact\nadditional products. Successful attacks of this vulnerability can result in\nunauthorized access to critical data or complete access to all Oracle VM\nVirtualBox accessible data. CVSS 3.0 Base Score 6.3 (Confidentiality\nimpacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-3091"],"bugs":[""],"patches":{"virtualbox":[]},"tags":{},"packages":[{"name":"virtualbox","source":"https://ubuntu.com/security/cve?package=virtualbox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=virtualbox","debian":"https://tracker.debian.org/pkg/virtualbox","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-3090","published":"2018-07-18T13:29:00","updated_at":"2025-07-11T07:41:09.568264+00:00","description":"\nVulnerability in the Oracle VM VirtualBox component of Oracle\nVirtualization (subcomponent: Core). The supported version that is affected\nis Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated\nattacker with logon to the infrastructure where Oracle VM VirtualBox\nexecutes to compromise Oracle VM VirtualBox. Successful attacks require\nhuman interaction from a person other than the attacker and while the\nvulnerability is in Oracle VM VirtualBox, attacks may significantly impact\nadditional products. Successful attacks of this vulnerability can result in\ntakeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality,\nIntegrity and Availability impacts). CVSS Vector:\n(CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-3090"],"bugs":[""],"patches":{"virtualbox":[]},"tags":{},"packages":[{"name":"virtualbox","source":"https://ubuntu.com/security/cve?package=virtualbox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=virtualbox","debian":"https://tracker.debian.org/pkg/virtualbox","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-3089","published":"2018-07-18T13:29:00","updated_at":"2025-07-11T07:41:09.568264+00:00","description":"\nVulnerability in the Oracle VM VirtualBox component of Oracle\nVirtualization (subcomponent: Core). The supported version that is affected\nis Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated\nattacker with logon to the infrastructure where Oracle VM VirtualBox\nexecutes to compromise Oracle VM VirtualBox. Successful attacks require\nhuman interaction from a person other than the attacker and while the\nvulnerability is in Oracle VM VirtualBox, attacks may significantly impact\nadditional products. Successful attacks of this vulnerability can result in\ntakeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality,\nIntegrity and Availability impacts). CVSS Vector:\n(CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-3089"],"bugs":[""],"patches":{"virtualbox":[]},"tags":{},"packages":[{"name":"virtualbox","source":"https://ubuntu.com/security/cve?package=virtualbox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=virtualbox","debian":"https://tracker.debian.org/pkg/virtualbox","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-3088","published":"2018-07-18T13:29:00","updated_at":"2025-07-11T07:41:09.568264+00:00","description":"\nVulnerability in the Oracle VM VirtualBox component of Oracle\nVirtualization (subcomponent: Core). The supported version that is affected\nis Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated\nattacker with logon to the infrastructure where Oracle VM VirtualBox\nexecutes to compromise Oracle VM VirtualBox. Successful attacks require\nhuman interaction from a person other than the attacker and while the\nvulnerability is in Oracle VM VirtualBox, attacks may significantly impact\nadditional products. Successful attacks of this vulnerability can result in\ntakeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality,\nIntegrity and Availability impacts). CVSS Vector:\n(CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-3088"],"bugs":[""],"patches":{"virtualbox":[]},"tags":{},"packages":[{"name":"virtualbox","source":"https://ubuntu.com/security/cve?package=virtualbox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=virtualbox","debian":"https://tracker.debian.org/pkg/virtualbox","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-3087","published":"2018-07-18T13:29:00","updated_at":"2025-07-11T07:41:09.568264+00:00","description":"\nVulnerability in the Oracle VM VirtualBox component of Oracle\nVirtualization (subcomponent: Core). The supported version that is affected\nis Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated\nattacker with logon to the infrastructure where Oracle VM VirtualBox\nexecutes to compromise Oracle VM VirtualBox. Successful attacks require\nhuman interaction from a person other than the attacker and while the\nvulnerability is in Oracle VM VirtualBox, attacks may significantly impact\nadditional products. Successful attacks of this vulnerability can result in\ntakeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality,\nIntegrity and Availability impacts). CVSS Vector:\n(CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-3087"],"bugs":[""],"patches":{"virtualbox":[]},"tags":{},"packages":[{"name":"virtualbox","source":"https://ubuntu.com/security/cve?package=virtualbox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=virtualbox","debian":"https://tracker.debian.org/pkg/virtualbox","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-3086","published":"2018-07-18T13:29:00","updated_at":"2025-07-11T07:41:09.568264+00:00","description":"\nVulnerability in the Oracle VM VirtualBox component of Oracle\nVirtualization (subcomponent: Core). The supported version that is affected\nis Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated\nattacker with logon to the infrastructure where Oracle VM VirtualBox\nexecutes to compromise Oracle VM VirtualBox. Successful attacks require\nhuman interaction from a person other than the attacker and while the\nvulnerability is in Oracle VM VirtualBox, attacks may significantly impact\nadditional products. Successful attacks of this vulnerability can result in\ntakeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality,\nIntegrity and Availability impacts). CVSS Vector:\n(CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-3086"],"bugs":[""],"patches":{"virtualbox":[]},"tags":{},"packages":[{"name":"virtualbox","source":"https://ubuntu.com/security/cve?package=virtualbox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=virtualbox","debian":"https://tracker.debian.org/pkg/virtualbox","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-3085","published":"2018-07-18T13:29:00","updated_at":"2025-07-11T07:41:09.568264+00:00","description":"\nVulnerability in the Oracle VM VirtualBox component of Oracle\nVirtualization (subcomponent: Core). The supported version that is affected\nis Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated\nattacker with logon to the infrastructure where Oracle VM VirtualBox\nexecutes to compromise Oracle VM VirtualBox. Successful attacks require\nhuman interaction from a person other than the attacker and while the\nvulnerability is in Oracle VM VirtualBox, attacks may significantly impact\nadditional products. Successful attacks of this vulnerability can result in\nunauthorized creation, deletion or modification access to critical data or\nall Oracle VM VirtualBox accessible data as well as unauthorized read\naccess to a subset of Oracle VM VirtualBox accessible data and unauthorized\nability to cause a hang or frequently repeatable crash (complete DOS) of\nOracle VM VirtualBox. CVSS 3.0 Base Score 8.5 (Confidentiality, Integrity\nand Availability impacts). CVSS Vector:\n(CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:H).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-3085"],"bugs":[""],"patches":{"virtualbox":[]},"tags":{},"packages":[{"name":"virtualbox","source":"https://ubuntu.com/security/cve?package=virtualbox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=virtualbox","debian":"https://tracker.debian.org/pkg/virtualbox","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-3055","published":"2018-07-18T13:29:00","updated_at":"2025-07-11T07:41:09.568264+00:00","description":"\nVulnerability in the Oracle VM VirtualBox component of Oracle\nVirtualization (subcomponent: Core). The supported version that is affected\nis Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated\nattacker with logon to the infrastructure where Oracle VM VirtualBox\nexecutes to compromise Oracle VM VirtualBox. Successful attacks require\nhuman interaction from a person other than the attacker and while the\nvulnerability is in Oracle VM VirtualBox, attacks may significantly impact\nadditional products. Successful attacks of this vulnerability can result in\nunauthorized ability to cause a hang or frequently repeatable crash\n(complete DOS) of Oracle VM VirtualBox and unauthorized read access to a\nsubset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 7.1\n(Confidentiality and Availability impacts). CVSS Vector:\n(CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:H).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-3055"],"bugs":[""],"patches":{"virtualbox":[]},"tags":{},"packages":[{"name":"virtualbox","source":"https://ubuntu.com/security/cve?package=virtualbox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=virtualbox","debian":"https://tracker.debian.org/pkg/virtualbox","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-3005","published":"2018-07-18T13:29:00","updated_at":"2025-07-11T07:41:09.568264+00:00","description":"\nVulnerability in the Oracle VM VirtualBox component of Oracle\nVirtualization (subcomponent: Core). The supported version that is affected\nis Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated\nattacker with logon to the infrastructure where Oracle VM VirtualBox\nexecutes to compromise Oracle VM VirtualBox. Successful attacks of this\nvulnerability can result in unauthorized ability to cause a partial denial\nof service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 4.0\n(Availability impacts). CVSS Vector:\n(CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-3005"],"bugs":[""],"patches":{"virtualbox":[]},"tags":{},"packages":[{"name":"virtualbox","source":"https://ubuntu.com/security/cve?package=virtualbox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=virtualbox","debian":"https://tracker.debian.org/pkg/virtualbox","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-2973","published":"2018-07-18T13:29:00","updated_at":"2025-08-25T22:53:48.503713+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded component of Oracle Java SE\n(subcomponent: JSSE). Supported versions that are affected are Java SE:\n6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Difficult to\nexploit vulnerability allows unauthenticated attacker with network access\nvia SSL/TLS to compromise Java SE, Java SE Embedded. Successful attacks of\nthis vulnerability can result in unauthorized creation, deletion or\nmodification access to critical data or all Java SE, Java SE Embedded\naccessible data. Note: This vulnerability applies to Java deployments,\ntypically in clients running sandboxed Java Web Start applications or\nsandboxed Java applets, that load and run untrusted code (e.g., code that\ncomes from the internet) and rely on the Java sandbox for security. This\nvulnerability does not apply to Java deployments, typically in servers,\nthat load and run only trusted code (e.g., code installed by an\nadministrator). CVSS 3.0 Base Score 5.9 (Integrity impacts). CVSS Vector:\n(CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).","ubuntu_description":"","notes":[{"author":"sbeattie","note":"Oracle Java only"}],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","https://www.cve.org/CVERecord?id=CVE-2018-2973"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[],"openjdk-8":[],"openjdk-9":[],"openjdk-lts":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-lts","source":"https://ubuntu.com/security/cve?package=openjdk-lts","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-lts","debian":"https://tracker.debian.org/pkg/openjdk-lts","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"Oracle Java only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.0.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-2964","published":"2018-07-18T13:29:00","updated_at":"2025-08-25T22:53:48.503713+00:00","description":"\nVulnerability in the Java SE component of Oracle Java SE (subcomponent:\nDeployment). Supported versions that are affected are Java SE: 8u172 and\n10.0.1. Difficult to exploit vulnerability allows unauthenticated attacker\nwith network access via multiple protocols to compromise Java SE.\nSuccessful attacks require human interaction from a person other than the\nattacker and while the vulnerability is in Java SE, attacks may\nsignificantly impact additional products. Successful attacks of this\nvulnerability can result in takeover of Java SE. Note: This vulnerability\napplies to Java deployments, typically in clients running sandboxed Java\nWeb Start applications or sandboxed Java applets, that load and run\nuntrusted code (e.g., code that comes from the internet) and rely on the\nJava sandbox for security. This vulnerability does not apply to Java\ndeployments, typically in servers, that load and run only trusted code\n(e.g., code installed by an administrator). CVSS 3.0 Base Score 8.3\n(Confidentiality, Integrity and Availability impacts). CVSS Vector:\n(CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).","ubuntu_description":"","notes":[{"author":"sbeattie","note":"deployment component only in oracle java"}],"codename":null,"priority":"medium","cvss3":8.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","https://www.cve.org/CVERecord?id=CVE-2018-2964"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[],"openjdk-8":[],"openjdk-9":[],"openjdk-lts":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [oracle only]","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [oracle only]","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"oracle only","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"oracle only","component":null,"pocket":"security"}]},{"name":"openjdk-lts","source":"https://ubuntu.com/security/cve?package=openjdk-lts","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-lts","debian":"https://tracker.debian.org/pkg/openjdk-lts","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-2942","published":"2018-07-18T13:29:00","updated_at":"2025-08-25T22:53:48.503713+00:00","description":"\nVulnerability in the Java SE component of Oracle Java SE (subcomponent:\nWindows DLL). Supported versions that are affected are Java SE: 7u181 and\n8u172. Difficult to exploit vulnerability allows unauthenticated attacker\nwith network access via multiple protocols to compromise Java SE.\nSuccessful attacks require human interaction from a person other than the\nattacker and while the vulnerability is in Java SE, attacks may\nsignificantly impact additional products. Successful attacks of this\nvulnerability can result in takeover of Java SE. Note: Applies to client\nand server deployment of Java. This vulnerability can be exploited through\nsandboxed Java Web Start applications and sandboxed Java applets. It can\nalso be exploited by supplying data to APIs in the specified Component\nwithout using sandboxed Java Web Start applications or sandboxed Java\napplets, such as through a web service. CVSS 3.0 Base Score 8.3\n(Confidentiality, Integrity and Availability impacts). CVSS Vector:\n(CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).","ubuntu_description":"","notes":[{"author":"sbeattie","note":"affects Windows DLLs, i.e. oracle java only"}],"codename":null,"priority":"medium","cvss3":8.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-2942"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[],"openjdk-8":[],"icedtea-web":[],"openjdk-9":[],"openjdk-lts":[]},"tags":{},"packages":[{"name":"icedtea-web","source":"https://ubuntu.com/security/cve?package=icedtea-web","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=icedtea-web","debian":"https://tracker.debian.org/pkg/icedtea-web","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [oracle only]","component":null,"pocket":"security"}]},{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [oracle only]","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [oracle only]","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"oracle only","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"oracle only","component":null,"pocket":"security"}]},{"name":"openjdk-lts","source":"https://ubuntu.com/security/cve?package=openjdk-lts","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-lts","debian":"https://tracker.debian.org/pkg/openjdk-lts","statuses":[{"release_codename":"bionic","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-2941","published":"2018-07-18T13:29:00","updated_at":"2025-08-26T12:09:06.577984+00:00","description":"\nVulnerability in the Java SE component of Oracle Java SE (subcomponent:\nJavaFX). Supported versions that are affected are Java SE: 7u181, 8u172 and\n10.0.1. Difficult to exploit vulnerability allows unauthenticated attacker\nwith network access via multiple protocols to compromise Java SE.\nSuccessful attacks require human interaction from a person other than the\nattacker and while the vulnerability is in Java SE, attacks may\nsignificantly impact additional products. Successful attacks of this\nvulnerability can result in takeover of Java SE. Note: This vulnerability\napplies to Java deployments, typically in clients running sandboxed Java\nWeb Start applications or sandboxed Java applets, that load and run\nuntrusted code (e.g., code that comes from the internet) and rely on the\nJava sandbox for security. This vulnerability does not apply to Java\ndeployments, typically in servers, that load and run only trusted code\n(e.g., code installed by an administrator). CVSS 3.0 Base Score 8.3\n(Confidentiality, Integrity and Availability impacts). CVSS Vector:\n(CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-2941"],"bugs":[""],"patches":{"openjfx":[]},"tags":{},"packages":[{"name":"openjfx","source":"https://ubuntu.com/security/cve?package=openjfx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjfx","debian":"https://tracker.debian.org/pkg/openjfx","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"11.0.2+1-1~18.04.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"11.0.2+1-1~18.10","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"11.0.2+1-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"11.0.2+1-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"11.0.2+1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"11.0.2+1-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"11.0.2+1-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"11.0.2+1-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"11.0.2+1-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"11.0.2+1-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"11.0.2+1-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"11.0.2+1-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"11.0.2+1-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"11.0.2+1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"11.0.2+1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"11.0.2+1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"11.0.2+1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-2940","published":"2018-07-18T13:29:00","updated_at":"2025-08-25T22:53:48.503713+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded component of Oracle Java SE\n(subcomponent: Libraries). Supported versions that are affected are Java\nSE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Easily\nexploitable vulnerability allows unauthenticated attacker with network\naccess via multiple protocols to compromise Java SE, Java SE Embedded.\nSuccessful attacks require human interaction from a person other than the\nattacker. Successful attacks of this vulnerability can result in\nunauthorized read access to a subset of Java SE, Java SE Embedded\naccessible data. Note: This vulnerability applies to Java deployments,\ntypically in clients running sandboxed Java Web Start applications or\nsandboxed Java applets, that load and run untrusted code (e.g., code that\ncomes from the internet) and rely on the Java sandbox for security. This\nvulnerability does not apply to Java deployments, typically in servers,\nthat load and run only trusted code (e.g., code installed by an\nadministrator). CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS\nVector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N).","ubuntu_description":"","notes":[{"author":"sbeattie","note":"oracle java only"}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","https://www.cve.org/CVERecord?id=CVE-2018-2940"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[],"openjdk-8":[],"openjdk-9":[],"openjdk-lts":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [oracle only]","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"upstream","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [oracle only]","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"oracle only","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"oracle only","component":null,"pocket":"security"}]},{"name":"openjdk-lts","source":"https://ubuntu.com/security/cve?package=openjdk-lts","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-lts","debian":"https://tracker.debian.org/pkg/openjdk-lts","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-2938","published":"2018-07-18T13:29:00","updated_at":"2025-08-25T22:53:48.503713+00:00","description":"\nVulnerability in the Java SE component of Oracle Java SE (subcomponent:\nJava DB). Supported versions that are affected are Java SE: 6u191, 7u181\nand 8u172. Difficult to exploit vulnerability allows unauthenticated\nattacker with network access via multiple protocols to compromise Java SE.\nWhile the vulnerability is in Java SE, attacks may significantly impact\nadditional products. Successful attacks of this vulnerability can result in\ntakeover of Java SE. Note: This vulnerability can only be exploited by\nsupplying data to APIs in the specified Component without using Untrusted\nJava Web Start applications or Untrusted Java applets, such as through a\nweb service. CVE-2018-2938 addresses CVE-2018-1313. CVSS 3.0 Base Score 9.0\n(Confidentiality, Integrity and Availability impacts). CVSS Vector:\n(CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).","ubuntu_description":"","notes":[{"author":"sbeattie","note":"CVE for embedded copy of Derby, original CVE was CVE-2018-1313.\nOracle's solution was to not include Derby anymore.\nderby is not included in openjdk, so not affected"}],"codename":null,"priority":"medium","cvss3":9.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.0,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-2938"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[],"openjdk-8":[],"icedtea-web":[],"openjdk-9":[]},"tags":{},"packages":[{"name":"icedtea-web","source":"https://ubuntu.com/security/cve?package=icedtea-web","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=icedtea-web","debian":"https://tracker.debian.org/pkg/icedtea-web","statuses":[{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":52220,"limit":20,"total_results":79316}