{"cves":[{"id":"CVE-2017-5452","published":"2018-06-11T21:29:00","updated_at":"2025-08-25T22:34:24.882299+00:00","description":"\nMalicious sites can display a spoofed addressbar on a page when the\nexisting location bar on the new page is scrolled out of view if an HTML\neditable page element is user selected. Note: This attack only affects\nFirefox for Android. Other operating systems are not affected. This\nvulnerability affects Firefox < 53.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Android only"}],"codename":null,"priority":"low","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2017-10/#CVE-2017-5452","https://www.cve.org/CVERecord?id=CVE-2017-5452"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"53.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5450","published":"2018-06-11T21:29:00","updated_at":"2025-08-25T22:34:24.882299+00:00","description":"\nA mechanism to spoof the Firefox for Android addressbar using a\n\"javascript:\" URI. On Firefox for Android, the base domain is parsed\nincorrectly, making the resulting location less visibly a spoofed site and\nshowing an incorrect domain in appended notifications. This vulnerability\naffects Firefox < 53.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Android only"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2017-10/#CVE-2017-5450","https://www.cve.org/CVERecord?id=CVE-2017-5450"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"53.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5425","published":"2018-06-11T21:29:00","updated_at":"2025-08-25T22:34:11.584873+00:00","description":"\nThe Gecko Media Plugin sandbox allows access to local files that match\nspecific regular expressions. On OS OX, this matching allows access to some\ndata in subdirectories of \"/private/var\" that could expose personal or\ntemporary data. This has been updated to not allow access to \"/private/var\"\nand its subdirectories. Note: this issue only affects OS X. Other operating\nsystems are not affected. This vulnerability affects Firefox < 52 and\nThunderbird < 52.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"OS X only"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2017-05/#CVE-2017-5425","https://www.cve.org/CVERecord?id=CVE-2017-5425"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"52.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5411","published":"2018-06-11T21:29:00","updated_at":"2025-08-25T22:34:07.041167+00:00","description":"\nA use-after-free can occur during buffer storage operations within the\nANGLE graphics library, used for WebGL content. The buffer storage can be\nfreed while still in use in some circumstances, leading to a potentially\nexploitable crash. Note: This issue is in \"libGLES\", which is only in use\non Windows. Other operating systems are not affected. This vulnerability\naffects Firefox < 52 and Thunderbird < 52.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Windows only"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2017-05/#CVE-2017-5411","https://www.cve.org/CVERecord?id=CVE-2017-5411"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"52.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5409","published":"2018-06-11T21:29:00","updated_at":"2025-08-25T22:34:07.041167+00:00","description":"\nThe Mozilla Windows updater can be called by a non-privileged user to\ndelete an arbitrary local file by passing a special path to the callback\nparameter through the Mozilla Maintenance Service, which has privileged\naccess. Note: This attack requires local system access and only affects\nWindows. Other operating systems are not affected. This vulnerability\naffects Firefox ESR < 45.8 and Firefox < 52.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Windows only"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2017-05/#CVE-2017-5409","https://www.cve.org/CVERecord?id=CVE-2017-5409"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"52.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5395","published":"2018-06-11T21:29:00","updated_at":"2025-08-25T22:34:02.565151+00:00","description":"\nMalicious sites can display a spoofed location bar on a subsequently loaded\npage when the existing location bar on the new page is scrolled out of view\nif navigations between pages can be timed correctly. Note: This issue only\naffects Firefox for Android. Other operating systems are not affected. This\nvulnerability affects Firefox < 51.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2017-01/#CVE-2017-5395","https://www.cve.org/CVERecord?id=CVE-2017-5395"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"only affects Firefox for Android","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [only affects Firefox for Android]]","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"51","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"only affects Firefox for Android","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"only affects Firefox for Android","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5394","published":"2018-06-11T21:29:00","updated_at":"2025-08-25T22:33:56.905907+00:00","description":"\nA location bar spoofing attack where the location bar of loaded page will\nbe shown over the content of another tab due to a series of JavaScript\nevents combined with fullscreen mode. Note: This issue only affects Firefox\nfor Android. Other operating systems are not affected. This vulnerability\naffects Firefox < 51.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2017-01/#CVE-2017-5394","https://www.cve.org/CVERecord?id=CVE-2017-5394"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"only affects Firefox for Android","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"51","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"only affects Firefox for Android","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"only affects Firefox for Android","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [only affects Firefox for Android]]","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5392","published":"2018-06-11T21:29:00","updated_at":"2025-08-25T22:33:56.905907+00:00","description":"\nWeak proxy objects have weak references on multiple threads when they\nshould only have them on one, resulting in incorrect memory usage and\ncorruption, which leads to potentially exploitable crashes. Note: This\nissue only affects Firefox for Android. Other operating systems are not\naffected. This vulnerability affects Firefox < 51.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2017-01/#CVE-2017-5392","https://www.cve.org/CVERecord?id=CVE-2017-5392"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"only affects Firefox for Android","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"51","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"only affects Firefox for Android","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"only affects Firefox for Android","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [only affects Firefox for Android]]","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9072","published":"2018-06-11T21:29:00","updated_at":"2025-08-25T22:13:05.268652+00:00","description":"\nWhen a new Firefox profile is created on 64-bit Windows installations, the\nsandbox for 64-bit NPAPI plugins is not enabled by default. Note: This\nissue only affects 64-bit Windows. 32-bit Windows and other operating\nsystems are unaffected. This vulnerability affects Firefox < 50.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"windows only"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2016-89/","https://www.cve.org/CVERecord?id=CVE-2016-9072"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"50","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [windows only]]","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"precise","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [windows only]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9065","published":"2018-06-11T21:29:00","updated_at":"2025-08-25T22:13:05.268652+00:00","description":"\nThe location bar in Firefox for Android can be spoofed by forcing a user\ninto fullscreen mode, blocking its exiting, and creating of a fake location\nbar without any user notification. Note: This issue only affects Firefox\nfor Android. Other versions and operating systems are unaffected. This\nvulnerability affects Firefox < 50.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"firefox for android only"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2016-89/","https://www.cve.org/CVERecord?id=CVE-2016-9065"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"50","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [android only]]","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"precise","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [android only]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9062","published":"2018-06-11T21:29:00","updated_at":"2025-08-25T22:12:59.869503+00:00","description":"\nPrivate browsing mode leaves metadata information, such as URLs, for sites\nvisited in \"browser.db\" and \"browser.db-wal\" files within the Firefox\nprofile after the mode is exited. Note: This issue only affects Firefox for\nAndroid. Other versions and operating systems are unaffected. This\nvulnerability affects Firefox < 50.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"firefox for android"}],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.3,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2016-89/","https://www.cve.org/CVERecord?id=CVE-2016-9062"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"50","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [android only]]","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"precise","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [android only]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9061","published":"2018-06-11T21:29:00","updated_at":"2025-08-25T22:12:59.869503+00:00","description":"\nA previously installed malicious Android application which defines a\nspecific signature-level permissions used by Firefox can access API keys\nmeant for Firefox only. Note: This issue only affects Firefox for Android.\nOther versions and operating systems are unaffected. This vulnerability\naffects Firefox < 50.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"firefox for android only"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2016-89/","https://www.cve.org/CVERecord?id=CVE-2016-9061"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"50","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [android only]]","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"precise","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [android only]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-5299","published":"2018-06-11T21:29:00","updated_at":"2025-08-25T22:06:18.398724+00:00","description":"\nA previously installed malicious Android application with same\nsignature-level permissions as Firefox can intercept AuthTokens meant for\nFirefox only. Note: This issue only affects Firefox for Android. Other\nversions and operating systems are unaffected. This vulnerability affects\nFirefox < 50.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"firefox for android only"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2016-89/","https://www.cve.org/CVERecord?id=CVE-2016-5299"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"50","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [android only]]","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"precise","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [android only]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-5298","published":"2018-06-11T21:29:00","updated_at":"2025-08-25T22:06:12.757059+00:00","description":"\nA mechanism where disruption of the loading of a new web page can cause the\nprevious page's favicon and SSL indicator to not be reset when the new page\nis loaded. Note: this issue only affects Firefox for Android. Desktop\nFirefox is unaffected. This vulnerability affects Firefox < 50.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"firefox for android only"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2016-89/","https://www.cve.org/CVERecord?id=CVE-2016-5298"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"50","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [android only]]","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"precise","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"android only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [android only]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-5295","published":"2018-06-11T21:29:00","updated_at":"2025-08-25T22:06:12.757059+00:00","description":"\nThis vulnerability allows an attacker to use the Mozilla Maintenance\nService to escalate privilege by having the Maintenance Service invoke the\nMozilla Updater to run malicious local files. This vulnerability requires\nlocal system access and is a variant of MFSA2013-44. Note: this issue only\naffects Windows operating systems. This vulnerability affects Firefox < 50.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"windows only"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2016-89/","https://www.cve.org/CVERecord?id=CVE-2016-5295"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"50","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [windows only]]","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"precise","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [windows only]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-5294","published":"2018-06-11T21:29:00","updated_at":"2025-08-25T22:06:12.757059+00:00","description":"\nThe Mozilla Updater can be made to choose an arbitrary target working\ndirectory for output files resulting from the update process. This\nvulnerability requires local system access. Note: this issue only affects\nWindows operating systems. This vulnerability affects Thunderbird < 45.5,\nFirefox ESR < 45.5, and Firefox < 50.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"windows only"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2016-5294"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"50","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [windows only]]","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"precise","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [windows only]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-5293","published":"2018-06-11T21:29:00","updated_at":"2025-08-25T22:06:12.757059+00:00","description":"\nWhen the Mozilla Updater is run, if the Updater's log file in the working\ndirectory points to a hardlink, data can be appended to an arbitrary local\nfile. This vulnerability requires local system access. Note: this issue\nonly affects Windows operating systems. This vulnerability affects Firefox\nESR < 45.5 and Firefox < 50.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"windows only"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2016-89/","https://www.cve.org/CVERecord?id=CVE-2016-5293"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"50","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [windows only]]","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"precise","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"windows only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [windows only]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-4181","published":"2018-06-11T15:29:00","updated_at":"2025-08-25T20:18:49.089964+00:00","description":"\nA vulnerability in open build service allows remote attackers to gain\naccess to source files even though source access is disabled. Affected\nreleases are SUSE open build service up to and including version 2.1.15\n(for 2.1) and before version 2.3.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://bugzilla.suse.com/show_bug.cgi?id=734003","https://github.com/openSUSE/open-build-service/commit/5281e4bff9df31f1f91e22a0d1e9086b93b23d7e","https://www.cve.org/CVERecord?id=CVE-2011-4181"],"bugs":[""],"patches":{"open-build-service":[]},"tags":{},"packages":[{"name":"open-build-service","source":"https://ubuntu.com/security/cve?package=open-build-service","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=open-build-service","debian":"https://tracker.debian.org/pkg/open-build-service","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.7.4-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.7.4-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.16","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-12109","published":"2018-06-11T13:29:00","updated_at":"2025-08-25T22:45:28.998919+00:00","description":"\nAn issue was discovered in Free Lossless Image Format (FLIF) 0.3. The\nTransformPaletteC::process function in transform/palette_C.hpp\nallows remote attackers to cause a denial of service (heap-based buffer\noverflow and application crash) or possibly have unspecified other impact\nvia a crafted PAM image file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/FLIF-hub/FLIF/issues/513","https://www.cve.org/CVERecord?id=CVE-2018-12109"],"bugs":[""],"patches":{"flif":[]},"tags":{},"packages":[{"name":"flif","source":"https://ubuntu.com/security/cve?package=flif","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flif","debian":"https://tracker.debian.org/pkg/flif","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-12108","published":"2018-06-11T13:29:00","updated_at":"2025-08-26T12:03:55.131776+00:00","description":"\nAn issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress\nfunction in validation.cc allows remote attackers to cause a denial of\nservice (SIGFPE and application crash) via a malformed file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/dropbox/lepton/issues/107","https://www.cve.org/CVERecord?id=CVE-2018-12108"],"bugs":[""],"patches":{"lepton":[]},"tags":{},"packages":[{"name":"lepton","source":"https://ubuntu.com/security/cve?package=lepton","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lepton","debian":"https://tracker.debian.org/pkg/lepton","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":52640,"limit":20,"total_results":79316}