{"cves":[{"id":"CVE-2016-1952","published":"2016-03-08T00:00:00","updated_at":"2025-08-25T21:55:55.038057+00:00","description":"\nMultiple unspecified vulnerabilities in the browser engine in Mozilla\nFirefox before 45.0 and Firefox ESR 38.x before 38.7 allow remote attackers\nto cause a denial of service (memory corruption and application crash) or\npossibly execute arbitrary code via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2016-16/","https://ubuntu.com/security/notices/USN-2917-1","https://ubuntu.com/security/notices/USN-2934-1","https://www.cve.org/CVERecord?id=CVE-2016-1952"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[],"mozjs38":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"trusty","status":"released","description":"45.0+build2-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"45.0+build2-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"45.0","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"45.0+build2-0ubuntu0.15.10.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"45.0+build2-0ubuntu1","component":null,"pocket":"security"}]},{"name":"mozjs38","source":"https://ubuntu.com/security/cve?package=mozjs38","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs38","debian":"https://tracker.debian.org/pkg/mozjs38","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"38.8.0~repack1-0ubuntu0.1","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"trusty","status":"released","description":"1:38.7.2+build1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:38.7.2+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"38.7","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:38.7.2+build1-0ubuntu0.15.10.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:38.7.2+build1-0ubuntu0.16.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2917-1","USN-2934-1"],"notices":[{"id":"USN-2917-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":[],"published":"2016-03-09T15:28:50.634167","description":"Francis Gabriel discovered a buffer overflow during ASN.1 decoding in NSS.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2016-1950)\n\nBob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel\nHolbert, Jesse Ruderman, Randell Jesup, Carsten Book, Gian-Carlo Pascutto,\nTyson Smith, Andrea Marchesini, and Jukka Jylänki discovered multiple\nmemory safety issues in Firefox. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit these to\ncause a denial of service via application crash, or execute arbitrary code\nwith the privileges of the user invoking Firefox. (CVE-2016-1952,\nCVE-2016-1953)\n\nNicolas Golubovic discovered that CSP violation reports can be used to\noverwrite local files. If a user were tricked in to opening a specially\ncrafted website with addon signing disabled and unpacked addons installed,\nan attacker could potentially exploit this to gain additional privileges.\n(CVE-2016-1954)\n\nMuneaki Nishimura discovered that CSP violation reports contained full\npaths for cross-origin iframe navigations. An attacker could potentially\nexploit this to steal confidential data. (CVE-2016-1955)\n\nUcha Gobejishvili discovered that performing certain WebGL operations\nresulted in memory resource exhaustion with some Intel GPUs, requiring\na reboot. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to cause a denial\nof service. (CVE-2016-1956)\n\nJose Martinez and Romina Santillan discovered a memory leak in\nlibstagefright during MPEG4 video file processing in some circumstances.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit this to cause a denial of service via\nmemory exhaustion. (CVE-2016-1957)\n\nAbdulrahman Alqabandi discovered that the addressbar could be blank or\nfilled with page defined content in some circumstances. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to conduct URL spoofing attacks. (CVE-2016-1958)\n\nLooben Yang discovered an out-of-bounds read in Service Worker Manager. If\na user were tricked in to opening a specially crafted website, an attacker\ncould potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2016-1959)\n\nA use-after-free was discovered in the HTML5 string parser. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash, or execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2016-1960)\n\nA use-after-free was discovered in the SetBody function of HTMLDocument.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2016-1961)\n\nDominique Hazaël-Massieux discovered a use-after-free when using multiple\nWebRTC data channels. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to cause a\ndenial of service via application crash, or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2016-1962)\n\nIt was discovered that Firefox crashes when local files are modified\nwhilst being read by the FileReader API. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2016-1963)\n\nNicolas Grégoire discovered a use-after-free during XML transformations.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2016-1964)\n\nTsubasa Iinuma discovered a mechanism to cause the addressbar to display\nan incorrect URL, using history navigations and the Location protocol\nproperty. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to conduct URL\nspoofing attacks. (CVE-2016-1965)\n\nA memory corruption issues was discovered in the NPAPI subsystem. If\na user were tricked in to opening a specially crafted website with a\nmalicious plugin installed, an attacker could potentially exploit this\nto cause a denial of service via application crash, or execute arbitrary\ncode with the privileges of the user invoking Firefox. (CVE-2016-1966)\n\nJordi Chancel discovered a same-origin-policy bypass when using\nperformance.getEntries and history navigation with session restore. If\na user were tricked in to opening a specially crafted website, an attacker\ncould potentially exploit this to steal confidential data. (CVE-2016-1967)\n\nLuke Li discovered a buffer overflow during Brotli decompression in some\ncircumstances. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to cause a denial of\nservice via application crash, or execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2016-1968)\n\nRonald Crane discovered a use-after-free in GetStaticInstance in WebRTC.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2016-1973)\n\nRonald Crane discovered an out-of-bounds read following a failed\nallocation in the HTML parser in some circumstances. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash, or execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2016-1974)\n\nHolger Fuhrmannek, Tyson Smith and Holger Fuhrmannek reported multiple\nmemory safety issues in the Graphite 2 library. If a user were tricked in\nto opening a specially crafted website, an attacker could potentially\nexploit these to cause a denial of service via application crash, or\nexecute arbitrary code with the privileges of the user invoking Firefox.\n(CVE-2016-1977, CVE-2016-2790, CVE-2016-2791, CVE-2016-2792,\nCVE-2016-2793, CVE-2016-2794, CVE-2016-2795, CVE-2016-2796, CVE-2016-2797,\nCVE-2016-2798, CVE-2016-2799, CVE-2016-2800, CVE-2016-2801, CVE-2016-2802)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"45.0+build2-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"45.0+build2-0ubuntu0.12.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.12.04.1"}],"trusty":[{"name":"firefox","version":"45.0+build2-0ubuntu0.14.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-dev","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-globalmenu","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-af","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-an","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ar","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-as","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ast","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-az","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-be","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-bg","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-bn","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-br","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-bs","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ca","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-cs","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-csb","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-cy","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-da","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-de","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-el","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-en","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-eo","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-es","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-et","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-eu","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fa","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fi","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fr","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fy","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ga","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-gd","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-gl","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-gn","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-gu","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-he","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hi","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hr","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hsb","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hu","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hy","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-id","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-is","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-it","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ja","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ka","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-kk","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-km","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-kn","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ko","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ku","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-lg","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-lt","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-lv","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mai","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mk","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ml","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mn","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mr","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ms","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nb","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nl","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nn","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nso","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-oc","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-or","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-pa","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-pl","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-pt","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ro","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ru","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-si","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sk","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sl","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sq","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sr","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sv","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sw","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ta","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-te","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-th","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-tr","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-uk","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-uz","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-vi","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-xh","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-zh-hans","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-zh-hant","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-zu","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-mozsymbols","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-testsuite","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"firefox","version":"45.0+build2-0ubuntu0.15.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"45.0+build2-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2016-1950","CVE-2016-1952","CVE-2016-1953","CVE-2016-1954","CVE-2016-1955","CVE-2016-1956","CVE-2016-1957","CVE-2016-1958","CVE-2016-1959","CVE-2016-1960","CVE-2016-1961","CVE-2016-1962","CVE-2016-1963","CVE-2016-1964","CVE-2016-1965","CVE-2016-1966","CVE-2016-1967","CVE-2016-1968","CVE-2016-1973","CVE-2016-1974","CVE-2016-1977","CVE-2016-2790","CVE-2016-2791","CVE-2016-2792","CVE-2016-2793","CVE-2016-2794","CVE-2016-2795","CVE-2016-2796","CVE-2016-2797","CVE-2016-2798","CVE-2016-2799","CVE-2016-2800","CVE-2016-2801","CVE-2016-2802"]},{"id":"USN-2934-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":[],"published":"2016-04-27T22:32:50.120074","description":"Bob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel\nHolbert, Jesse Ruderman, and Randell Jesup discovered multiple memory\nsafety issues in Thunderbird. If a user were tricked in to opening a\nspecially crafted message, an attacker could potentially exploit these to\ncause a denial of service via application crash, or execute arbitrary code\nwith the privileges of the user invoking Thunderbird. (CVE-2016-1952)\n\nNicolas Golubovic discovered that CSP violation reports can be used to\noverwrite local files. If a user were tricked in to opening a specially\ncrafted website in a browsing context with addon signing disabled and\nunpacked addons installed, an attacker could potentially exploit this to\ngain additional privileges. (CVE-2016-1954)\n\nJose Martinez and Romina Santillan discovered a memory leak in\nlibstagefright during MPEG4 video file processing in some circumstances.\nIf a user were tricked in to opening a specially crafted website in a\nbrowsing context, an attacker could potentially exploit this to cause a\ndenial of service via memory exhaustion. (CVE-2016-1957)\n\nA use-after-free was discovered in the HTML5 string parser. If a user were\ntricked in to opening a specially crafted website in a browsing context, an\nattacker could potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the user\ninvoking Thunderbird. (CVE-2016-1960)\n\nA use-after-free was discovered in the SetBody function of HTMLDocument.\nIf a user were tricked in to opening a specially crafted website in a\nbrowsing context, an attacker could potentially exploit this to cause a\ndenial of service via application crash, or execute arbitrary code with\nthe privileges of the user invoking Thunderbird. (CVE-2016-1961)\n\nNicolas Grégoire discovered a use-after-free during XML transformations.\nIf a user were tricked in to opening a specially crafted website in a\nbrowsing context, an attacker could potentially exploit this to cause a\ndenial of service via application crash, or execute arbitrary code with\nthe privileges of the user invoking Thunderbird. (CVE-2016-1964)\n\nA memory corruption issues was discovered in the NPAPI subsystem. If\na user were tricked in to opening a specially crafted website in a\nbrowsing context with a malicious plugin installed, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash, or execute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2016-1966)\n\nRonald Crane discovered an out-of-bounds read following a failed\nallocation in the HTML parser in some circumstances. If a user were\ntricked in to opening a specially crafted website in a browsing context,\nan attacker could potentially exploit this to cause a denial of service\nvia application crash, or execute arbitrary code with the privileges of\nthe user invoking Thunderbird. (CVE-2016-1974)\n\nFrancis Gabriel discovered a buffer overflow during ASN.1 decoding in NSS.\nA remote attacker could potentially exploit this to cause a denial of\nservice via application crash, or execute arbitrary code with the\nprivileges of the user invoking Thunderbird. (CVE-2016-1950)\n\nHolger Fuhrmannek, Tyson Smith and Holger Fuhrmannek reported multiple\nmemory safety issues in the Graphite 2 library. If a user were tricked in\nto opening a specially crafted message, an attacker could potentially\nexploit these to cause a denial of service via application crash, or\nexecute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2016-1977, CVE-2016-2790, CVE-2016-2791, CVE-2016-2792,\nCVE-2016-2793, CVE-2016-2794, CVE-2016-2795, CVE-2016-2796, CVE-2016-2797,\nCVE-2016-2798, CVE-2016-2799, CVE-2016-2800, CVE-2016-2801, CVE-2016-2802)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"1:38.7.2+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:38.7.2+build1-0ubuntu0.12.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.12.04.1"}],"trusty":[{"name":"thunderbird","version":"1:38.7.2+build1-0ubuntu0.14.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-dev","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-globalmenu","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-gnome-support","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-af","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ar","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ast","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-be","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-bg","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-bn","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-bn-bd","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-br","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ca","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-cs","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-cy","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-da","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-de","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-dsb","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-el","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-en","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-en-gb","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-en-us","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-es","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-es-ar","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-es-es","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-et","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-eu","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-fi","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-fr","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-fy","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-fy-nl","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ga","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ga-ie","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-gd","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-gl","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-he","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-hr","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-hsb","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-hu","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-hy","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-id","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-is","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-it","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ja","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ka","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ko","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-lt","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-mk","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-nb","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-nb-no","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-nl","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-nn","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-nn-no","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-pa","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-pa-in","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-pl","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-pt","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-pt-br","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-pt-pt","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-rm","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ro","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ru","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-si","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-sk","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-sl","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-sq","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-sr","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-sv","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-sv-se","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ta","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ta-lk","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-tr","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-uk","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-vi","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-zh-cn","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-zh-hans","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-zh-hant","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-zh-tw","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-mozsymbols","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-testsuite","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"xul-ext-calendar-timezones","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"xul-ext-gdata-provider","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"xul-ext-lightning","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"thunderbird","version":"1:38.7.2+build1-0ubuntu0.15.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:38.7.2+build1-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.15.10.1"}],"xenial":[{"name":"thunderbird","version":"1:38.7.2+build1-0ubuntu0.16.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-dev","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-globalmenu","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-gnome-support","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-af","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ar","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ast","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-be","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-bg","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-bn","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-bn-bd","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-br","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ca","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-cs","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-cy","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-da","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-de","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-dsb","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-el","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-en","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-en-gb","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-en-us","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-es","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-es-ar","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-es-es","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-et","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-eu","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-fi","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-fr","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-fy","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-fy-nl","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ga","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ga-ie","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-gd","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-gl","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-he","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-hr","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-hsb","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-hu","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-hy","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-id","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-is","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-it","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ja","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ka","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ko","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-lt","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-mk","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-nb","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-nb-no","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-nl","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-nn","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-nn-no","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-pa","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-pa-in","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-pl","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-pt","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-pt-br","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-pt-pt","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-rm","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ro","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ru","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-si","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-sk","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-sl","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-sq","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-sr","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-sv","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-sv-se","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ta","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ta-lk","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-tr","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-uk","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-vi","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-zh-cn","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-zh-hans","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-zh-hant","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-zh-tw","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-mozsymbols","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-testsuite","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"xul-ext-calendar-timezones","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"xul-ext-gdata-provider","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"xul-ext-lightning","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-1950","CVE-2016-1952","CVE-2016-1954","CVE-2016-1957","CVE-2016-1960","CVE-2016-1961","CVE-2016-1964","CVE-2016-1966","CVE-2016-1974","CVE-2016-1977","CVE-2016-2790","CVE-2016-2791","CVE-2016-2792","CVE-2016-2793","CVE-2016-2794","CVE-2016-2795","CVE-2016-2796","CVE-2016-2797","CVE-2016-2798","CVE-2016-2799","CVE-2016-2800","CVE-2016-2801","CVE-2016-2802"]}]},{"id":"CVE-2016-1950","published":"2016-03-08T00:00:00","updated_at":"2025-08-25T21:55:55.038057+00:00","description":"\nHeap-based buffer overflow in Mozilla Network Security Services (NSS)\nbefore 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla\nFirefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote\nattackers to execute arbitrary code via crafted ASN.1 data in an X.509\ncertificate.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2016-35/","https://ubuntu.com/security/notices/USN-2917-1","https://ubuntu.com/security/notices/USN-2924-1","https://ubuntu.com/security/notices/USN-2934-1","https://www.cve.org/CVERecord?id=CVE-2016-1950"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=1245528"],"patches":{"firefox":[],"thunderbird":[],"nss":["upstream: http://hg.mozilla.org/projects/nss/rev/b9a31471759d"]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"released","description":"45.0+build2-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"45.0+build2-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"45.0","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"45.0+build2-0ubuntu0.15.10.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"45.0+build2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"45.0+build2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"45.0+build2-0ubuntu1","component":null,"pocket":"security"}]},{"name":"nss","source":"https://ubuntu.com/security/cve?package=nss","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nss","debian":"https://tracker.debian.org/pkg/nss","statuses":[{"release_codename":"precise","status":"released","description":"2:3.21-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2:3.21-0ubuntu0.14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.21.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"2:3.21-0ubuntu0.15.10.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2:3.21-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2:3.21-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"2:3.21-1ubuntu4","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"precise","status":"released","description":"1:38.7.2+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"38.7","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:38.7.2+build1-0ubuntu0.15.10.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:38.7.2+build1-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1:38.8.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1:38.8.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:38.7.2+build1-0ubuntu0.14.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2924-1","USN-2917-1","USN-2934-1"],"notices":[{"id":"USN-2924-1","title":"NSS vulnerability","summary":"NSS could be made to crash or run programs if it received specially crafted\ninput.\n","instructions":"After a standard system update you need to restart any applications that\nuse NSS, such as Evolution and Chromium, to make all the necessary changes.\n","references":[],"published":"2016-03-09T15:55:46.220955","description":"Francis Gabriel discovered that NSS incorrectly handled decoding certain\nASN.1 data. An remote attacker could use this issue to cause NSS to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"precise":[{"name":"nss","version":"2:3.21-0ubuntu0.12.04.3","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"2:3.21-0ubuntu0.12.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.21-0ubuntu0.12.04.3"}],"trusty":[{"name":"nss","version":"2:3.21-0ubuntu0.14.04.2","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"2:3.21-0ubuntu0.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.21-0ubuntu0.14.04.2","pocket":"security"},{"name":"libnss3-1d","version":"2:3.21-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.21-0ubuntu0.14.04.2","pocket":"security"},{"name":"libnss3-dev","version":"2:3.21-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.21-0ubuntu0.14.04.2","pocket":"security"},{"name":"libnss3-nssdb","version":"2:3.21-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.21-0ubuntu0.14.04.2","pocket":"security"},{"name":"libnss3-tools","version":"2:3.21-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.21-0ubuntu0.14.04.2","pocket":"security"}],"wily":[{"name":"nss","version":"2:3.21-0ubuntu0.15.10.2","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"2:3.21-0ubuntu0.15.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.21-0ubuntu0.15.10.2"}]},"type":"USN","cves_ids":["CVE-2016-1950"]},{"id":"USN-2917-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":[],"published":"2016-03-09T15:28:50.634167","description":"Francis Gabriel discovered a buffer overflow during ASN.1 decoding in NSS.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2016-1950)\n\nBob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel\nHolbert, Jesse Ruderman, Randell Jesup, Carsten Book, Gian-Carlo Pascutto,\nTyson Smith, Andrea Marchesini, and Jukka Jylänki discovered multiple\nmemory safety issues in Firefox. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit these to\ncause a denial of service via application crash, or execute arbitrary code\nwith the privileges of the user invoking Firefox. (CVE-2016-1952,\nCVE-2016-1953)\n\nNicolas Golubovic discovered that CSP violation reports can be used to\noverwrite local files. If a user were tricked in to opening a specially\ncrafted website with addon signing disabled and unpacked addons installed,\nan attacker could potentially exploit this to gain additional privileges.\n(CVE-2016-1954)\n\nMuneaki Nishimura discovered that CSP violation reports contained full\npaths for cross-origin iframe navigations. An attacker could potentially\nexploit this to steal confidential data. (CVE-2016-1955)\n\nUcha Gobejishvili discovered that performing certain WebGL operations\nresulted in memory resource exhaustion with some Intel GPUs, requiring\na reboot. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to cause a denial\nof service. (CVE-2016-1956)\n\nJose Martinez and Romina Santillan discovered a memory leak in\nlibstagefright during MPEG4 video file processing in some circumstances.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit this to cause a denial of service via\nmemory exhaustion. (CVE-2016-1957)\n\nAbdulrahman Alqabandi discovered that the addressbar could be blank or\nfilled with page defined content in some circumstances. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to conduct URL spoofing attacks. (CVE-2016-1958)\n\nLooben Yang discovered an out-of-bounds read in Service Worker Manager. If\na user were tricked in to opening a specially crafted website, an attacker\ncould potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2016-1959)\n\nA use-after-free was discovered in the HTML5 string parser. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash, or execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2016-1960)\n\nA use-after-free was discovered in the SetBody function of HTMLDocument.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2016-1961)\n\nDominique Hazaël-Massieux discovered a use-after-free when using multiple\nWebRTC data channels. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to cause a\ndenial of service via application crash, or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2016-1962)\n\nIt was discovered that Firefox crashes when local files are modified\nwhilst being read by the FileReader API. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2016-1963)\n\nNicolas Grégoire discovered a use-after-free during XML transformations.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2016-1964)\n\nTsubasa Iinuma discovered a mechanism to cause the addressbar to display\nan incorrect URL, using history navigations and the Location protocol\nproperty. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to conduct URL\nspoofing attacks. (CVE-2016-1965)\n\nA memory corruption issues was discovered in the NPAPI subsystem. If\na user were tricked in to opening a specially crafted website with a\nmalicious plugin installed, an attacker could potentially exploit this\nto cause a denial of service via application crash, or execute arbitrary\ncode with the privileges of the user invoking Firefox. (CVE-2016-1966)\n\nJordi Chancel discovered a same-origin-policy bypass when using\nperformance.getEntries and history navigation with session restore. If\na user were tricked in to opening a specially crafted website, an attacker\ncould potentially exploit this to steal confidential data. (CVE-2016-1967)\n\nLuke Li discovered a buffer overflow during Brotli decompression in some\ncircumstances. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to cause a denial of\nservice via application crash, or execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2016-1968)\n\nRonald Crane discovered a use-after-free in GetStaticInstance in WebRTC.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2016-1973)\n\nRonald Crane discovered an out-of-bounds read following a failed\nallocation in the HTML parser in some circumstances. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash, or execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2016-1974)\n\nHolger Fuhrmannek, Tyson Smith and Holger Fuhrmannek reported multiple\nmemory safety issues in the Graphite 2 library. If a user were tricked in\nto opening a specially crafted website, an attacker could potentially\nexploit these to cause a denial of service via application crash, or\nexecute arbitrary code with the privileges of the user invoking Firefox.\n(CVE-2016-1977, CVE-2016-2790, CVE-2016-2791, CVE-2016-2792,\nCVE-2016-2793, CVE-2016-2794, CVE-2016-2795, CVE-2016-2796, CVE-2016-2797,\nCVE-2016-2798, CVE-2016-2799, CVE-2016-2800, CVE-2016-2801, CVE-2016-2802)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"45.0+build2-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"45.0+build2-0ubuntu0.12.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.12.04.1"}],"trusty":[{"name":"firefox","version":"45.0+build2-0ubuntu0.14.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-dev","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-globalmenu","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-af","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-an","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ar","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-as","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ast","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-az","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-be","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-bg","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-bn","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-br","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-bs","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ca","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-cs","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-csb","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-cy","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-da","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-de","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-el","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-en","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-eo","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-es","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-et","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-eu","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fa","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fi","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fr","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fy","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ga","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-gd","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-gl","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-gn","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-gu","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-he","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hi","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hr","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hsb","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hu","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hy","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-id","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-is","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-it","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ja","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ka","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-kk","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-km","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-kn","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ko","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ku","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-lg","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-lt","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-lv","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mai","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mk","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ml","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mn","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mr","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ms","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nb","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nl","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nn","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nso","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-oc","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-or","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-pa","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-pl","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-pt","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ro","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ru","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-si","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sk","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sl","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sq","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sr","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sv","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sw","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ta","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-te","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-th","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-tr","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-uk","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-uz","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-vi","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-xh","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-zh-hans","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-zh-hant","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-zu","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-mozsymbols","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-testsuite","version":"45.0+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"firefox","version":"45.0+build2-0ubuntu0.15.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"45.0+build2-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/45.0+build2-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2016-1950","CVE-2016-1952","CVE-2016-1953","CVE-2016-1954","CVE-2016-1955","CVE-2016-1956","CVE-2016-1957","CVE-2016-1958","CVE-2016-1959","CVE-2016-1960","CVE-2016-1961","CVE-2016-1962","CVE-2016-1963","CVE-2016-1964","CVE-2016-1965","CVE-2016-1966","CVE-2016-1967","CVE-2016-1968","CVE-2016-1973","CVE-2016-1974","CVE-2016-1977","CVE-2016-2790","CVE-2016-2791","CVE-2016-2792","CVE-2016-2793","CVE-2016-2794","CVE-2016-2795","CVE-2016-2796","CVE-2016-2797","CVE-2016-2798","CVE-2016-2799","CVE-2016-2800","CVE-2016-2801","CVE-2016-2802"]},{"id":"USN-2934-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":[],"published":"2016-04-27T22:32:50.120074","description":"Bob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel\nHolbert, Jesse Ruderman, and Randell Jesup discovered multiple memory\nsafety issues in Thunderbird. If a user were tricked in to opening a\nspecially crafted message, an attacker could potentially exploit these to\ncause a denial of service via application crash, or execute arbitrary code\nwith the privileges of the user invoking Thunderbird. (CVE-2016-1952)\n\nNicolas Golubovic discovered that CSP violation reports can be used to\noverwrite local files. If a user were tricked in to opening a specially\ncrafted website in a browsing context with addon signing disabled and\nunpacked addons installed, an attacker could potentially exploit this to\ngain additional privileges. (CVE-2016-1954)\n\nJose Martinez and Romina Santillan discovered a memory leak in\nlibstagefright during MPEG4 video file processing in some circumstances.\nIf a user were tricked in to opening a specially crafted website in a\nbrowsing context, an attacker could potentially exploit this to cause a\ndenial of service via memory exhaustion. (CVE-2016-1957)\n\nA use-after-free was discovered in the HTML5 string parser. If a user were\ntricked in to opening a specially crafted website in a browsing context, an\nattacker could potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the user\ninvoking Thunderbird. (CVE-2016-1960)\n\nA use-after-free was discovered in the SetBody function of HTMLDocument.\nIf a user were tricked in to opening a specially crafted website in a\nbrowsing context, an attacker could potentially exploit this to cause a\ndenial of service via application crash, or execute arbitrary code with\nthe privileges of the user invoking Thunderbird. (CVE-2016-1961)\n\nNicolas Grégoire discovered a use-after-free during XML transformations.\nIf a user were tricked in to opening a specially crafted website in a\nbrowsing context, an attacker could potentially exploit this to cause a\ndenial of service via application crash, or execute arbitrary code with\nthe privileges of the user invoking Thunderbird. (CVE-2016-1964)\n\nA memory corruption issues was discovered in the NPAPI subsystem. If\na user were tricked in to opening a specially crafted website in a\nbrowsing context with a malicious plugin installed, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash, or execute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2016-1966)\n\nRonald Crane discovered an out-of-bounds read following a failed\nallocation in the HTML parser in some circumstances. If a user were\ntricked in to opening a specially crafted website in a browsing context,\nan attacker could potentially exploit this to cause a denial of service\nvia application crash, or execute arbitrary code with the privileges of\nthe user invoking Thunderbird. (CVE-2016-1974)\n\nFrancis Gabriel discovered a buffer overflow during ASN.1 decoding in NSS.\nA remote attacker could potentially exploit this to cause a denial of\nservice via application crash, or execute arbitrary code with the\nprivileges of the user invoking Thunderbird. (CVE-2016-1950)\n\nHolger Fuhrmannek, Tyson Smith and Holger Fuhrmannek reported multiple\nmemory safety issues in the Graphite 2 library. If a user were tricked in\nto opening a specially crafted message, an attacker could potentially\nexploit these to cause a denial of service via application crash, or\nexecute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2016-1977, CVE-2016-2790, CVE-2016-2791, CVE-2016-2792,\nCVE-2016-2793, CVE-2016-2794, CVE-2016-2795, CVE-2016-2796, CVE-2016-2797,\nCVE-2016-2798, CVE-2016-2799, CVE-2016-2800, CVE-2016-2801, CVE-2016-2802)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"1:38.7.2+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:38.7.2+build1-0ubuntu0.12.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.12.04.1"}],"trusty":[{"name":"thunderbird","version":"1:38.7.2+build1-0ubuntu0.14.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-dev","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-globalmenu","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-gnome-support","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-af","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ar","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ast","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-be","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-bg","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-bn","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-bn-bd","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-br","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ca","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-cs","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-cy","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-da","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-de","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-dsb","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-el","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-en","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-en-gb","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-en-us","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-es","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-es-ar","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-es-es","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-et","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-eu","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-fi","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-fr","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-fy","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-fy-nl","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ga","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ga-ie","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-gd","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-gl","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-he","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-hr","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-hsb","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-hu","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-hy","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-id","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-is","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-it","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ja","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ka","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ko","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-lt","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-mk","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-nb","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-nb-no","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-nl","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-nn","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-nn-no","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-pa","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-pa-in","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-pl","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-pt","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-pt-br","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-pt-pt","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-rm","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ro","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ru","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-si","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-sk","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-sl","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-sq","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-sr","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-sv","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-sv-se","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ta","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-ta-lk","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-tr","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-uk","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-vi","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-zh-cn","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-zh-hans","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-zh-hant","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-locale-zh-tw","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-mozsymbols","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"thunderbird-testsuite","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"xul-ext-calendar-timezones","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"xul-ext-gdata-provider","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"xul-ext-lightning","version":"1:38.7.2+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"thunderbird","version":"1:38.7.2+build1-0ubuntu0.15.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:38.7.2+build1-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.15.10.1"}],"xenial":[{"name":"thunderbird","version":"1:38.7.2+build1-0ubuntu0.16.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-dev","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-globalmenu","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-gnome-support","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-af","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ar","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ast","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-be","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-bg","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-bn","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-bn-bd","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-br","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ca","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-cs","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-cy","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-da","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-de","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-dsb","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-el","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-en","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-en-gb","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-en-us","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-es","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-es-ar","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-es-es","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-et","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-eu","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-fi","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-fr","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-fy","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-fy-nl","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ga","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ga-ie","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-gd","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-gl","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-he","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-hr","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-hsb","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-hu","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-hy","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-id","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-is","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-it","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ja","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ka","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ko","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-lt","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-mk","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-nb","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-nb-no","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-nl","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-nn","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-nn-no","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-pa","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-pa-in","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-pl","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-pt","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-pt-br","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-pt-pt","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-rm","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ro","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ru","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-si","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-sk","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-sl","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-sq","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-sr","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-sv","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-sv-se","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ta","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-ta-lk","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-tr","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-uk","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-vi","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-zh-cn","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-zh-hans","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-zh-hant","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-locale-zh-tw","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-mozsymbols","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"thunderbird-testsuite","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"xul-ext-calendar-timezones","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"xul-ext-gdata-provider","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"},{"name":"xul-ext-lightning","version":"1:38.7.2+build1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:38.7.2+build1-0ubuntu0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-1950","CVE-2016-1952","CVE-2016-1954","CVE-2016-1957","CVE-2016-1960","CVE-2016-1961","CVE-2016-1964","CVE-2016-1966","CVE-2016-1974","CVE-2016-1977","CVE-2016-2790","CVE-2016-2791","CVE-2016-2792","CVE-2016-2793","CVE-2016-2794","CVE-2016-2795","CVE-2016-2796","CVE-2016-2797","CVE-2016-2798","CVE-2016-2799","CVE-2016-2800","CVE-2016-2801","CVE-2016-2802"]}]},{"id":"CVE-2016-0771","published":"2016-03-08T00:00:00","updated_at":"2025-08-25T21:50:59.651924+00:00","description":"\nThe internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9,\n4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured,\nallows remote authenticated users to cause a denial of service\n(out-of-bounds read) or possibly obtain sensitive information from process\nmemory by uploading a crafted DNS TXT record.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"4.0+ only"}],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.samba.org/samba/security/CVE-2016-0771.html","https://ubuntu.com/security/notices/USN-2922-1","https://www.cve.org/CVERecord?id=CVE-2016-0771"],"bugs":["https://bugzilla.samba.org/show_bug.cgi?id=11128","https://bugzilla.samba.org/show_bug.cgi?id=11686","https://bugzilla.samba.org/show_bug.cgi?id=11630"],"patches":{"samba":[],"samba4":[]},"tags":{},"packages":[{"name":"samba","source":"https://ubuntu.com/security/cve?package=samba","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba","debian":"https://tracker.debian.org/pkg/samba","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2:4.1.6+dfsg-1ubuntu2.14.04.13","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"2:4.1.17+dfsg-4ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2:4.3.6+dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2:4.3.6+dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"2:4.3.6+dfsg-1ubuntu1","component":null,"pocket":"security"}]},{"name":"samba4","source":"https://ubuntu.com/security/cve?package=samba4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba4","debian":"https://tracker.debian.org/pkg/samba4","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2922-1"],"notices":[{"id":"USN-2922-1","title":"Samba vulnerabilities","summary":"Several security issues were fixed in Samba.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-03-08T13:51:17.021563","description":"Jeremy Allison discovered that Samba incorrectly handled ACLs on symlink\npaths. A remote attacker could use this issue to overwrite the ownership of\nACLs using symlinks. (CVE-2015-7560)\n\nGarming Sam and Douglas Bagnall discovered that the Samba internal DNS\nserver incorrectly handled certain DNS TXT records. A remote attacker could\nuse this issue to cause Samba to crash, resulting in a denial of service,\nor possibly obtain uninitialized memory contents. This issue only applied\nto Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2016-0771)\n\nIt was discovered that the Samba Web Administration Tool (SWAT) was\nvulnerable to clickjacking and cross-site request forgery attacks. This\nissue only affected Ubuntu 12.04 LTS. (CVE-2013-0213, CVE-2013-0214)\n","is_hidden":false,"release_packages":{"precise":[{"name":"samba","version":"2:3.6.3-2ubuntu2.17","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"samba","version":"2:3.6.3-2ubuntu2.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.3-2ubuntu2.17"},{"name":"swat","version":"2:3.6.3-2ubuntu2.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.3-2ubuntu2.17"}],"trusty":[{"name":"samba","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"libnss-winbind","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"libpam-smbpass","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"libpam-winbind","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"libparse-pidl-perl","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"libsmbclient","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"libsmbclient-dev","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"libsmbsharemodes-dev","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"libsmbsharemodes0","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"libwbclient-dev","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"libwbclient0","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"python-samba","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"registry-tools","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"samba","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"samba-common","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"samba-common-bin","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"samba-dev","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"samba-doc","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"samba-dsdb-modules","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"samba-libs","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"samba-testsuite","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"samba-vfs-modules","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"smbclient","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"winbind","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"}],"wily":[{"name":"samba","version":"2:4.1.17+dfsg-4ubuntu3.3","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"samba","version":"2:4.1.17+dfsg-4ubuntu3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.17+dfsg-4ubuntu3.3"}]},"type":"USN","cves_ids":["CVE-2013-0213","CVE-2013-0214","CVE-2015-7560","CVE-2016-0771"]}]},{"id":"CVE-2015-7560","published":"2016-03-08T00:00:00","updated_at":"2025-08-25T21:45:33.455350+00:00","description":"\nThe SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x\nbefore 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote\nauthenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to\ncreate a symlink, and then using a non-UNIX SMB1 call to write to the ACL\ncontent.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.samba.org/samba/security/CVE-2015-7560.html","https://ubuntu.com/security/notices/USN-2922-1","https://www.cve.org/CVERecord?id=CVE-2015-7560"],"bugs":["https://bugzilla.samba.org/show_bug.cgi?id=11648","https://bugzilla.samba.org/show_bug.cgi?id=11630"],"patches":{"samba":[],"samba4":[]},"tags":{},"packages":[{"name":"samba","source":"https://ubuntu.com/security/cve?package=samba","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba","debian":"https://tracker.debian.org/pkg/samba","statuses":[{"release_codename":"precise","status":"released","description":"2:3.6.3-2ubuntu2.17","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2:4.1.6+dfsg-1ubuntu2.14.04.13","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"2:4.1.17+dfsg-4ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2:4.3.6+dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2:4.3.6+dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"2:4.3.6+dfsg-1ubuntu1","component":null,"pocket":"security"}]},{"name":"samba4","source":"https://ubuntu.com/security/cve?package=samba4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba4","debian":"https://tracker.debian.org/pkg/samba4","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2922-1"],"notices":[{"id":"USN-2922-1","title":"Samba vulnerabilities","summary":"Several security issues were fixed in Samba.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-03-08T13:51:17.021563","description":"Jeremy Allison discovered that Samba incorrectly handled ACLs on symlink\npaths. A remote attacker could use this issue to overwrite the ownership of\nACLs using symlinks. (CVE-2015-7560)\n\nGarming Sam and Douglas Bagnall discovered that the Samba internal DNS\nserver incorrectly handled certain DNS TXT records. A remote attacker could\nuse this issue to cause Samba to crash, resulting in a denial of service,\nor possibly obtain uninitialized memory contents. This issue only applied\nto Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2016-0771)\n\nIt was discovered that the Samba Web Administration Tool (SWAT) was\nvulnerable to clickjacking and cross-site request forgery attacks. This\nissue only affected Ubuntu 12.04 LTS. (CVE-2013-0213, CVE-2013-0214)\n","is_hidden":false,"release_packages":{"precise":[{"name":"samba","version":"2:3.6.3-2ubuntu2.17","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"samba","version":"2:3.6.3-2ubuntu2.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.3-2ubuntu2.17"},{"name":"swat","version":"2:3.6.3-2ubuntu2.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.3-2ubuntu2.17"}],"trusty":[{"name":"samba","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"libnss-winbind","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"libpam-smbpass","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"libpam-winbind","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"libparse-pidl-perl","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"libsmbclient","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"libsmbclient-dev","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"libsmbsharemodes-dev","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"libsmbsharemodes0","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"libwbclient-dev","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"libwbclient0","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"python-samba","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"registry-tools","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"samba","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"samba-common","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"samba-common-bin","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"samba-dev","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"samba-doc","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"samba-dsdb-modules","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"samba-libs","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"samba-testsuite","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"samba-vfs-modules","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"smbclient","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"},{"name":"winbind","version":"2:4.1.6+dfsg-1ubuntu2.14.04.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.6+dfsg-1ubuntu2.14.04.13","pocket":"security"}],"wily":[{"name":"samba","version":"2:4.1.17+dfsg-4ubuntu3.3","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"samba","version":"2:4.1.17+dfsg-4ubuntu3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.1.17+dfsg-4ubuntu3.3"}]},"type":"USN","cves_ids":["CVE-2013-0213","CVE-2013-0214","CVE-2015-7560","CVE-2016-0771"]}]},{"id":"CVE-2016-1640","published":"2016-03-06T02:59:00","updated_at":"2025-08-25T21:54:41.566036+00:00","description":"\nThe Web Store inline-installer implementation in the Extensions UI in\nGoogle Chrome before 49.0.2623.75 does not block installations upon\ndeletion of an installation frame, which makes it easier for remote\nattackers to trick a user into believing that an installation request\noriginated from the user's next navigation target via a crafted web site.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.ca/2016/03/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2016-1640"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"49.0.2623.87-0ubuntu0.14.04.1.1112","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"49.0.2623.75","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"49.0.2623.87-0ubuntu0.15.10.1.1222","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-1639","published":"2016-03-06T02:59:00","updated_at":"2025-08-25T21:54:41.566036+00:00","description":"\nUse-after-free vulnerability in\nbrowser/extensions/api/webrtc_audio_private/webrtc_audio_private_api.cc in\nthe WebRTC Audio Private API implementation in Google Chrome before\n49.0.2623.75 allows remote attackers to cause a denial of service or\npossibly have unspecified other impact by leveraging incorrect reliance on\nthe resource context pointer.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.ca/2016/03/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2016-1639"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"49.0.2623.87-0ubuntu0.14.04.1.1112","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"49.0.2623.75","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"49.0.2623.87-0ubuntu0.15.10.1.1222","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-1638","published":"2016-03-06T02:59:00","updated_at":"2025-08-25T21:54:41.566036+00:00","description":"\nextensions/renderer/resources/platform_app.js in the Extensions subsystem\nin Google Chrome before 49.0.2623.75 does not properly restrict use of Web\nAPIs, which allows remote attackers to bypass intended access restrictions\nvia a crafted platform app.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.ca/2016/03/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2016-1638"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"49.0.2623.87-0ubuntu0.14.04.1.1112","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"49.0.2623.75","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"49.0.2623.87-0ubuntu0.15.10.1.1222","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-1635","published":"2016-03-06T02:59:00","updated_at":"2025-08-25T21:54:41.566036+00:00","description":"\nextensions/renderer/render_frame_observer_natives.cc in Google Chrome\nbefore 49.0.2623.75 does not properly consider object lifetimes and\nre-entrancy issues during OnDocumentElementCreated handling, which allows\nremote attackers to cause a denial of service (use-after-free) or possibly\nhave unspecified other impact via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.ca/2016/03/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2016-1635"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"49.0.2623.87-0ubuntu0.14.04.1.1112","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"49.0.2623.75","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"49.0.2623.87-0ubuntu0.15.10.1.1222","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-1632","published":"2016-03-06T02:59:00","updated_at":"2025-08-25T21:54:41.566036+00:00","description":"\nThe Extensions subsystem in Google Chrome before 49.0.2623.75 does not\nproperly maintain own properties, which allows remote attackers to bypass\nintended access restrictions via crafted JavaScript code that triggers an\nincorrect cast, related to extensions/renderer/v8_helpers.h and\ngin/converter.h.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.ca/2016/03/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2016-1632"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"49.0.2623.87-0ubuntu0.14.04.1.1112","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"49.0.2623.75","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"49.0.2623.87-0ubuntu0.15.10.1.1222","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-2845","published":"2016-03-05T00:00:00","updated_at":"2025-08-25T21:59:03.257936+00:00","description":"\nThe Content Security Policy (CSP) implementation in Blink, as used in\nGoogle Chrome before 49.0.2623.75, does not ignore a URL's path component\nin the case of a ServiceWorker fetch, which allows remote attackers to\nobtain sensitive information about visited web pages by reading CSP\nviolation reports, related to FrameFetchContext.cpp and\nResourceFetcher.cpp.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://codereview.chromium.org/1454003003/","https://code.google.com/p/chromium/issues/detail?id=591402","https://bugs.chromium.org/p/chromium/issues/detail?id=542060","http://homakov.blogspot.com/2014/01/using-content-security-policy-for-evil.html","http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2920-1","https://www.cve.org/CVERecord?id=CVE-2016-2845"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"49.0.2623.87-0ubuntu0.14.04.1.1112","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"49.0.2623.75","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"49.0.2623.87-0ubuntu0.15.10.1.1222","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.13.6-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.13.6","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.13.6-0ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2920-1"],"notices":[{"id":"USN-2920-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-03-10T17:22:56.088009","description":"It was discovered that the ContainerNode::parserRemoveChild function in\nBlink mishandled widget updates in some circumstances. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1630)\n\nIt was discovered that the PPB_Flash_MessageLoop_Impl::InternalRun \nfunction in Chromium mishandled nested message loops. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1631)\n\nMultiple use-after-frees were discovered in Blink. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1633, CVE-2016-1634, CVE-2016-1644)\n\nIt was discovered that the PendingScript::notifyFinished function in\nBlink relied on memory-cache information about integrity-check occurrences\ninstead of integrity-check successes. If a user were tricked in to opening\na specially crafted website, an attacker could potentially exploit this to\nbypass Subresource Integrity (SRI) protections. (CVE-2016-1636)\n\nIt was discovered that the SkATan2_255 function in Skia mishandled\narctangent calculations. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to obtain\nsensitive information. (CVE-2016-1637)\n\nA use-after-free was discovered in Chromium. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash, or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2016-1641)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2016-1642)\n\nA type-confusion bug was discovered in Blink. If a user were tricked in\nto opening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1643)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2016-2843)\n\nAn invalid cast was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via renderer crash or execute arbitrary\ncode with the privileges of the sandboxed render process. (CVE-2016-2844)\n\nIt was discovered that the Content Security Policy (CSP) implementation in\nBlink did not ignore a URL's path component in the case of a ServiceWorker\nfetch. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit this to obtain sensitive\ninformation. (CVE-2016-2845)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.14.04.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqmlscene","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.15.10.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2016-1630","CVE-2016-1631","CVE-2016-1633","CVE-2016-1634","CVE-2016-1636","CVE-2016-1637","CVE-2016-1641","CVE-2016-1642","CVE-2016-1643","CVE-2016-1644","CVE-2016-2843","CVE-2016-2844","CVE-2016-2845"]}]},{"id":"CVE-2016-2844","published":"2016-03-05T00:00:00","updated_at":"2025-08-25T21:59:03.257936+00:00","description":"\nWebKit/Source/core/layout/LayoutBlock.cpp in Blink, as used in Google\nChrome before 49.0.2623.75, does not properly determine when anonymous\nblock wrappers may exist, which allows remote attackers to cause a denial\nof service (incorrect cast and assertion failure) or possibly have\nunspecified other impact via crafted JavaScript code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://codereview.chromium.org/1423573002","https://code.google.com/p/chromium/issues/detail?id=591402","https://bugs.chromium.org/p/chromium/issues/detail?id=546849","http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2920-1","https://www.cve.org/CVERecord?id=CVE-2016-2844"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"49.0.2623.87-0ubuntu0.14.04.1.1112","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"49.0.2623.75","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"49.0.2623.87-0ubuntu0.15.10.1.1222","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.13.6-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.13.6","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.13.6-0ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2920-1"],"notices":[{"id":"USN-2920-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-03-10T17:22:56.088009","description":"It was discovered that the ContainerNode::parserRemoveChild function in\nBlink mishandled widget updates in some circumstances. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1630)\n\nIt was discovered that the PPB_Flash_MessageLoop_Impl::InternalRun \nfunction in Chromium mishandled nested message loops. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1631)\n\nMultiple use-after-frees were discovered in Blink. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1633, CVE-2016-1634, CVE-2016-1644)\n\nIt was discovered that the PendingScript::notifyFinished function in\nBlink relied on memory-cache information about integrity-check occurrences\ninstead of integrity-check successes. If a user were tricked in to opening\na specially crafted website, an attacker could potentially exploit this to\nbypass Subresource Integrity (SRI) protections. (CVE-2016-1636)\n\nIt was discovered that the SkATan2_255 function in Skia mishandled\narctangent calculations. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to obtain\nsensitive information. (CVE-2016-1637)\n\nA use-after-free was discovered in Chromium. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash, or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2016-1641)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2016-1642)\n\nA type-confusion bug was discovered in Blink. If a user were tricked in\nto opening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1643)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2016-2843)\n\nAn invalid cast was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via renderer crash or execute arbitrary\ncode with the privileges of the sandboxed render process. (CVE-2016-2844)\n\nIt was discovered that the Content Security Policy (CSP) implementation in\nBlink did not ignore a URL's path component in the case of a ServiceWorker\nfetch. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit this to obtain sensitive\ninformation. (CVE-2016-2845)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.14.04.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqmlscene","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.15.10.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2016-1630","CVE-2016-1631","CVE-2016-1633","CVE-2016-1634","CVE-2016-1636","CVE-2016-1637","CVE-2016-1641","CVE-2016-1642","CVE-2016-1643","CVE-2016-1644","CVE-2016-2843","CVE-2016-2844","CVE-2016-2845"]}]},{"id":"CVE-2016-2843","published":"2016-03-05T00:00:00","updated_at":"2025-08-25T21:59:03.257936+00:00","description":"\nMultiple unspecified vulnerabilities in Google V8 before 4.9.385.26, as\nused in Google Chrome before 49.0.2623.75, allow attackers to cause a\ndenial of service or possibly have other impact via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2920-1","https://www.cve.org/CVERecord?id=CVE-2016-2843"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"49.0.2623.87-0ubuntu0.14.04.1.1112","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"49.0.2623.75","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"49.0.2623.87-0ubuntu0.15.10.1.1222","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.13.6-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.13.6","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.13.6-0ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2920-1"],"notices":[{"id":"USN-2920-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-03-10T17:22:56.088009","description":"It was discovered that the ContainerNode::parserRemoveChild function in\nBlink mishandled widget updates in some circumstances. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1630)\n\nIt was discovered that the PPB_Flash_MessageLoop_Impl::InternalRun \nfunction in Chromium mishandled nested message loops. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1631)\n\nMultiple use-after-frees were discovered in Blink. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1633, CVE-2016-1634, CVE-2016-1644)\n\nIt was discovered that the PendingScript::notifyFinished function in\nBlink relied on memory-cache information about integrity-check occurrences\ninstead of integrity-check successes. If a user were tricked in to opening\na specially crafted website, an attacker could potentially exploit this to\nbypass Subresource Integrity (SRI) protections. (CVE-2016-1636)\n\nIt was discovered that the SkATan2_255 function in Skia mishandled\narctangent calculations. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to obtain\nsensitive information. (CVE-2016-1637)\n\nA use-after-free was discovered in Chromium. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash, or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2016-1641)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2016-1642)\n\nA type-confusion bug was discovered in Blink. If a user were tricked in\nto opening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1643)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2016-2843)\n\nAn invalid cast was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via renderer crash or execute arbitrary\ncode with the privileges of the sandboxed render process. (CVE-2016-2844)\n\nIt was discovered that the Content Security Policy (CSP) implementation in\nBlink did not ignore a URL's path component in the case of a ServiceWorker\nfetch. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit this to obtain sensitive\ninformation. (CVE-2016-2845)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.14.04.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqmlscene","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.15.10.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2016-1630","CVE-2016-1631","CVE-2016-1633","CVE-2016-1634","CVE-2016-1636","CVE-2016-1637","CVE-2016-1641","CVE-2016-1642","CVE-2016-1643","CVE-2016-1644","CVE-2016-2843","CVE-2016-2844","CVE-2016-2845"]}]},{"id":"CVE-2016-1642","published":"2016-03-05T00:00:00","updated_at":"2025-08-25T21:54:46.416655+00:00","description":"\nMultiple unspecified vulnerabilities in Google Chrome before 49.0.2623.75\nallow attackers to cause a denial of service or possibly have other impact\nvia unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.ca/2016/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2920-1","https://www.cve.org/CVERecord?id=CVE-2016-1642"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"49.0.2623.87-0ubuntu0.14.04.1.1112","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"49.0.2623.75","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"49.0.2623.87-0ubuntu0.15.10.1.1222","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.13.6-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.13.6","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.13.6-0ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2920-1"],"notices":[{"id":"USN-2920-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-03-10T17:22:56.088009","description":"It was discovered that the ContainerNode::parserRemoveChild function in\nBlink mishandled widget updates in some circumstances. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1630)\n\nIt was discovered that the PPB_Flash_MessageLoop_Impl::InternalRun \nfunction in Chromium mishandled nested message loops. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1631)\n\nMultiple use-after-frees were discovered in Blink. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1633, CVE-2016-1634, CVE-2016-1644)\n\nIt was discovered that the PendingScript::notifyFinished function in\nBlink relied on memory-cache information about integrity-check occurrences\ninstead of integrity-check successes. If a user were tricked in to opening\na specially crafted website, an attacker could potentially exploit this to\nbypass Subresource Integrity (SRI) protections. (CVE-2016-1636)\n\nIt was discovered that the SkATan2_255 function in Skia mishandled\narctangent calculations. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to obtain\nsensitive information. (CVE-2016-1637)\n\nA use-after-free was discovered in Chromium. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash, or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2016-1641)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2016-1642)\n\nA type-confusion bug was discovered in Blink. If a user were tricked in\nto opening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1643)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2016-2843)\n\nAn invalid cast was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via renderer crash or execute arbitrary\ncode with the privileges of the sandboxed render process. (CVE-2016-2844)\n\nIt was discovered that the Content Security Policy (CSP) implementation in\nBlink did not ignore a URL's path component in the case of a ServiceWorker\nfetch. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit this to obtain sensitive\ninformation. (CVE-2016-2845)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.14.04.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqmlscene","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.15.10.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2016-1630","CVE-2016-1631","CVE-2016-1633","CVE-2016-1634","CVE-2016-1636","CVE-2016-1637","CVE-2016-1641","CVE-2016-1642","CVE-2016-1643","CVE-2016-1644","CVE-2016-2843","CVE-2016-2844","CVE-2016-2845"]}]},{"id":"CVE-2016-1641","published":"2016-03-05T00:00:00","updated_at":"2025-08-25T21:54:41.566036+00:00","description":"\nUse-after-free vulnerability in\ncontent/browser/web_contents/web_contents_impl.cc in Google Chrome before\n49.0.2623.75 allows remote attackers to cause a denial of service or\npossibly have unspecified other impact by triggering an image download\nafter a certain data structure is deleted, as demonstrated by a favicon.ico\ndownload.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.ca/2016/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2920-1","https://www.cve.org/CVERecord?id=CVE-2016-1641"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"49.0.2623.87-0ubuntu0.14.04.1.1112","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"49.0.2623.75","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"49.0.2623.87-0ubuntu0.15.10.1.1222","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.13.6-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.13.6","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.13.6-0ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2920-1"],"notices":[{"id":"USN-2920-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-03-10T17:22:56.088009","description":"It was discovered that the ContainerNode::parserRemoveChild function in\nBlink mishandled widget updates in some circumstances. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1630)\n\nIt was discovered that the PPB_Flash_MessageLoop_Impl::InternalRun \nfunction in Chromium mishandled nested message loops. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1631)\n\nMultiple use-after-frees were discovered in Blink. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1633, CVE-2016-1634, CVE-2016-1644)\n\nIt was discovered that the PendingScript::notifyFinished function in\nBlink relied on memory-cache information about integrity-check occurrences\ninstead of integrity-check successes. If a user were tricked in to opening\na specially crafted website, an attacker could potentially exploit this to\nbypass Subresource Integrity (SRI) protections. (CVE-2016-1636)\n\nIt was discovered that the SkATan2_255 function in Skia mishandled\narctangent calculations. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to obtain\nsensitive information. (CVE-2016-1637)\n\nA use-after-free was discovered in Chromium. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash, or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2016-1641)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2016-1642)\n\nA type-confusion bug was discovered in Blink. If a user were tricked in\nto opening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1643)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2016-2843)\n\nAn invalid cast was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via renderer crash or execute arbitrary\ncode with the privileges of the sandboxed render process. (CVE-2016-2844)\n\nIt was discovered that the Content Security Policy (CSP) implementation in\nBlink did not ignore a URL's path component in the case of a ServiceWorker\nfetch. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit this to obtain sensitive\ninformation. (CVE-2016-2845)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.14.04.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqmlscene","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.15.10.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2016-1630","CVE-2016-1631","CVE-2016-1633","CVE-2016-1634","CVE-2016-1636","CVE-2016-1637","CVE-2016-1641","CVE-2016-1642","CVE-2016-1643","CVE-2016-1644","CVE-2016-2843","CVE-2016-2844","CVE-2016-2845"]}]},{"id":"CVE-2016-1637","published":"2016-03-05T00:00:00","updated_at":"2025-08-25T21:54:41.566036+00:00","description":"\nThe SkATan2_255 function in effects/gradients/SkSweepGradient.cpp in Skia,\nas used in Google Chrome before 49.0.2623.75, mishandles arctangent\ncalculations, which allows remote attackers to obtain sensitive information\nvia a crafted web site.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.ca/2016/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2920-1","https://www.cve.org/CVERecord?id=CVE-2016-1637"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"49.0.2623.87-0ubuntu0.14.04.1.1112","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"49.0.2623.75","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"49.0.2623.87-0ubuntu0.15.10.1.1222","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.13.6-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.13.6","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.13.6-0ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2920-1"],"notices":[{"id":"USN-2920-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-03-10T17:22:56.088009","description":"It was discovered that the ContainerNode::parserRemoveChild function in\nBlink mishandled widget updates in some circumstances. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1630)\n\nIt was discovered that the PPB_Flash_MessageLoop_Impl::InternalRun \nfunction in Chromium mishandled nested message loops. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1631)\n\nMultiple use-after-frees were discovered in Blink. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1633, CVE-2016-1634, CVE-2016-1644)\n\nIt was discovered that the PendingScript::notifyFinished function in\nBlink relied on memory-cache information about integrity-check occurrences\ninstead of integrity-check successes. If a user were tricked in to opening\na specially crafted website, an attacker could potentially exploit this to\nbypass Subresource Integrity (SRI) protections. (CVE-2016-1636)\n\nIt was discovered that the SkATan2_255 function in Skia mishandled\narctangent calculations. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to obtain\nsensitive information. (CVE-2016-1637)\n\nA use-after-free was discovered in Chromium. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash, or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2016-1641)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2016-1642)\n\nA type-confusion bug was discovered in Blink. If a user were tricked in\nto opening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1643)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2016-2843)\n\nAn invalid cast was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via renderer crash or execute arbitrary\ncode with the privileges of the sandboxed render process. (CVE-2016-2844)\n\nIt was discovered that the Content Security Policy (CSP) implementation in\nBlink did not ignore a URL's path component in the case of a ServiceWorker\nfetch. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit this to obtain sensitive\ninformation. (CVE-2016-2845)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.14.04.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqmlscene","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.15.10.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2016-1630","CVE-2016-1631","CVE-2016-1633","CVE-2016-1634","CVE-2016-1636","CVE-2016-1637","CVE-2016-1641","CVE-2016-1642","CVE-2016-1643","CVE-2016-1644","CVE-2016-2843","CVE-2016-2844","CVE-2016-2845"]}]},{"id":"CVE-2016-1636","published":"2016-03-05T00:00:00","updated_at":"2025-08-25T21:54:41.566036+00:00","description":"\nThe PendingScript::notifyFinished function in\nWebKit/Source/core/dom/PendingScript.cpp in Google Chrome before\n49.0.2623.75 relies on memory-cache information about integrity-check\noccurrences instead of integrity-check successes, which allows remote\nattackers to bypass the Subresource Integrity (aka SRI) protection\nmechanism by triggering two loads of the same resource.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.ca/2016/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2920-1","https://www.cve.org/CVERecord?id=CVE-2016-1636"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"49.0.2623.87-0ubuntu0.14.04.1.1112","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"49.0.2623.75","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"49.0.2623.87-0ubuntu0.15.10.1.1222","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.13.6-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.13.6","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.13.6-0ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2920-1"],"notices":[{"id":"USN-2920-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-03-10T17:22:56.088009","description":"It was discovered that the ContainerNode::parserRemoveChild function in\nBlink mishandled widget updates in some circumstances. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1630)\n\nIt was discovered that the PPB_Flash_MessageLoop_Impl::InternalRun \nfunction in Chromium mishandled nested message loops. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1631)\n\nMultiple use-after-frees were discovered in Blink. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1633, CVE-2016-1634, CVE-2016-1644)\n\nIt was discovered that the PendingScript::notifyFinished function in\nBlink relied on memory-cache information about integrity-check occurrences\ninstead of integrity-check successes. If a user were tricked in to opening\na specially crafted website, an attacker could potentially exploit this to\nbypass Subresource Integrity (SRI) protections. (CVE-2016-1636)\n\nIt was discovered that the SkATan2_255 function in Skia mishandled\narctangent calculations. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to obtain\nsensitive information. (CVE-2016-1637)\n\nA use-after-free was discovered in Chromium. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash, or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2016-1641)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2016-1642)\n\nA type-confusion bug was discovered in Blink. If a user were tricked in\nto opening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1643)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2016-2843)\n\nAn invalid cast was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via renderer crash or execute arbitrary\ncode with the privileges of the sandboxed render process. (CVE-2016-2844)\n\nIt was discovered that the Content Security Policy (CSP) implementation in\nBlink did not ignore a URL's path component in the case of a ServiceWorker\nfetch. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit this to obtain sensitive\ninformation. (CVE-2016-2845)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.14.04.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqmlscene","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.15.10.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2016-1630","CVE-2016-1631","CVE-2016-1633","CVE-2016-1634","CVE-2016-1636","CVE-2016-1637","CVE-2016-1641","CVE-2016-1642","CVE-2016-1643","CVE-2016-1644","CVE-2016-2843","CVE-2016-2844","CVE-2016-2845"]}]},{"id":"CVE-2016-1634","published":"2016-03-05T00:00:00","updated_at":"2025-08-25T21:54:41.566036+00:00","description":"\nUse-after-free vulnerability in the StyleResolver::appendCSSStyleSheet\nfunction in WebKit/Source/core/css/resolver/StyleResolver.cpp in Blink, as\nused in Google Chrome before 49.0.2623.75, allows remote attackers to cause\na denial of service or possibly have unspecified other impact via a crafted\nweb site that triggers Cascading Style Sheets (CSS) style invalidation\nduring a certain subtree-removal action.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.ca/2016/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2920-1","https://www.cve.org/CVERecord?id=CVE-2016-1634"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"49.0.2623.87-0ubuntu0.14.04.1.1112","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"49.0.2623.75","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"49.0.2623.87-0ubuntu0.15.10.1.1222","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.13.6-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.13.6","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.13.6-0ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2920-1"],"notices":[{"id":"USN-2920-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-03-10T17:22:56.088009","description":"It was discovered that the ContainerNode::parserRemoveChild function in\nBlink mishandled widget updates in some circumstances. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1630)\n\nIt was discovered that the PPB_Flash_MessageLoop_Impl::InternalRun \nfunction in Chromium mishandled nested message loops. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1631)\n\nMultiple use-after-frees were discovered in Blink. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1633, CVE-2016-1634, CVE-2016-1644)\n\nIt was discovered that the PendingScript::notifyFinished function in\nBlink relied on memory-cache information about integrity-check occurrences\ninstead of integrity-check successes. If a user were tricked in to opening\na specially crafted website, an attacker could potentially exploit this to\nbypass Subresource Integrity (SRI) protections. (CVE-2016-1636)\n\nIt was discovered that the SkATan2_255 function in Skia mishandled\narctangent calculations. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to obtain\nsensitive information. (CVE-2016-1637)\n\nA use-after-free was discovered in Chromium. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash, or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2016-1641)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2016-1642)\n\nA type-confusion bug was discovered in Blink. If a user were tricked in\nto opening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1643)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2016-2843)\n\nAn invalid cast was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via renderer crash or execute arbitrary\ncode with the privileges of the sandboxed render process. (CVE-2016-2844)\n\nIt was discovered that the Content Security Policy (CSP) implementation in\nBlink did not ignore a URL's path component in the case of a ServiceWorker\nfetch. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit this to obtain sensitive\ninformation. (CVE-2016-2845)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.14.04.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqmlscene","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.15.10.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2016-1630","CVE-2016-1631","CVE-2016-1633","CVE-2016-1634","CVE-2016-1636","CVE-2016-1637","CVE-2016-1641","CVE-2016-1642","CVE-2016-1643","CVE-2016-1644","CVE-2016-2843","CVE-2016-2844","CVE-2016-2845"]}]},{"id":"CVE-2016-1633","published":"2016-03-05T00:00:00","updated_at":"2025-08-25T21:54:41.566036+00:00","description":"\nUse-after-free vulnerability in Blink, as used in Google Chrome before\n49.0.2623.75, allows remote attackers to cause a denial of service or\npossibly have unspecified other impact via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.ca/2016/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2920-1","https://www.cve.org/CVERecord?id=CVE-2016-1633"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"49.0.2623.87-0ubuntu0.14.04.1.1112","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"49.0.2623.75","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"49.0.2623.87-0ubuntu0.15.10.1.1222","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.13.6-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.13.6","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.13.6-0ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2920-1"],"notices":[{"id":"USN-2920-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-03-10T17:22:56.088009","description":"It was discovered that the ContainerNode::parserRemoveChild function in\nBlink mishandled widget updates in some circumstances. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1630)\n\nIt was discovered that the PPB_Flash_MessageLoop_Impl::InternalRun \nfunction in Chromium mishandled nested message loops. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1631)\n\nMultiple use-after-frees were discovered in Blink. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1633, CVE-2016-1634, CVE-2016-1644)\n\nIt was discovered that the PendingScript::notifyFinished function in\nBlink relied on memory-cache information about integrity-check occurrences\ninstead of integrity-check successes. If a user were tricked in to opening\na specially crafted website, an attacker could potentially exploit this to\nbypass Subresource Integrity (SRI) protections. (CVE-2016-1636)\n\nIt was discovered that the SkATan2_255 function in Skia mishandled\narctangent calculations. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to obtain\nsensitive information. (CVE-2016-1637)\n\nA use-after-free was discovered in Chromium. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash, or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2016-1641)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2016-1642)\n\nA type-confusion bug was discovered in Blink. If a user were tricked in\nto opening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1643)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2016-2843)\n\nAn invalid cast was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via renderer crash or execute arbitrary\ncode with the privileges of the sandboxed render process. (CVE-2016-2844)\n\nIt was discovered that the Content Security Policy (CSP) implementation in\nBlink did not ignore a URL's path component in the case of a ServiceWorker\nfetch. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit this to obtain sensitive\ninformation. (CVE-2016-2845)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.14.04.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqmlscene","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.15.10.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2016-1630","CVE-2016-1631","CVE-2016-1633","CVE-2016-1634","CVE-2016-1636","CVE-2016-1637","CVE-2016-1641","CVE-2016-1642","CVE-2016-1643","CVE-2016-1644","CVE-2016-2843","CVE-2016-2844","CVE-2016-2845"]}]},{"id":"CVE-2016-1631","published":"2016-03-05T00:00:00","updated_at":"2025-08-25T21:54:36.673372+00:00","description":"\nThe PPB_Flash_MessageLoop_Impl::InternalRun function in\ncontent/renderer/pepper/ppb_flash_message_loop_impl.cc in the Pepper plugin\nin Google Chrome before 49.0.2623.75 mishandles nested message loops, which\nallows remote attackers to bypass the Same Origin Policy via a crafted web\nsite.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.ca/2016/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2920-1","https://www.cve.org/CVERecord?id=CVE-2016-1631"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"49.0.2623.87-0ubuntu0.14.04.1.1112","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"49.0.2623.75","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"49.0.2623.87-0ubuntu0.15.10.1.1222","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.13.6-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.13.6","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.13.6-0ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2920-1"],"notices":[{"id":"USN-2920-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-03-10T17:22:56.088009","description":"It was discovered that the ContainerNode::parserRemoveChild function in\nBlink mishandled widget updates in some circumstances. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1630)\n\nIt was discovered that the PPB_Flash_MessageLoop_Impl::InternalRun \nfunction in Chromium mishandled nested message loops. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1631)\n\nMultiple use-after-frees were discovered in Blink. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1633, CVE-2016-1634, CVE-2016-1644)\n\nIt was discovered that the PendingScript::notifyFinished function in\nBlink relied on memory-cache information about integrity-check occurrences\ninstead of integrity-check successes. If a user were tricked in to opening\na specially crafted website, an attacker could potentially exploit this to\nbypass Subresource Integrity (SRI) protections. (CVE-2016-1636)\n\nIt was discovered that the SkATan2_255 function in Skia mishandled\narctangent calculations. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to obtain\nsensitive information. (CVE-2016-1637)\n\nA use-after-free was discovered in Chromium. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash, or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2016-1641)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2016-1642)\n\nA type-confusion bug was discovered in Blink. If a user were tricked in\nto opening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1643)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2016-2843)\n\nAn invalid cast was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via renderer crash or execute arbitrary\ncode with the privileges of the sandboxed render process. (CVE-2016-2844)\n\nIt was discovered that the Content Security Policy (CSP) implementation in\nBlink did not ignore a URL's path component in the case of a ServiceWorker\nfetch. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit this to obtain sensitive\ninformation. (CVE-2016-2845)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.14.04.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqmlscene","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.15.10.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2016-1630","CVE-2016-1631","CVE-2016-1633","CVE-2016-1634","CVE-2016-1636","CVE-2016-1637","CVE-2016-1641","CVE-2016-1642","CVE-2016-1643","CVE-2016-1644","CVE-2016-2843","CVE-2016-2844","CVE-2016-2845"]}]},{"id":"CVE-2016-1630","published":"2016-03-05T00:00:00","updated_at":"2025-08-25T21:54:36.673372+00:00","description":"\nThe ContainerNode::parserRemoveChild function in\nWebKit/Source/core/dom/ContainerNode.cpp in Blink, as used in Google Chrome\nbefore 49.0.2623.75, mishandles widget updates, which makes it easier for\nremote attackers to bypass the Same Origin Policy via a crafted web site.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.ca/2016/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2920-1","https://www.cve.org/CVERecord?id=CVE-2016-1630"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"49.0.2623.75","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"49.0.2623.87-0ubuntu0.14.04.1.1112","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"49.0.2623.87-0ubuntu0.15.10.1.1222","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.13.6-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.13.6","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.13.6-0ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2920-1"],"notices":[{"id":"USN-2920-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-03-10T17:22:56.088009","description":"It was discovered that the ContainerNode::parserRemoveChild function in\nBlink mishandled widget updates in some circumstances. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1630)\n\nIt was discovered that the PPB_Flash_MessageLoop_Impl::InternalRun \nfunction in Chromium mishandled nested message loops. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1631)\n\nMultiple use-after-frees were discovered in Blink. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1633, CVE-2016-1634, CVE-2016-1644)\n\nIt was discovered that the PendingScript::notifyFinished function in\nBlink relied on memory-cache information about integrity-check occurrences\ninstead of integrity-check successes. If a user were tricked in to opening\na specially crafted website, an attacker could potentially exploit this to\nbypass Subresource Integrity (SRI) protections. (CVE-2016-1636)\n\nIt was discovered that the SkATan2_255 function in Skia mishandled\narctangent calculations. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to obtain\nsensitive information. (CVE-2016-1637)\n\nA use-after-free was discovered in Chromium. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash, or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2016-1641)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2016-1642)\n\nA type-confusion bug was discovered in Blink. If a user were tricked in\nto opening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2016-1643)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2016-2843)\n\nAn invalid cast was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via renderer crash or execute arbitrary\ncode with the privileges of the sandboxed render process. (CVE-2016-2844)\n\nIt was discovered that the Content Security Policy (CSP) implementation in\nBlink did not ignore a URL's path component in the case of a ServiceWorker\nfetch. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit this to obtain sensitive\ninformation. (CVE-2016-2845)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.14.04.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick-dev","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick0","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqmlscene","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.13.6-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"oxide-qt","version":"1.13.6-0ubuntu0.15.10.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.13.6-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2016-1630","CVE-2016-1631","CVE-2016-1633","CVE-2016-1634","CVE-2016-1636","CVE-2016-1637","CVE-2016-1641","CVE-2016-1642","CVE-2016-1643","CVE-2016-1644","CVE-2016-2843","CVE-2016-2844","CVE-2016-2845"]}]}],"offset":61440,"limit":20,"total_results":79316}