{"cves":[{"id":"CVE-2015-8540","published":"2015-12-11T00:00:00","updated_at":"2025-08-25T21:48:05.362609+00:00","description":"\nInteger underflow in the png_check_keyword function in pngwutil.c in libpng\n0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56,\n1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote\nattackers to have unspecified impact via a space character as a keyword in\na PNG image, which triggers an out-of-bounds read.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/12/10/6","https://ubuntu.com/security/notices/USN-2861-1","https://www.cve.org/CVERecord?id=CVE-2015-8540"],"bugs":["https://sourceforge.net/p/libpng/bugs/244/","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=807694"],"patches":{"libpng":["upstream: http://sourceforge.net/p/libpng/code/ci/d9006f683c641793252d92254a75ae9b815b42ed/","upstream: https://github.com/glennrp/libpng/commit/520b373ee53e92dce93917fea5a609b2a0291472"],"firefox":[],"thunderbird":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"not-affected","description":"uses system libpng","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"uses system libpng","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"uses system libpng","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [uses system libpng]]","component":null,"pocket":"security"}]},{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"bundles libpng 1.6.18","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"bundles libpng 1.6.18","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"bundles libpng 1.6.18","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"bundles libpng 1.6.18","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [bundles libpng 1.6.18]]","component":null,"pocket":"security"}]},{"name":"libpng","source":"https://ubuntu.com/security/cve?package=libpng","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpng","debian":"https://tracker.debian.org/pkg/libpng","statuses":[{"release_codename":"precise","status":"released","description":"1.2.46-3ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.2.50-1ubuntu2.14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"1.0.66, 1.2.56, 1.4.19, and 1.5.26","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.2.51-0ubuntu3.15.04.2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.2.51-0ubuntu3.15.10.2","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"precise","status":"not-affected","description":"bundles libpng 1.6.16","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"bundles libpng 1.6.16","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"bundles libpng 1.6.16","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"bundles libpng 1.6.16","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [bundles libpng 1.6.16]]","component":null,"pocket":"security"}]}],"notices_ids":["USN-2861-1"],"notices":[{"id":"USN-2861-1","title":"libpng vulnerabilities","summary":"libpng could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2016-01-06T17:36:40.396599","description":"It was discovered that libpng incorrectly handled certain small bit-depth\nvalues. If a user or automated system using libpng were tricked into\nopening a specially crafted image, an attacker could exploit this to cause\na denial of service or execute code with the privileges of the user\ninvoking the program. (CVE-2015-8472)\n\nQixue Xiao and Chen Yu discovered that libpng incorrectly handled certain\nmalformed images. If a user or automated system using libpng were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service. (CVE-2015-8540)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libpng","version":"1.2.46-3ubuntu4.2","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.46-3ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.46-3ubuntu4.2"}],"trusty":[{"name":"libpng","version":"1.2.50-1ubuntu2.14.04.2","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.50-1ubuntu2.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.50-1ubuntu2.14.04.2","pocket":"security"},{"name":"libpng12-0-udeb","version":"1.2.50-1ubuntu2.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.50-1ubuntu2.14.04.2","pocket":"security"},{"name":"libpng12-dev","version":"1.2.50-1ubuntu2.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.50-1ubuntu2.14.04.2","pocket":"security"},{"name":"libpng3","version":"1.2.50-1ubuntu2.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.50-1ubuntu2.14.04.2","pocket":"security"}],"vivid":[{"name":"libpng","version":"1.2.51-0ubuntu3.15.04.2","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.51-0ubuntu3.15.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.51-0ubuntu3.15.04.2"}],"wily":[{"name":"libpng","version":"1.2.51-0ubuntu3.15.10.2","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.51-0ubuntu3.15.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.51-0ubuntu3.15.10.2"}]},"type":"USN","cves_ids":["CVE-2015-8472","CVE-2015-8540"]}]},{"id":"CVE-2015-8370","published":"2015-12-11T00:00:00","updated_at":"2025-08-25T21:47:23.162008+00:00","description":"\nMultiple integer underflows in Grub2 1.98 through 2.02 allow physically\nproximate attackers to bypass authentication, obtain sensitive information,\nor cause a denial of service (disk corruption) via backspace characters in\nthe (1) grub_username_get function in grub-core/normal/auth.c or the (2)\ngrub_password_get function in lib/crypto.c, which trigger an \"Off-by-two\"\nor \"Out of bounds overwrite\" memory error.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.4,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://twitter.com/lostinsecurity/status/674925944524640257","http://hmarco.org/bugs/CVE-2015-8370-Grub2-authentication-bypass.html","https://ubuntu.com/security/notices/USN-2836-1","https://www.cve.org/CVERecord?id=CVE-2015-8370"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=807614","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-8370"],"patches":{"grub2":["distro: https://bugzilla.redhat.com/attachment.cgi?id=1100986&action=diff"]},"tags":{},"packages":[{"name":"grub2","source":"https://ubuntu.com/security/cve?package=grub2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grub2","debian":"https://tracker.debian.org/pkg/grub2","statuses":[{"release_codename":"precise","status":"released","description":"1.99-21ubuntu3.19","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.02~beta2-9ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"2.02~beta2-22ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"2.02~beta2-29ubuntu0.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-2836-1"],"notices":[{"id":"USN-2836-1","title":"GRUB vulnerability","summary":"GRUB password protection can be bypassed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2015-12-15T19:23:48.715491","description":"Hector Marco and Ismael Ripoll discovered that GRUB incorrectly handled\nthe backspace key when configured to use authentication. A local attacker\ncould use this issue to bypass GRUB password protection.\n","is_hidden":false,"release_packages":{"precise":[{"name":"grub2","version":"1.99-21ubuntu3.19","description":"GRand Unified Bootloader","is_source":true},{"name":"grub2-common","version":"1.99-21ubuntu3.19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/1.99-21ubuntu3.19"}],"trusty":[{"name":"grub2","version":"2.02~beta2-9ubuntu1.6","description":"GRand Unified Bootloader","is_source":true},{"name":"grub-common","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-coreboot","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-coreboot-bin","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-efi","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-efi-amd64","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-efi-amd64-bin","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-efi-arm","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-efi-arm-bin","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-efi-arm64","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-efi-arm64-bin","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-efi-ia32","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-efi-ia32-bin","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-emu","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-firmware-qemu","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-ieee1275","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-ieee1275-bin","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-linuxbios","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-mount-udeb","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-pc","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-pc-bin","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-rescue-pc","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-theme-starfield","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-uboot","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-uboot-bin","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-xen","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub-xen-bin","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub2","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"},{"name":"grub2-common","version":"2.02~beta2-9ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6","pocket":"security"}],"vivid":[{"name":"grub2","version":"2.02~beta2-22ubuntu1.4","description":"GRand Unified Bootloader","is_source":true},{"name":"grub2-common","version":"2.02~beta2-22ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-22ubuntu1.4"}],"wily":[{"name":"grub2","version":"2.02~beta2-29ubuntu0.2","description":"GRand Unified Bootloader","is_source":true},{"name":"grub2-common","version":"2.02~beta2-29ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/grub2","version_link":"https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-29ubuntu0.2"}]},"type":"USN","cves_ids":["CVE-2015-8370"]}]},{"id":"CVE-2015-7529","published":"2015-12-11T00:00:00","updated_at":"2025-08-25T21:45:22.910651+00:00","description":"\nsosreport in SoS 3.x allows local users to obtain sensitive information\nfrom sosreport files or gain privileges via a symlink attack on an archive\nfile in a temporary directory, as demonstrated by\nsosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2845-1","https://www.cve.org/CVERecord?id=CVE-2015-7529"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1282542"],"patches":{"sosreport":["upstream: https://github.com/sosreport/sos/commit/4a9b919a7f1b9542a23982e49cc9035e84551e13","upstream: https://github.com/sosreport/sos/commit/19e2bbccb6a86d6ea94f5c82860bed4d2276bbf3","upstream: https://github.com/sosreport/sos/commit/7f2727749d0c37095a20c5d4cf6f9a2e086a2375","upstream: https://github.com/sosreport/sos/commit/6038fdf8617319a13b0b42f3283ec2066d54b283","upstream: https://github.com/sosreport/sos/commit/08121d877741e33333a1ae01280f6898d7d4ca15"]},"tags":{"sosreport":["symlink-restriction"]},"packages":[{"name":"sosreport","source":"https://ubuntu.com/security/cve?package=sosreport","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sosreport","debian":"https://tracker.debian.org/pkg/sosreport","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.1-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2+git276-g7da50d6-3","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"3.2-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.2-2ubuntu1.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2845-1"],"notices":[{"id":"USN-2845-1","title":"SoS vulnerabilities","summary":"sosreport could be made to expose sensitive information or overwrite files\nas the administrator.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-12-18T03:39:01.461560","description":"Dolev Farhi discovered an information disclosure issue in SoS. If the\n/etc/fstab file contained passwords, the passwords were included in the\nSoS report. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-3925)\n\nMateusz Guzik discovered that SoS incorrectly handled temporary files. A\nlocal attacker could possibly use this issue to overwrite arbitrary files\nor gain access to temporary file contents containing sensitive system\ninformation. (CVE-2015-7529)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"sosreport","version":"3.1-1ubuntu2.2","description":"Set of tools to gather troubleshooting data from a system","is_source":true},{"name":"sosreport","version":"3.1-1ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sosreport","version_link":"https://launchpad.net/ubuntu/+source/sosreport/3.1-1ubuntu2.2","pocket":"security"}],"vivid":[{"name":"sosreport","version":"3.2-2ubuntu0.1","description":"Set of tools to gather troubleshooting data from a system","is_source":true},{"name":"sosreport","version":"3.2-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sosreport","version_link":"https://launchpad.net/ubuntu/+source/sosreport/3.2-2ubuntu0.1"}],"wily":[{"name":"sosreport","version":"3.2-2ubuntu1.1","description":"Set of tools to gather troubleshooting data from a system","is_source":true},{"name":"sosreport","version":"3.2-2ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sosreport","version_link":"https://launchpad.net/ubuntu/+source/sosreport/3.2-2ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2014-3925","CVE-2015-7529"]}]},{"id":"CVE-2015-8457","published":"2015-12-10T06:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in Adobe Flash Player before 18.0.0.268 and\n19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554\non Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and\nAdobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute\narbitrary code via unspecified vectors, a different vulnerability than\nCVE-2015-8407.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-32.html","https://www.cve.org/CVERecord?id=CVE-2015-8457"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20151208.1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20151208.1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20151208.1-0ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:20151208.1-0ubuntu0.15.10.1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.554ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.554ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.554ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"11.2.202.554ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8456","published":"2015-12-10T06:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on\nWindows and OS X and before 11.2.202.554 on Linux, Adobe AIR before\n20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler\nbefore 20.0.0.204 allow attackers to execute arbitrary code by leveraging\nan unspecified \"type confusion,\" a different vulnerability than\nCVE-2015-8439.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-32.html","https://www.cve.org/CVERecord?id=CVE-2015-8456"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20151208.1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20151208.1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20151208.1-0ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:20151208.1-0ubuntu0.15.10.1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.554ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.554ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.554ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"11.2.202.554ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8455","published":"2015-12-10T06:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on\nWindows and OS X and before 11.2.202.554 on Linux, Adobe AIR before\n20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler\nbefore 20.0.0.204 allow attackers to execute arbitrary code or cause a\ndenial of service (memory corruption) via unspecified vectors, a different\nvulnerability than CVE-2015-8045, CVE-2015-8047, CVE-2015-8060,\nCVE-2015-8408, CVE-2015-8416, CVE-2015-8417, CVE-2015-8418, CVE-2015-8419,\nCVE-2015-8443, CVE-2015-8444, and CVE-2015-8451.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-32.html","https://www.cve.org/CVERecord?id=CVE-2015-8455"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20151208.1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20151208.1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20151208.1-0ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:20151208.1-0ubuntu0.15.10.1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.554ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.554ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.554ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"11.2.202.554ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8454","published":"2015-12-10T06:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and\n19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554\non Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and\nAdobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute\narbitrary code via unspecified vectors, a different vulnerability than\nCVE-2015-8048, CVE-2015-8049, CVE-2015-8050, CVE-2015-8055, CVE-2015-8056,\nCVE-2015-8057, CVE-2015-8058, CVE-2015-8059, CVE-2015-8061, CVE-2015-8062,\nCVE-2015-8063, CVE-2015-8064, CVE-2015-8065, CVE-2015-8066, CVE-2015-8067,\nCVE-2015-8068, CVE-2015-8069, CVE-2015-8070, CVE-2015-8071, CVE-2015-8401,\nCVE-2015-8402, CVE-2015-8403, CVE-2015-8404, CVE-2015-8405, CVE-2015-8406,\nCVE-2015-8410, CVE-2015-8411, CVE-2015-8412, CVE-2015-8413, CVE-2015-8414,\nCVE-2015-8420, CVE-2015-8421, CVE-2015-8422, CVE-2015-8423, CVE-2015-8424,\nCVE-2015-8425, CVE-2015-8426, CVE-2015-8427, CVE-2015-8428, CVE-2015-8429,\nCVE-2015-8430, CVE-2015-8431, CVE-2015-8432, CVE-2015-8433, CVE-2015-8434,\nCVE-2015-8435, CVE-2015-8436, CVE-2015-8437, CVE-2015-8441, CVE-2015-8442,\nCVE-2015-8447, CVE-2015-8448, CVE-2015-8449, CVE-2015-8450, and\nCVE-2015-8452.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-32.html","https://www.cve.org/CVERecord?id=CVE-2015-8454"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20151208.1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20151208.1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20151208.1-0ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:20151208.1-0ubuntu0.15.10.1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.554ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.554ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.554ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"11.2.202.554ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8453","published":"2015-12-10T06:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on\nWindows and OS X and before 11.2.202.554 on Linux, Adobe AIR before\n20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler\nbefore 20.0.0.204 allow attackers to bypass the ASLR protection mechanism\nvia JIT data, a different vulnerability than CVE-2015-8409 and\nCVE-2015-8440.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-32.html","http://zerodayinitiative.com/advisories/ZDI-15-614","https://www.cve.org/CVERecord?id=CVE-2015-8453"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20151208.1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20151208.1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20151208.1-0ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:20151208.1-0ubuntu0.15.10.1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.554ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.554ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.554ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"11.2.202.554ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8452","published":"2015-12-10T06:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and\n19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554\non Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and\nAdobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute\narbitrary code via unspecified vectors, a different vulnerability than\nCVE-2015-8048, CVE-2015-8049, CVE-2015-8050, CVE-2015-8055, CVE-2015-8056,\nCVE-2015-8057, CVE-2015-8058, CVE-2015-8059, CVE-2015-8061, CVE-2015-8062,\nCVE-2015-8063, CVE-2015-8064, CVE-2015-8065, CVE-2015-8066, CVE-2015-8067,\nCVE-2015-8068, CVE-2015-8069, CVE-2015-8070, CVE-2015-8071, CVE-2015-8401,\nCVE-2015-8402, CVE-2015-8403, CVE-2015-8404, CVE-2015-8405, CVE-2015-8406,\nCVE-2015-8410, CVE-2015-8411, CVE-2015-8412, CVE-2015-8413, CVE-2015-8414,\nCVE-2015-8420, CVE-2015-8421, CVE-2015-8422, CVE-2015-8423, CVE-2015-8424,\nCVE-2015-8425, CVE-2015-8426, CVE-2015-8427, CVE-2015-8428, CVE-2015-8429,\nCVE-2015-8430, CVE-2015-8431, CVE-2015-8432, CVE-2015-8433, CVE-2015-8434,\nCVE-2015-8435, CVE-2015-8436, CVE-2015-8437, CVE-2015-8441, CVE-2015-8442,\nCVE-2015-8447, CVE-2015-8448, CVE-2015-8449, CVE-2015-8450, and\nCVE-2015-8454.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-32.html","https://www.cve.org/CVERecord?id=CVE-2015-8452"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20151208.1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20151208.1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20151208.1-0ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:20151208.1-0ubuntu0.15.10.1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.554ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.554ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.554ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"11.2.202.554ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8451","published":"2015-12-10T06:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on\nWindows and OS X and before 11.2.202.554 on Linux, Adobe AIR before\n20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler\nbefore 20.0.0.204 allow attackers to execute arbitrary code or cause a\ndenial of service (memory corruption) via unspecified vectors, a different\nvulnerability than CVE-2015-8045, CVE-2015-8047, CVE-2015-8060,\nCVE-2015-8408, CVE-2015-8416, CVE-2015-8417, CVE-2015-8418, CVE-2015-8419,\nCVE-2015-8443, CVE-2015-8444, and CVE-2015-8455.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-32.html","https://www.cve.org/CVERecord?id=CVE-2015-8451"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20151208.1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20151208.1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20151208.1-0ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:20151208.1-0ubuntu0.15.10.1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.554ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.554ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.554ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"11.2.202.554ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8450","published":"2015-12-10T06:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and\n19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554\non Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and\nAdobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute\narbitrary code via a crafted filters property value in a TextField object,\na different vulnerability than CVE-2015-8048, CVE-2015-8049, CVE-2015-8050,\nCVE-2015-8055, CVE-2015-8056, CVE-2015-8057, CVE-2015-8058, CVE-2015-8059,\nCVE-2015-8061, CVE-2015-8062, CVE-2015-8063, CVE-2015-8064, CVE-2015-8065,\nCVE-2015-8066, CVE-2015-8067, CVE-2015-8068, CVE-2015-8069, CVE-2015-8070,\nCVE-2015-8071, CVE-2015-8401, CVE-2015-8402, CVE-2015-8403, CVE-2015-8404,\nCVE-2015-8405, CVE-2015-8406, CVE-2015-8410, CVE-2015-8411, CVE-2015-8412,\nCVE-2015-8413, CVE-2015-8414, CVE-2015-8420, CVE-2015-8421, CVE-2015-8422,\nCVE-2015-8423, CVE-2015-8424, CVE-2015-8425, CVE-2015-8426, CVE-2015-8427,\nCVE-2015-8428, CVE-2015-8429, CVE-2015-8430, CVE-2015-8431, CVE-2015-8432,\nCVE-2015-8433, CVE-2015-8434, CVE-2015-8435, CVE-2015-8436, CVE-2015-8437,\nCVE-2015-8441, CVE-2015-8442, CVE-2015-8447, CVE-2015-8448, CVE-2015-8449,\nCVE-2015-8452, and CVE-2015-8454.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-32.html","http://zerodayinitiative.com/advisories/ZDI-15-613","https://www.cve.org/CVERecord?id=CVE-2015-8450"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20151208.1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20151208.1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20151208.1-0ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:20151208.1-0ubuntu0.15.10.1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.554ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.554ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.554ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"11.2.202.554ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8449","published":"2015-12-10T06:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the MovieClip object implementation in\nAdobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on\nWindows and OS X and before 11.2.202.554 on Linux, Adobe AIR before\n20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler\nbefore 20.0.0.204 allows attackers to execute arbitrary code via a crafted\nlineTo method call, a different vulnerability than CVE-2015-8048,\nCVE-2015-8049, CVE-2015-8050, CVE-2015-8055, CVE-2015-8056, CVE-2015-8057,\nCVE-2015-8058, CVE-2015-8059, CVE-2015-8061, CVE-2015-8062, CVE-2015-8063,\nCVE-2015-8064, CVE-2015-8065, CVE-2015-8066, CVE-2015-8067, CVE-2015-8068,\nCVE-2015-8069, CVE-2015-8070, CVE-2015-8071, CVE-2015-8401, CVE-2015-8402,\nCVE-2015-8403, CVE-2015-8404, CVE-2015-8405, CVE-2015-8406, CVE-2015-8410,\nCVE-2015-8411, CVE-2015-8412, CVE-2015-8413, CVE-2015-8414, CVE-2015-8420,\nCVE-2015-8421, CVE-2015-8422, CVE-2015-8423, CVE-2015-8424, CVE-2015-8425,\nCVE-2015-8426, CVE-2015-8427, CVE-2015-8428, CVE-2015-8429, CVE-2015-8430,\nCVE-2015-8431, CVE-2015-8432, CVE-2015-8433, CVE-2015-8434, CVE-2015-8435,\nCVE-2015-8436, CVE-2015-8437, CVE-2015-8441, CVE-2015-8442, CVE-2015-8447,\nCVE-2015-8448, CVE-2015-8450, CVE-2015-8452, and CVE-2015-8454.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-32.html","http://zerodayinitiative.com/advisories/ZDI-15-612","https://www.cve.org/CVERecord?id=CVE-2015-8449"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20151208.1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20151208.1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20151208.1-0ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:20151208.1-0ubuntu0.15.10.1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.554ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.554ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.554ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"11.2.202.554ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8448","published":"2015-12-10T06:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the DisplacementMapFilter object\nimplementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x\nbefore 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux,\nAdobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR\nSDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code\nvia a crafted mapBitmap property value, a different vulnerability than\nCVE-2015-8048, CVE-2015-8049, CVE-2015-8050, CVE-2015-8055, CVE-2015-8056,\nCVE-2015-8057, CVE-2015-8058, CVE-2015-8059, CVE-2015-8061, CVE-2015-8062,\nCVE-2015-8063, CVE-2015-8064, CVE-2015-8065, CVE-2015-8066, CVE-2015-8067,\nCVE-2015-8068, CVE-2015-8069, CVE-2015-8070, CVE-2015-8071, CVE-2015-8401,\nCVE-2015-8402, CVE-2015-8403, CVE-2015-8404, CVE-2015-8405, CVE-2015-8406,\nCVE-2015-8410, CVE-2015-8411, CVE-2015-8412, CVE-2015-8413, CVE-2015-8414,\nCVE-2015-8420, CVE-2015-8421, CVE-2015-8422, CVE-2015-8423, CVE-2015-8424,\nCVE-2015-8425, CVE-2015-8426, CVE-2015-8427, CVE-2015-8428, CVE-2015-8429,\nCVE-2015-8430, CVE-2015-8431, CVE-2015-8432, CVE-2015-8433, CVE-2015-8434,\nCVE-2015-8435, CVE-2015-8436, CVE-2015-8437, CVE-2015-8441, CVE-2015-8442,\nCVE-2015-8447, CVE-2015-8449, CVE-2015-8450, CVE-2015-8452, and\nCVE-2015-8454.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-32.html","http://zerodayinitiative.com/advisories/ZDI-15-611","https://www.cve.org/CVERecord?id=CVE-2015-8448"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20151208.1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20151208.1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20151208.1-0ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:20151208.1-0ubuntu0.15.10.1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.554ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.554ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.554ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"11.2.202.554ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8447","published":"2015-12-10T06:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the Color object implementation in Adobe\nFlash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on\nWindows and OS X and before 11.2.202.554 on Linux, Adobe AIR before\n20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler\nbefore 20.0.0.204 allows attackers to execute arbitrary code via crafted\nsetTransform arguments, a different vulnerability than CVE-2015-8048,\nCVE-2015-8049, CVE-2015-8050, CVE-2015-8055, CVE-2015-8056, CVE-2015-8057,\nCVE-2015-8058, CVE-2015-8059, CVE-2015-8061, CVE-2015-8062, CVE-2015-8063,\nCVE-2015-8064, CVE-2015-8065, CVE-2015-8066, CVE-2015-8067, CVE-2015-8068,\nCVE-2015-8069, CVE-2015-8070, CVE-2015-8071, CVE-2015-8401, CVE-2015-8402,\nCVE-2015-8403, CVE-2015-8404, CVE-2015-8405, CVE-2015-8406, CVE-2015-8410,\nCVE-2015-8411, CVE-2015-8412, CVE-2015-8413, CVE-2015-8414, CVE-2015-8420,\nCVE-2015-8421, CVE-2015-8422, CVE-2015-8423, CVE-2015-8424, CVE-2015-8425,\nCVE-2015-8426, CVE-2015-8427, CVE-2015-8428, CVE-2015-8429, CVE-2015-8430,\nCVE-2015-8431, CVE-2015-8432, CVE-2015-8433, CVE-2015-8434, CVE-2015-8435,\nCVE-2015-8436, CVE-2015-8437, CVE-2015-8441, CVE-2015-8442, CVE-2015-8448,\nCVE-2015-8449, CVE-2015-8450, CVE-2015-8452, and CVE-2015-8454.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-32.html","http://zerodayinitiative.com/advisories/ZDI-15-610","https://www.cve.org/CVERecord?id=CVE-2015-8447"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20151208.1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20151208.1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20151208.1-0ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:20151208.1-0ubuntu0.15.10.1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.554ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.554ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.554ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"11.2.202.554ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8446","published":"2015-12-10T06:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x\nand 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on\nLinux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and\nAdobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute\narbitrary code via an MP3 file with COMM tags that are mishandled during\nmemory allocation, a different vulnerability than CVE-2015-8438.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-32.html","http://zerodayinitiative.com/advisories/ZDI-15-609","https://www.cve.org/CVERecord?id=CVE-2015-8446"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20151208.1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20151208.1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20151208.1-0ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:20151208.1-0ubuntu0.15.10.1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.554ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.554ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.554ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"11.2.202.554ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8445","published":"2015-12-10T06:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the Shader filter implementation in Adobe Flash Player\nbefore 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X\nand before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR\nSDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204\nallows attackers to execute arbitrary code via a large BitmapData source\nobject.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-32.html","http://zerodayinitiative.com/advisories/ZDI-15-608","https://www.cve.org/CVERecord?id=CVE-2015-8445"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20151208.1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20151208.1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20151208.1-0ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:20151208.1-0ubuntu0.15.10.1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.554ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.554ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.554ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"11.2.202.554ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8444","published":"2015-12-10T06:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on\nWindows and OS X and before 11.2.202.554 on Linux, Adobe AIR before\n20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler\nbefore 20.0.0.204 allow attackers to execute arbitrary code or cause a\ndenial of service (memory corruption) via unspecified vectors, a different\nvulnerability than CVE-2015-8045, CVE-2015-8047, CVE-2015-8060,\nCVE-2015-8408, CVE-2015-8416, CVE-2015-8417, CVE-2015-8418, CVE-2015-8419,\nCVE-2015-8443, CVE-2015-8451, and CVE-2015-8455.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-32.html","https://www.cve.org/CVERecord?id=CVE-2015-8444"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20151208.1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20151208.1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20151208.1-0ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:20151208.1-0ubuntu0.15.10.1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.554ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.554ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.554ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"11.2.202.554ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8443","published":"2015-12-10T06:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on\nWindows and OS X and before 11.2.202.554 on Linux, Adobe AIR before\n20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler\nbefore 20.0.0.204 allow attackers to execute arbitrary code or cause a\ndenial of service (memory corruption) via unspecified vectors, a different\nvulnerability than CVE-2015-8045, CVE-2015-8047, CVE-2015-8060,\nCVE-2015-8408, CVE-2015-8416, CVE-2015-8417, CVE-2015-8418, CVE-2015-8419,\nCVE-2015-8444, CVE-2015-8451, and CVE-2015-8455.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-32.html","https://www.cve.org/CVERecord?id=CVE-2015-8443"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20151208.1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20151208.1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20151208.1-0ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:20151208.1-0ubuntu0.15.10.1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.554ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.554ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.554ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"11.2.202.554ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8442","published":"2015-12-10T06:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the MovieClip object implementation in\nAdobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on\nWindows and OS X and before 11.2.202.554 on Linux, Adobe AIR before\n20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler\nbefore 20.0.0.204 allows attackers to execute arbitrary code via a crafted\nfilters property value, a different vulnerability than CVE-2015-8048,\nCVE-2015-8049, CVE-2015-8050, CVE-2015-8055, CVE-2015-8056, CVE-2015-8057,\nCVE-2015-8058, CVE-2015-8059, CVE-2015-8061, CVE-2015-8062, CVE-2015-8063,\nCVE-2015-8064, CVE-2015-8065, CVE-2015-8066, CVE-2015-8067, CVE-2015-8068,\nCVE-2015-8069, CVE-2015-8070, CVE-2015-8071, CVE-2015-8401, CVE-2015-8402,\nCVE-2015-8403, CVE-2015-8404, CVE-2015-8405, CVE-2015-8406, CVE-2015-8410,\nCVE-2015-8411, CVE-2015-8412, CVE-2015-8413, CVE-2015-8414, CVE-2015-8420,\nCVE-2015-8421, CVE-2015-8422, CVE-2015-8423, CVE-2015-8424, CVE-2015-8425,\nCVE-2015-8426, CVE-2015-8427, CVE-2015-8428, CVE-2015-8429, CVE-2015-8430,\nCVE-2015-8431, CVE-2015-8432, CVE-2015-8433, CVE-2015-8434, CVE-2015-8435,\nCVE-2015-8436, CVE-2015-8437, CVE-2015-8441, CVE-2015-8447, CVE-2015-8448,\nCVE-2015-8449, CVE-2015-8450, CVE-2015-8452, and CVE-2015-8454.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-32.html","http://zerodayinitiative.com/advisories/ZDI-15-607","https://www.cve.org/CVERecord?id=CVE-2015-8442"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20151208.1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20151208.1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20151208.1-0ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:20151208.1-0ubuntu0.15.10.1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.554ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.554ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.554ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"11.2.202.554ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8441","published":"2015-12-10T06:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and\n19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554\non Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and\nAdobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute\narbitrary code via unspecified vectors, a different vulnerability than\nCVE-2015-8048, CVE-2015-8049, CVE-2015-8050, CVE-2015-8055, CVE-2015-8056,\nCVE-2015-8057, CVE-2015-8058, CVE-2015-8059, CVE-2015-8061, CVE-2015-8062,\nCVE-2015-8063, CVE-2015-8064, CVE-2015-8065, CVE-2015-8066, CVE-2015-8067,\nCVE-2015-8068, CVE-2015-8069, CVE-2015-8070, CVE-2015-8071, CVE-2015-8401,\nCVE-2015-8402, CVE-2015-8403, CVE-2015-8404, CVE-2015-8405, CVE-2015-8406,\nCVE-2015-8410, CVE-2015-8411, CVE-2015-8412, CVE-2015-8413, CVE-2015-8414,\nCVE-2015-8420, CVE-2015-8421, CVE-2015-8422, CVE-2015-8423, CVE-2015-8424,\nCVE-2015-8425, CVE-2015-8426, CVE-2015-8427, CVE-2015-8428, CVE-2015-8429,\nCVE-2015-8430, CVE-2015-8431, CVE-2015-8432, CVE-2015-8433, CVE-2015-8434,\nCVE-2015-8435, CVE-2015-8436, CVE-2015-8437, CVE-2015-8442, CVE-2015-8447,\nCVE-2015-8448, CVE-2015-8449, CVE-2015-8450, CVE-2015-8452, and\nCVE-2015-8454.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-32.html","https://www.cve.org/CVERecord?id=CVE-2015-8441"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20151208.1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20151208.1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20151208.1-0ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:20151208.1-0ubuntu0.15.10.1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.554ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.554ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.554ubuntu0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"11.2.202.554ubuntu0.15.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":62040,"limit":20,"total_results":79316}