{"cves":[{"id":"CVE-2015-6247","published":"2015-08-24T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dissect_openflow_tablemod_v5 function in\nepan/dissectors/packet-openflow_v5.c in the OpenFlow dissector in Wireshark\n1.12.x before 1.12.7 does not validate a certain offset value, which allows\nremote attackers to cause a denial of service (infinite loop) via a crafted\npacket.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=828358d22c6bcf0a1ade5b3ffaa8018a385bfc6c","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11358","http://www.wireshark.org/security/wnpa-sec-2015-27.html","https://www.cve.org/CVERecord?id=CVE-2015-6247"],"bugs":[""],"patches":{"wireshark":["upstream: https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=828358d22c6bcf0a1ade5b3ffaa8018a385bfc6c"]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12.7","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4+deb8u3build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6246","published":"2015-08-24T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dissect_wa_payload function in epan/dissectors/packet-waveagent.c in\nthe WaveAgent dissector in Wireshark 1.12.x before 1.12.7 mishandles large\ntag values, which allows remote attackers to cause a denial of service\n(application crash) via a crafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=5523726e6960fe9d7e301376fd7a94599f65fd42","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11358","http://www.wireshark.org/security/wnpa-sec-2015-26.html","https://www.cve.org/CVERecord?id=CVE-2015-6246"],"bugs":[""],"patches":{"wireshark":["upstream: https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=5523726e6960fe9d7e301376fd7a94599f65fd42"]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12.7","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4+deb8u3build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6245","published":"2015-08-24T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nepan/dissectors/packet-gsm_rlcmac.c in the GSM RLC/MAC dissector in\nWireshark 1.12.x before 1.12.7 uses incorrect integer data types, which\nallows remote attackers to cause a denial of service (infinite loop) via a\ncrafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=78bc3dd93a562ca1b1c5dbc8f71d2967008be7ed","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11358","http://www.wireshark.org/security/wnpa-sec-2015-25.html","https://www.cve.org/CVERecord?id=CVE-2015-6245"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12.7","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4+deb8u3build0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6244","published":"2015-08-24T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c\nin the ZigBee dissector in Wireshark 1.12.x before 1.12.7 improperly relies\non length fields contained in packet data, which allows remote attackers to\ncause a denial of service (application crash) via a crafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=655b0dc623e29da212be3e205314624fe3182562","https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=43c2e5769a17f0945fdcdabe35204a13ca9bbc85","https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=31571144be5f03f054a9c7e195b38c2f5792fe54","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11389","http://www.wireshark.org/security/wnpa-sec-2015-24.html","https://www.cve.org/CVERecord?id=CVE-2015-6244"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12.7","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4+deb8u3build0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6243","published":"2015-08-24T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dissector-table implementation in epan/packet.c in Wireshark 1.12.x\nbefore 1.12.7 mishandles table searches for empty strings, which allows\nremote attackers to cause a denial of service (application crash) via a\ncrafted packet, related to the (1) dissector_get_string_handle and (2)\ndissector_get_default_string_handle functions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=eb1ccbdccde89701f255f921d88992878057477d","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11381","http://www.wireshark.org/security/wnpa-sec-2015-23.html","https://www.cve.org/CVERecord?id=CVE-2015-6243"],"bugs":[""],"patches":{"wireshark":["upstream: https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=eb1ccbdccde89701f255f921d88992878057477d"]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.7","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4+deb8u3build0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6242","published":"2015-08-24T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe wmem_block_split_free_chunk function in\nepan/wmem/wmem_allocator_block.c in the wmem block allocator in the memory\nmanager in Wireshark 1.12.x before 1.12.7 does not properly consider a\ncertain case of multiple realloc operations that restore a memory chunk to\nits original size, which allows remote attackers to cause a denial of\nservice (incorrect free operation and application crash) via a crafted\npacket.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=eaf1aad31e7c0a4908c20a42ae118c4dc8d474b6","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11373","http://www.wireshark.org/security/wnpa-sec-2015-22.html","https://www.cve.org/CVERecord?id=CVE-2015-6242"],"bugs":[""],"patches":{"wireshark":["upstream: https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=eaf1aad31e7c0a4908c20a42ae118c4dc8d474b6"]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.7","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4+deb8u3build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6241","published":"2015-08-24T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe proto_tree_add_bytes_item function in epan/proto.c in the protocol-tree\nimplementation in Wireshark 1.12.x before 1.12.7 does not properly\nterminate a data structure after a failure to locate a number within a\nstring, which allows remote attackers to cause a denial of service\n(application crash) via a crafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=6126a6455058696dd0ac2073032bdfe066a6ae38","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11309","http://www.wireshark.org/security/wnpa-sec-2015-21.html","https://www.cve.org/CVERecord?id=CVE-2015-6241"],"bugs":[""],"patches":{"wireshark":["upstream: https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=6126a6455058696dd0ac2073032bdfe066a6ae38"]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.7","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4+deb8u3build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-9744","published":"2015-08-24T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMemory leak in PolarSSL before 1.3.9 allows remote attackers to cause a\ndenial of service (memory consumption) via a large number of ClientHello\nmessages. NOTE: this identifier was SPLIT from CVE-2014-8628 per ADT3 due\nto different affected versions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://polarssl.org/tech-updates/releases/polarssl-1.3.9-released","http://lists.opensuse.org/opensuse-updates/2014-11/msg00079.html","https://www.cve.org/CVERecord?id=CVE-2014-9744"],"bugs":[""],"patches":{"polarssl":[],"mbedtls":[]},"tags":{},"packages":[{"name":"mbedtls","source":"https://ubuntu.com/security/cve?package=mbedtls","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mbedtls","debian":"https://tracker.debian.org/pkg/mbedtls","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.3.9-2.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.3.9-2.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.3.9-2.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.3.9-2.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.9","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.3.9-2.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.3.9-2.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.3.9-2.1","component":null,"pocket":"security"}]},{"name":"polarssl","source":"https://ubuntu.com/security/cve?package=polarssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=polarssl","debian":"https://tracker.debian.org/pkg/polarssl","statuses":[{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.9","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-8987","published":"2015-08-24T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the \"set configuration\" box in\nthe Configuration Report page (adm_config_report.php) in MantisBT 1.2.13\nthrough 1.2.17 allows remote administrators to inject arbitrary web script\nor HTML via the config_option parameter, a different vulnerability than\nCVE-2014-8986.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per Debian, affected code introduced later"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/mantisbt/mantisbt/commit/49c3d089","http://www.mantisbt.org/bugs/view.php?id=17870","https://www.cve.org/CVERecord?id=CVE-2014-8987"],"bugs":[""],"patches":{"mantis":[]},"tags":{},"packages":[{"name":"mantis","source":"https://ubuntu.com/security/cve?package=mantis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mantis","debian":"https://tracker.debian.org/pkg/mantis","statuses":[{"release_codename":"lucid","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-8628","published":"2015-08-24T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMemory leak in PolarSSL before 1.2.12 and 1.3.x before 1.3.9 allows remote\nattackers to cause a denial of service (memory consumption) via a large\nnumber of crafted X.509 certificates. NOTE: this identifier has been SPLIT\nper ADT3 due to different affected versions. See CVE-2014-9744 for the\nClientHello message issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://polarssl.org/tech-updates/releases/polarssl-1.3.9-released","https://www.cve.org/CVERecord?id=CVE-2014-8628"],"bugs":[""],"patches":{"polarssl":[],"mbedtls":[]},"tags":{},"packages":[{"name":"mbedtls","source":"https://ubuntu.com/security/cve?package=mbedtls","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mbedtls","debian":"https://tracker.debian.org/pkg/mbedtls","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.3.9-2.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.3.9-2.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.3.9-2.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.3.9-2.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.9-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.3.9-2.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.3.9-2.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.3.9-2.1","component":null,"pocket":"security"}]},{"name":"polarssl","source":"https://ubuntu.com/security/cve?package=polarssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=polarssl","debian":"https://tracker.debian.org/pkg/polarssl","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.9-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.3.9-2.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6665","published":"2015-08-24T14:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x\nbefore 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows\nremote attackers to inject arbitrary web script or HTML via vectors\ninvolving a whitelisted HTML element, possibly related to the \"a\" tag.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.drupal.org/SA-CORE-2015-003","https://www.drupal.org/node/2554145","https://www.drupal.org/node/2554133","https://www.cve.org/CVERecord?id=CVE-2015-6665"],"bugs":[""],"patches":{"drupal6":[],"drupal7":[]},"tags":{},"packages":[{"name":"drupal6","source":"https://ubuntu.com/security/cve?package=drupal6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal6","debian":"https://tracker.debian.org/pkg/drupal6","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.x-1.14","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"drupal7","source":"https://ubuntu.com/security/cve?package=drupal7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal7","debian":"https://tracker.debian.org/pkg/drupal7","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.39-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"7.32-1+deb8u5build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"7.44-1ubuntu1~16.04.0","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6661","published":"2015-08-24T14:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDrupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to\nobtain sensitive node titles by reading the menu.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.drupal.org/SA-CORE-2015-003","https://www.cve.org/CVERecord?id=CVE-2015-6661"],"bugs":[""],"patches":{"drupal6":[],"drupal7":[]},"tags":{},"packages":[{"name":"drupal6","source":"https://ubuntu.com/security/cve?package=drupal6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal6","debian":"https://tracker.debian.org/pkg/drupal6","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.37","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"drupal7","source":"https://ubuntu.com/security/cve?package=drupal7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal7","debian":"https://tracker.debian.org/pkg/drupal7","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.39-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"7.32-1+deb8u5build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"7.44-1ubuntu1~16.04.0","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6660","published":"2015-08-24T14:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not\nproperly validate the form token, which allows remote attackers to conduct\nCSRF attacks that upload files in a different user's account via vectors\nrelated to \"file upload value callbacks.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.drupal.org/SA-CORE-2015-003","https://www.cve.org/CVERecord?id=CVE-2015-6660"],"bugs":[""],"patches":{"drupal6":[],"drupal7":[]},"tags":{},"packages":[{"name":"drupal6","source":"https://ubuntu.com/security/cve?package=drupal6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal6","debian":"https://tracker.debian.org/pkg/drupal6","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.37","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"drupal7","source":"https://ubuntu.com/security/cve?package=drupal7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal7","debian":"https://tracker.debian.org/pkg/drupal7","statuses":[{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.39-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"7.32-1+deb8u5build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"7.44-1ubuntu1~16.04.0","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6659","published":"2015-08-24T14:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSQL injection vulnerability in the SQL comment filtering system in the\nDatabase API in Drupal 7.x before 7.39 allows remote attackers to execute\narbitrary SQL commands via an SQL comment.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.drupal.org/SA-CORE-2015-003","https://www.cve.org/CVERecord?id=CVE-2015-6659"],"bugs":[""],"patches":{"drupal6":[],"drupal7":[]},"tags":{},"packages":[{"name":"drupal6","source":"https://ubuntu.com/security/cve?package=drupal6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal6","debian":"https://tracker.debian.org/pkg/drupal6","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.37","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"drupal7","source":"https://ubuntu.com/security/cve?package=drupal7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal7","debian":"https://tracker.debian.org/pkg/drupal7","statuses":[{"release_codename":"vivid","status":"released","description":"7.32-1+deb8u5build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.39-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"7.44-1ubuntu1~16.04.0","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6658","published":"2015-08-24T14:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the Autocomplete system in\nDrupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to\ninject arbitrary web script or HTML via a crafted URL, related to uploading\nfiles.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.drupal.org/SA-CORE-2015-003","https://www.cve.org/CVERecord?id=CVE-2015-6658"],"bugs":[""],"patches":{"drupal6":[],"drupal7":[]},"tags":{},"packages":[{"name":"drupal6","source":"https://ubuntu.com/security/cve?package=drupal6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal6","debian":"https://tracker.debian.org/pkg/drupal6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.37","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"drupal7","source":"https://ubuntu.com/security/cve?package=drupal7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal7","debian":"https://tracker.debian.org/pkg/drupal7","statuses":[{"release_codename":"vivid","status":"released","description":"7.32-1+deb8u5build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.39-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"7.44-1ubuntu1~16.04.0","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6525","published":"2015-08-24T14:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer overflows in the evbuffer API in Libevent 2.0.x before\n2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to\ncause a denial of service or possibly have other unspecified impact via\n\"insanely large inputs\" to the (1) evbuffer_add, (2) evbuffer_prepend, (3)\nevbuffer_expand, (4) exbuffer_reserve_space, or (5) evbuffer_read function,\nwhich triggers a heap-based buffer overflow or an infinite loop. NOTE:\nthis identifier was SPLIT from CVE-2014-6272 per ADT3 due to different\naffected versions.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"CVE was split from CVE-2014-6272, but fixes were already applied\nin usn-2477-1"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.debian.org/security/2015/dsa-3119","http://archives.seul.org/libevent/users/Jan-2015/msg00010.html","https://ubuntu.com/security/notices/USN-2477-1","https://www.cve.org/CVERecord?id=CVE-2015-6525"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774645"],"patches":{"libevent":["upstream: https://github.com/libevent/libevent/commit/7b21c4eabf1f3946d3f63cce1319c490caab8ecf","upstream: https://github.com/libevent/libevent/commit/20d6d4458bee5d88bda1511c225c25b2d3198d6c","upstream: https://github.com/libevent/libevent/commit/841ecbd96105c84ac2e7c9594aeadbcc6fb38bc4"]},"tags":{},"packages":[{"name":"libevent","source":"https://ubuntu.com/security/cve?package=libevent","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libevent","debian":"https://tracker.debian.org/pkg/libevent","statuses":[{"release_codename":"precise","status":"released","description":"2.0.16-stable-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.0.21-stable-1ubuntu1.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.15-stable, 2.0.22-stable, 2.1.5-beta","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"2.0.21-stable-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6524","published":"2015-08-24T14:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe LDAPLoginModule implementation in the Java Authentication and\nAuthorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows\nwildcard operators in usernames, which allows remote attackers to obtain\ncredentials via a brute force attack. NOTE: this identifier was SPLIT from\nCVE-2014-3612 per ADT2 due to different vulnerability types.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"fixed with CVE-2014-3612"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://activemq.apache.org/security-advisories.data/CVE-2014-3612-announcement.txt","https://www.cve.org/CVERecord?id=CVE-2015-6524"],"bugs":[""],"patches":{"activemq":[]},"tags":{},"packages":[{"name":"activemq","source":"https://ubuntu.com/security/cve?package=activemq","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=activemq","debian":"https://tracker.debian.org/pkg/activemq","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.6.0+dfsg-1+deb7u1build0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.0+dfsg1-4","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"5.6.0+dfsg1-4+deb8u1ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"5.13.2+dfsg-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"5.13.2+dfsg-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"5.13.2+dfsg-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6496","published":"2015-08-24T14:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nconntrackd in conntrack-tools 1.4.2 and earlier does not ensure that the\noptional kernel modules are loaded before using them, which allows remote\nattackers to cause a denial of service (crash) via a (1) DCCP, (2) SCTP, or\n(3) ICMPv6 packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/08/14/4","https://www.cve.org/CVERecord?id=CVE-2015-6496"],"bugs":["http://bugzilla.netfilter.org/show_bug.cgi?id=910","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=796103"],"patches":{"conntrack":["upstream: https://git.netfilter.org/conntrack-tools/commit/?id=c392c159605956c7bd4a264ab4490e2b2704c0cd"],"conntrack-tools":["upstream: https://git.netfilter.org/conntrack-tools/commit/?id=c392c159605956c7bd4a264ab4490e2b2704c0cd"]},"tags":{},"packages":[{"name":"conntrack","source":"https://ubuntu.com/security/cve?package=conntrack","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=conntrack","debian":"https://tracker.debian.org/pkg/conntrack","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:1.4.2-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]},{"name":"conntrack-tools","source":"https://ubuntu.com/security/cve?package=conntrack-tools","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=conntrack-tools","debian":"https://tracker.debian.org/pkg/conntrack-tools","statuses":[{"release_codename":"artful","status":"not-affected","description":"1:1.4.2-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:1.4.2-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:1.4.2-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:1.4.2-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1:1.4.2-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1:1.4.2-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1:1.4.2-3ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3612","published":"2015-08-24T14:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe LDAPLoginModule implementation in the Java Authentication and\nAuthorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows\nremote attackers to bypass authentication by logging in with an empty\npassword and valid username, which triggers an unauthenticated bind. NOTE:\nthis identifier has been SPLIT per ADT2 due to different vulnerability\ntypes. See CVE-2015-6524 for the use of wildcard operators in usernames.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://activemq.apache.org/security-advisories.data/CVE-2014-3612-announcement.txt","http://seclists.org/oss-sec/2015/q1/427","http://rhn.redhat.com/errata/RHSA-2015-0137.html","http://rhn.redhat.com/errata/RHSA-2015-0138.html","https://www.cve.org/CVERecord?id=CVE-2014-3612"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=777196"],"patches":{"activemq":[]},"tags":{},"packages":[{"name":"activemq","source":"https://ubuntu.com/security/cve?package=activemq","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=activemq","debian":"https://tracker.debian.org/pkg/activemq","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.6.0+dfsg-1+deb7u1build0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.0+dfsg1-4","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"5.6.0+dfsg1-4+deb8u1ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5566","published":"2015-08-24T10:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on\nWindows and OS X and before 11.2.202.508 on Linux, Adobe AIR before\n18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler\nbefore 18.0.0.199 allows attackers to execute arbitrary code via\nunspecified vectors, a different vulnerability than CVE-2015-5127,\nCVE-2015-5130, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5550,\nCVE-2015-5551, CVE-2015-5556, CVE-2015-5557, CVE-2015-5559, CVE-2015-5561,\nCVE-2015-5563, CVE-2015-5564, and CVE-2015-5565.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-19.html","https://www.cve.org/CVERecord?id=CVE-2015-5566"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20150811.1-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20150811.1-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20150811.1-0vivid1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.508ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.508ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.508ubuntu0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":62820,"limit":20,"total_results":79316}