{"cves":[{"id":"CVE-2015-3744","published":"2015-08-16T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x\nbefore 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-08-13-1 and\nAPPLE-SA-2015-08-13-3.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://www.cve.org/CVERecord?id=CVE-2015-3744"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3742","published":"2015-08-16T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x\nbefore 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-08-13-1 and\nAPPLE-SA-2015-08-13-3.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://www.cve.org/CVERecord?id=CVE-2015-3742"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3740","published":"2015-08-16T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x\nbefore 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-08-13-1 and\nAPPLE-SA-2015-08-13-3.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://www.cve.org/CVERecord?id=CVE-2015-3740"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3739","published":"2015-08-16T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x\nbefore 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-08-13-1 and\nAPPLE-SA-2015-08-13-3.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://www.cve.org/CVERecord?id=CVE-2015-3739"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3738","published":"2015-08-16T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x\nbefore 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-08-13-1 and\nAPPLE-SA-2015-08-13-3.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://www.cve.org/CVERecord?id=CVE-2015-3738"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3737","published":"2015-08-16T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x\nbefore 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-08-13-1 and\nAPPLE-SA-2015-08-13-3.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://www.cve.org/CVERecord?id=CVE-2015-3737"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3736","published":"2015-08-16T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x\nbefore 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-08-13-1 and\nAPPLE-SA-2015-08-13-3.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://www.cve.org/CVERecord?id=CVE-2015-3736"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3735","published":"2015-08-16T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x\nbefore 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-08-13-1 and\nAPPLE-SA-2015-08-13-3.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://www.cve.org/CVERecord?id=CVE-2015-3735"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3734","published":"2015-08-16T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x\nbefore 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-08-13-1 and\nAPPLE-SA-2015-08-13-3.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://www.cve.org/CVERecord?id=CVE-2015-3734"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3733","published":"2015-08-16T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x\nbefore 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-08-13-1 and\nAPPLE-SA-2015-08-13-3.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://www.cve.org/CVERecord?id=CVE-2015-3733"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3732","published":"2015-08-16T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x\nbefore 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-08-13-1 and\nAPPLE-SA-2015-08-13-3.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://www.cve.org/CVERecord?id=CVE-2015-3732"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3730","published":"2015-08-16T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x\nbefore 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-08-13-1 and\nAPPLE-SA-2015-08-13-3.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://www.cve.org/CVERecord?id=CVE-2015-3730"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-4496","published":"2015-08-16T01:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer overflows in libstagefright in Mozilla Firefox before 38.0\nallow remote attackers to execute arbitrary code via crafted sample\nmetadata in an MPEG-4 video file, a related issue to CVE-2015-1538.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2015-93/","https://bugzilla.mozilla.org/show_bug.cgi?id=1149605","http://www.mozilla.org/security/announce/2015/mfsa2015-93.html","https://www.cve.org/CVERecord?id=CVE-2015-4496"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"released","description":"40.0+build4-0ubuntu0.12.04.4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"40.0+build4-0ubuntu0.14.04.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"38.0","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"40.0+build4-0ubuntu0.15.04.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-4483","published":"2015-08-16T01:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox before 40.0 allows man-in-the-middle attackers to bypass a\nmixed-content protection mechanism via a feed: URL in a POST request.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2015-86/","https://bugzilla.mozilla.org/show_bug.cgi?id=1148732","http://www.mozilla.org/security/announce/2015/mfsa2015-86.html","https://www.cve.org/CVERecord?id=CVE-2015-4483"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"released","description":"40.0+build4-0ubuntu0.12.04.4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"40.0+build4-0ubuntu0.14.04.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"40","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"40.0+build4-0ubuntu0.15.04.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-4482","published":"2015-08-16T01:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmar_read.c in the Updater in Mozilla Firefox before 40.0 and Firefox ESR\n38.x before 38.2 allows local users to gain privileges or cause a denial of\nservice (out-of-bounds write) via a crafted name of a Mozilla Archive (aka\nMAR) file.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Affects Mozilla updater"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2015-85/","https://www.cve.org/CVERecord?id=CVE-2015-4482"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"40.0","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"38.2.0","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-4481","published":"2015-08-16T01:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nRace condition in the Mozilla Maintenance Service in Mozilla Firefox before\n40.0 and Firefox ESR 38.x before 38.2 on Windows allows local users to\nwrite to arbitrary files and consequently gain privileges via vectors\ninvolving a hard link to a log file during an update.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Windows only"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2015-84/","https://www.cve.org/CVERecord?id=CVE-2015-4481"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"40.0","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3752","published":"2015-08-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Content Security Policy implementation in WebKit in Apple Safari before\n6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1\nand other products, does not properly restrict cookie transmission for\nreport requests, which allows remote attackers to obtain sensitive\ninformation via vectors involving (1) a cross-origin request or (2) a\nprivate-browsing request.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://ubuntu.com/security/notices/USN-2937-1","https://www.cve.org/CVERecord?id=CVE-2015-3752"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.4.10-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"2.4.10-0ubuntu0.15.10.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.10-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2.4.10-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2937-1"],"notices":[{"id":"USN-2937-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany and Evolution, to make all the\nnecessary changes.\n","references":[],"published":"2016-03-21T18:05:45.619980","description":"A large number of security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"webkitgtk","version":"2.4.10-0ubuntu0.14.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-1.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit-1.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit2-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-1.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-1.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-bin","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit2gtk-3.0-25","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit2gtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-1.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-1.0-common","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-common","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-common-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"webkitgtk","version":"2.4.10-0ubuntu0.15.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-1.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libjavascriptcoregtk-3.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libwebkitgtk-1.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libwebkitgtk-3.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2014-1748","CVE-2015-1071","CVE-2015-1076","CVE-2015-1081","CVE-2015-1083","CVE-2015-1120","CVE-2015-1122","CVE-2015-1127","CVE-2015-1153","CVE-2015-1155","CVE-2015-3658","CVE-2015-3659","CVE-2015-3727","CVE-2015-3731","CVE-2015-3741","CVE-2015-3743","CVE-2015-3745","CVE-2015-3747","CVE-2015-3748","CVE-2015-3749","CVE-2015-3752","CVE-2015-5788","CVE-2015-5794","CVE-2015-5801","CVE-2015-5809","CVE-2015-5822","CVE-2015-5928"]}]},{"id":"CVE-2015-3749","published":"2015-08-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x\nbefore 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-08-13-1 and\nAPPLE-SA-2015-08-13-3.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://ubuntu.com/security/notices/USN-2937-1","https://www.cve.org/CVERecord?id=CVE-2015-3749"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.4.10-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"2.4.10-0ubuntu0.15.10.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.10-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2.4.10-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2937-1"],"notices":[{"id":"USN-2937-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany and Evolution, to make all the\nnecessary changes.\n","references":[],"published":"2016-03-21T18:05:45.619980","description":"A large number of security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"webkitgtk","version":"2.4.10-0ubuntu0.14.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-1.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit-1.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit2-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-1.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-1.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-bin","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit2gtk-3.0-25","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit2gtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-1.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-1.0-common","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-common","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-common-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"webkitgtk","version":"2.4.10-0ubuntu0.15.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-1.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libjavascriptcoregtk-3.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libwebkitgtk-1.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libwebkitgtk-3.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2014-1748","CVE-2015-1071","CVE-2015-1076","CVE-2015-1081","CVE-2015-1083","CVE-2015-1120","CVE-2015-1122","CVE-2015-1127","CVE-2015-1153","CVE-2015-1155","CVE-2015-3658","CVE-2015-3659","CVE-2015-3727","CVE-2015-3731","CVE-2015-3741","CVE-2015-3743","CVE-2015-3745","CVE-2015-3747","CVE-2015-3748","CVE-2015-3749","CVE-2015-3752","CVE-2015-5788","CVE-2015-5794","CVE-2015-5801","CVE-2015-5809","CVE-2015-5822","CVE-2015-5928"]}]},{"id":"CVE-2015-3748","published":"2015-08-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x\nbefore 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-08-13-1 and\nAPPLE-SA-2015-08-13-3.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://ubuntu.com/security/notices/USN-2937-1","https://www.cve.org/CVERecord?id=CVE-2015-3748"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.4.10-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"2.4.10-0ubuntu0.15.10.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.10-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2.4.10-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2937-1"],"notices":[{"id":"USN-2937-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany and Evolution, to make all the\nnecessary changes.\n","references":[],"published":"2016-03-21T18:05:45.619980","description":"A large number of security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"webkitgtk","version":"2.4.10-0ubuntu0.14.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-1.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit-1.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit2-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-1.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-1.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-bin","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit2gtk-3.0-25","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit2gtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-1.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-1.0-common","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-common","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-common-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"webkitgtk","version":"2.4.10-0ubuntu0.15.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-1.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libjavascriptcoregtk-3.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libwebkitgtk-1.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libwebkitgtk-3.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2014-1748","CVE-2015-1071","CVE-2015-1076","CVE-2015-1081","CVE-2015-1083","CVE-2015-1120","CVE-2015-1122","CVE-2015-1127","CVE-2015-1153","CVE-2015-1155","CVE-2015-3658","CVE-2015-3659","CVE-2015-3727","CVE-2015-3731","CVE-2015-3741","CVE-2015-3743","CVE-2015-3745","CVE-2015-3747","CVE-2015-3748","CVE-2015-3749","CVE-2015-3752","CVE-2015-5788","CVE-2015-5794","CVE-2015-5801","CVE-2015-5809","CVE-2015-5822","CVE-2015-5928"]}]},{"id":"CVE-2015-3747","published":"2015-08-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x\nbefore 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-08-13-1 and\nAPPLE-SA-2015-08-13-3.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://ubuntu.com/security/notices/USN-2937-1","https://www.cve.org/CVERecord?id=CVE-2015-3747"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.4.10-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"2.4.10-0ubuntu0.15.10.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.10-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2.4.10-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2937-1"],"notices":[{"id":"USN-2937-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany and Evolution, to make all the\nnecessary changes.\n","references":[],"published":"2016-03-21T18:05:45.619980","description":"A large number of security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"webkitgtk","version":"2.4.10-0ubuntu0.14.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-1.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit-1.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit2-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-1.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-1.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-bin","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit2gtk-3.0-25","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit2gtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-1.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-1.0-common","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-common","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-common-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"webkitgtk","version":"2.4.10-0ubuntu0.15.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-1.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libjavascriptcoregtk-3.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libwebkitgtk-1.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libwebkitgtk-3.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2014-1748","CVE-2015-1071","CVE-2015-1076","CVE-2015-1081","CVE-2015-1083","CVE-2015-1120","CVE-2015-1122","CVE-2015-1127","CVE-2015-1153","CVE-2015-1155","CVE-2015-3658","CVE-2015-3659","CVE-2015-3727","CVE-2015-3731","CVE-2015-3741","CVE-2015-3743","CVE-2015-3745","CVE-2015-3747","CVE-2015-3748","CVE-2015-3749","CVE-2015-3752","CVE-2015-5788","CVE-2015-5794","CVE-2015-5801","CVE-2015-5809","CVE-2015-5822","CVE-2015-5928"]}]}],"offset":62860,"limit":20,"total_results":79316}