{"cves":[{"id":"CVE-2015-3745","published":"2015-08-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x\nbefore 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-08-13-1 and\nAPPLE-SA-2015-08-13-3.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://ubuntu.com/security/notices/USN-2937-1","https://www.cve.org/CVERecord?id=CVE-2015-3745"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.4.10-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"2.4.10-0ubuntu0.15.10.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.10-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2.4.10-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2937-1"],"notices":[{"id":"USN-2937-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany and Evolution, to make all the\nnecessary changes.\n","references":[],"published":"2016-03-21T18:05:45.619980","description":"A large number of security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"webkitgtk","version":"2.4.10-0ubuntu0.14.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-1.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit-1.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit2-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-1.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-1.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-bin","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit2gtk-3.0-25","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit2gtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-1.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-1.0-common","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-common","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-common-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"webkitgtk","version":"2.4.10-0ubuntu0.15.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-1.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libjavascriptcoregtk-3.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libwebkitgtk-1.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libwebkitgtk-3.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2014-1748","CVE-2015-1071","CVE-2015-1076","CVE-2015-1081","CVE-2015-1083","CVE-2015-1120","CVE-2015-1122","CVE-2015-1127","CVE-2015-1153","CVE-2015-1155","CVE-2015-3658","CVE-2015-3659","CVE-2015-3727","CVE-2015-3731","CVE-2015-3741","CVE-2015-3743","CVE-2015-3745","CVE-2015-3747","CVE-2015-3748","CVE-2015-3749","CVE-2015-3752","CVE-2015-5788","CVE-2015-5794","CVE-2015-5801","CVE-2015-5809","CVE-2015-5822","CVE-2015-5928"]}]},{"id":"CVE-2015-3743","published":"2015-08-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x\nbefore 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-08-13-1 and\nAPPLE-SA-2015-08-13-3.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://ubuntu.com/security/notices/USN-2937-1","https://www.cve.org/CVERecord?id=CVE-2015-3743"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.4.10-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"2.4.10-0ubuntu0.15.10.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.10-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2.4.10-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2937-1"],"notices":[{"id":"USN-2937-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany and Evolution, to make all the\nnecessary changes.\n","references":[],"published":"2016-03-21T18:05:45.619980","description":"A large number of security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"webkitgtk","version":"2.4.10-0ubuntu0.14.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-1.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit-1.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit2-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-1.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-1.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-bin","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit2gtk-3.0-25","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit2gtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-1.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-1.0-common","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-common","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-common-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"webkitgtk","version":"2.4.10-0ubuntu0.15.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-1.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libjavascriptcoregtk-3.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libwebkitgtk-1.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libwebkitgtk-3.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2014-1748","CVE-2015-1071","CVE-2015-1076","CVE-2015-1081","CVE-2015-1083","CVE-2015-1120","CVE-2015-1122","CVE-2015-1127","CVE-2015-1153","CVE-2015-1155","CVE-2015-3658","CVE-2015-3659","CVE-2015-3727","CVE-2015-3731","CVE-2015-3741","CVE-2015-3743","CVE-2015-3745","CVE-2015-3747","CVE-2015-3748","CVE-2015-3749","CVE-2015-3752","CVE-2015-5788","CVE-2015-5794","CVE-2015-5801","CVE-2015-5809","CVE-2015-5822","CVE-2015-5928"]}]},{"id":"CVE-2015-3741","published":"2015-08-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x\nbefore 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-08-13-1 and\nAPPLE-SA-2015-08-13-3.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://ubuntu.com/security/notices/USN-2937-1","https://www.cve.org/CVERecord?id=CVE-2015-3741"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.4.10-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"2.4.10-0ubuntu0.15.10.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.10-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2.4.10-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2937-1"],"notices":[{"id":"USN-2937-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany and Evolution, to make all the\nnecessary changes.\n","references":[],"published":"2016-03-21T18:05:45.619980","description":"A large number of security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"webkitgtk","version":"2.4.10-0ubuntu0.14.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-1.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit-1.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit2-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-1.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-1.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-bin","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit2gtk-3.0-25","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit2gtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-1.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-1.0-common","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-common","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-common-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"webkitgtk","version":"2.4.10-0ubuntu0.15.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-1.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libjavascriptcoregtk-3.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libwebkitgtk-1.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libwebkitgtk-3.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2014-1748","CVE-2015-1071","CVE-2015-1076","CVE-2015-1081","CVE-2015-1083","CVE-2015-1120","CVE-2015-1122","CVE-2015-1127","CVE-2015-1153","CVE-2015-1155","CVE-2015-3658","CVE-2015-3659","CVE-2015-3727","CVE-2015-3731","CVE-2015-3741","CVE-2015-3743","CVE-2015-3745","CVE-2015-3747","CVE-2015-3748","CVE-2015-3749","CVE-2015-3752","CVE-2015-5788","CVE-2015-5794","CVE-2015-5801","CVE-2015-5809","CVE-2015-5822","CVE-2015-5928"]}]},{"id":"CVE-2015-3731","published":"2015-08-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x\nbefore 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-08-13-1 and\nAPPLE-SA-2015-08-13-3.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/kb/HT205033","https://support.apple.com/kb/HT205030","http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html","https://ubuntu.com/security/notices/USN-2937-1","https://www.cve.org/CVERecord?id=CVE-2015-3731"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.4.10-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"2.4.10-0ubuntu0.15.10.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.10-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2.4.10-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2937-1"],"notices":[{"id":"USN-2937-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany and Evolution, to make all the\nnecessary changes.\n","references":[],"published":"2016-03-21T18:05:45.619980","description":"A large number of security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"webkitgtk","version":"2.4.10-0ubuntu0.14.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-1.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit-1.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"gir1.2-webkit2-3.0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-1.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-1.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-bin","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit2gtk-3.0-25","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkit2gtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-1.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-1.0-common","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-0","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-common","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-3.0-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-common-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"},{"name":"libwebkitgtk-dev","version":"2.4.10-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"webkitgtk","version":"2.4.10-0ubuntu0.15.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-1.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libjavascriptcoregtk-3.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libwebkitgtk-1.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"},{"name":"libwebkitgtk-3.0-0","version":"2.4.10-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkitgtk","version_link":"https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1"}]},"type":"USN","cves_ids":["CVE-2014-1748","CVE-2015-1071","CVE-2015-1076","CVE-2015-1081","CVE-2015-1083","CVE-2015-1120","CVE-2015-1122","CVE-2015-1127","CVE-2015-1153","CVE-2015-1155","CVE-2015-3658","CVE-2015-3659","CVE-2015-3727","CVE-2015-3731","CVE-2015-3741","CVE-2015-3743","CVE-2015-3745","CVE-2015-3747","CVE-2015-3748","CVE-2015-3749","CVE-2015-3752","CVE-2015-5788","CVE-2015-5794","CVE-2015-5801","CVE-2015-5809","CVE-2015-5822","CVE-2015-5928"]}]},{"id":"CVE-2013-7422","published":"2015-08-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger underflow in regcomp.c in Perl before 5.20, as used in Apple OS X\nbefore 10.10.5 and other products, allows context-dependent attackers to\nexecute arbitrary code or cause a denial of service (application crash) via\na long digit string associated with an invalid backreference within a\nregular expression.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2916-1","https://www.cve.org/CVERecord?id=CVE-2013-7422"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776046","https://rt.perl.org/Public/Bug/Display.html?id=119505"],"patches":{"perl":["upstream: http://perl5.git.perl.org/perl.git/commitdiff/0c2990d652e985784f095bba4bc356481a66aa06"]},"tags":{},"packages":[{"name":"perl","source":"https://ubuntu.com/security/cve?package=perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=perl","debian":"https://tracker.debian.org/pkg/perl","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.14.2-6ubuntu2.5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.18.2-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.20.0-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"5.20.1-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2916-1"],"notices":[{"id":"USN-2916-1","title":"Perl vulnerabilities","summary":"Several security issues were fixed in Perl.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-03-02T13:37:19.802600","description":"It was discovered that Perl incorrectly handled certain regular expressions\nwith an invalid backreference. An attacker could use this issue to cause\nPerl to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2013-7422)\n\nMarkus Vervier discovered that Perl incorrectly handled nesting in the\nData::Dumper module. An attacker could use this issue to cause Perl to\nconsume memory and crash, resulting in a denial of service. (CVE-2014-4330)\n\nStephane Chazelas discovered that Perl incorrectly handled duplicate\nenvironment variables. An attacker could possibly use this issue to bypass\nthe taint protection mechanism. (CVE-2016-2381)\n","is_hidden":false,"release_packages":{"precise":[{"name":"perl","version":"5.14.2-6ubuntu2.5","description":"Practical Extraction and Report Language","is_source":true},{"name":"perl","version":"5.14.2-6ubuntu2.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.14.2-6ubuntu2.5"}],"trusty":[{"name":"perl","version":"5.18.2-2ubuntu1.1","description":"Practical Extraction and Report Language","is_source":true},{"name":"libcgi-fast-perl","version":"5.18.2-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.18.2-2ubuntu1.1","pocket":"security"},{"name":"libperl-dev","version":"5.18.2-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.18.2-2ubuntu1.1","pocket":"security"},{"name":"libperl5.18","version":"5.18.2-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.18.2-2ubuntu1.1","pocket":"security"},{"name":"perl","version":"5.18.2-2ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.18.2-2ubuntu1.1","pocket":"security"},{"name":"perl-base","version":"5.18.2-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.18.2-2ubuntu1.1","pocket":"security"},{"name":"perl-debug","version":"5.18.2-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.18.2-2ubuntu1.1","pocket":"security"},{"name":"perl-doc","version":"5.18.2-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.18.2-2ubuntu1.1","pocket":"security"},{"name":"perl-modules","version":"5.18.2-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.18.2-2ubuntu1.1","pocket":"security"}],"wily":[{"name":"perl","version":"5.20.2-6ubuntu0.2","description":"Practical Extraction and Report Language","is_source":true},{"name":"perl","version":"5.20.2-6ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.20.2-6ubuntu0.2"}]},"type":"USN","cves_ids":["CVE-2013-7422","CVE-2014-4330","CVE-2016-2381"]}]},{"id":"CVE-2015-5475","published":"2015-08-14T18:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in Request Tracker (RT)\n4.x before 4.2.12 allow remote attackers to inject arbitrary web script or\nHTML via vectors related to the (1) user and (2) group rights management\npages.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/bestpractical/rt/commit/67d517ba3421ba462e349c73207a627d137ef8ac (4.2.x)","https://github.com/bestpractical/rt/commit/4ec786bb4743f67a35a634c1bf43b13d3d3b39a9 (4.0.x)","https://www.cve.org/CVERecord?id=CVE-2015-5475"],"bugs":[""],"patches":{"request-tracker3.8":[],"request-tracker4":[]},"tags":{},"packages":[{"name":"request-tracker3.8","source":"https://ubuntu.com/security/cve?package=request-tracker3.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=request-tracker3.8","debian":"https://tracker.debian.org/pkg/request-tracker3.8","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"request-tracker4","source":"https://ubuntu.com/security/cve?package=request-tracker4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=request-tracker4","debian":"https://tracker.debian.org/pkg/request-tracker4","statuses":[{"release_codename":"vivid","status":"released","description":"4.2.8-3+deb8u1build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.2.11-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.11-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.2.11-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.2.11-2","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"4.2.11-2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.2.11-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.2.11-2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.2.11-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.2.11-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3289","published":"2015-08-14T18:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOpenStack Glance before 2015.1.1 (kilo) allows remote authenticated users\nto cause a denial of service (disk consumption) by repeatedly using the\nimport task flow API to create images and then deleting them.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/07/28/6","https://www.cve.org/CVERecord?id=CVE-2015-3289"],"bugs":["https://bugs.launchpad.net/glance/+bug/1454087","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=793896"],"patches":{"glance":["upstream: https://review.openstack.org/#/c/181816/","upstream: https://review.openstack.org/#/c/181345/"]},"tags":{},"packages":[{"name":"glance","source":"https://ubuntu.com/security/cve?package=glance","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=glance","debian":"https://tracker.debian.org/pkg/glance","statuses":[{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2015.1.1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1:2015.1.1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [code not present]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3576","published":"2015-08-14T18:59:00","updated_at":"2025-08-25T21:18:15.329518+00:00","description":"\nThe processControlCommand function in broker/TransportConnection.java in\nApache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of\nservice (shutdown) via a shutdown command.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2014-3576"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=792857","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-3576"],"patches":{"activemq":[]},"tags":{},"packages":[{"name":"activemq","source":"https://ubuntu.com/security/cve?package=activemq","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=activemq","debian":"https://tracker.debian.org/pkg/activemq","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.6.0+dfsg-1+deb7u1build0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.11.0","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"5.6.0+dfsg1-4+deb8u1ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"5.13.2+dfsg-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"5.13.2+dfsg-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"5.13.2+dfsg-2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"5.6.0+dfsg1-4+deb8u1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5565","published":"2015-08-14T01:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on\nWindows and OS X and before 11.2.202.508 on Linux, Adobe AIR before\n18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler\nbefore 18.0.0.199 allows attackers to execute arbitrary code via\nunspecified vectors, a different vulnerability than CVE-2015-5127,\nCVE-2015-5130, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5550,\nCVE-2015-5551, CVE-2015-5556, CVE-2015-5557, CVE-2015-5559, CVE-2015-5561,\nCVE-2015-5563, and CVE-2015-5564.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-19.html","https://www.cve.org/CVERecord?id=CVE-2015-5565"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20150811.1-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20150811.1-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20150811.1-0vivid1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.508ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.508ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.508ubuntu0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5564","published":"2015-08-14T01:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on\nWindows and OS X and before 11.2.202.508 on Linux, Adobe AIR before\n18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler\nbefore 18.0.0.199 allows attackers to execute arbitrary code via\nunspecified vectors, a different vulnerability than CVE-2015-5127,\nCVE-2015-5130, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5550,\nCVE-2015-5551, CVE-2015-5556, CVE-2015-5557, CVE-2015-5559, CVE-2015-5561,\nCVE-2015-5563, and CVE-2015-5565.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-19.html","https://www.cve.org/CVERecord?id=CVE-2015-5564"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20150811.1-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20150811.1-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20150811.1-0vivid1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.508ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.508ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.508ubuntu0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5563","published":"2015-08-14T01:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on\nWindows and OS X and before 11.2.202.508 on Linux, Adobe AIR before\n18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler\nbefore 18.0.0.199 allows attackers to execute arbitrary code via\nunspecified vectors, a different vulnerability than CVE-2015-5127,\nCVE-2015-5130, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5550,\nCVE-2015-5551, CVE-2015-5556, CVE-2015-5557, CVE-2015-5559, CVE-2015-5561,\nCVE-2015-5564, and CVE-2015-5565.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-19.html","https://www.cve.org/CVERecord?id=CVE-2015-5563"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20150811.1-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20150811.1-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20150811.1-0vivid1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.508ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.508ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.508ubuntu0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5562","published":"2015-08-14T01:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 18.0.0.232 on Windows and OS X and before\n11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before\n18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allow attackers\nto execute arbitrary code by leveraging an unspecified \"type confusion,\" a\ndifferent vulnerability than CVE-2015-5554, CVE-2015-5555, and\nCVE-2015-5558.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-19.html","https://www.cve.org/CVERecord?id=CVE-2015-5562"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20150811.1-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20150811.1-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20150811.1-0vivid1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.508ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.508ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.508ubuntu0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5561","published":"2015-08-14T01:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on\nWindows and OS X and before 11.2.202.508 on Linux, Adobe AIR before\n18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler\nbefore 18.0.0.199 allows attackers to execute arbitrary code via\nunspecified vectors, a different vulnerability than CVE-2015-5127,\nCVE-2015-5130, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5550,\nCVE-2015-5551, CVE-2015-5556, CVE-2015-5557, CVE-2015-5559, CVE-2015-5563,\nCVE-2015-5564, and CVE-2015-5565.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-19.html","https://www.cve.org/CVERecord?id=CVE-2015-5561"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20150811.1-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20150811.1-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20150811.1-0vivid1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.508ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.508ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.508ubuntu0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5560","published":"2015-08-14T01:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS\nX and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR\nSDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199\nallows attackers to execute arbitrary code via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-19.html","https://www.cve.org/CVERecord?id=CVE-2015-5560"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20150811.1-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20150811.1-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20150811.1-0vivid1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.508ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.508ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.508ubuntu0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5559","published":"2015-08-14T01:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on\nWindows and OS X and before 11.2.202.508 on Linux, Adobe AIR before\n18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler\nbefore 18.0.0.199 allows attackers to execute arbitrary code via\nunspecified vectors, a different vulnerability than CVE-2015-5127,\nCVE-2015-5130, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5550,\nCVE-2015-5551, CVE-2015-5556, CVE-2015-5557, CVE-2015-5561, CVE-2015-5563,\nCVE-2015-5564, and CVE-2015-5565.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-19.html","https://www.cve.org/CVERecord?id=CVE-2015-5559"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20150811.1-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20150811.1-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20150811.1-0vivid1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.508ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.508ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.508ubuntu0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5558","published":"2015-08-14T01:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 18.0.0.232 on Windows and OS X and before\n11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before\n18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allow attackers\nto execute arbitrary code by leveraging an unspecified \"type confusion,\" a\ndifferent vulnerability than CVE-2015-5554, CVE-2015-5555, and\nCVE-2015-5562.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-19.html","https://www.cve.org/CVERecord?id=CVE-2015-5558"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20150811.1-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20150811.1-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20150811.1-0vivid1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.508ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.508ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.508ubuntu0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5557","published":"2015-08-14T01:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on\nWindows and OS X and before 11.2.202.508 on Linux, Adobe AIR before\n18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler\nbefore 18.0.0.199 allows attackers to execute arbitrary code via\nunspecified vectors, a different vulnerability than CVE-2015-5127,\nCVE-2015-5130, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5550,\nCVE-2015-5551, CVE-2015-5556, CVE-2015-5559, CVE-2015-5561, CVE-2015-5563,\nCVE-2015-5564, and CVE-2015-5565.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-19.html","https://www.cve.org/CVERecord?id=CVE-2015-5557"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20150811.1-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20150811.1-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20150811.1-0vivid1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.508ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.508ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.508ubuntu0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5556","published":"2015-08-14T01:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on\nWindows and OS X and before 11.2.202.508 on Linux, Adobe AIR before\n18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler\nbefore 18.0.0.199 allows attackers to execute arbitrary code via\nunspecified vectors, a different vulnerability than CVE-2015-5127,\nCVE-2015-5130, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5550,\nCVE-2015-5551, CVE-2015-5557, CVE-2015-5559, CVE-2015-5561, CVE-2015-5563,\nCVE-2015-5564, and CVE-2015-5565.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-19.html","https://www.cve.org/CVERecord?id=CVE-2015-5556"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20150811.1-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20150811.1-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20150811.1-0vivid1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.508ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.508ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.508ubuntu0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5555","published":"2015-08-14T01:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 18.0.0.232 on Windows and OS X and before\n11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before\n18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allow attackers\nto execute arbitrary code by leveraging an unspecified \"type confusion,\" a\ndifferent vulnerability than CVE-2015-5554, CVE-2015-5558, and\nCVE-2015-5562.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-19.html","https://www.cve.org/CVERecord?id=CVE-2015-5555"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20150811.1-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20150811.1-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20150811.1-0vivid1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.508ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.508ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.508ubuntu0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5554","published":"2015-08-14T01:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 18.0.0.232 on Windows and OS X and before\n11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before\n18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allow attackers\nto execute arbitrary code by leveraging an unspecified \"type confusion,\" a\ndifferent vulnerability than CVE-2015-5555, CVE-2015-5558, and\nCVE-2015-5562.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-19.html","https://www.cve.org/CVERecord?id=CVE-2015-5554"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"released","description":"1:20150811.1-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:20150811.1-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:20150811.1-0vivid1","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"released","description":"11.2.202.508ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.508ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.508","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"11.2.202.508ubuntu0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":62880,"limit":20,"total_results":79316}