{"cves":[{"id":"CVE-2015-2192","published":"2015-03-08T02:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the dissect_osd2_cdb_continuation function in\nepan/dissectors/packet-scsi-osd.c in the SCSI OSD dissector in Wireshark\n1.12.x before 1.12.4 allows remote attackers to cause a denial of service\n(infinite loop) via a crafted length field in a packet.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"Versions 1.12.0 to 1.12.3 are affected"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.wireshark.org/security/wnpa-sec-2015-11.html","https://www.cve.org/CVERecord?id=CVE-2015-2192"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11024","https://bugs.launchpad.net/bugs/1440202"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12.4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.12.1+g01b65bf-2ubuntu14.10.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-2191","published":"2015-03-08T02:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the dissect_tnef function in\nepan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x\nbefore 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a\ndenial of service (infinite loop) via a crafted length field in a packet.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"Version 1.12.0 to 1.12.3, 1.10.0 to 1.10.10 are affected"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.wireshark.org/security/wnpa-sec-2015-10.html","https://www.cve.org/CVERecord?id=CVE-2015-2191"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11023","https://bugs.launchpad.net/bugs/1440202"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"released","description":"1.12.1+g01b65bf-4","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.6.7-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.10.13, 1.12.4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.12.1+g01b65bf-2ubuntu14.10.3","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.12.1+g01b65bf-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1.12.1+g01b65bf-4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1.12.1+g01b65bf-4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-2190","published":"2015-03-08T02:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nepan/proto.c in Wireshark 1.12.x before 1.12.4 does not properly handle\ninteger data types greater than 32 bits in size, which allows remote\nattackers to cause a denial of service (assertion failure and application\nexit) via a crafted packet that is improperly handled by the LLDP\ndissector.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"Versions 1.12.0 to 1.12.3 are affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.wireshark.org/security/wnpa-sec-2015-09.html","https://www.cve.org/CVERecord?id=CVE-2015-2190"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10983","https://bugs.launchpad.net/bugs/1440202"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12.4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.12.1+g01b65bf-2ubuntu14.10.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-2189","published":"2015-03-08T02:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOff-by-one error in the pcapng_read function in wiretap/pcapng.c in the\npcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x before\n1.12.4 allows remote attackers to cause a denial of service (out-of-bounds\nread and application crash) via an invalid Interface Statistics Block (ISB)\ninterface ID in a crafted packet.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"Version 1.12.0 to 1.12.3, 1.10.0 to 1.10.12 are affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.wireshark.org/security/wnpa-sec-2015-08.html","https://www.cve.org/CVERecord?id=CVE-2015-2189"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10895","https://bugs.launchpad.net/bugs/1440202"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"released","description":"1.12.1+g01b65bf-4","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.6.7-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.10.13, 1.12.4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.12.1+g01b65bf-2ubuntu14.10.3","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.12.1+g01b65bf-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1.12.1+g01b65bf-4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1.12.1+g01b65bf-4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-2188","published":"2015-03-08T02:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nepan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x\nbefore 1.10.13 and 1.12.x before 1.12.4 does not properly initialize a data\nstructure, which allows remote attackers to cause a denial of service\n(out-of-bounds read and application crash) via a crafted packet that is\nimproperly handled during decompression.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"Version 1.12.0 to 1.12.3, 1.10.0 to 1.10.12 are affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.wireshark.org/security/wnpa-sec-2015-07.html","https://www.cve.org/CVERecord?id=CVE-2015-2188"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10844","https://bugs.launchpad.net/bugs/1440202"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"released","description":"1.12.1+g01b65bf-4","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.6.7-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.10.13, 1.12.4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.12.1+g01b65bf-2ubuntu14.10.3","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.12.1+g01b65bf-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1.12.1+g01b65bf-4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1.12.1+g01b65bf-4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-2187","published":"2015-03-08T02:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dissect_atn_cpdlc_heur function in\nasn1/atn-cpdlc/packet-atn-cpdlc-template.c in the ATN-CPDLC dissector in\nWireshark 1.12.x before 1.12.4 does not properly follow the TRY/ENDTRY code\nrequirements, which allows remote attackers to cause a denial of service\n(stack memory corruption and application crash) via a crafted packet.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"Version 1.12.0 to 1.12.3 are affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.wireshark.org/security/wnpa-sec-2015-06.html","https://www.cve.org/CVERecord?id=CVE-2015-2187"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9952","https://bugs.launchpad.net/bugs/1440202"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12.4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.12.1+g01b65bf-2ubuntu14.10.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-2238","published":"2015-03-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in Google V8 before 4.1.0.21, as used\nin Google Chrome before 41.0.2272.76, allow attackers to cause a denial of\nservice or possibly have other impact via unknown vectors.","ubuntu_description":"","notes":[{"author":"mikesalvatore","note":"The Ubuntu Security Team does not support libv8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2521-1","https://www.cve.org/CVERecord?id=CVE-2015-2238"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[],"libv8-3.14":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"artful","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"41.0.2272.76-0ubuntu0.14.04.1.1076","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"41.0.2272.76","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"41.0.2272.76-0ubuntu0.14.10.1.1118","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"}]},{"name":"libv8-3.14","source":"https://ubuntu.com/security/cve?package=libv8-3.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libv8-3.14","debian":"https://tracker.debian.org/pkg/libv8-3.14","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [libv8 not supported]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"artful","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.5-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.5.5-0ubuntu0.14.10.2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2521-1"],"notices":[{"id":"USN-2521-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-03-10T15:28:14.926912","description":"Several out-of-bounds write bugs were discovered in Skia. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nthe program. (CVE-2015-1213, CVE-2015-1214, CVE-2015-1215)\n\nA use-after-free was discovered in the V8 bindings in Blink. If a user\nwere tricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via renderer crash,\nor execute arbitrary code with the privileges of the sandboxed render\nprocess. (CVE-2015-1216)\n\nMultiple type confusion bugs were discovered in the V8 bindings in Blink.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit these to cause a denial of service via\nrenderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1217, CVE-2015-1230)\n\nMultiple use-after-free bugs were discovered in the DOM implementation in\nBlink. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit these to cause a denial of service\nvia renderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1218, CVE-2015-1223)\n\nAn integer overflow was discovered in Skia. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2015-1219)\n\nA use-after-free was discovered in the GIF image decoder in Blink. If a\nuser were tricked in to opening a specially crafted website, an attacker\ncould potentially exploit this to cause a denial of service via renderer\ncrash, or execute arbitrary code with the privileges of the sandboxed\nrender process. (CVE-2015-1220)\n\nA use-after-free was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash, or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2015-1221)\n\nMultiple use-after-free bugs were discovered in the service worker\nimplementation in Chromium. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit these\nto cause a denial of service via application crash or execute arbitrary\ncode with the privileges of the user invoking the program. (CVE-2015-1222)\n\nAn out-of-bounds read was discovered in the VPX decoder implementation in\nChromium. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to cause a denial of\nservice via renderer crash. (CVE-2015-1224)\n\nIt was discovered that Blink did not initialize memory for image drawing\nin some circumstances. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to read\nuninitialized memory. (CVE-2015-1227)\n\nIt was discovered that Blink did not initialize memory for a data\nstructure in some circumstances. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\ncause a denial of service via renderer crash, or execute arbitrary code\nwith the privileges of the sandboxed render process. (CVE-2015-1228)\n\nIt was discovered that a web proxy returning a 407 response could inject\ncookies in to the originally requested domain. If a user connected to a\nmalicious web proxy, an attacker could potentially exploit this to conduct\nsession-fixation attacks. (CVE-2015-1229)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2015-1231)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-2238)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.04.3","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtquick0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqmlscene","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"}],"utopic":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.10.2","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"}]},"type":"USN","cves_ids":["CVE-2015-1213","CVE-2015-1214","CVE-2015-1215","CVE-2015-1216","CVE-2015-1217","CVE-2015-1218","CVE-2015-1219","CVE-2015-1220","CVE-2015-1221","CVE-2015-1222","CVE-2015-1223","CVE-2015-1224","CVE-2015-1227","CVE-2015-1228","CVE-2015-1229","CVE-2015-1230","CVE-2015-1231","CVE-2015-2238"]}]},{"id":"CVE-2015-1231","published":"2015-03-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in Google Chrome before 41.0.2272.76\nallow attackers to cause a denial of service or possibly have other impact\nvia unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.google.com/p/chromium/issues/detail?id=463349","https://code.google.com/p/chromium/issues/detail?id=460145","https://code.google.com/p/chromium/issues/detail?id=459115","https://code.google.com/p/chromium/issues/detail?id=453994","https://code.google.com/p/chromium/issues/detail?id=453126","https://code.google.com/p/chromium/issues/detail?id=452455","https://code.google.com/p/chromium/issues/detail?id=452324","https://code.google.com/p/chromium/issues/detail?id=451755","https://code.google.com/p/chromium/issues/detail?id=451753","https://code.google.com/p/chromium/issues/detail?id=451685","https://code.google.com/p/chromium/issues/detail?id=450654","https://code.google.com/p/chromium/issues/detail?id=450653","https://code.google.com/p/chromium/issues/detail?id=449777","https://code.google.com/p/chromium/issues/detail?id=449610","https://code.google.com/p/chromium/issues/detail?id=449049","https://code.google.com/p/chromium/issues/detail?id=449045","https://code.google.com/p/chromium/issues/detail?id=448056","https://code.google.com/p/chromium/issues/detail?id=445831","https://code.google.com/p/chromium/issues/detail?id=442756","https://code.google.com/p/chromium/issues/detail?id=439877","https://code.google.com/p/chromium/issues/detail?id=438638","https://code.google.com/p/chromium/issues/detail?id=438364","https://code.google.com/p/chromium/issues/detail?id=437636","https://code.google.com/p/chromium/issues/detail?id=433078","https://code.google.com/p/chromium/issues/detail?id=429679","https://code.google.com/p/chromium/issues/detail?id=429379","https://code.google.com/p/chromium/issues/detail?id=426762","https://code.google.com/p/chromium/issues/detail?id=421499","https://code.google.com/p/chromium/issues/detail?id=406871","https://code.google.com/p/chromium/issues/detail?id=404300","https://code.google.com/p/chromium/issues/detail?id=383777","http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2521-1","https://www.cve.org/CVERecord?id=CVE-2015-1231"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"41.0.2272.76-0ubuntu0.14.04.1.1076","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"41.0.2272.76","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"41.0.2272.76-0ubuntu0.14.10.1.1118","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.5-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.5.5-0ubuntu0.14.10.2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2521-1"],"notices":[{"id":"USN-2521-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-03-10T15:28:14.926912","description":"Several out-of-bounds write bugs were discovered in Skia. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nthe program. (CVE-2015-1213, CVE-2015-1214, CVE-2015-1215)\n\nA use-after-free was discovered in the V8 bindings in Blink. If a user\nwere tricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via renderer crash,\nor execute arbitrary code with the privileges of the sandboxed render\nprocess. (CVE-2015-1216)\n\nMultiple type confusion bugs were discovered in the V8 bindings in Blink.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit these to cause a denial of service via\nrenderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1217, CVE-2015-1230)\n\nMultiple use-after-free bugs were discovered in the DOM implementation in\nBlink. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit these to cause a denial of service\nvia renderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1218, CVE-2015-1223)\n\nAn integer overflow was discovered in Skia. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2015-1219)\n\nA use-after-free was discovered in the GIF image decoder in Blink. If a\nuser were tricked in to opening a specially crafted website, an attacker\ncould potentially exploit this to cause a denial of service via renderer\ncrash, or execute arbitrary code with the privileges of the sandboxed\nrender process. (CVE-2015-1220)\n\nA use-after-free was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash, or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2015-1221)\n\nMultiple use-after-free bugs were discovered in the service worker\nimplementation in Chromium. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit these\nto cause a denial of service via application crash or execute arbitrary\ncode with the privileges of the user invoking the program. (CVE-2015-1222)\n\nAn out-of-bounds read was discovered in the VPX decoder implementation in\nChromium. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to cause a denial of\nservice via renderer crash. (CVE-2015-1224)\n\nIt was discovered that Blink did not initialize memory for image drawing\nin some circumstances. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to read\nuninitialized memory. (CVE-2015-1227)\n\nIt was discovered that Blink did not initialize memory for a data\nstructure in some circumstances. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\ncause a denial of service via renderer crash, or execute arbitrary code\nwith the privileges of the sandboxed render process. (CVE-2015-1228)\n\nIt was discovered that a web proxy returning a 407 response could inject\ncookies in to the originally requested domain. If a user connected to a\nmalicious web proxy, an attacker could potentially exploit this to conduct\nsession-fixation attacks. (CVE-2015-1229)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2015-1231)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-2238)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.04.3","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtquick0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqmlscene","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"}],"utopic":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.10.2","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"}]},"type":"USN","cves_ids":["CVE-2015-1213","CVE-2015-1214","CVE-2015-1215","CVE-2015-1216","CVE-2015-1217","CVE-2015-1218","CVE-2015-1219","CVE-2015-1220","CVE-2015-1221","CVE-2015-1222","CVE-2015-1223","CVE-2015-1224","CVE-2015-1227","CVE-2015-1228","CVE-2015-1229","CVE-2015-1230","CVE-2015-1231","CVE-2015-2238"]}]},{"id":"CVE-2015-1230","published":"2015-03-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in\nBlink, as used in Google Chrome before 41.0.2272.76, has a name conflict\nwith the AudioContext class, which allows remote attackers to cause a\ndenial of service or possibly have unspecified other impact via JavaScript\ncode that adds an AudioContext event listener and triggers \"type\nconfusion.\"","ubuntu_description":"","notes":[{"author":"mikesalvatore","note":"The Ubuntu Security Team does not support libv8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=189006&view=revision","https://code.google.com/p/chromium/issues/detail?id=449610","http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2521-1","https://www.cve.org/CVERecord?id=CVE-2015-1230"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[],"libv8-3.14":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"artful","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"41.0.2272.76-0ubuntu0.14.04.1.1076","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"41.0.2272.76","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"41.0.2272.76-0ubuntu0.14.10.1.1118","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"}]},{"name":"libv8-3.14","source":"https://ubuntu.com/security/cve?package=libv8-3.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libv8-3.14","debian":"https://tracker.debian.org/pkg/libv8-3.14","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [libv8 not supported]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"artful","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.5-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.5.5-0ubuntu0.14.10.2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2521-1"],"notices":[{"id":"USN-2521-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-03-10T15:28:14.926912","description":"Several out-of-bounds write bugs were discovered in Skia. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nthe program. (CVE-2015-1213, CVE-2015-1214, CVE-2015-1215)\n\nA use-after-free was discovered in the V8 bindings in Blink. If a user\nwere tricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via renderer crash,\nor execute arbitrary code with the privileges of the sandboxed render\nprocess. (CVE-2015-1216)\n\nMultiple type confusion bugs were discovered in the V8 bindings in Blink.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit these to cause a denial of service via\nrenderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1217, CVE-2015-1230)\n\nMultiple use-after-free bugs were discovered in the DOM implementation in\nBlink. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit these to cause a denial of service\nvia renderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1218, CVE-2015-1223)\n\nAn integer overflow was discovered in Skia. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2015-1219)\n\nA use-after-free was discovered in the GIF image decoder in Blink. If a\nuser were tricked in to opening a specially crafted website, an attacker\ncould potentially exploit this to cause a denial of service via renderer\ncrash, or execute arbitrary code with the privileges of the sandboxed\nrender process. (CVE-2015-1220)\n\nA use-after-free was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash, or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2015-1221)\n\nMultiple use-after-free bugs were discovered in the service worker\nimplementation in Chromium. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit these\nto cause a denial of service via application crash or execute arbitrary\ncode with the privileges of the user invoking the program. (CVE-2015-1222)\n\nAn out-of-bounds read was discovered in the VPX decoder implementation in\nChromium. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to cause a denial of\nservice via renderer crash. (CVE-2015-1224)\n\nIt was discovered that Blink did not initialize memory for image drawing\nin some circumstances. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to read\nuninitialized memory. (CVE-2015-1227)\n\nIt was discovered that Blink did not initialize memory for a data\nstructure in some circumstances. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\ncause a denial of service via renderer crash, or execute arbitrary code\nwith the privileges of the sandboxed render process. (CVE-2015-1228)\n\nIt was discovered that a web proxy returning a 407 response could inject\ncookies in to the originally requested domain. If a user connected to a\nmalicious web proxy, an attacker could potentially exploit this to conduct\nsession-fixation attacks. (CVE-2015-1229)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2015-1231)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-2238)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.04.3","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtquick0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqmlscene","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"}],"utopic":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.10.2","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"}]},"type":"USN","cves_ids":["CVE-2015-1213","CVE-2015-1214","CVE-2015-1215","CVE-2015-1216","CVE-2015-1217","CVE-2015-1218","CVE-2015-1219","CVE-2015-1220","CVE-2015-1221","CVE-2015-1222","CVE-2015-1223","CVE-2015-1224","CVE-2015-1227","CVE-2015-1228","CVE-2015-1229","CVE-2015-1230","CVE-2015-1231","CVE-2015-2238"]}]},{"id":"CVE-2015-1229","published":"2015-03-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nnet/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does\nnot properly handle a 407 (aka Proxy Authentication Required) HTTP status\ncode accompanied by a Set-Cookie header, which allows remote proxy servers\nto conduct cookie-injection attacks via a crafted response.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://codereview.chromium.org/769043003","https://code.google.com/p/chromium/issues/detail?id=431504","http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2521-1","https://www.cve.org/CVERecord?id=CVE-2015-1229"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"41.0.2272.76-0ubuntu0.14.04.1.1076","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"41.0.2272.76","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"41.0.2272.76-0ubuntu0.14.10.1.1118","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.5-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.5.5-0ubuntu0.14.10.2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2521-1"],"notices":[{"id":"USN-2521-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-03-10T15:28:14.926912","description":"Several out-of-bounds write bugs were discovered in Skia. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nthe program. (CVE-2015-1213, CVE-2015-1214, CVE-2015-1215)\n\nA use-after-free was discovered in the V8 bindings in Blink. If a user\nwere tricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via renderer crash,\nor execute arbitrary code with the privileges of the sandboxed render\nprocess. (CVE-2015-1216)\n\nMultiple type confusion bugs were discovered in the V8 bindings in Blink.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit these to cause a denial of service via\nrenderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1217, CVE-2015-1230)\n\nMultiple use-after-free bugs were discovered in the DOM implementation in\nBlink. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit these to cause a denial of service\nvia renderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1218, CVE-2015-1223)\n\nAn integer overflow was discovered in Skia. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2015-1219)\n\nA use-after-free was discovered in the GIF image decoder in Blink. If a\nuser were tricked in to opening a specially crafted website, an attacker\ncould potentially exploit this to cause a denial of service via renderer\ncrash, or execute arbitrary code with the privileges of the sandboxed\nrender process. (CVE-2015-1220)\n\nA use-after-free was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash, or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2015-1221)\n\nMultiple use-after-free bugs were discovered in the service worker\nimplementation in Chromium. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit these\nto cause a denial of service via application crash or execute arbitrary\ncode with the privileges of the user invoking the program. (CVE-2015-1222)\n\nAn out-of-bounds read was discovered in the VPX decoder implementation in\nChromium. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to cause a denial of\nservice via renderer crash. (CVE-2015-1224)\n\nIt was discovered that Blink did not initialize memory for image drawing\nin some circumstances. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to read\nuninitialized memory. (CVE-2015-1227)\n\nIt was discovered that Blink did not initialize memory for a data\nstructure in some circumstances. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\ncause a denial of service via renderer crash, or execute arbitrary code\nwith the privileges of the sandboxed render process. (CVE-2015-1228)\n\nIt was discovered that a web proxy returning a 407 response could inject\ncookies in to the originally requested domain. If a user connected to a\nmalicious web proxy, an attacker could potentially exploit this to conduct\nsession-fixation attacks. (CVE-2015-1229)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2015-1231)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-2238)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.04.3","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtquick0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqmlscene","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"}],"utopic":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.10.2","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"}]},"type":"USN","cves_ids":["CVE-2015-1213","CVE-2015-1214","CVE-2015-1215","CVE-2015-1216","CVE-2015-1217","CVE-2015-1218","CVE-2015-1219","CVE-2015-1220","CVE-2015-1221","CVE-2015-1222","CVE-2015-1223","CVE-2015-1224","CVE-2015-1227","CVE-2015-1228","CVE-2015-1229","CVE-2015-1230","CVE-2015-1231","CVE-2015-2238"]}]},{"id":"CVE-2015-1228","published":"2015-03-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe RenderCounter::updateCounter function in\ncore/rendering/RenderCounter.cpp in Blink, as used in Google Chrome before\n41.0.2272.76, does not force a relayout operation and consequently does not\ninitialize memory for a data structure, which allows remote attackers to\ncause a denial of service (application crash) or possibly have unspecified\nother impact via a crafted Cascading Style Sheets (CSS) token sequence.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=188180&view=revision","https://code.google.com/p/chromium/issues/detail?id=444707","http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2521-1","https://www.cve.org/CVERecord?id=CVE-2015-1228"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"41.0.2272.76-0ubuntu0.14.04.1.1076","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"41.0.2272.76","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"41.0.2272.76-0ubuntu0.14.10.1.1118","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.5-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.5.5-0ubuntu0.14.10.2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2521-1"],"notices":[{"id":"USN-2521-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-03-10T15:28:14.926912","description":"Several out-of-bounds write bugs were discovered in Skia. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nthe program. (CVE-2015-1213, CVE-2015-1214, CVE-2015-1215)\n\nA use-after-free was discovered in the V8 bindings in Blink. If a user\nwere tricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via renderer crash,\nor execute arbitrary code with the privileges of the sandboxed render\nprocess. (CVE-2015-1216)\n\nMultiple type confusion bugs were discovered in the V8 bindings in Blink.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit these to cause a denial of service via\nrenderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1217, CVE-2015-1230)\n\nMultiple use-after-free bugs were discovered in the DOM implementation in\nBlink. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit these to cause a denial of service\nvia renderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1218, CVE-2015-1223)\n\nAn integer overflow was discovered in Skia. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2015-1219)\n\nA use-after-free was discovered in the GIF image decoder in Blink. If a\nuser were tricked in to opening a specially crafted website, an attacker\ncould potentially exploit this to cause a denial of service via renderer\ncrash, or execute arbitrary code with the privileges of the sandboxed\nrender process. (CVE-2015-1220)\n\nA use-after-free was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash, or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2015-1221)\n\nMultiple use-after-free bugs were discovered in the service worker\nimplementation in Chromium. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit these\nto cause a denial of service via application crash or execute arbitrary\ncode with the privileges of the user invoking the program. (CVE-2015-1222)\n\nAn out-of-bounds read was discovered in the VPX decoder implementation in\nChromium. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to cause a denial of\nservice via renderer crash. (CVE-2015-1224)\n\nIt was discovered that Blink did not initialize memory for image drawing\nin some circumstances. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to read\nuninitialized memory. (CVE-2015-1227)\n\nIt was discovered that Blink did not initialize memory for a data\nstructure in some circumstances. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\ncause a denial of service via renderer crash, or execute arbitrary code\nwith the privileges of the sandboxed render process. (CVE-2015-1228)\n\nIt was discovered that a web proxy returning a 407 response could inject\ncookies in to the originally requested domain. If a user connected to a\nmalicious web proxy, an attacker could potentially exploit this to conduct\nsession-fixation attacks. (CVE-2015-1229)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2015-1231)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-2238)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.04.3","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtquick0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqmlscene","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"}],"utopic":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.10.2","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"}]},"type":"USN","cves_ids":["CVE-2015-1213","CVE-2015-1214","CVE-2015-1215","CVE-2015-1216","CVE-2015-1217","CVE-2015-1218","CVE-2015-1219","CVE-2015-1220","CVE-2015-1221","CVE-2015-1222","CVE-2015-1223","CVE-2015-1224","CVE-2015-1227","CVE-2015-1228","CVE-2015-1229","CVE-2015-1230","CVE-2015-1231","CVE-2015-2238"]}]},{"id":"CVE-2015-1227","published":"2015-03-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe DragImage::create function in platform/DragImage.cpp in Blink, as used\nin Google Chrome before 41.0.2272.76, does not initialize memory for image\ndrawing, which allows remote attackers to have an unspecified impact by\ntriggering a failed image decoding, as demonstrated by an image for which\nthe default orientation cannot be used.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=189816&view=revision","https://src.chromium.org/viewvc/blink?revision=189585&view=revision","https://code.google.com/p/chromium/issues/detail?id=450389","http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2521-1","https://www.cve.org/CVERecord?id=CVE-2015-1227"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"41.0.2272.76-0ubuntu0.14.04.1.1076","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"41.0.2272.76","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"41.0.2272.76-0ubuntu0.14.10.1.1118","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.5-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.5.5-0ubuntu0.14.10.2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2521-1"],"notices":[{"id":"USN-2521-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-03-10T15:28:14.926912","description":"Several out-of-bounds write bugs were discovered in Skia. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nthe program. (CVE-2015-1213, CVE-2015-1214, CVE-2015-1215)\n\nA use-after-free was discovered in the V8 bindings in Blink. If a user\nwere tricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via renderer crash,\nor execute arbitrary code with the privileges of the sandboxed render\nprocess. (CVE-2015-1216)\n\nMultiple type confusion bugs were discovered in the V8 bindings in Blink.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit these to cause a denial of service via\nrenderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1217, CVE-2015-1230)\n\nMultiple use-after-free bugs were discovered in the DOM implementation in\nBlink. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit these to cause a denial of service\nvia renderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1218, CVE-2015-1223)\n\nAn integer overflow was discovered in Skia. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2015-1219)\n\nA use-after-free was discovered in the GIF image decoder in Blink. If a\nuser were tricked in to opening a specially crafted website, an attacker\ncould potentially exploit this to cause a denial of service via renderer\ncrash, or execute arbitrary code with the privileges of the sandboxed\nrender process. (CVE-2015-1220)\n\nA use-after-free was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash, or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2015-1221)\n\nMultiple use-after-free bugs were discovered in the service worker\nimplementation in Chromium. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit these\nto cause a denial of service via application crash or execute arbitrary\ncode with the privileges of the user invoking the program. (CVE-2015-1222)\n\nAn out-of-bounds read was discovered in the VPX decoder implementation in\nChromium. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to cause a denial of\nservice via renderer crash. (CVE-2015-1224)\n\nIt was discovered that Blink did not initialize memory for image drawing\nin some circumstances. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to read\nuninitialized memory. (CVE-2015-1227)\n\nIt was discovered that Blink did not initialize memory for a data\nstructure in some circumstances. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\ncause a denial of service via renderer crash, or execute arbitrary code\nwith the privileges of the sandboxed render process. (CVE-2015-1228)\n\nIt was discovered that a web proxy returning a 407 response could inject\ncookies in to the originally requested domain. If a user connected to a\nmalicious web proxy, an attacker could potentially exploit this to conduct\nsession-fixation attacks. (CVE-2015-1229)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2015-1231)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-2238)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.04.3","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtquick0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqmlscene","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"}],"utopic":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.10.2","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"}]},"type":"USN","cves_ids":["CVE-2015-1213","CVE-2015-1214","CVE-2015-1215","CVE-2015-1216","CVE-2015-1217","CVE-2015-1218","CVE-2015-1219","CVE-2015-1220","CVE-2015-1221","CVE-2015-1222","CVE-2015-1223","CVE-2015-1224","CVE-2015-1227","CVE-2015-1228","CVE-2015-1229","CVE-2015-1230","CVE-2015-1231","CVE-2015-2238"]}]},{"id":"CVE-2015-1224","published":"2015-03-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe VpxVideoDecoder::VpxDecode function in\nmedia/filters/vpx_video_decoder.cc in the vpxdecoder implementation in\nGoogle Chrome before 41.0.2272.76 does not ensure that alpha-plane\ndimensions are identical to image dimensions, which allows remote attackers\nto cause a denial of service (out-of-bounds read) via crafted VPx video\ndata.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://codereview.chromium.org/858303002","https://code.google.com/p/chromium/issues/detail?id=449958","http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2521-1","https://www.cve.org/CVERecord?id=CVE-2015-1224"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"41.0.2272.76-0ubuntu0.14.04.1.1076","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"41.0.2272.76","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"41.0.2272.76-0ubuntu0.14.10.1.1118","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.5-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.5.5-0ubuntu0.14.10.2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2521-1"],"notices":[{"id":"USN-2521-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-03-10T15:28:14.926912","description":"Several out-of-bounds write bugs were discovered in Skia. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nthe program. (CVE-2015-1213, CVE-2015-1214, CVE-2015-1215)\n\nA use-after-free was discovered in the V8 bindings in Blink. If a user\nwere tricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via renderer crash,\nor execute arbitrary code with the privileges of the sandboxed render\nprocess. (CVE-2015-1216)\n\nMultiple type confusion bugs were discovered in the V8 bindings in Blink.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit these to cause a denial of service via\nrenderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1217, CVE-2015-1230)\n\nMultiple use-after-free bugs were discovered in the DOM implementation in\nBlink. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit these to cause a denial of service\nvia renderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1218, CVE-2015-1223)\n\nAn integer overflow was discovered in Skia. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2015-1219)\n\nA use-after-free was discovered in the GIF image decoder in Blink. If a\nuser were tricked in to opening a specially crafted website, an attacker\ncould potentially exploit this to cause a denial of service via renderer\ncrash, or execute arbitrary code with the privileges of the sandboxed\nrender process. (CVE-2015-1220)\n\nA use-after-free was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash, or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2015-1221)\n\nMultiple use-after-free bugs were discovered in the service worker\nimplementation in Chromium. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit these\nto cause a denial of service via application crash or execute arbitrary\ncode with the privileges of the user invoking the program. (CVE-2015-1222)\n\nAn out-of-bounds read was discovered in the VPX decoder implementation in\nChromium. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to cause a denial of\nservice via renderer crash. (CVE-2015-1224)\n\nIt was discovered that Blink did not initialize memory for image drawing\nin some circumstances. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to read\nuninitialized memory. (CVE-2015-1227)\n\nIt was discovered that Blink did not initialize memory for a data\nstructure in some circumstances. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\ncause a denial of service via renderer crash, or execute arbitrary code\nwith the privileges of the sandboxed render process. (CVE-2015-1228)\n\nIt was discovered that a web proxy returning a 407 response could inject\ncookies in to the originally requested domain. If a user connected to a\nmalicious web proxy, an attacker could potentially exploit this to conduct\nsession-fixation attacks. (CVE-2015-1229)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2015-1231)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-2238)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.04.3","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtquick0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqmlscene","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"}],"utopic":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.10.2","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"}]},"type":"USN","cves_ids":["CVE-2015-1213","CVE-2015-1214","CVE-2015-1215","CVE-2015-1216","CVE-2015-1217","CVE-2015-1218","CVE-2015-1219","CVE-2015-1220","CVE-2015-1221","CVE-2015-1222","CVE-2015-1223","CVE-2015-1224","CVE-2015-1227","CVE-2015-1228","CVE-2015-1229","CVE-2015-1230","CVE-2015-1231","CVE-2015-2238"]}]},{"id":"CVE-2015-1223","published":"2015-03-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple use-after-free vulnerabilities in core/html/HTMLInputElement.cpp\nin the DOM implementation in Blink, as used in Google Chrome before\n41.0.2272.76, allow remote attackers to cause a denial of service or\npossibly have unspecified other impact via vectors that trigger extraneous\nchange events, as demonstrated by events for invalid input or input to\nread-only fields, related to the initializeTypeInParsing and updateType\nfunctions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.google.com/p/chromium/issues/detail?id=454231","https://chromium.googlesource.com/chromium/blink.git/+/de1fee41e2c1bbfea7a564ad81e0b511a462fe0b","http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2521-1","https://www.cve.org/CVERecord?id=CVE-2015-1223"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"41.0.2272.76-0ubuntu0.14.04.1.1076","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"41.0.2272.76","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"41.0.2272.76-0ubuntu0.14.10.1.1118","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.5-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.5.5-0ubuntu0.14.10.2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2521-1"],"notices":[{"id":"USN-2521-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-03-10T15:28:14.926912","description":"Several out-of-bounds write bugs were discovered in Skia. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nthe program. (CVE-2015-1213, CVE-2015-1214, CVE-2015-1215)\n\nA use-after-free was discovered in the V8 bindings in Blink. If a user\nwere tricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via renderer crash,\nor execute arbitrary code with the privileges of the sandboxed render\nprocess. (CVE-2015-1216)\n\nMultiple type confusion bugs were discovered in the V8 bindings in Blink.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit these to cause a denial of service via\nrenderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1217, CVE-2015-1230)\n\nMultiple use-after-free bugs were discovered in the DOM implementation in\nBlink. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit these to cause a denial of service\nvia renderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1218, CVE-2015-1223)\n\nAn integer overflow was discovered in Skia. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2015-1219)\n\nA use-after-free was discovered in the GIF image decoder in Blink. If a\nuser were tricked in to opening a specially crafted website, an attacker\ncould potentially exploit this to cause a denial of service via renderer\ncrash, or execute arbitrary code with the privileges of the sandboxed\nrender process. (CVE-2015-1220)\n\nA use-after-free was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash, or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2015-1221)\n\nMultiple use-after-free bugs were discovered in the service worker\nimplementation in Chromium. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit these\nto cause a denial of service via application crash or execute arbitrary\ncode with the privileges of the user invoking the program. (CVE-2015-1222)\n\nAn out-of-bounds read was discovered in the VPX decoder implementation in\nChromium. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to cause a denial of\nservice via renderer crash. (CVE-2015-1224)\n\nIt was discovered that Blink did not initialize memory for image drawing\nin some circumstances. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to read\nuninitialized memory. (CVE-2015-1227)\n\nIt was discovered that Blink did not initialize memory for a data\nstructure in some circumstances. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\ncause a denial of service via renderer crash, or execute arbitrary code\nwith the privileges of the sandboxed render process. (CVE-2015-1228)\n\nIt was discovered that a web proxy returning a 407 response could inject\ncookies in to the originally requested domain. If a user connected to a\nmalicious web proxy, an attacker could potentially exploit this to conduct\nsession-fixation attacks. (CVE-2015-1229)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2015-1231)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-2238)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.04.3","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtquick0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqmlscene","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"}],"utopic":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.10.2","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"}]},"type":"USN","cves_ids":["CVE-2015-1213","CVE-2015-1214","CVE-2015-1215","CVE-2015-1216","CVE-2015-1217","CVE-2015-1218","CVE-2015-1219","CVE-2015-1220","CVE-2015-1221","CVE-2015-1222","CVE-2015-1223","CVE-2015-1224","CVE-2015-1227","CVE-2015-1228","CVE-2015-1229","CVE-2015-1230","CVE-2015-1231","CVE-2015-2238"]}]},{"id":"CVE-2015-1222","published":"2015-03-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple use-after-free vulnerabilities in the ServiceWorkerScriptCacheMap\nimplementation in\ncontent/browser/service_worker/service_worker_script_cache_map.cc in Google\nChrome before 41.0.2272.76 allow remote attackers to cause a denial of\nservice or possibly have unspecified other impact via vectors that trigger\na ServiceWorkerContextWrapper::DeleteAndStartOver call, related to the\nNotifyStartedCaching and NotifyFinishedCaching functions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://codereview.chromium.org/798883005","https://code.google.com/p/chromium/issues/detail?id=448082","http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2521-1","https://www.cve.org/CVERecord?id=CVE-2015-1222"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"41.0.2272.76-0ubuntu0.14.04.1.1076","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"41.0.2272.76","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"41.0.2272.76-0ubuntu0.14.10.1.1118","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.5-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.5.5-0ubuntu0.14.10.2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2521-1"],"notices":[{"id":"USN-2521-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-03-10T15:28:14.926912","description":"Several out-of-bounds write bugs were discovered in Skia. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nthe program. (CVE-2015-1213, CVE-2015-1214, CVE-2015-1215)\n\nA use-after-free was discovered in the V8 bindings in Blink. If a user\nwere tricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via renderer crash,\nor execute arbitrary code with the privileges of the sandboxed render\nprocess. (CVE-2015-1216)\n\nMultiple type confusion bugs were discovered in the V8 bindings in Blink.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit these to cause a denial of service via\nrenderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1217, CVE-2015-1230)\n\nMultiple use-after-free bugs were discovered in the DOM implementation in\nBlink. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit these to cause a denial of service\nvia renderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1218, CVE-2015-1223)\n\nAn integer overflow was discovered in Skia. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2015-1219)\n\nA use-after-free was discovered in the GIF image decoder in Blink. If a\nuser were tricked in to opening a specially crafted website, an attacker\ncould potentially exploit this to cause a denial of service via renderer\ncrash, or execute arbitrary code with the privileges of the sandboxed\nrender process. (CVE-2015-1220)\n\nA use-after-free was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash, or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2015-1221)\n\nMultiple use-after-free bugs were discovered in the service worker\nimplementation in Chromium. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit these\nto cause a denial of service via application crash or execute arbitrary\ncode with the privileges of the user invoking the program. (CVE-2015-1222)\n\nAn out-of-bounds read was discovered in the VPX decoder implementation in\nChromium. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to cause a denial of\nservice via renderer crash. (CVE-2015-1224)\n\nIt was discovered that Blink did not initialize memory for image drawing\nin some circumstances. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to read\nuninitialized memory. (CVE-2015-1227)\n\nIt was discovered that Blink did not initialize memory for a data\nstructure in some circumstances. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\ncause a denial of service via renderer crash, or execute arbitrary code\nwith the privileges of the sandboxed render process. (CVE-2015-1228)\n\nIt was discovered that a web proxy returning a 407 response could inject\ncookies in to the originally requested domain. If a user connected to a\nmalicious web proxy, an attacker could potentially exploit this to conduct\nsession-fixation attacks. (CVE-2015-1229)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2015-1231)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-2238)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.04.3","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtquick0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqmlscene","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"}],"utopic":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.10.2","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"}]},"type":"USN","cves_ids":["CVE-2015-1213","CVE-2015-1214","CVE-2015-1215","CVE-2015-1216","CVE-2015-1217","CVE-2015-1218","CVE-2015-1219","CVE-2015-1220","CVE-2015-1221","CVE-2015-1222","CVE-2015-1223","CVE-2015-1224","CVE-2015-1227","CVE-2015-1228","CVE-2015-1229","CVE-2015-1230","CVE-2015-1231","CVE-2015-2238"]}]},{"id":"CVE-2015-1221","published":"2015-03-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Blink, as used in Google Chrome before\n41.0.2272.76, allows remote attackers to cause a denial of service or\npossibly have unspecified other impact by leveraging incorrect ordering of\noperations in the Web SQL Database thread relative to Blink's main thread,\nrelated to the shutdown function in web/WebKit.cpp.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=190035&view=revision","https://src.chromium.org/viewvc/blink?revision=190021&view=revision","https://code.google.com/p/chromium/issues/detail?id=455368","http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2521-1","https://www.cve.org/CVERecord?id=CVE-2015-1221"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"41.0.2272.76-0ubuntu0.14.04.1.1076","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"41.0.2272.76","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"41.0.2272.76-0ubuntu0.14.10.1.1118","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.5-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.5.5-0ubuntu0.14.10.2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2521-1"],"notices":[{"id":"USN-2521-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-03-10T15:28:14.926912","description":"Several out-of-bounds write bugs were discovered in Skia. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nthe program. (CVE-2015-1213, CVE-2015-1214, CVE-2015-1215)\n\nA use-after-free was discovered in the V8 bindings in Blink. If a user\nwere tricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via renderer crash,\nor execute arbitrary code with the privileges of the sandboxed render\nprocess. (CVE-2015-1216)\n\nMultiple type confusion bugs were discovered in the V8 bindings in Blink.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit these to cause a denial of service via\nrenderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1217, CVE-2015-1230)\n\nMultiple use-after-free bugs were discovered in the DOM implementation in\nBlink. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit these to cause a denial of service\nvia renderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1218, CVE-2015-1223)\n\nAn integer overflow was discovered in Skia. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2015-1219)\n\nA use-after-free was discovered in the GIF image decoder in Blink. If a\nuser were tricked in to opening a specially crafted website, an attacker\ncould potentially exploit this to cause a denial of service via renderer\ncrash, or execute arbitrary code with the privileges of the sandboxed\nrender process. (CVE-2015-1220)\n\nA use-after-free was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash, or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2015-1221)\n\nMultiple use-after-free bugs were discovered in the service worker\nimplementation in Chromium. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit these\nto cause a denial of service via application crash or execute arbitrary\ncode with the privileges of the user invoking the program. (CVE-2015-1222)\n\nAn out-of-bounds read was discovered in the VPX decoder implementation in\nChromium. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to cause a denial of\nservice via renderer crash. (CVE-2015-1224)\n\nIt was discovered that Blink did not initialize memory for image drawing\nin some circumstances. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to read\nuninitialized memory. (CVE-2015-1227)\n\nIt was discovered that Blink did not initialize memory for a data\nstructure in some circumstances. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\ncause a denial of service via renderer crash, or execute arbitrary code\nwith the privileges of the sandboxed render process. (CVE-2015-1228)\n\nIt was discovered that a web proxy returning a 407 response could inject\ncookies in to the originally requested domain. If a user connected to a\nmalicious web proxy, an attacker could potentially exploit this to conduct\nsession-fixation attacks. (CVE-2015-1229)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2015-1231)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-2238)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.04.3","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtquick0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqmlscene","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"}],"utopic":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.10.2","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"}]},"type":"USN","cves_ids":["CVE-2015-1213","CVE-2015-1214","CVE-2015-1215","CVE-2015-1216","CVE-2015-1217","CVE-2015-1218","CVE-2015-1219","CVE-2015-1220","CVE-2015-1221","CVE-2015-1222","CVE-2015-1223","CVE-2015-1224","CVE-2015-1227","CVE-2015-1228","CVE-2015-1229","CVE-2015-1230","CVE-2015-1231","CVE-2015-2238"]}]},{"id":"CVE-2015-1220","published":"2015-03-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the GIFImageReader::parseData function in\nplatform/image-decoders/gif/GIFImageReader.cpp in Blink, as used in Google\nChrome before 41.0.2272.76, allows remote attackers to cause a denial of\nservice or possibly have unspecified other impact via a crafted frame size\nin a GIF image.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=188423&view=revision","https://code.google.com/p/chromium/issues/detail?id=437651","http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2521-1","https://www.cve.org/CVERecord?id=CVE-2015-1220"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"41.0.2272.76-0ubuntu0.14.04.1.1076","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"41.0.2272.76","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"41.0.2272.76-0ubuntu0.14.10.1.1118","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.5-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.5.5-0ubuntu0.14.10.2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2521-1"],"notices":[{"id":"USN-2521-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-03-10T15:28:14.926912","description":"Several out-of-bounds write bugs were discovered in Skia. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nthe program. (CVE-2015-1213, CVE-2015-1214, CVE-2015-1215)\n\nA use-after-free was discovered in the V8 bindings in Blink. If a user\nwere tricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via renderer crash,\nor execute arbitrary code with the privileges of the sandboxed render\nprocess. (CVE-2015-1216)\n\nMultiple type confusion bugs were discovered in the V8 bindings in Blink.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit these to cause a denial of service via\nrenderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1217, CVE-2015-1230)\n\nMultiple use-after-free bugs were discovered in the DOM implementation in\nBlink. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit these to cause a denial of service\nvia renderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1218, CVE-2015-1223)\n\nAn integer overflow was discovered in Skia. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2015-1219)\n\nA use-after-free was discovered in the GIF image decoder in Blink. If a\nuser were tricked in to opening a specially crafted website, an attacker\ncould potentially exploit this to cause a denial of service via renderer\ncrash, or execute arbitrary code with the privileges of the sandboxed\nrender process. (CVE-2015-1220)\n\nA use-after-free was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash, or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2015-1221)\n\nMultiple use-after-free bugs were discovered in the service worker\nimplementation in Chromium. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit these\nto cause a denial of service via application crash or execute arbitrary\ncode with the privileges of the user invoking the program. (CVE-2015-1222)\n\nAn out-of-bounds read was discovered in the VPX decoder implementation in\nChromium. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to cause a denial of\nservice via renderer crash. (CVE-2015-1224)\n\nIt was discovered that Blink did not initialize memory for image drawing\nin some circumstances. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to read\nuninitialized memory. (CVE-2015-1227)\n\nIt was discovered that Blink did not initialize memory for a data\nstructure in some circumstances. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\ncause a denial of service via renderer crash, or execute arbitrary code\nwith the privileges of the sandboxed render process. (CVE-2015-1228)\n\nIt was discovered that a web proxy returning a 407 response could inject\ncookies in to the originally requested domain. If a user connected to a\nmalicious web proxy, an attacker could potentially exploit this to conduct\nsession-fixation attacks. (CVE-2015-1229)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2015-1231)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-2238)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.04.3","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtquick0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqmlscene","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"}],"utopic":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.10.2","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"}]},"type":"USN","cves_ids":["CVE-2015-1213","CVE-2015-1214","CVE-2015-1215","CVE-2015-1216","CVE-2015-1217","CVE-2015-1218","CVE-2015-1219","CVE-2015-1220","CVE-2015-1221","CVE-2015-1222","CVE-2015-1223","CVE-2015-1224","CVE-2015-1227","CVE-2015-1228","CVE-2015-1229","CVE-2015-1230","CVE-2015-1231","CVE-2015-2238"]}]},{"id":"CVE-2015-1219","published":"2015-03-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the SkMallocPixelRef::NewAllocate function in\ncore/SkMallocPixelRef.cpp in Skia, as used in Google Chrome before\n41.0.2272.76, allows remote attackers to cause a denial of service or\npossibly have unspecified other impact via vectors that trigger an\nattempted allocation of a large amount of memory during WebGL rendering.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://skia.googlesource.com/skia/+/2ff257bd95c732b9cebc3aac03fbed72d6e6082a","https://code.google.com/p/chromium/issues/detail?id=446164","http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2521-1","https://www.cve.org/CVERecord?id=CVE-2015-1219"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"41.0.2272.76-0ubuntu0.14.04.1.1076","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"41.0.2272.76","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"41.0.2272.76-0ubuntu0.14.10.1.1118","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.5-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.5.5-0ubuntu0.14.10.2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2521-1"],"notices":[{"id":"USN-2521-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-03-10T15:28:14.926912","description":"Several out-of-bounds write bugs were discovered in Skia. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nthe program. (CVE-2015-1213, CVE-2015-1214, CVE-2015-1215)\n\nA use-after-free was discovered in the V8 bindings in Blink. If a user\nwere tricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via renderer crash,\nor execute arbitrary code with the privileges of the sandboxed render\nprocess. (CVE-2015-1216)\n\nMultiple type confusion bugs were discovered in the V8 bindings in Blink.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit these to cause a denial of service via\nrenderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1217, CVE-2015-1230)\n\nMultiple use-after-free bugs were discovered in the DOM implementation in\nBlink. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit these to cause a denial of service\nvia renderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1218, CVE-2015-1223)\n\nAn integer overflow was discovered in Skia. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2015-1219)\n\nA use-after-free was discovered in the GIF image decoder in Blink. If a\nuser were tricked in to opening a specially crafted website, an attacker\ncould potentially exploit this to cause a denial of service via renderer\ncrash, or execute arbitrary code with the privileges of the sandboxed\nrender process. (CVE-2015-1220)\n\nA use-after-free was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash, or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2015-1221)\n\nMultiple use-after-free bugs were discovered in the service worker\nimplementation in Chromium. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit these\nto cause a denial of service via application crash or execute arbitrary\ncode with the privileges of the user invoking the program. (CVE-2015-1222)\n\nAn out-of-bounds read was discovered in the VPX decoder implementation in\nChromium. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to cause a denial of\nservice via renderer crash. (CVE-2015-1224)\n\nIt was discovered that Blink did not initialize memory for image drawing\nin some circumstances. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to read\nuninitialized memory. (CVE-2015-1227)\n\nIt was discovered that Blink did not initialize memory for a data\nstructure in some circumstances. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\ncause a denial of service via renderer crash, or execute arbitrary code\nwith the privileges of the sandboxed render process. (CVE-2015-1228)\n\nIt was discovered that a web proxy returning a 407 response could inject\ncookies in to the originally requested domain. If a user connected to a\nmalicious web proxy, an attacker could potentially exploit this to conduct\nsession-fixation attacks. (CVE-2015-1229)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2015-1231)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-2238)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.04.3","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtquick0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqmlscene","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"}],"utopic":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.10.2","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"}]},"type":"USN","cves_ids":["CVE-2015-1213","CVE-2015-1214","CVE-2015-1215","CVE-2015-1216","CVE-2015-1217","CVE-2015-1218","CVE-2015-1219","CVE-2015-1220","CVE-2015-1221","CVE-2015-1222","CVE-2015-1223","CVE-2015-1224","CVE-2015-1227","CVE-2015-1228","CVE-2015-1229","CVE-2015-1230","CVE-2015-1231","CVE-2015-2238"]}]},{"id":"CVE-2015-1218","published":"2015-03-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple use-after-free vulnerabilities in the DOM implementation in Blink,\nas used in Google Chrome before 41.0.2272.76, allow remote attackers to\ncause a denial of service or possibly have unspecified other impact via\nvectors that trigger movement of a SCRIPT element to different documents,\nrelated to (1) the HTMLScriptElement::didMoveToNewDocument function in\ncore/html/HTMLScriptElement.cpp and (2) the\nSVGScriptElement::didMoveToNewDocument function in\ncore/svg/SVGScriptElement.cpp.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=189886&view=revision","https://code.google.com/p/chromium/issues/detail?id=456059","http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2521-1","https://www.cve.org/CVERecord?id=CVE-2015-1218"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"41.0.2272.76-0ubuntu0.14.04.1.1076","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"41.0.2272.76","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"41.0.2272.76-0ubuntu0.14.10.1.1118","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.5","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.5-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.5.5-0ubuntu0.14.10.2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2521-1"],"notices":[{"id":"USN-2521-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-03-10T15:28:14.926912","description":"Several out-of-bounds write bugs were discovered in Skia. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nthe program. (CVE-2015-1213, CVE-2015-1214, CVE-2015-1215)\n\nA use-after-free was discovered in the V8 bindings in Blink. If a user\nwere tricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via renderer crash,\nor execute arbitrary code with the privileges of the sandboxed render\nprocess. (CVE-2015-1216)\n\nMultiple type confusion bugs were discovered in the V8 bindings in Blink.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit these to cause a denial of service via\nrenderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1217, CVE-2015-1230)\n\nMultiple use-after-free bugs were discovered in the DOM implementation in\nBlink. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit these to cause a denial of service\nvia renderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1218, CVE-2015-1223)\n\nAn integer overflow was discovered in Skia. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2015-1219)\n\nA use-after-free was discovered in the GIF image decoder in Blink. If a\nuser were tricked in to opening a specially crafted website, an attacker\ncould potentially exploit this to cause a denial of service via renderer\ncrash, or execute arbitrary code with the privileges of the sandboxed\nrender process. (CVE-2015-1220)\n\nA use-after-free was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash, or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2015-1221)\n\nMultiple use-after-free bugs were discovered in the service worker\nimplementation in Chromium. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit these\nto cause a denial of service via application crash or execute arbitrary\ncode with the privileges of the user invoking the program. (CVE-2015-1222)\n\nAn out-of-bounds read was discovered in the VPX decoder implementation in\nChromium. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to cause a denial of\nservice via renderer crash. (CVE-2015-1224)\n\nIt was discovered that Blink did not initialize memory for image drawing\nin some circumstances. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to read\nuninitialized memory. (CVE-2015-1227)\n\nIt was discovered that Blink did not initialize memory for a data\nstructure in some circumstances. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\ncause a denial of service via renderer crash, or execute arbitrary code\nwith the privileges of the sandboxed render process. (CVE-2015-1228)\n\nIt was discovered that a web proxy returning a 407 response could inject\ncookies in to the originally requested domain. If a user connected to a\nmalicious web proxy, an attacker could potentially exploit this to conduct\nsession-fixation attacks. (CVE-2015-1229)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2015-1231)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-2238)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.04.3","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtquick0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqmlscene","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"}],"utopic":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.10.2","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"}]},"type":"USN","cves_ids":["CVE-2015-1213","CVE-2015-1214","CVE-2015-1215","CVE-2015-1216","CVE-2015-1217","CVE-2015-1218","CVE-2015-1219","CVE-2015-1220","CVE-2015-1221","CVE-2015-1222","CVE-2015-1223","CVE-2015-1224","CVE-2015-1227","CVE-2015-1228","CVE-2015-1229","CVE-2015-1230","CVE-2015-1231","CVE-2015-2238"]}]},{"id":"CVE-2015-1217","published":"2015-03-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe V8LazyEventListener::prepareListenerObject function in\nbindings/core/v8/V8LazyEventListener.cpp in the V8 bindings in Blink, as\nused in Google Chrome before 41.0.2272.76, does not properly compile\nlisteners, which allows remote attackers to cause a denial of service or\npossibly have unspecified other impact via vectors that leverage \"type\nconfusion.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=189796&view=revision","https://codereview.chromium.org/958543002","https://codereview.chromium.org/910683002","https://code.google.com/p/chromium/issues/detail?id=456192","http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html","https://ubuntu.com/security/notices/USN-2521-1","https://www.cve.org/CVERecord?id=CVE-2015-1217"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"41.0.2272.76-0ubuntu0.14.04.1.1076","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"41.0.2272.76","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"41.0.2272.76-0ubuntu0.14.10.1.1118","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"41.0.2272.76-0ubuntu1.1134","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.5-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.5.5-0ubuntu0.14.10.2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.5.5-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2521-1"],"notices":[{"id":"USN-2521-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-03-10T15:28:14.926912","description":"Several out-of-bounds write bugs were discovered in Skia. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nthe program. (CVE-2015-1213, CVE-2015-1214, CVE-2015-1215)\n\nA use-after-free was discovered in the V8 bindings in Blink. If a user\nwere tricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via renderer crash,\nor execute arbitrary code with the privileges of the sandboxed render\nprocess. (CVE-2015-1216)\n\nMultiple type confusion bugs were discovered in the V8 bindings in Blink.\nIf a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit these to cause a denial of service via\nrenderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1217, CVE-2015-1230)\n\nMultiple use-after-free bugs were discovered in the DOM implementation in\nBlink. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit these to cause a denial of service\nvia renderer crash, or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-1218, CVE-2015-1223)\n\nAn integer overflow was discovered in Skia. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2015-1219)\n\nA use-after-free was discovered in the GIF image decoder in Blink. If a\nuser were tricked in to opening a specially crafted website, an attacker\ncould potentially exploit this to cause a denial of service via renderer\ncrash, or execute arbitrary code with the privileges of the sandboxed\nrender process. (CVE-2015-1220)\n\nA use-after-free was discovered in Blink. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service via renderer crash, or execute\narbitrary code with the privileges of the sandboxed render process.\n(CVE-2015-1221)\n\nMultiple use-after-free bugs were discovered in the service worker\nimplementation in Chromium. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit these\nto cause a denial of service via application crash or execute arbitrary\ncode with the privileges of the user invoking the program. (CVE-2015-1222)\n\nAn out-of-bounds read was discovered in the VPX decoder implementation in\nChromium. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to cause a denial of\nservice via renderer crash. (CVE-2015-1224)\n\nIt was discovered that Blink did not initialize memory for image drawing\nin some circumstances. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to read\nuninitialized memory. (CVE-2015-1227)\n\nIt was discovered that Blink did not initialize memory for a data\nstructure in some circumstances. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\ncause a denial of service via renderer crash, or execute arbitrary code\nwith the privileges of the sandboxed render process. (CVE-2015-1228)\n\nIt was discovered that a web proxy returning a 407 response could inject\ncookies in to the originally requested domain. If a user connected to a\nmalicious web proxy, an attacker could potentially exploit this to conduct\nsession-fixation attacks. (CVE-2015-1229)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service via application crash or execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2015-1231)\n\nMultiple security issues were discovered in V8. If a user were tricked\nin to opening a specially crafted website, an attacker could potentially\nexploit these to read uninitialized memory, cause a denial of service via\nrenderer crash or execute arbitrary code with the privileges of the\nsandboxed render process. (CVE-2015-2238)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.04.3","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"liboxideqtquick0","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqmlscene","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3","pocket":"security"}],"utopic":[{"name":"oxide-qt","version":"1.5.5-0ubuntu0.14.10.2","description":"Web browser engine library for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-chromedriver","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"},{"name":"oxideqt-codecs-extra","version":"1.5.5-0ubuntu0.14.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2"}]},"type":"USN","cves_ids":["CVE-2015-1213","CVE-2015-1214","CVE-2015-1215","CVE-2015-1216","CVE-2015-1217","CVE-2015-1218","CVE-2015-1219","CVE-2015-1220","CVE-2015-1221","CVE-2015-1222","CVE-2015-1223","CVE-2015-1224","CVE-2015-1227","CVE-2015-1228","CVE-2015-1229","CVE-2015-1230","CVE-2015-1231","CVE-2015-2238"]}]}],"offset":63760,"limit":20,"total_results":79316}