{"cves":[{"id":"CVE-2014-0490","published":"2014-09-16T16:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe apt-get download command in APT before 1.0.9 does not properly validate\nsignatures for packages, which allows remote attackers to execute arbitrary\ncode via a crafted package.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2348-1","https://www.cve.org/CVERecord?id=CVE-2014-0490"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1366702"],"patches":{"apt":[]},"tags":{},"packages":[{"name":"apt","source":"https://ubuntu.com/security/cve?package=apt","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=apt","debian":"https://tracker.debian.org/pkg/apt","statuses":[{"release_codename":"lucid","status":"released","description":"0.7.25.3ubuntu9.16","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"0.8.16~exp12ubuntu10.19","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.0.1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2348-1"],"notices":[{"id":"USN-2348-1","title":"APT vulnerabilities","summary":"Several security issues were fixed in APT.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-09-16T16:20:05.077872","description":"It was discovered that APT did not re-verify downloaded files when the\nIf-Modified-Since wasn't met. (CVE-2014-0487)\n\nIt was discovered that APT did not invalidate repository data when it\nswitched from an unauthenticated to an authenticated state. (CVE-2014-0488)\n\nIt was discovered that the APT Acquire::GzipIndexes option caused APT to\nskip checksum validation. This issue only applied to Ubuntu 12.04 LTS and\nUbuntu 14.04 LTS, and was not enabled by default. (CVE-2014-0489)\n\nIt was discovered that APT did not correctly validate signatures when\nmanually downloading packages using the download command. This issue only\napplied to Ubuntu 12.04 LTS. (CVE-2014-0490)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"apt","version":"0.7.25.3ubuntu9.16","description":"Advanced front-end for dpkg","is_source":true},{"name":"apt","version":"0.7.25.3ubuntu9.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/0.7.25.3ubuntu9.16"}],"precise":[{"name":"apt","version":"0.8.16~exp12ubuntu10.19","description":"Advanced front-end for dpkg","is_source":true},{"name":"apt","version":"0.8.16~exp12ubuntu10.19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/0.8.16~exp12ubuntu10.19"}],"trusty":[{"name":"apt","version":"1.0.1ubuntu2.3","description":"Advanced front-end for dpkg","is_source":true},{"name":"apt","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"apt-doc","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"apt-transport-https","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"apt-utils","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"libapt-inst1.5","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"libapt-pkg-dev","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"libapt-pkg-doc","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"libapt-pkg4.12","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0487","CVE-2014-0488","CVE-2014-0489","CVE-2014-0490"]}]},{"id":"CVE-2014-0489","published":"2014-09-16T16:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAPT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not\nvalidate checksums, which allows remote attackers to execute arbitrary code\nvia a crafted package.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2348-1","https://www.cve.org/CVERecord?id=CVE-2014-0489"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1366702"],"patches":{"apt":[]},"tags":{},"packages":[{"name":"apt","source":"https://ubuntu.com/security/cve?package=apt","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=apt","debian":"https://tracker.debian.org/pkg/apt","statuses":[{"release_codename":"lucid","status":"released","description":"0.7.25.3ubuntu9.16","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"0.8.16~exp12ubuntu10.19","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.0.1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2348-1"],"notices":[{"id":"USN-2348-1","title":"APT vulnerabilities","summary":"Several security issues were fixed in APT.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-09-16T16:20:05.077872","description":"It was discovered that APT did not re-verify downloaded files when the\nIf-Modified-Since wasn't met. (CVE-2014-0487)\n\nIt was discovered that APT did not invalidate repository data when it\nswitched from an unauthenticated to an authenticated state. (CVE-2014-0488)\n\nIt was discovered that the APT Acquire::GzipIndexes option caused APT to\nskip checksum validation. This issue only applied to Ubuntu 12.04 LTS and\nUbuntu 14.04 LTS, and was not enabled by default. (CVE-2014-0489)\n\nIt was discovered that APT did not correctly validate signatures when\nmanually downloading packages using the download command. This issue only\napplied to Ubuntu 12.04 LTS. (CVE-2014-0490)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"apt","version":"0.7.25.3ubuntu9.16","description":"Advanced front-end for dpkg","is_source":true},{"name":"apt","version":"0.7.25.3ubuntu9.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/0.7.25.3ubuntu9.16"}],"precise":[{"name":"apt","version":"0.8.16~exp12ubuntu10.19","description":"Advanced front-end for dpkg","is_source":true},{"name":"apt","version":"0.8.16~exp12ubuntu10.19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/0.8.16~exp12ubuntu10.19"}],"trusty":[{"name":"apt","version":"1.0.1ubuntu2.3","description":"Advanced front-end for dpkg","is_source":true},{"name":"apt","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"apt-doc","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"apt-transport-https","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"apt-utils","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"libapt-inst1.5","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"libapt-pkg-dev","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"libapt-pkg-doc","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"libapt-pkg4.12","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0487","CVE-2014-0488","CVE-2014-0489","CVE-2014-0490"]}]},{"id":"CVE-2014-0488","published":"2014-09-16T16:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAPT before 1.0.9 does not \"invalidate repository data\" when moving from an\nunauthenticated to authenticated state, which allows remote attackers to\nhave unspecified impact via crafted repository data.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2348-1","https://www.cve.org/CVERecord?id=CVE-2014-0488"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1366702"],"patches":{"apt":[]},"tags":{},"packages":[{"name":"apt","source":"https://ubuntu.com/security/cve?package=apt","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=apt","debian":"https://tracker.debian.org/pkg/apt","statuses":[{"release_codename":"lucid","status":"released","description":"0.7.25.3ubuntu9.16","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"0.8.16~exp12ubuntu10.19","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.0.1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2348-1"],"notices":[{"id":"USN-2348-1","title":"APT vulnerabilities","summary":"Several security issues were fixed in APT.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-09-16T16:20:05.077872","description":"It was discovered that APT did not re-verify downloaded files when the\nIf-Modified-Since wasn't met. (CVE-2014-0487)\n\nIt was discovered that APT did not invalidate repository data when it\nswitched from an unauthenticated to an authenticated state. (CVE-2014-0488)\n\nIt was discovered that the APT Acquire::GzipIndexes option caused APT to\nskip checksum validation. This issue only applied to Ubuntu 12.04 LTS and\nUbuntu 14.04 LTS, and was not enabled by default. (CVE-2014-0489)\n\nIt was discovered that APT did not correctly validate signatures when\nmanually downloading packages using the download command. This issue only\napplied to Ubuntu 12.04 LTS. (CVE-2014-0490)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"apt","version":"0.7.25.3ubuntu9.16","description":"Advanced front-end for dpkg","is_source":true},{"name":"apt","version":"0.7.25.3ubuntu9.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/0.7.25.3ubuntu9.16"}],"precise":[{"name":"apt","version":"0.8.16~exp12ubuntu10.19","description":"Advanced front-end for dpkg","is_source":true},{"name":"apt","version":"0.8.16~exp12ubuntu10.19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/0.8.16~exp12ubuntu10.19"}],"trusty":[{"name":"apt","version":"1.0.1ubuntu2.3","description":"Advanced front-end for dpkg","is_source":true},{"name":"apt","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"apt-doc","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"apt-transport-https","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"apt-utils","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"libapt-inst1.5","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"libapt-pkg-dev","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"libapt-pkg-doc","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"libapt-pkg4.12","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0487","CVE-2014-0488","CVE-2014-0489","CVE-2014-0490"]}]},{"id":"CVE-2014-0487","published":"2014-09-16T16:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAPT before 1.0.9 does not verify downloaded files if they have been\nmodified as indicated using the If-Modified-Since header, which has\nunspecified impact and attack vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2348-1","https://www.cve.org/CVERecord?id=CVE-2014-0487"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1366702"],"patches":{"apt":[]},"tags":{},"packages":[{"name":"apt","source":"https://ubuntu.com/security/cve?package=apt","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=apt","debian":"https://tracker.debian.org/pkg/apt","statuses":[{"release_codename":"lucid","status":"released","description":"0.7.25.3ubuntu9.16","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"0.8.16~exp12ubuntu10.19","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.0.1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2348-1"],"notices":[{"id":"USN-2348-1","title":"APT vulnerabilities","summary":"Several security issues were fixed in APT.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-09-16T16:20:05.077872","description":"It was discovered that APT did not re-verify downloaded files when the\nIf-Modified-Since wasn't met. (CVE-2014-0487)\n\nIt was discovered that APT did not invalidate repository data when it\nswitched from an unauthenticated to an authenticated state. (CVE-2014-0488)\n\nIt was discovered that the APT Acquire::GzipIndexes option caused APT to\nskip checksum validation. This issue only applied to Ubuntu 12.04 LTS and\nUbuntu 14.04 LTS, and was not enabled by default. (CVE-2014-0489)\n\nIt was discovered that APT did not correctly validate signatures when\nmanually downloading packages using the download command. This issue only\napplied to Ubuntu 12.04 LTS. (CVE-2014-0490)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"apt","version":"0.7.25.3ubuntu9.16","description":"Advanced front-end for dpkg","is_source":true},{"name":"apt","version":"0.7.25.3ubuntu9.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/0.7.25.3ubuntu9.16"}],"precise":[{"name":"apt","version":"0.8.16~exp12ubuntu10.19","description":"Advanced front-end for dpkg","is_source":true},{"name":"apt","version":"0.8.16~exp12ubuntu10.19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/0.8.16~exp12ubuntu10.19"}],"trusty":[{"name":"apt","version":"1.0.1ubuntu2.3","description":"Advanced front-end for dpkg","is_source":true},{"name":"apt","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"apt-doc","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"apt-transport-https","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"apt-utils","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"libapt-inst1.5","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"libapt-pkg-dev","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"libapt-pkg-doc","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"},{"name":"libapt-pkg4.12","version":"1.0.1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apt","version_link":"https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0487","CVE-2014-0488","CVE-2014-0489","CVE-2014-0490"]}]},{"id":"CVE-2014-3617","published":"2014-09-15T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe forum_print_latest_discussions function in mod/forum/lib.php in Moodle\nthrough 2.4.11, 2.5.x before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before\n2.7.2 allows remote authenticated users to bypass the individual\nanswer-posting requirement without the mod/forum:viewqandawithoutposting\ncapability, and discover an author's username, by leveraging the student\nrole and visiting a Q&A forum.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-46619","https://moodle.org/mod/forum/discuss.php?d=269591","http://openwall.com/lists/oss-security/2014/09/15/1","https://www.cve.org/CVERecord?id=CVE-2014-3617"],"bugs":[""],"patches":{"moodle":["upstream: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-46619"]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.7.5+dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.7.5+dfsg-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.7.5+dfsg-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.7.5+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4444","published":"2014-09-12T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40,\nin certain situations involving outdated java.io.File code and a custom JMX\nconfiguration, allows remote attackers to execute arbitrary code by\nuploading and accessing a JSP file.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per upstream, 7.0.0 to 7.0.39"},{"author":"mdeslaur","note":"This is the same issue as CVE-2013-2185 issued by Red Hat"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-4444"],"bugs":[""],"patches":{"tomcat7":[]},"tags":{},"packages":[{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"7.0.52-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.40-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-6270","published":"2014-09-12T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOff-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x\nand 3.x, when an SNMP port is configured, allows remote attackers to cause\na denial of service (crash) or possibly execute arbitrary code via a\ncrafted UDP SNMP request, which triggers a heap-based buffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://seclists.org/oss-sec/2014/q3/542","http://www.squid-cache.org/Advisories/SQUID-2014_3.txt","https://ubuntu.com/security/notices/USN-2921-1","https://www.cve.org/CVERecord?id=CVE-2014-6270"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=761002","https://bugzilla.novell.com/show_bug.cgi?id=895773"],"patches":{"squid3":["other: https://bugzilla.novell.com/show_bug.cgi?id=895773","upstream: http://bazaar.launchpad.net/~squid/squid/trunk/revision/13574","upstream: http://bazaar.launchpad.net/~squid/squid/trunk/revision/13582","upstream: http://www.squid-cache.org/Versions/v3/3.3/changesets/squid-3.3-12682.patch","upstream: http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10489.patch"]},"tags":{},"packages":[{"name":"squid3","source":"https://ubuntu.com/security/cve?package=squid3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=squid3","debian":"https://tracker.debian.org/pkg/squid3","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.1.19-1ubuntu3.12.04.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.4.8-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.3.8-1ubuntu6.6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.3.8-1ubuntu16.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-2921-1"],"notices":[{"id":"USN-2921-1","title":"Squid vulnerabilities","summary":"Several security issues were fixed in Squid.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-03-07T12:56:15.861444","description":"Sebastian Krahmer discovered that Squid incorrectly handled certain SNMP\nrequests. If SNMP is enabled, a remote attacker could use this issue to\ncause Squid to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2014-6270)\n\nAlex Rousskov discovered that Squid incorrectly handled certain malformed\nresponses. A remote attacker could possibly use this issue to cause Squid\nto crash, resulting in a denial of service. (CVE-2016-2571)\n","is_hidden":false,"release_packages":{"precise":[{"name":"squid3","version":"3.1.19-1ubuntu3.12.04.6","description":"Web proxy cache server","is_source":true},{"name":"squid3","version":"3.1.19-1ubuntu3.12.04.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.1.19-1ubuntu3.12.04.6"}],"trusty":[{"name":"squid3","version":"3.3.8-1ubuntu6.6","description":"Web proxy cache server","is_source":true},{"name":"squid","version":"3.3.8-1ubuntu6.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.6","pocket":"security"},{"name":"squid-cgi","version":"3.3.8-1ubuntu6.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.6","pocket":"security"},{"name":"squid-purge","version":"3.3.8-1ubuntu6.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.6","pocket":"security"},{"name":"squid3","version":"3.3.8-1ubuntu6.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.6","pocket":"security"},{"name":"squid3-common","version":"3.3.8-1ubuntu6.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.6","pocket":"security"},{"name":"squidclient","version":"3.3.8-1ubuntu6.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.6","pocket":"security"}],"wily":[{"name":"squid3","version":"3.3.8-1ubuntu16.2","description":"Web proxy cache server","is_source":true},{"name":"squid3","version":"3.3.8-1ubuntu16.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu16.2"}]},"type":"USN","cves_ids":["CVE-2014-6270","CVE-2016-2571"]}]},{"id":"CVE-2014-6070","published":"2014-09-11T14:16:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer\nbefore 3.6.6 allow remote attackers to inject arbitrary web script or HTML\nvia the hostname in (1) index.php or (2) detail.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2014-6070"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=760372"],"patches":{"loganalyzer":[]},"tags":{},"packages":[{"name":"loganalyzer","source":"https://ubuntu.com/security/cve?package=loganalyzer","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=loganalyzer","debian":"https://tracker.debian.org/pkg/loganalyzer","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.6.6+dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.6.6+dfsg-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.6.6+dfsg-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.6.6+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-5519","published":"2014-09-11T14:16:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute\narbitrary code via shell metacharacters in a device option in the\nedit[content] parameter to index.php/HeIp.  NOTE: some of these details are\nobtained from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2014-5519"],"bugs":[""],"patches":{"phpwiki":[]},"tags":{},"packages":[{"name":"phpwiki","source":"https://ubuntu.com/security/cve?package=phpwiki","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=phpwiki","debian":"https://tracker.debian.org/pkg/phpwiki","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-5313","published":"2014-09-10T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the management page in Six\nApart Movable Type before 5.2 allows remote authenticated users to inject\narbitrary web script or HTML via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://jvndb.jvn.jp/jvndb/JVNDB-2014-000104","http://jvn.jp/en/jp/JVN73357573/index.html","http://jvn.jp/en/jp/JVN73357573/370331/index.html","https://www.cve.org/CVERecord?id=CVE-2014-5313"],"bugs":[""],"patches":{"movabletype-opensource":[]},"tags":{},"packages":[{"name":"movabletype-opensource","source":"https://ubuntu.com/security/cve?package=movabletype-opensource","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=movabletype-opensource","debian":"https://tracker.debian.org/pkg/movabletype-opensource","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [5.2.9+dfsg-1]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0554","published":"2014-09-10T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on\nWindows and OS X and before 11.2.202.406 on Linux, Adobe AIR before\n15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR\nSDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow\nattackers to bypass intended access restrictions via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/flash-player/apsb14-21.html","https://www.cve.org/CVERecord?id=CVE-2014-0554"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0559","published":"2014-09-10T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x\nand 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on\nLinux, Adobe AIR before 15.0.0.249 on Windows and OS X and before\n15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK &\nCompiler before 15.0.0.249 allows attackers to execute arbitrary code via\nunspecified vectors, a different vulnerability than CVE-2014-0556.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/flash-player/apsb14-21.html","https://www.cve.org/CVERecord?id=CVE-2014-0559"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0557","published":"2014-09-10T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on\nWindows and OS X and before 11.2.202.406 on Linux, Adobe AIR before\n15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR\nSDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 do\nnot properly restrict discovery of memory addresses, which allows attackers\nto bypass the ASLR protection mechanism via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/flash-player/apsb14-21.html","https://www.cve.org/CVERecord?id=CVE-2014-0557"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0556","published":"2014-09-10T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x\nand 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on\nLinux, Adobe AIR before 15.0.0.249 on Windows and OS X and before\n15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK &\nCompiler before 15.0.0.249 allows attackers to execute arbitrary code via\nunspecified vectors, a different vulnerability than CVE-2014-0559.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/flash-player/apsb14-21.html","https://www.cve.org/CVERecord?id=CVE-2014-0556"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0555","published":"2014-09-10T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on\nWindows and OS X and before 11.2.202.406 on Linux, Adobe AIR before\n15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR\nSDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow\nattackers to execute arbitrary code or cause a denial of service (memory\ncorruption) via unspecified vectors, a different vulnerability than\nCVE-2014-0547, CVE-2014-0549, CVE-2014-0550, CVE-2014-0551, and\nCVE-2014-0552.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/flash-player/apsb14-21.html","https://www.cve.org/CVERecord?id=CVE-2014-0555"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0553","published":"2014-09-10T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Adobe Flash Player before 13.0.0.244 and\n14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406\non Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before\n15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK &\nCompiler before 15.0.0.249 allows attackers to execute arbitrary code via\nunspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/flash-player/apsb14-21.html","https://www.cve.org/CVERecord?id=CVE-2014-0553"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0552","published":"2014-09-10T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on\nWindows and OS X and before 11.2.202.406 on Linux, Adobe AIR before\n15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR\nSDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow\nattackers to execute arbitrary code or cause a denial of service (memory\ncorruption) via unspecified vectors, a different vulnerability than\nCVE-2014-0547, CVE-2014-0549, CVE-2014-0550, CVE-2014-0551, and\nCVE-2014-0555.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/flash-player/apsb14-21.html","https://www.cve.org/CVERecord?id=CVE-2014-0552"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0551","published":"2014-09-10T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on\nWindows and OS X and before 11.2.202.406 on Linux, Adobe AIR before\n15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR\nSDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow\nattackers to execute arbitrary code or cause a denial of service (memory\ncorruption) via unspecified vectors, a different vulnerability than\nCVE-2014-0547, CVE-2014-0549, CVE-2014-0550, CVE-2014-0552, and\nCVE-2014-0555.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/flash-player/apsb14-21.html","https://www.cve.org/CVERecord?id=CVE-2014-0551"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0550","published":"2014-09-10T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on\nWindows and OS X and before 11.2.202.406 on Linux, Adobe AIR before\n15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR\nSDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow\nattackers to execute arbitrary code or cause a denial of service (memory\ncorruption) via unspecified vectors, a different vulnerability than\nCVE-2014-0547, CVE-2014-0549, CVE-2014-0551, CVE-2014-0552, and\nCVE-2014-0555.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/flash-player/apsb14-21.html","https://www.cve.org/CVERecord?id=CVE-2014-0550"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0549","published":"2014-09-10T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on\nWindows and OS X and before 11.2.202.406 on Linux, Adobe AIR before\n15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR\nSDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow\nattackers to execute arbitrary code or cause a denial of service (memory\ncorruption) via unspecified vectors, a different vulnerability than\nCVE-2014-0547, CVE-2014-0550, CVE-2014-0551, CVE-2014-0552, and\nCVE-2014-0555.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/flash-player/apsb14-21.html","https://www.cve.org/CVERecord?id=CVE-2014-0549"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406-0precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.406ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.406ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.406","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":64880,"limit":20,"total_results":79316}