{"cves":[{"id":"CVE-2013-1810","published":"2014-05-15T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in core/summary_api.php\nin MantisBT 1.2.12 allow remote authenticated users with manager or\nadministrator permissions to inject arbitrary web script or HTML via a (1)\ncategory name in the summary_print_by_category function or (2) project name\nin the summary_print_by_project function.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"only 1.2.12 was affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/03/03/7","https://www.cve.org/CVERecord?id=CVE-2013-1810"],"bugs":[""],"patches":{"mantis":[]},"tags":{},"packages":[{"name":"mantis","source":"https://ubuntu.com/security/cve?package=mantis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mantis","debian":"https://tracker.debian.org/pkg/mantis","statuses":[{"release_codename":"hardy","status":"not-affected","description":"1.0.8-4ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.1.8+dfsg-4","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.8-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.2.11-1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.13","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-0197","published":"2014-05-15T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the filter_draw_selection_area2\nfunction in core/filter_api.php in MantisBT 1.2.12 before 1.2.13 allows\nremote attackers to inject arbitrary web script or HTML via the match_type\nparameter to bugs/search.php.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"marc.info URL reports 1.2.12-only"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mantisbt.org/bugs/view.php?id=15373","http://marc.info/?l=oss-security&m=135876600302683&w=2","https://www.cve.org/CVERecord?id=CVE-2013-0197"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=698481"],"patches":{"mantis":["upstream: https://github.com/mantisbt/mantisbt/commit/5b491868"]},"tags":{},"packages":[{"name":"mantis","source":"https://ubuntu.com/security/cve?package=mantis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mantis","debian":"https://tracker.debian.org/pkg/mantis","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.1.8+dfsg-4","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.8-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.2.10-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.2.11-1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.13","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3461","published":"2014-05-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nhw/usb/bus.c in QEMU 1.6.2 allows remote attackers to execute arbitrary\ncode via crafted savevm data, which triggers a heap-based buffer overflow,\nrelated to \"USB post load checks.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://article.gmane.org/gmane.comp.emulators.qemu/272322","https://ubuntu.com/security/notices/USN-2342-1","https://www.cve.org/CVERecord?id=CVE-2014-3461"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=739589"],"patches":{"qemu-kvm":[],"qemu":["upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=719ffe1f5f72b1c7ace4afe9ba2815bcb53a829e"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.0.0+dfsg-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"lucid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.0+noroms-0ubuntu14.17","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2342-1"],"notices":[{"id":"USN-2342-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2014-09-08T17:35:27.624875","description":"Michael S. Tsirkin, Anthony Liguori, and Michael Roth discovered multiple\nissues with QEMU state loading after migration. An attacker able to modify\nthe state data could use these issues to cause a denial of service, or\npossibly execute arbitrary code. (CVE-2013-4148, CVE-2013-4149,\nCVE-2013-4150, CVE-2013-4151, CVE-2013-4526, CVE-2013-4527, CVE-2013-4529,\nCVE-2013-4530, CVE-2013-4531, CVE-2013-4532, CVE-2013-4533, CVE-2013-4534,\nCVE-2013-4535, CVE-2013-4536, CVE-2013-4537, CVE-2013-4538, CVE-2013-4539,\nCVE-2013-4540, CVE-2013-4541, CVE-2013-4542, CVE-2013-6399, CVE-2014-0182,\nCVE-2014-3461)\n\nKevin Wolf, Stefan Hajnoczi, Fam Zheng, Jeff Cody, Stefan Hajnoczi, and\nothers discovered multiple issues in the QEMU block drivers. An attacker\nable to modify disk images could use these issues to cause a denial of\nservice, or possibly execute arbitrary code. (CVE-2014-0142, CVE-2014-0143,\nCVE-2014-0144, CVE-2014-0145, CVE-2014-0146, CVE-2014-0147, CVE-2014-0222,\nCVE-2014-0223)\n\nIt was discovered that QEMU incorrectly handled certain PCIe bus hotplug\noperations. A malicious guest could use this issue to crash the QEMU host,\nresulting in a denial of service. (CVE-2014-3471)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"qemu-kvm","version":"0.12.3+noroms-0ubuntu9.24","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"0.12.3+noroms-0ubuntu9.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/0.12.3+noroms-0ubuntu9.24"}],"precise":[{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.17","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/1.0+noroms-0ubuntu14.17"}],"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.3","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2013-4148","CVE-2013-4149","CVE-2013-4150","CVE-2013-4151","CVE-2013-4526","CVE-2013-4527","CVE-2013-4529","CVE-2013-4530","CVE-2013-4531","CVE-2013-4532","CVE-2013-4533","CVE-2013-4534","CVE-2013-4535","CVE-2013-4536","CVE-2013-4537","CVE-2013-4538","CVE-2013-4539","CVE-2013-4540","CVE-2013-4541","CVE-2013-4542","CVE-2013-6399","CVE-2014-0142","CVE-2014-0143","CVE-2014-0144","CVE-2014-0145","CVE-2014-0146","CVE-2014-0147","CVE-2014-0182","CVE-2014-0222","CVE-2014-0223","CVE-2014-3461","CVE-2014-3471"]}]},{"id":"CVE-2014-3441","published":"2014-05-14T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ncodec\\libpng_plugin.dll in VideoLAN VLC Media Player 2.1.3 allows remote\nattackers to cause a denial of service (crash) via a crafted .png file, as\ndemonstrated by a png in a .wave file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"we use system libpng, so not affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://packetstormsecurity.com/files/126564/VLC-Player-2.1.3-Memory-Corruption.html","https://www.cve.org/CVERecord?id=CVE-2014-3441"],"bugs":[""],"patches":{"vlc":[]},"tags":{},"packages":[{"name":"vlc","source":"https://ubuntu.com/security/cve?package=vlc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vlc","debian":"https://tracker.debian.org/pkg/vlc","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4471","published":"2014-05-14T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not\nrequire the current password when changing passwords for user accounts,\nwhich makes it easier for remote attackers to change a user password by\nleveraging the authentication token for that user.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"v3 api introduced in grizzly (Ubuntu 13.04)\nupstream is not issuing a patch for grizzly (13.04) but instead\nproviding only an OSSN (not issued yet) to for people to change the\nconfiguration defaults in keystone\nhorizon on Ubuntu 13.04 explictly uses the keystoneclient v2 API\nand is therefore not affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://bugs.launchpad.net/horizon/+bug/1237989","https://review.openstack.org/#/c/50962/","https://www.cve.org/CVERecord?id=CVE-2013-4471"],"bugs":["https://bugs.launchpad.net/horizon/+bug/1237989"],"patches":{"horizon":["upstream: https://review.openstack.org/#/c/51157/"]},"tags":{},"packages":[{"name":"horizon","source":"https://ubuntu.com/security/cve?package=horizon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=horizon","debian":"https://tracker.debian.org/pkg/horizon","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1:2013.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2013.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2226","published":"2014-05-14T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple SQL injection vulnerabilities in GLPI before 0.83.9 allow remote\nattackers to execute arbitrary SQL commands via the (1) users_id_assign\nparameter to ajax/ticketassigninformation.php, (2) filename parameter to\nfront/document.form.php, or (3) table parameter to ajax/comments.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-2226"],"bugs":[""],"patches":{"glpi":[]},"tags":{},"packages":[{"name":"glpi","source":"https://ubuntu.com/security/cve?package=glpi","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=glpi","debian":"https://tracker.debian.org/pkg/glpi","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"0.83.91-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.83.91-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"0.84.3+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"0.84.3+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"0.84.3+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"0.84.3+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"0.84.3+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [0.84.3+dfsg.1-1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2087","published":"2014-05-14T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before\n3.0.7 allow remote attackers to inject arbitrary web script or HTML via the\n(1) movie title to modules/gallery/controllers/movies.php or (2) key\nvariable to modules/gallery/views/error_admin.html.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-2087"],"bugs":[""],"patches":{"gallery":[]},"tags":{},"packages":[{"name":"gallery","source":"https://ubuntu.com/security/cve?package=gallery","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gallery","debian":"https://tracker.debian.org/pkg/gallery","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2034","published":"2014-05-14T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site request forgery (CSRF) vulnerabilities in Jenkins\nbefore 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1\nand 1.480.x before 1.480.4.1 allow remote attackers to hijack the\nauthentication of administrators for requests that (1) execute arbitrary\ncode or (2) initiate deployment of binaries to a Maven repository via\nunspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-2034"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=706725"],"patches":{"jenkins":[]},"tags":{},"packages":[{"name":"jenkins","source":"https://ubuntu.com/security/cve?package=jenkins","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jenkins","debian":"https://tracker.debian.org/pkg/jenkins","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.509.1,1.514","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0529","published":"2014-05-14T11:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x\nbefore 11.0.07 on Windows and OS X allows attackers to execute arbitrary\ncode via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/reader/apsb14-15.html","https://www.cve.org/CVERecord?id=CVE-2014-0529"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.10, 11.0.07","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0528","published":"2014-05-14T11:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDouble free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.10\nand 11.x before 11.0.07 on Windows and OS X allows attackers to execute\narbitrary code via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/reader/apsb14-15.html","https://www.cve.org/CVERecord?id=CVE-2014-0528"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.10, 11.0.07","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0527","published":"2014-05-14T11:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Adobe Reader and Acrobat 10.x before\n10.1.10 and 11.x before 11.0.07 on Windows and OS X allows attackers to\nexecute arbitrary code via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/reader/apsb14-15.html","https://www.cve.org/CVERecord?id=CVE-2014-0527"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.10, 11.0.07","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0526","published":"2014-05-14T11:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on\nWindows and OS X allow attackers to execute arbitrary code or cause a\ndenial of service (memory corruption) via unspecified vectors, a different\nvulnerability than CVE-2014-0522, CVE-2014-0523, and CVE-2014-0524.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/reader/apsb14-15.html","https://www.cve.org/CVERecord?id=CVE-2014-0526"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.10, 11.0.07","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0525","published":"2014-05-14T11:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe API in Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before\n11.0.07 on Windows and OS X does not prevent access to unmapped memory,\nwhich allows attackers to execute arbitrary code via unspecified API calls.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/reader/apsb14-15.html","https://www.cve.org/CVERecord?id=CVE-2014-0525"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.10, 11.0.07","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0524","published":"2014-05-14T11:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on\nWindows and OS X allow attackers to execute arbitrary code or cause a\ndenial of service (memory corruption) via unspecified vectors, a different\nvulnerability than CVE-2014-0522, CVE-2014-0523, and CVE-2014-0526.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/reader/apsb14-15.html","https://www.cve.org/CVERecord?id=CVE-2014-0524"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.10, 11.0.07","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0523","published":"2014-05-14T11:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on\nWindows and OS X allow attackers to execute arbitrary code or cause a\ndenial of service (memory corruption) via unspecified vectors, a different\nvulnerability than CVE-2014-0522, CVE-2014-0524, and CVE-2014-0526.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/reader/apsb14-15.html","https://www.cve.org/CVERecord?id=CVE-2014-0523"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.10, 11.0.07","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0522","published":"2014-05-14T11:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on\nWindows and OS X allow attackers to execute arbitrary code or cause a\ndenial of service (memory corruption) via unspecified vectors, a different\nvulnerability than CVE-2014-0523, CVE-2014-0524, and CVE-2014-0526.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/reader/apsb14-15.html","https://www.cve.org/CVERecord?id=CVE-2014-0522"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.10, 11.0.07","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0521","published":"2014-05-14T11:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on\nWindows and OS X do not properly implement JavaScript APIs, which allows\nremote attackers to obtain sensitive information via a crafted PDF\ndocument.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/reader/apsb14-15.html","https://www.cve.org/CVERecord?id=CVE-2014-0521"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.10, 11.0.07","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0520","published":"2014-05-14T11:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 13.0.0.214 on Windows and OS X and before\n11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK &\nCompiler before 13.0.0.111 allow attackers to bypass intended access\nrestrictions via unspecified vectors, a different vulnerability than\nCVE-2014-0517, CVE-2014-0518, and CVE-2014-0519.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/flash-player/apsb14-14.html","https://www.cve.org/CVERecord?id=CVE-2014-0520"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.359-0precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.359-0quantal1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.359-0saucy1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.359-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.359","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.359ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.359ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.359ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.359ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.359","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0519","published":"2014-05-14T11:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 13.0.0.214 on Windows and OS X and before\n11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK &\nCompiler before 13.0.0.111 allow attackers to bypass intended access\nrestrictions via unspecified vectors, a different vulnerability than\nCVE-2014-0517, CVE-2014-0518, and CVE-2014-0520.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/flash-player/apsb14-14.html","https://www.cve.org/CVERecord?id=CVE-2014-0519"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.359-0precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.359-0quantal1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.359-0saucy1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.359-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.359","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.359ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.359ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.359ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.359ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.359","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0518","published":"2014-05-14T11:13:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 13.0.0.214 on Windows and OS X and before\n11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK &\nCompiler before 13.0.0.111 allow attackers to bypass intended access\nrestrictions via unspecified vectors, a different vulnerability than\nCVE-2014-0517, CVE-2014-0519, and CVE-2014-0520.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/flash-player/apsb14-14.html","https://www.cve.org/CVERecord?id=CVE-2014-0518"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.359-0precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.359-0quantal1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.359-0saucy1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.359-0trusty1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.359","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.359ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.359ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.359ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"11.2.202.359ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.359","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":65480,"limit":20,"total_results":79316}