{"cves":[{"id":"CVE-2014-0165","published":"2014-04-10T00:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated\nusers to publish posts by leveraging the Contributor role, related to\nwp-admin/includes/post.php and\nwp-admin/includes/class-wp-posts-list-table.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2014-0165"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744018"],"patches":{"wordpress":[]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8.2+dfsg-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.8.2+dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.8.2+dfsg-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.8.2+dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.8.2+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.8.2+dfsg-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"3.8.2+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.8.2+dfsg-1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-2583","published":"2014-04-10T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple directory traversal vulnerabilities in pam_timestamp.c in the\npam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users to\ncreate arbitrary files or possibly bypass authentication via a .. (dot dot)\nin the (1) PAM_RUSER value to the get_ruser function or (2) PAM_TTY value\nto the check_tty function, which is used by the format_timestamp_name\nfunction.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Ubuntu does not use pam_timestamp.so by default"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/03/26","http://www.openwall.com/lists/oss-security/2014/03/24/5","https://ubuntu.com/security/notices/USN-2935-1","https://www.cve.org/CVERecord?id=CVE-2014-2583"],"bugs":[""],"patches":{"pam":["upstream: https://git.fedorahosted.org/cgit/linux-pam.git/commit/?id=9dcead87e6d7f66d34e7a56d11a30daca367dffb"]},"tags":{},"packages":[{"name":"pam","source":"https://ubuntu.com/security/cve?package=pam","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pam","debian":"https://tracker.debian.org/pkg/pam","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.1.3-7ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.1.8-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.8-3.1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1.1.8-3.1ubuntu3","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.1.8-3.1ubuntu3","component":null,"pocket":"security"}]}],"notices_ids":["USN-2935-1"],"notices":[{"id":"USN-2935-1","title":"PAM vulnerabilities","summary":"Several security issues were fixed in PAM.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-03-16T13:45:39.506195","description":"It was discovered that the PAM pam_userdb module incorrectly used a\ncase-insensitive method when comparing hashed passwords. A local attacker\ncould possibly use this issue to make brute force attacks easier. This\nissue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041)\n\nSebastian Krahmer discovered that the PAM pam_timestamp module incorrectly\nperformed filtering. A local attacker could use this issue to create\narbitrary files, or possibly bypass authentication. This issue only\naffected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-2583)\n\nSebastien Macke discovered that the PAM pam_unix module incorrectly handled\nlarge passwords. A local attacker could possibly use this issue in certain\nenvironments to enumerate usernames or cause a denial of service.\n(CVE-2015-3238)\n","is_hidden":false,"release_packages":{"precise":[{"name":"pam","version":"1.1.3-7ubuntu2.1","description":"Pluggable Authentication Modules","is_source":true},{"name":"libpam-modules","version":"1.1.3-7ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.3-7ubuntu2.1"}],"trusty":[{"name":"pam","version":"1.1.8-1ubuntu2.1","description":"Pluggable Authentication Modules","is_source":true},{"name":"libpam-cracklib","version":"1.1.8-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.8-1ubuntu2.1","pocket":"security"},{"name":"libpam-doc","version":"1.1.8-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.8-1ubuntu2.1","pocket":"security"},{"name":"libpam-modules","version":"1.1.8-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.8-1ubuntu2.1","pocket":"security"},{"name":"libpam-modules-bin","version":"1.1.8-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.8-1ubuntu2.1","pocket":"security"},{"name":"libpam-runtime","version":"1.1.8-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.8-1ubuntu2.1","pocket":"security"},{"name":"libpam0g","version":"1.1.8-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.8-1ubuntu2.1","pocket":"security"},{"name":"libpam0g-dev","version":"1.1.8-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.8-1ubuntu2.1","pocket":"security"}],"wily":[{"name":"pam","version":"1.1.8-3.1ubuntu3.1","description":"Pluggable Authentication Modules","is_source":true},{"name":"libpam-modules","version":"1.1.8-3.1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.8-3.1ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2013-7041","CVE-2014-2583","CVE-2015-3238"]}]},{"id":"CVE-2014-1729","published":"2014-04-09T10:57:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in Google V8 before 3.24.35.22, as\nused in Google Chrome before 34.0.1847.116, allow attackers to cause a\ndenial of service or possibly have other impact via unknown vectors.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Issue was fixed prior to Oxide r501, the first version to\nbe included in an Ubuntu release"},{"author":"mikesalvatore","note":"The Ubuntu Security Team does not support libv8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.google.com/p/v8/source/detail?r=20409","https://code.google.com/p/v8/source/detail?r=20345","https://code.google.com/p/v8/source/detail?r=20033","https://code.google.com/p/v8/source/detail?r=19923","https://code.google.com/p/v8/source/detail?r=19584","https://code.google.com/p/v8/source/detail?r=19572","https://code.google.com/p/chromium/issues/detail?id=358059","https://code.google.com/p/chromium/issues/detail?id=355586","https://code.google.com/p/chromium/issues/detail?id=352982","https://code.google.com/p/chromium/issues/detail?id=350863","https://code.google.com/p/chromium/issues/detail?id=348319","https://code.google.com/p/chromium/issues/detail?id=347262","https://code.google.com/p/chromium/issues/detail?id=345820","http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2014-1729"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[],"libv8":[],"libv8-3.14":[],"qtjsbackend-opensource-src":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"artful","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"34.0.1847.116-0ubuntu~1.12.04.0~pkg884","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"34.0.1847.116-0ubuntu~1.12.10.0~pkg900","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"34.0.1847.116-0ubuntu~1.13.10.0~pkg991","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"34.0.1847.116","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [34.0.1847.116-0ubuntu2]","component":null,"pocket":"security"}]},{"name":"libv8","source":"https://ubuntu.com/security/cve?package=libv8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libv8","debian":"https://tracker.debian.org/pkg/libv8","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"libv8-3.14","source":"https://ubuntu.com/security/cve?package=libv8-3.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libv8-3.14","debian":"https://tracker.debian.org/pkg/libv8-3.14","statuses":[{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [libv8 not supported]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"qtjsbackend-opensource-src","source":"https://ubuntu.com/security/cve?package=qtjsbackend-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtjsbackend-opensource-src","debian":"https://tracker.debian.org/pkg/qtjsbackend-opensource-src","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1728","published":"2014-04-09T10:57:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in Google Chrome before 34.0.1847.116\nallow attackers to cause a denial of service or possibly have other impact\nvia unknown vectors.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Issue was fixed prior to Oxide r501, the first version to\nbe included in an Ubuntu release"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.google.com/p/chromium/issues/detail?id=360298","https://code.google.com/p/chromium/issues/detail?id=358059","https://code.google.com/p/chromium/issues/detail?id=356517","https://code.google.com/p/chromium/issues/detail?id=356235","https://code.google.com/p/chromium/issues/detail?id=355586","https://code.google.com/p/chromium/issues/detail?id=354297","https://code.google.com/p/chromium/issues/detail?id=353013","https://code.google.com/p/chromium/issues/detail?id=352982","https://code.google.com/p/chromium/issues/detail?id=351815","https://code.google.com/p/chromium/issues/detail?id=350863","https://code.google.com/p/chromium/issues/detail?id=350537","https://code.google.com/p/chromium/issues/detail?id=350533","https://code.google.com/p/chromium/issues/detail?id=348319","https://code.google.com/p/chromium/issues/detail?id=347262","https://code.google.com/p/chromium/issues/detail?id=345820","http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2014-1728"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"34.0.1847.116-0ubuntu~1.12.04.0~pkg884","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"34.0.1847.116-0ubuntu~1.12.10.0~pkg900","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"34.0.1847.116-0ubuntu~1.13.10.0~pkg991","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"34.0.1847.116","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [34.0.1847.116-0ubuntu2]]","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1727","published":"2014-04-09T10:57:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in\ncontent/renderer/renderer_webcolorchooser_impl.h in Google Chrome before\n34.0.1847.116 allows remote attackers to cause a denial of service or\npossibly have unspecified other impact via vectors related to forms.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Issue was fixed prior to Oxide r501, the first version to\nbe included in an Ubuntu release"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/chrome?revision=255276&view=revision","https://code.google.com/p/chromium/issues/detail?id=342735","http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2014-1727"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"34.0.1847.116-0ubuntu~1.12.04.0~pkg884","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"34.0.1847.116-0ubuntu~1.12.10.0~pkg900","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"34.0.1847.116-0ubuntu~1.13.10.0~pkg991","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"34.0.1847.116","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [34.0.1847.116-0ubuntu2]]","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1726","published":"2014-04-09T10:57:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe drag implementation in Google Chrome before 34.0.1847.116 allows\nuser-assisted remote attackers to bypass the Same Origin Policy and forge\nlocal pathnames by leveraging renderer access.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Drag / drop currently not implemented in Oxide"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/chrome?revision=259353&view=revision","https://code.google.com/p/chromium/issues/detail?id=346135","http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2014-1726"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"34.0.1847.116-0ubuntu~1.12.04.0~pkg884","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"34.0.1847.116-0ubuntu~1.12.10.0~pkg900","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"34.0.1847.116-0ubuntu~1.13.10.0~pkg991","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"34.0.1847.116","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [34.0.1847.116-0ubuntu2]]","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1725","published":"2014-04-09T10:57:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe base64DecodeInternal function in wtf/text/Base64.cpp in Blink, as used\nin Google Chrome before 34.0.1847.116, does not properly handle string data\ncomposed exclusively of whitespace characters, which allows remote\nattackers to cause a denial of service (out-of-bounds read) via a\nwindow.atob method call.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Issue was fixed prior to Oxide r501, the first version to\nbe included in an Ubuntu release"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=170264&view=revision","https://code.google.com/p/chromium/issues/detail?id=357332","http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2014-1725"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"34.0.1847.116-0ubuntu~1.12.04.0~pkg884","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"34.0.1847.116-0ubuntu~1.12.10.0~pkg900","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"34.0.1847.116-0ubuntu~1.13.10.0~pkg991","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"34.0.1847.116","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [34.0.1847.116-0ubuntu2]]","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1724","published":"2014-04-09T10:57:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Free(b)soft Laboratory Speech Dispatcher\n0.7.1, as used in Google Chrome before 34.0.1847.116, allows remote\nattackers to cause a denial of service (application hang) or possibly have\nunspecified other impact via a text-to-speech request.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Issues is outside of content"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/chrome?revision=259109&view=revision","https://code.google.com/p/chromium/issues/detail?id=327295","http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2014-1724"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"34.0.1847.116-0ubuntu~1.12.04.0~pkg884","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"34.0.1847.116-0ubuntu~1.12.10.0~pkg900","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"34.0.1847.116-0ubuntu~1.13.10.0~pkg991","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"34.0.1847.116","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [34.0.1847.116-0ubuntu2]]","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1723","published":"2014-04-09T10:57:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe UnescapeURLWithOffsetsImpl function in net/base/escape.cc in Google\nChrome before 34.0.1847.116 does not properly handle bidirectional\nInternationalized Resource Identifiers (IRIs), which makes it easier for\nremote attackers to spoof URLs via crafted use of right-to-left (RTL)\nUnicode text.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Issue was fixed prior to Oxide r501, the first version to\nbe included in an Ubuntu release"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/chrome?revision=254091&view=revision","https://code.google.com/p/chromium/issues/detail?id=337746","http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2014-1723"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"34.0.1847.116-0ubuntu~1.12.04.0~pkg884","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"34.0.1847.116-0ubuntu~1.12.10.0~pkg900","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"34.0.1847.116-0ubuntu~1.13.10.0~pkg991","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"34.0.1847.116","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [34.0.1847.116-0ubuntu2]]","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1722","published":"2014-04-09T10:57:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the\nRenderBlock::addChildIgnoringAnonymousColumnBlocks function in\ncore/rendering/RenderBlock.cpp in Blink, as used in Google Chrome before\n34.0.1847.116, allows remote attackers to cause a denial of service or\npossibly have unspecified other impact via vectors involving addition of a\nchild node.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Issue was fixed prior to Oxide r501, the first version to\nbe included in an Ubuntu release"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=164405&view=revision","https://code.google.com/p/chromium/issues/detail?id=330626","http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2014-1722"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"34.0.1847.116-0ubuntu~1.12.04.0~pkg884","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"34.0.1847.116-0ubuntu~1.12.10.0~pkg900","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"34.0.1847.116-0ubuntu~1.13.10.0~pkg991","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"34.0.1847.116","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [34.0.1847.116-0ubuntu2]]","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1721","published":"2014-04-09T10:57:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle V8, as used in Google Chrome before 34.0.1847.116, does not properly\nimplement lazy deoptimization, which allows remote attackers to cause a\ndenial of service (memory corruption) or possibly have unspecified other\nimpact via crafted JavaScript code, as demonstrated by improper handling of\na heap allocation of a number outside the Small Integer (aka smi) range.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Issue was fixed prior to Oxide r501, the first version to\nbe included in an Ubuntu release"},{"author":"mikesalvatore","note":"The Ubuntu Security Team does not support libv8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.google.com/p/v8/source/detail?r=19834","https://code.google.com/p/chromium/issues/detail?id=350434","http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2014-1721"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[],"libv8":[],"libv8-3.14":[],"qtjsbackend-opensource-src":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"vivid","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"34.0.1847.116-0ubuntu~1.12.04.0~pkg884","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"34.0.1847.116-0ubuntu~1.12.10.0~pkg900","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"34.0.1847.116-0ubuntu~1.13.10.0~pkg991","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"34.0.1847.116","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [34.0.1847.116-0ubuntu2]","component":null,"pocket":"security"}]},{"name":"libv8","source":"https://ubuntu.com/security/cve?package=libv8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libv8","debian":"https://tracker.debian.org/pkg/libv8","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"libv8-3.14","source":"https://ubuntu.com/security/cve?package=libv8-3.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libv8-3.14","debian":"https://tracker.debian.org/pkg/libv8-3.14","statuses":[{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [libv8 not supported]","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"qtjsbackend-opensource-src","source":"https://ubuntu.com/security/cve?package=qtjsbackend-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtjsbackend-opensource-src","debian":"https://tracker.debian.org/pkg/qtjsbackend-opensource-src","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1720","published":"2014-04-09T10:57:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the HTMLBodyElement::insertedInto function\nin core/html/HTMLBodyElement.cpp in Blink, as used in Google Chrome before\n34.0.1847.116, allows remote attackers to cause a denial of service or\npossibly have unspecified other impact via vectors involving attributes.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Issue was fixed prior to Oxide r501, the first version to\nbe included in an Ubuntu release"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=170216&view=revision","https://code.google.com/p/chromium/issues/detail?id=356095","http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2014-1720"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"34.0.1847.116-0ubuntu~1.12.04.0~pkg884","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"34.0.1847.116-0ubuntu~1.12.10.0~pkg900","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"34.0.1847.116-0ubuntu~1.13.10.0~pkg991","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"34.0.1847.116","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [34.0.1847.116-0ubuntu2]]","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1719","published":"2014-04-09T10:57:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the\nWebSharedWorkerStub::OnTerminateWorkerContext function in\ncontent/worker/websharedworker_stub.cc in the Web Workers implementation in\nGoogle Chrome before 34.0.1847.116 allows remote attackers to cause a\ndenial of service (heap memory corruption) or possibly have unspecified\nother impact via vectors that trigger a SharedWorker termination during\nscript loading.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Issue was fixed prior to Oxide r501, the first version to\nbe included in an Ubuntu release"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/chrome?revision=252010&view=revision","https://code.google.com/p/chromium/issues/detail?id=343661","http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2014-1719"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"upstream","status":"released","description":"34.0.1847.116","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [34.0.1847.116-0ubuntu2]]","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"34.0.1847.116-0ubuntu~1.12.04.0~pkg884","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"34.0.1847.116-0ubuntu~1.12.10.0~pkg900","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"34.0.1847.116-0ubuntu~1.13.10.0~pkg991","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1718","published":"2014-04-09T10:57:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the SoftwareFrameManager::SwapToNewFrame function in\ncontent/browser/renderer_host/software_frame_manager.cc in the software\ncompositor in Google Chrome before 34.0.1847.116 allows remote attackers to\ncause a denial of service or possibly have unspecified other impact via\nvectors that trigger an attempted mapping of a large amount of renderer\nmemory.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"SoftwareFrameManager is only used in the Mac port"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/chrome?revision=261817&view=revision","https://src.chromium.org/viewvc/chrome?revision=260969&view=revision","https://src.chromium.org/viewvc/chrome?revision=258418&view=revision","https://src.chromium.org/viewvc/chrome?revision=257417&view=revision","https://code.google.com/p/chromium/issues/detail?id=348332","http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2014-1718"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"34.0.1847.116-0ubuntu~1.12.04.0~pkg884","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"34.0.1847.116-0ubuntu~1.12.10.0~pkg900","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"34.0.1847.116-0ubuntu~1.13.10.0~pkg991","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"34.0.1847.116","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [34.0.1847.116-0ubuntu2]]","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1717","published":"2014-04-09T10:57:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle V8, as used in Google Chrome before 34.0.1847.116, does not properly\nuse numeric casts during handling of typed arrays, which allows remote\nattackers to cause a denial of service (out-of-bounds array access) or\npossibly have unspecified other impact via crafted JavaScript code.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Issue was fixed prior to Oxide r501, the first version to\nbe included in an Ubuntu release"},{"author":"mikesalvatore","note":"The Ubuntu Security Team does not support libv8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.google.com/p/v8/source/detail?r=20020","https://code.google.com/p/chromium/issues/detail?id=353004","http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2014-1717"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[],"libv8":[],"libv8-3.14":[],"qtjsbackend-opensource-src":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"artful","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"34.0.1847.116-0ubuntu~1.12.04.0~pkg884","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"34.0.1847.116-0ubuntu~1.12.10.0~pkg900","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"34.0.1847.116-0ubuntu~1.13.10.0~pkg991","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"34.0.1847.116","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [34.0.1847.116-0ubuntu2]","component":null,"pocket":"security"}]},{"name":"libv8","source":"https://ubuntu.com/security/cve?package=libv8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libv8","debian":"https://tracker.debian.org/pkg/libv8","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"libv8-3.14","source":"https://ubuntu.com/security/cve?package=libv8-3.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libv8-3.14","debian":"https://tracker.debian.org/pkg/libv8-3.14","statuses":[{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [libv8 not supported]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"qtjsbackend-opensource-src","source":"https://ubuntu.com/security/cve?package=qtjsbackend-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtjsbackend-opensource-src","debian":"https://tracker.debian.org/pkg/qtjsbackend-opensource-src","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1716","published":"2014-04-09T10:56:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the Runtime_SetPrototype\nfunction in runtime.cc in Google V8, as used in Google Chrome before\n34.0.1847.116, allows remote attackers to inject arbitrary web script or\nHTML via unspecified vectors, aka \"Universal XSS (UXSS).\"","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Issue was fixed prior to Oxide r501, the first version to\nbe included in an Ubuntu release"},{"author":"mikesalvatore","note":"The Ubuntu Security Team does not support libv8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.google.com/p/v8/source/detail?r=20138","https://code.google.com/p/chromium/issues/detail?id=354123","http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2014-1716"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[],"libv8":[],"libv8-3.14":[],"qtjsbackend-opensource-src":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"vivid","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"34.0.1847.116-0ubuntu~1.12.04.0~pkg884","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"34.0.1847.116-0ubuntu~1.12.10.0~pkg900","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"34.0.1847.116-0ubuntu~1.13.10.0~pkg991","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"34.0.1847.116","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"34.0.1847.116-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [34.0.1847.116-0ubuntu2]","component":null,"pocket":"security"}]},{"name":"libv8","source":"https://ubuntu.com/security/cve?package=libv8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libv8","debian":"https://tracker.debian.org/pkg/libv8","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"libv8-3.14","source":"https://ubuntu.com/security/cve?package=libv8-3.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libv8-3.14","debian":"https://tracker.debian.org/pkg/libv8-3.14","statuses":[{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [libv8 not supported]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"qtjsbackend-opensource-src","source":"https://ubuntu.com/security/cve?package=qtjsbackend-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtjsbackend-opensource-src","debian":"https://tracker.debian.org/pkg/qtjsbackend-opensource-src","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0509","published":"2014-04-08T23:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Adobe Flash Player before\n11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS\nX and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android,\nAdobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before\n13.0.0.83 allows remote attackers to inject arbitrary web script or HTML\nvia unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/flash-player/apsb14-09.html","https://www.cve.org/CVERecord?id=CVE-2014-0509"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.350-0precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.350-0quantal1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.350-0saucy1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.350","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.350ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.350ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.350ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.350","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0508","published":"2014-04-08T23:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before\n13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR\nbefore 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR\nSDK & Compiler before 13.0.0.83 allow attackers to bypass intended access\nrestrictions and obtain sensitive information via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/flash-player/apsb14-09.html","https://www.cve.org/CVERecord?id=CVE-2014-0508"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.350-0precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.350-0quantal1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.350-0saucy1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.350","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.350ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.350ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.350ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.350","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0507","published":"2014-04-08T23:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in Adobe Flash Player before 11.7.700.275 and 11.8.x\nthrough 13.0.x before 13.0.0.182 on Windows and OS X and before\n11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK\nbefore 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allows\nattackers to execute arbitrary code via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/flash-player/apsb14-09.html","https://www.cve.org/CVERecord?id=CVE-2014-0507"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.350-0precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.350-0quantal1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.350-0saucy1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.350","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.350ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.350ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.350ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.350","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-0033","published":"2014-04-08T14:22:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe CBounceDCCMod::OnPrivCTCP function in bouncedcc.cpp in the bouncedcc\nmodule in ZNC 0.200 and 0.202 allows remote attackers to cause a denial of\nservice (crash) via a crafted DCC RESUME request.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Only affects 0.200 and 0.202"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://packages.qa.debian.org/z/znc/news/20120107T145601Z.html","https://www.cve.org/CVERecord?id=CVE-2012-0033"],"bugs":[""],"patches":{"znc":["upstream: https://github.com/znc/znc/commit/11508aa72efab4fad0dbd8292b9614d9371b20a9"]},"tags":{},"packages":[{"name":"znc","source":"https://ubuntu.com/security/cve?package=znc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=znc","debian":"https://tracker.debian.org/pkg/znc","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.202-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":65760,"limit":20,"total_results":79316}