{"cves":[{"id":"CVE-2013-6371","published":"2014-04-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe hash functionality in json-c before 0.12 allows context-dependent\nattackers to cause a denial of service (CPU consumption) via crafted JSON\ndata, involving collisions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2245-1","https://www.cve.org/CVERecord?id=CVE-2013-6371"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744008","https://bugzilla.redhat.com/show_bug.cgi?id=1032311","https://bugs.launchpad.net/ubuntu/+source/json-c/+bug/1311397"],"patches":{"json-c":["upstream: https://github.com/json-c/json-c/commit/64e36901a0614bf64a19bc3396469c66dcd0b015"]},"tags":{},"packages":[{"name":"json-c","source":"https://ubuntu.com/security/cve?package=json-c","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=json-c","debian":"https://tracker.debian.org/pkg/json-c","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"0.9-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"0.11-2ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.11-3ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.11-4","component":null,"pocket":"security"}]}],"notices_ids":["USN-2245-1"],"notices":[{"id":"USN-2245-1","title":"json-c vulnerabilities","summary":"json-c could be made to crash or consume CPU if it processed a specially\ncrafted JSON document.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-06-12T16:30:16.150565","description":"Florian Weimer discovered that json-c incorrectly handled buffer lengths.\nAn attacker could use this issue with a specially-crafted large JSON\ndocument to cause json-c to crash, resulting in a denial of service.\n(CVE-2013-6370)\n\nFlorian Weimer discovered that json-c incorrectly handled hash arrays. An\nattacker could use this issue with a specially-crafted JSON document to\ncause json-c to consume CPU resources, resulting in a denial of service.\n(CVE-2013-6371)\n","is_hidden":false,"release_packages":{"precise":[{"name":"json-c","version":"0.9-1ubuntu1.1","description":"JSON manipulation library","is_source":true},{"name":"libjson0","version":"0.9-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/json-c","version_link":"https://launchpad.net/ubuntu/+source/json-c/0.9-1ubuntu1.1"}],"saucy":[{"name":"json-c","version":"0.11-2ubuntu1.2","description":"JSON manipulation library","is_source":true},{"name":"libjson0","version":"0.11-2ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/json-c","version_link":"https://launchpad.net/ubuntu/+source/json-c/0.11-2ubuntu1.2"}],"trusty":[{"name":"json-c","version":"0.11-3ubuntu1.2","description":"JSON manipulation library","is_source":true},{"name":"libjson-c-dev","version":"0.11-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/json-c","version_link":"https://launchpad.net/ubuntu/+source/json-c/0.11-3ubuntu1.2","pocket":"security"},{"name":"libjson-c-doc","version":"0.11-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/json-c","version_link":"https://launchpad.net/ubuntu/+source/json-c/0.11-3ubuntu1.2","pocket":"security"},{"name":"libjson-c2","version":"0.11-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/json-c","version_link":"https://launchpad.net/ubuntu/+source/json-c/0.11-3ubuntu1.2","pocket":"security"},{"name":"libjson0","version":"0.11-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/json-c","version_link":"https://launchpad.net/ubuntu/+source/json-c/0.11-3ubuntu1.2","pocket":"security"},{"name":"libjson0-dev","version":"0.11-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/json-c","version_link":"https://launchpad.net/ubuntu/+source/json-c/0.11-3ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2013-6370","CVE-2013-6371"]}]},{"id":"CVE-2013-6370","published":"2014-04-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the printbuf APIs in json-c before 0.12 allows remote\nattackers to cause a denial of service via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2245-1","https://www.cve.org/CVERecord?id=CVE-2013-6370"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744008","https://bugzilla.redhat.com/show_bug.cgi?id=1032322","https://bugs.launchpad.net/ubuntu/+source/json-c/+bug/1311397"],"patches":{"json-c":["upstream: https://github.com/json-c/json-c/commit/64e36901a0614bf64a19bc3396469c66dcd0b015"]},"tags":{},"packages":[{"name":"json-c","source":"https://ubuntu.com/security/cve?package=json-c","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=json-c","debian":"https://tracker.debian.org/pkg/json-c","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"0.9-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"0.11-2ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.11-3ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.11-4","component":null,"pocket":"security"}]}],"notices_ids":["USN-2245-1"],"notices":[{"id":"USN-2245-1","title":"json-c vulnerabilities","summary":"json-c could be made to crash or consume CPU if it processed a specially\ncrafted JSON document.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-06-12T16:30:16.150565","description":"Florian Weimer discovered that json-c incorrectly handled buffer lengths.\nAn attacker could use this issue with a specially-crafted large JSON\ndocument to cause json-c to crash, resulting in a denial of service.\n(CVE-2013-6370)\n\nFlorian Weimer discovered that json-c incorrectly handled hash arrays. An\nattacker could use this issue with a specially-crafted JSON document to\ncause json-c to consume CPU resources, resulting in a denial of service.\n(CVE-2013-6371)\n","is_hidden":false,"release_packages":{"precise":[{"name":"json-c","version":"0.9-1ubuntu1.1","description":"JSON manipulation library","is_source":true},{"name":"libjson0","version":"0.9-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/json-c","version_link":"https://launchpad.net/ubuntu/+source/json-c/0.9-1ubuntu1.1"}],"saucy":[{"name":"json-c","version":"0.11-2ubuntu1.2","description":"JSON manipulation library","is_source":true},{"name":"libjson0","version":"0.11-2ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/json-c","version_link":"https://launchpad.net/ubuntu/+source/json-c/0.11-2ubuntu1.2"}],"trusty":[{"name":"json-c","version":"0.11-3ubuntu1.2","description":"JSON manipulation library","is_source":true},{"name":"libjson-c-dev","version":"0.11-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/json-c","version_link":"https://launchpad.net/ubuntu/+source/json-c/0.11-3ubuntu1.2","pocket":"security"},{"name":"libjson-c-doc","version":"0.11-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/json-c","version_link":"https://launchpad.net/ubuntu/+source/json-c/0.11-3ubuntu1.2","pocket":"security"},{"name":"libjson-c2","version":"0.11-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/json-c","version_link":"https://launchpad.net/ubuntu/+source/json-c/0.11-3ubuntu1.2","pocket":"security"},{"name":"libjson0","version":"0.11-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/json-c","version_link":"https://launchpad.net/ubuntu/+source/json-c/0.11-3ubuntu1.2","pocket":"security"},{"name":"libjson0-dev","version":"0.11-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/json-c","version_link":"https://launchpad.net/ubuntu/+source/json-c/0.11-3ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2013-6370","CVE-2013-6371"]}]},{"id":"CVE-2012-2095","published":"2014-04-07T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe SetWiredProperty function in the D-Bus interface in WICD before 1.7.2\nallows local users to write arbitrary configuration settings and gain\nprivileges via a crafted property name in a dbus message.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://launchpad.net/wicd/+announcement/9888","https://www.cve.org/CVERecord?id=CVE-2012-2095"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=668397","https://bugs.launchpad.net/ubuntu/+source/wicd/+bug/979221"],"patches":{"wicd":["upstream: http://bazaar.launchpad.net/~wicd-devel/wicd/experimental/revision/751"]},"tags":{},"packages":[{"name":"wicd","source":"https://ubuntu.com/security/cve?package=wicd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wicd","debian":"https://tracker.debian.org/pkg/wicd","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.7.0+ds1-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.7.0+ds1-6ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"1.7.0+ds1-6ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.7.2.3-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.7.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0160","published":"2014-04-07T00:00:00","updated_at":"2025-08-25T21:09:53.217776+00:00","description":"\nThe (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do\nnot properly handle Heartbeat Extension packets, which allows remote\nattackers to obtain sensitive information from process memory via crafted\npackets that trigger a buffer over-read, as demonstrated by reading private\nkeys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openssl.org/news/secadv_20140407.txt","http://heartbleed.com/","https://ubuntu.com/security/notices/USN-2165-1","https://www.cve.org/CVERecord?id=CVE-2014-0160","https://www.cisa.gov/known-exploited-vulnerabilities-catalog"],"bugs":[""],"patches":{"openssl":["upstream: http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=96db9023b881d7cd9f379b0c154650d6c108e9a3"],"openssl098":[]},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"lucid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.0.1-4ubuntu5.12","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1.0.1c-3ubuntu2.7","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1.0.1e-3ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.1g","component":null,"pocket":"security"}]},{"name":"openssl098","source":"https://ubuntu.com/security/cve?package=openssl098","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl098","debian":"https://tracker.debian.org/pkg/openssl098","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2165-1"],"notices":[{"id":"USN-2165-1","title":"OpenSSL vulnerabilities","summary":"OpenSSL could be made to expose sensitive information over the network,\npossibly including private keys.\n","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes. Since this issue may have resulted in compromised\nprivate keys, it is recommended to regenerate them.\n","references":[],"published":"2014-04-07T21:52:42.563252","description":"Neel Mehta discovered that OpenSSL incorrectly handled memory in the TLS\nheartbeat extension. An attacker could use this issue to obtain up to 64k\nof memory contents from the client or server, possibly leading to the\ndisclosure of private keys and other sensitive information. (CVE-2014-0160)\n\nYuval Yarom and Naomi Benger discovered that OpenSSL incorrectly handled\ntiming during swap operations in the Montgomery ladder implementation. An\nattacker could use this issue to perform side-channel attacks and possibly\nrecover ECDSA nonces. (CVE-2014-0076)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openssl","version":"1.0.1-4ubuntu5.12","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl1.0.0","version":"1.0.1-4ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.12"}],"saucy":[{"name":"openssl","version":"1.0.1e-3ubuntu1.2","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl1.0.0","version":"1.0.1e-3ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1e-3ubuntu1.2"}],"quantal":[{"name":"openssl","version":"1.0.1c-3ubuntu2.7","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl1.0.0","version":"1.0.1c-3ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1c-3ubuntu2.7"}]},"type":"USN","cves_ids":["CVE-2014-0076","CVE-2014-0160"]}]},{"id":"CVE-2013-5680","published":"2014-04-06T16:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in hfaxd in HylaFAX+ 5.2.4 through 5.5.3, when\nusing LDAP authentication, might allow remote attackers to cause a denial\nof service (child hang) or execute arbitrary code via a long USER command.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"not built with ldap support"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.securityfocus.com/archive/1/528943/30/0/threaded","https://www.cve.org/CVERecord?id=CVE-2013-5680"],"bugs":[""],"patches":{"hylafax":[]},"tags":{},"packages":[{"name":"hylafax","source":"https://ubuntu.com/security/cve?package=hylafax","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=hylafax","debian":"https://tracker.debian.org/pkg/hylafax","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-6640","published":"2014-04-05T21:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Horde Internet Mail Program\n(IMP) before 5.0.22, as used in Horde Groupware Webmail Edition before\n4.0.9, allows remote attackers to inject arbitrary web script or HTML via a\ncrafted SVG image attachment, a different vulnerability than CVE-2012-5565.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/horde/horde/commit/08c699f744b6d2be1a5f3a2ba7203f4631b4c5dc","http://lists.horde.org/archives/announce/2012/000840.html","http://lists.horde.org/archives/announce/2012/000775.html","https://www.cve.org/CVERecord?id=CVE-2012-6640"],"bugs":[""],"patches":{"horde3":[]},"tags":{},"packages":[{"name":"horde3","source":"https://ubuntu.com/security/cve?package=horde3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=horde3","debian":"https://tracker.debian.org/pkg/horde3","statuses":[{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.22","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-5567","published":"2014-04-05T21:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith\nCalendar Application H4 before 3.0.18, as used in Horde Groupware Webmail\nEdition before 4.0.9, allow remote attackers to inject arbitrary web script\nor HTML via crafted event location parameters in the (1) month, (2)\nmonthlist, or (3) prevmonthlist fields, related to portal blocks.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2012/11/23","https://www.cve.org/CVERecord?id=CVE-2012-5567"],"bugs":[""],"patches":{"kronolith2":["upstream: http://git.horde.org/horde-git/-/commit/d865c564beb6e98532880aa51a04a79f3311cd1e"]},"tags":{},"packages":[{"name":"kronolith2","source":"https://ubuntu.com/security/cve?package=kronolith2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kronolith2","debian":"https://tracker.debian.org/pkg/kronolith2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.18","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-5566","published":"2014-04-05T21:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith\nCalendar Application H4 before 3.0.17, as used in Horde Groupware Webmail\nEdition before 4.0.8, allow remote attackers to inject arbitrary web script\nor HTML via the (1) tasks view or (2) search view.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2012/11/23","https://www.cve.org/CVERecord?id=CVE-2012-5566"],"bugs":[""],"patches":{"kronolith2":["upstream: http://git.horde.org/horde-git/-/commit/1228a6825a8dab3333d0a8c8986fc10d1f3d11b2"]},"tags":{},"packages":[{"name":"kronolith2","source":"https://ubuntu.com/security/cve?package=kronolith2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kronolith2","debian":"https://tracker.debian.org/pkg/kronolith2","statuses":[{"release_codename":"hardy","status":"not-affected","description":"2.1.5-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.3.3+debian0-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.3.4+debian0-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"2.3.4+debian0-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"introduced in 3.0.x","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2001-1593","published":"2014-04-05T21:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nJakub Wilk found that a2ps, a tool to convert text and other types of\nfiles to PostScript, insecurely used a temporary file in spy_user(). A\nlocal attacker could use this flaw to perform a symbolic link attack to\nmodify an arbitrary file accessible to the user running a2ps.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2001-1593"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737385","https://bugzilla.redhat.com/show_bug.cgi?id=1060630"],"patches":{"a2ps":["fedora: http://pkgs.fedoraproject.org/cgit/a2ps.git/plain/a2ps-4.13-security.patch"]},"tags":{},"packages":[{"name":"a2ps","source":"https://ubuntu.com/security/cve?package=a2ps","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=a2ps","debian":"https://tracker.debian.org/pkg/a2ps","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:4.14-1.1+deb7u1build0.12.04.1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1:4.14-1.2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1:4.14-1.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [1:4.14-1.2]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0466","published":"2014-04-03T16:15:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe fixps script in a2ps 4.14 does not use the -dSAFER option when\nexecuting gs, which allows context-dependent attackers to delete arbitrary\nfiles or execute arbitrary commands via a crafted PostScript file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2014-0466"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742902"],"patches":{"a2ps":[]},"tags":{},"packages":[{"name":"a2ps","source":"https://ubuntu.com/security/cve?package=a2ps","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=a2ps","debian":"https://tracker.debian.org/pkg/a2ps","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:4.14-1.1+deb7u1build0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:4.14-1.3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1:4.14-1.3","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1:4.14-1.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [1:4.14-1.3]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1313","published":"2014-04-02T16:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows\nremote attackers to execute arbitrary code or cause a denial of service\n(memory corruption and application crash) via a crafted web site, a\ndifferent vulnerability than other WebKit CVEs listed in\nAPPLE-SA-2014-04-01-1.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://archives.neohapsis.com/archives/bugtraq/2014-04/0136.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0135.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0009.html","https://www.cve.org/CVERecord?id=CVE-2014-1313"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1312","published":"2014-04-02T16:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows\nremote attackers to execute arbitrary code or cause a denial of service\n(memory corruption and application crash) via a crafted web site, a\ndifferent vulnerability than other WebKit CVEs listed in\nAPPLE-SA-2014-04-01-1.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://archives.neohapsis.com/archives/bugtraq/2014-04/0136.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0135.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0009.html","https://www.cve.org/CVERecord?id=CVE-2014-1312"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1311","published":"2014-04-02T16:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows\nremote attackers to execute arbitrary code or cause a denial of service\n(memory corruption and application crash) via a crafted web site, a\ndifferent vulnerability than other WebKit CVEs listed in\nAPPLE-SA-2014-04-01-1.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://archives.neohapsis.com/archives/bugtraq/2014-04/0136.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0135.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0009.html","https://www.cve.org/CVERecord?id=CVE-2014-1311"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1310","published":"2014-04-02T16:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows\nremote attackers to execute arbitrary code or cause a denial of service\n(memory corruption and application crash) via a crafted web site, a\ndifferent vulnerability than other WebKit CVEs listed in\nAPPLE-SA-2014-04-01-1.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://archives.neohapsis.com/archives/bugtraq/2014-04/0136.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0135.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0009.html","https://www.cve.org/CVERecord?id=CVE-2014-1310"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1309","published":"2014-04-02T16:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows\nremote attackers to execute arbitrary code or cause a denial of service\n(memory corruption and application crash) via a crafted web site, a\ndifferent vulnerability than other WebKit CVEs listed in\nAPPLE-SA-2014-04-01-1.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://archives.neohapsis.com/archives/bugtraq/2014-04/0136.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0135.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0009.html","https://www.cve.org/CVERecord?id=CVE-2014-1309"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1308","published":"2014-04-02T16:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows\nremote attackers to execute arbitrary code or cause a denial of service\n(memory corruption and application crash) via a crafted web site, a\ndifferent vulnerability than other WebKit CVEs listed in\nAPPLE-SA-2014-04-01-1.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://archives.neohapsis.com/archives/bugtraq/2014-04/0136.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0135.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0009.html","https://www.cve.org/CVERecord?id=CVE-2014-1308"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1307","published":"2014-04-02T16:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows\nremote attackers to execute arbitrary code or cause a denial of service\n(memory corruption and application crash) via a crafted web site, a\ndifferent vulnerability than other WebKit CVEs listed in\nAPPLE-SA-2014-04-01-1.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://archives.neohapsis.com/archives/bugtraq/2014-04/0136.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0135.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0009.html","https://www.cve.org/CVERecord?id=CVE-2014-1307"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1305","published":"2014-04-02T16:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows\nremote attackers to execute arbitrary code or cause a denial of service\n(memory corruption and application crash) via a crafted web site, a\ndifferent vulnerability than other WebKit CVEs listed in\nAPPLE-SA-2014-04-01-1.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://archives.neohapsis.com/archives/bugtraq/2014-04/0136.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0135.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0009.html","https://www.cve.org/CVERecord?id=CVE-2014-1305"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1304","published":"2014-04-02T16:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows\nremote attackers to execute arbitrary code or cause a denial of service\n(memory corruption and application crash) via a crafted web site, a\ndifferent vulnerability than other WebKit CVEs listed in\nAPPLE-SA-2014-04-01-1.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://archives.neohapsis.com/archives/bugtraq/2014-04/0136.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0135.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0009.html","https://www.cve.org/CVERecord?id=CVE-2014-1304"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1302","published":"2014-04-02T16:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows\nremote attackers to execute arbitrary code or cause a denial of service\n(memory corruption and application crash) via a crafted web site, a\ndifferent vulnerability than other WebKit CVEs listed in\nAPPLE-SA-2014-04-01-1.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://archives.neohapsis.com/archives/bugtraq/2014-04/0136.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0135.html","http://archives.neohapsis.com/archives/bugtraq/2014-04/0009.html","https://www.cve.org/CVERecord?id=CVE-2014-1302"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":65780,"limit":20,"total_results":79316}