{"cves":[{"id":"CVE-2013-5612","published":"2013-12-11T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and\nSeaMonkey before 2.23 makes it easier for remote attackers to inject\narbitrary web script or HTML by leveraging a Same Origin Policy violation\ntriggered by lack of a charset parameter in a Content-Type HTTP header.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-106.html","https://ubuntu.com/security/notices/USN-2052-1","https://www.cve.org/CVERecord?id=CVE-2013-5612"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"26.0+build2-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"26.0+build2-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"26.0+build2-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"26.0+build2-0ubuntu0.13.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"26.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-2052-1"],"notices":[{"id":"USN-2052-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1258513"],"published":"2013-12-11T14:29:12.911591","description":"Ben Turner, Bobby Holley, Jesse Ruderman, Christian Holler and Christoph\nDiehl discovered multiple memory safety issues in Firefox. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to cause a denial of service via application\ncrash, or execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2013-5609, CVE-2013-5610)\n\nMyk Melez discovered that the doorhanger notification for web app\ninstallation could persist between page navigations. An attacker could\npotentially exploit this to conduct clickjacking attacks. (CVE-2013-5611)\n\nMasato Kinugawa discovered that pages with missing character set encoding\ninformation can inherit character encodings across navigations from\nanother domain. An attacker could potentially exploit this to conduct\ncross-site scripting attacks. (CVE-2013-5612)\n\nDaniel Veditz discovered that a sandboxed iframe could use an object\nelement to bypass its own restrictions. (CVE-2013-5614)\n\nTyson Smith and Jesse Schwartzentruber discovered a use-after-free in\nevent listeners. An attacker could potentially exploit this to cause a\ndenial of service via application crash, or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2013-5616)\n\nA use-after-free was discovered in the table editing interface. An\nattacker could potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5618)\n\nDan Gohman discovered that binary search algorithms in Spidermonkey\nused arithmetic prone to overflow in several places. However, this\nis issue not believed to be exploitable. (CVE-2013-5619)\n\nTyson Smith and Jesse Schwartzentruber discovered a crash when inserting\nan ordered list in to a document using script. An attacker could\npotentially exploit this to execute arbitrary code with the privileges\nof the user invoking Firefox. (CVE-2013-6671)\n\nVincent Lefevre discovered that web content could access clipboard data\nunder certain circumstances, resulting in information disclosure.\n(CVE-2013-6672)\n\nSijie Xia discovered that trust settings for built-in EV root certificates\nwere ignored under certain circumstances, removing the ability for a user\nto manually untrust certificates from specific authorities.\n(CVE-2013-6673)\n\nTyson Smith, Jesse Schwartzentruber and Atte Kettunen discovered a\nuse-after-free in functions for synthetic mouse movement handling. An\nattacker could potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5613)\n\nEric Faust discovered that GetElementIC typed array stubs can be generated\noutside observed typesets. An attacker could possibly exploit this to\ncause undefined behaviour with a potential security impact.\n(CVE-2013-5615)\n\nMichal Zalewski discovered several issues with JPEG image handling. An\nattacker could potentially exploit these to obtain sensitive information.\n(CVE-2013-6629, CVE-2013-6630)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"26.0+build2-0ubuntu0.12.04.2","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"26.0+build2-0ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/26.0+build2-0ubuntu0.12.04.2"}],"saucy":[{"name":"firefox","version":"26.0+build2-0ubuntu0.13.10.2","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"26.0+build2-0ubuntu0.13.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/26.0+build2-0ubuntu0.13.10.2"}],"quantal":[{"name":"firefox","version":"26.0+build2-0ubuntu0.12.10.2","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"26.0+build2-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/26.0+build2-0ubuntu0.12.10.2"}],"raring":[{"name":"firefox","version":"26.0+build2-0ubuntu0.13.04.2","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"26.0+build2-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/26.0+build2-0ubuntu0.13.04.2"}]},"type":"USN","cves_ids":["CVE-2013-5609","CVE-2013-5610","CVE-2013-5611","CVE-2013-5612","CVE-2013-5613","CVE-2013-5614","CVE-2013-5615","CVE-2013-5616","CVE-2013-5618","CVE-2013-5619","CVE-2013-6629","CVE-2013-6630","CVE-2013-6671","CVE-2013-6672","CVE-2013-6673"]}]},{"id":"CVE-2013-5611","published":"2013-12-11T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox before 26.0 does not properly remove the Application\nInstallation doorhanger, which makes it easier for remote attackers to\nspoof a Web App installation site by controlling the timing of page\nnavigation.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-105.html","https://ubuntu.com/security/notices/USN-2052-1","https://www.cve.org/CVERecord?id=CVE-2013-5611"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"26.0+build2-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"26.0+build2-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"26.0+build2-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"26.0+build2-0ubuntu0.13.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"26.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-2052-1"],"notices":[{"id":"USN-2052-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1258513"],"published":"2013-12-11T14:29:12.911591","description":"Ben Turner, Bobby Holley, Jesse Ruderman, Christian Holler and Christoph\nDiehl discovered multiple memory safety issues in Firefox. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to cause a denial of service via application\ncrash, or execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2013-5609, CVE-2013-5610)\n\nMyk Melez discovered that the doorhanger notification for web app\ninstallation could persist between page navigations. An attacker could\npotentially exploit this to conduct clickjacking attacks. (CVE-2013-5611)\n\nMasato Kinugawa discovered that pages with missing character set encoding\ninformation can inherit character encodings across navigations from\nanother domain. An attacker could potentially exploit this to conduct\ncross-site scripting attacks. (CVE-2013-5612)\n\nDaniel Veditz discovered that a sandboxed iframe could use an object\nelement to bypass its own restrictions. (CVE-2013-5614)\n\nTyson Smith and Jesse Schwartzentruber discovered a use-after-free in\nevent listeners. An attacker could potentially exploit this to cause a\ndenial of service via application crash, or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2013-5616)\n\nA use-after-free was discovered in the table editing interface. An\nattacker could potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5618)\n\nDan Gohman discovered that binary search algorithms in Spidermonkey\nused arithmetic prone to overflow in several places. However, this\nis issue not believed to be exploitable. (CVE-2013-5619)\n\nTyson Smith and Jesse Schwartzentruber discovered a crash when inserting\nan ordered list in to a document using script. An attacker could\npotentially exploit this to execute arbitrary code with the privileges\nof the user invoking Firefox. (CVE-2013-6671)\n\nVincent Lefevre discovered that web content could access clipboard data\nunder certain circumstances, resulting in information disclosure.\n(CVE-2013-6672)\n\nSijie Xia discovered that trust settings for built-in EV root certificates\nwere ignored under certain circumstances, removing the ability for a user\nto manually untrust certificates from specific authorities.\n(CVE-2013-6673)\n\nTyson Smith, Jesse Schwartzentruber and Atte Kettunen discovered a\nuse-after-free in functions for synthetic mouse movement handling. An\nattacker could potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5613)\n\nEric Faust discovered that GetElementIC typed array stubs can be generated\noutside observed typesets. An attacker could possibly exploit this to\ncause undefined behaviour with a potential security impact.\n(CVE-2013-5615)\n\nMichal Zalewski discovered several issues with JPEG image handling. An\nattacker could potentially exploit these to obtain sensitive information.\n(CVE-2013-6629, CVE-2013-6630)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"26.0+build2-0ubuntu0.12.04.2","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"26.0+build2-0ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/26.0+build2-0ubuntu0.12.04.2"}],"saucy":[{"name":"firefox","version":"26.0+build2-0ubuntu0.13.10.2","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"26.0+build2-0ubuntu0.13.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/26.0+build2-0ubuntu0.13.10.2"}],"quantal":[{"name":"firefox","version":"26.0+build2-0ubuntu0.12.10.2","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"26.0+build2-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/26.0+build2-0ubuntu0.12.10.2"}],"raring":[{"name":"firefox","version":"26.0+build2-0ubuntu0.13.04.2","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"26.0+build2-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/26.0+build2-0ubuntu0.13.04.2"}]},"type":"USN","cves_ids":["CVE-2013-5609","CVE-2013-5610","CVE-2013-5611","CVE-2013-5612","CVE-2013-5613","CVE-2013-5614","CVE-2013-5615","CVE-2013-5616","CVE-2013-5618","CVE-2013-5619","CVE-2013-6629","CVE-2013-6630","CVE-2013-6671","CVE-2013-6672","CVE-2013-6673"]}]},{"id":"CVE-2013-5610","published":"2013-12-11T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in the browser engine in Mozilla\nFirefox before 26.0 and SeaMonkey before 2.23 allow remote attackers to\ncause a denial of service (memory corruption and application crash) or\npossibly execute arbitrary code via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-104.html","https://ubuntu.com/security/notices/USN-2052-1","https://www.cve.org/CVERecord?id=CVE-2013-5610"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"26.0+build2-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"26.0+build2-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"26.0+build2-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"26.0+build2-0ubuntu0.13.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"26.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-2052-1"],"notices":[{"id":"USN-2052-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1258513"],"published":"2013-12-11T14:29:12.911591","description":"Ben Turner, Bobby Holley, Jesse Ruderman, Christian Holler and Christoph\nDiehl discovered multiple memory safety issues in Firefox. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to cause a denial of service via application\ncrash, or execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2013-5609, CVE-2013-5610)\n\nMyk Melez discovered that the doorhanger notification for web app\ninstallation could persist between page navigations. An attacker could\npotentially exploit this to conduct clickjacking attacks. (CVE-2013-5611)\n\nMasato Kinugawa discovered that pages with missing character set encoding\ninformation can inherit character encodings across navigations from\nanother domain. An attacker could potentially exploit this to conduct\ncross-site scripting attacks. (CVE-2013-5612)\n\nDaniel Veditz discovered that a sandboxed iframe could use an object\nelement to bypass its own restrictions. (CVE-2013-5614)\n\nTyson Smith and Jesse Schwartzentruber discovered a use-after-free in\nevent listeners. An attacker could potentially exploit this to cause a\ndenial of service via application crash, or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2013-5616)\n\nA use-after-free was discovered in the table editing interface. An\nattacker could potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5618)\n\nDan Gohman discovered that binary search algorithms in Spidermonkey\nused arithmetic prone to overflow in several places. However, this\nis issue not believed to be exploitable. (CVE-2013-5619)\n\nTyson Smith and Jesse Schwartzentruber discovered a crash when inserting\nan ordered list in to a document using script. An attacker could\npotentially exploit this to execute arbitrary code with the privileges\nof the user invoking Firefox. (CVE-2013-6671)\n\nVincent Lefevre discovered that web content could access clipboard data\nunder certain circumstances, resulting in information disclosure.\n(CVE-2013-6672)\n\nSijie Xia discovered that trust settings for built-in EV root certificates\nwere ignored under certain circumstances, removing the ability for a user\nto manually untrust certificates from specific authorities.\n(CVE-2013-6673)\n\nTyson Smith, Jesse Schwartzentruber and Atte Kettunen discovered a\nuse-after-free in functions for synthetic mouse movement handling. An\nattacker could potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5613)\n\nEric Faust discovered that GetElementIC typed array stubs can be generated\noutside observed typesets. An attacker could possibly exploit this to\ncause undefined behaviour with a potential security impact.\n(CVE-2013-5615)\n\nMichal Zalewski discovered several issues with JPEG image handling. An\nattacker could potentially exploit these to obtain sensitive information.\n(CVE-2013-6629, CVE-2013-6630)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"26.0+build2-0ubuntu0.12.04.2","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"26.0+build2-0ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/26.0+build2-0ubuntu0.12.04.2"}],"saucy":[{"name":"firefox","version":"26.0+build2-0ubuntu0.13.10.2","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"26.0+build2-0ubuntu0.13.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/26.0+build2-0ubuntu0.13.10.2"}],"quantal":[{"name":"firefox","version":"26.0+build2-0ubuntu0.12.10.2","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"26.0+build2-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/26.0+build2-0ubuntu0.12.10.2"}],"raring":[{"name":"firefox","version":"26.0+build2-0ubuntu0.13.04.2","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"26.0+build2-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/26.0+build2-0ubuntu0.13.04.2"}]},"type":"USN","cves_ids":["CVE-2013-5609","CVE-2013-5610","CVE-2013-5611","CVE-2013-5612","CVE-2013-5613","CVE-2013-5614","CVE-2013-5615","CVE-2013-5616","CVE-2013-5618","CVE-2013-5619","CVE-2013-6629","CVE-2013-6630","CVE-2013-6671","CVE-2013-6672","CVE-2013-6673"]}]},{"id":"CVE-2013-5609","published":"2013-12-11T00:00:00","updated_at":"2025-08-25T20:58:52.202805+00:00","description":"\nMultiple unspecified vulnerabilities in the browser engine in Mozilla\nFirefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2,\nand SeaMonkey before 2.23 allow remote attackers to cause a denial of\nservice (memory corruption and application crash) or possibly execute\narbitrary code via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-104.html","https://ubuntu.com/security/notices/USN-2052-1","https://ubuntu.com/security/notices/USN-2053-1","https://www.cve.org/CVERecord?id=CVE-2013-5609"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"26.0+build2-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"26.0+build2-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"26.0+build2-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"26.0+build2-0ubuntu0.13.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"26.0","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:24.2.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1:24.2.0+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1:24.2.0+build1-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1:24.2.0+build1-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"24.2.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-2052-1","USN-2053-1"],"notices":[{"id":"USN-2052-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1258513"],"published":"2013-12-11T14:29:12.911591","description":"Ben Turner, Bobby Holley, Jesse Ruderman, Christian Holler and Christoph\nDiehl discovered multiple memory safety issues in Firefox. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to cause a denial of service via application\ncrash, or execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2013-5609, CVE-2013-5610)\n\nMyk Melez discovered that the doorhanger notification for web app\ninstallation could persist between page navigations. An attacker could\npotentially exploit this to conduct clickjacking attacks. (CVE-2013-5611)\n\nMasato Kinugawa discovered that pages with missing character set encoding\ninformation can inherit character encodings across navigations from\nanother domain. An attacker could potentially exploit this to conduct\ncross-site scripting attacks. (CVE-2013-5612)\n\nDaniel Veditz discovered that a sandboxed iframe could use an object\nelement to bypass its own restrictions. (CVE-2013-5614)\n\nTyson Smith and Jesse Schwartzentruber discovered a use-after-free in\nevent listeners. An attacker could potentially exploit this to cause a\ndenial of service via application crash, or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2013-5616)\n\nA use-after-free was discovered in the table editing interface. An\nattacker could potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5618)\n\nDan Gohman discovered that binary search algorithms in Spidermonkey\nused arithmetic prone to overflow in several places. However, this\nis issue not believed to be exploitable. (CVE-2013-5619)\n\nTyson Smith and Jesse Schwartzentruber discovered a crash when inserting\nan ordered list in to a document using script. An attacker could\npotentially exploit this to execute arbitrary code with the privileges\nof the user invoking Firefox. (CVE-2013-6671)\n\nVincent Lefevre discovered that web content could access clipboard data\nunder certain circumstances, resulting in information disclosure.\n(CVE-2013-6672)\n\nSijie Xia discovered that trust settings for built-in EV root certificates\nwere ignored under certain circumstances, removing the ability for a user\nto manually untrust certificates from specific authorities.\n(CVE-2013-6673)\n\nTyson Smith, Jesse Schwartzentruber and Atte Kettunen discovered a\nuse-after-free in functions for synthetic mouse movement handling. An\nattacker could potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5613)\n\nEric Faust discovered that GetElementIC typed array stubs can be generated\noutside observed typesets. An attacker could possibly exploit this to\ncause undefined behaviour with a potential security impact.\n(CVE-2013-5615)\n\nMichal Zalewski discovered several issues with JPEG image handling. An\nattacker could potentially exploit these to obtain sensitive information.\n(CVE-2013-6629, CVE-2013-6630)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"26.0+build2-0ubuntu0.12.04.2","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"26.0+build2-0ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/26.0+build2-0ubuntu0.12.04.2"}],"saucy":[{"name":"firefox","version":"26.0+build2-0ubuntu0.13.10.2","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"26.0+build2-0ubuntu0.13.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/26.0+build2-0ubuntu0.13.10.2"}],"quantal":[{"name":"firefox","version":"26.0+build2-0ubuntu0.12.10.2","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"26.0+build2-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/26.0+build2-0ubuntu0.12.10.2"}],"raring":[{"name":"firefox","version":"26.0+build2-0ubuntu0.13.04.2","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"26.0+build2-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/26.0+build2-0ubuntu0.13.04.2"}]},"type":"USN","cves_ids":["CVE-2013-5609","CVE-2013-5610","CVE-2013-5611","CVE-2013-5612","CVE-2013-5613","CVE-2013-5614","CVE-2013-5615","CVE-2013-5616","CVE-2013-5618","CVE-2013-5619","CVE-2013-6629","CVE-2013-6630","CVE-2013-6671","CVE-2013-6672","CVE-2013-6673"]},{"id":"USN-2053-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1258653"],"published":"2013-12-11T15:14:40.591483","description":"Ben Turner, Bobby Holley, Jesse Ruderman and Christian Holler discovered\nmultiple memory safety issues in Thunderbird. If a user were tricked in to\nopening a specially crafted message with scripting enabled, an attacker\ncould potentially exploit these to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Thunderbird. (CVE-2013-5609)\n\nTyson Smith and Jesse Schwartzentruber discovered a use-after-free in\nevent listeners. If a user had enabled scripting, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash, or execute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5616)\n\nA use-after-free was discovered in the table editing interface. An\nattacker could potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code with the privileges of the\nuser invoking Thunderbird. (CVE-2013-5618)\n\nTyson Smith and Jesse Schwartzentruber discovered a crash when inserting\nan ordered list in to a document using script. If a user had enabled\nscripting, an attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Thunderbird.\n(CVE-2013-6671)\n\nSijie Xia discovered that trust settings for built-in EV root certificates\nwere ignored under certain circumstances, removing the ability for a user\nto manually untrust certificates from specific authorities.\n(CVE-2013-6673)\n\nTyson Smith, Jesse Schwartzentruber and Atte Kettunen discovered a\nuse-after-free in functions for synthetic mouse movement handling. If a\nuser had enabled scripting, an attacker could potentially exploit this\nto cause a denial of service via application crash, or execute arbitrary\ncode with the privileges of the user invoking Thunderbird. (CVE-2013-5613)\n\nEric Faust discovered that GetElementIC typed array stubs can be generated\noutside observed typesets. If a user had enabled scripting, an attacker\ncould possibly exploit this to cause undefined behaviour with a potential\nsecurity impact. (CVE-2013-5615)\n\nMichal Zalewski discovered several issues with JPEG image handling. An\nattacker could potentially exploit these to obtain sensitive information.\n(CVE-2013-6629, CVE-2013-6630)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"1:24.2.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.2.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.2.0+build1-0ubuntu0.12.04.1"}],"saucy":[{"name":"thunderbird","version":"1:24.2.0+build1-0ubuntu0.13.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.2.0+build1-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.2.0+build1-0ubuntu0.13.10.1"}],"quantal":[{"name":"thunderbird","version":"1:24.2.0+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.2.0+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.2.0+build1-0ubuntu0.12.10.1"}],"raring":[{"name":"thunderbird","version":"1:24.2.0+build1-0ubuntu0.13.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.2.0+build1-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.2.0+build1-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-5609","CVE-2013-5613","CVE-2013-5615","CVE-2013-5616","CVE-2013-5618","CVE-2013-6629","CVE-2013-6630","CVE-2013-6671","CVE-2013-6673"]}]},{"id":"CVE-2013-7024","published":"2013-12-09T16:36:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg\nbefore 2.1 does not consider the component number in certain calculations,\nwhich allows remote attackers to cause a denial of service (out-of-bounds\narray access) or possibly have unspecified other impact via crafted\nJPEG2000 data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/FFmpeg/FFmpeg/commit/fe448cd28d674c3eff3072552eae366d0b659ce9","https://trac.ffmpeg.org/ticket/2921","http://www.openwall.com/lists/oss-security/2013/12/08","https://www.cve.org/CVERecord?id=CVE-2013-7024"],"bugs":[""],"patches":{"ffmpeg":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-7023","published":"2013-12-09T16:36:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ff_combine_frame function in libavcodec/parser.c in FFmpeg before 2.1\ndoes not properly handle certain memory-allocation errors, which allows\nremote attackers to cause a denial of service (out-of-bounds array access)\nor possibly have unspecified other impact via crafted data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/FFmpeg/FFmpeg/commit/f31011e9abfb2ae75bb32bc44e2c34194c8dc40a","https://trac.ffmpeg.org/ticket/2982","http://www.openwall.com/lists/oss-security/2013/12/08","https://www.cve.org/CVERecord?id=CVE-2013-7023"],"bugs":[""],"patches":{"ffmpeg":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-7022","published":"2013-12-09T16:36:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1\ndoes not properly allocate memory for tiles, which allows remote attackers\nto cause a denial of service (out-of-bounds array access) or possibly have\nunspecified other impact via crafted Go2Webinar data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/FFmpeg/FFmpeg/commit/e07ac727c1cc9eed39e7f9117c97006f719864bd","https://trac.ffmpeg.org/ticket/2971","http://www.openwall.com/lists/oss-security/2013/12/08","https://www.cve.org/CVERecord?id=CVE-2013-7022"],"bugs":[""],"patches":{"ffmpeg":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-7021","published":"2013-12-09T16:36:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe filter_frame function in libavfilter/vf_fps.c in FFmpeg before 2.1 does\nnot properly ensure the availability of FIFO content, which allows remote\nattackers to cause a denial of service (double free) or possibly have\nunspecified other impact via crafted data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/FFmpeg/FFmpeg/commit/cdd5df8189ff1537f7abe8defe971f80602cc2d2","https://trac.ffmpeg.org/ticket/2905","http://www.openwall.com/lists/oss-security/2013/12/08","https://www.cve.org/CVERecord?id=CVE-2013-7021"],"bugs":[""],"patches":{"ffmpeg":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-7020","published":"2013-12-09T16:36:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does\nnot properly enforce certain bit-count and colorspace constraints, which\nallows remote attackers to cause a denial of service (out-of-bounds array\naccess) or possibly have unspecified other impact via crafted FFV1 data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/FFmpeg/FFmpeg/commit/b05cd1ea7e45a836f7f6071a716c38bb30326e0f","http://www.openwall.com/lists/oss-security/2013/12/08","https://www.cve.org/CVERecord?id=CVE-2013-7020"],"bugs":[""],"patches":{"ffmpeg":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-7019","published":"2013-12-09T16:36:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe get_cox function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does\nnot properly validate the reduction factor, which allows remote attackers\nto cause a denial of service (out-of-bounds array access) or possibly have\nunspecified other impact via crafted JPEG2000 data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/FFmpeg/FFmpeg/commit/a1b9004b768bef606ee98d417bceb9392ceb788d","https://trac.ffmpeg.org/ticket/2898","http://www.openwall.com/lists/oss-security/2013/12/08","https://www.cve.org/CVERecord?id=CVE-2013-7019"],"bugs":[""],"patches":{"ffmpeg":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-7018","published":"2013-12-09T16:36:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlibavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not ensure the use of\nvalid code-block dimension values, which allows remote attackers to cause a\ndenial of service (out-of-bounds array access) or possibly have unspecified\nother impact via crafted JPEG2000 data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/FFmpeg/FFmpeg/commit/9a271a9368eaabf99e6c2046103acb33957e63b7","https://trac.ffmpeg.org/ticket/2895","http://www.openwall.com/lists/oss-security/2013/12/08","https://www.cve.org/CVERecord?id=CVE-2013-7018"],"bugs":[""],"patches":{"ffmpeg":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-7017","published":"2013-12-09T16:36:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlibavcodec/jpeg2000.c in FFmpeg before 2.1 allows remote attackers to cause\na denial of service (invalid pointer dereference) or possibly have\nunspecified other impact via crafted JPEG2000 data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/FFmpeg/FFmpeg/commit/912ce9dd2080c5837285a471d750fa311e09b555","http://www.openwall.com/lists/oss-security/2013/12/08","https://www.cve.org/CVERecord?id=CVE-2013-7017"],"bugs":[""],"patches":{"ffmpeg":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-7016","published":"2013-12-09T16:36:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe get_siz function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does\nnot ensure the expected sample separation, which allows remote attackers to\ncause a denial of service (out-of-bounds array access) or possibly have\nunspecified other impact via crafted JPEG2000 data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/FFmpeg/FFmpeg/commit/8bb11c3ca77b52e05a9ed1496a65f8a76e6e2d8f","https://trac.ffmpeg.org/ticket/2848","http://www.openwall.com/lists/oss-security/2013/12/08","https://www.cve.org/CVERecord?id=CVE-2013-7016"],"bugs":[""],"patches":{"ffmpeg":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-7015","published":"2013-12-09T16:36:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe flashsv_decode_frame function in libavcodec/flashsv.c in FFmpeg before\n2.1 does not properly validate a certain height value, which allows remote\nattackers to cause a denial of service (out-of-bounds array access) or\npossibly have unspecified other impact via crafted Flash Screen Video data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/FFmpeg/FFmpeg/commit/880c73cd76109697447fbfbaa8e5ee5683309446","https://trac.ffmpeg.org/ticket/2844","http://www.openwall.com/lists/oss-security/2013/12/08","https://www.cve.org/CVERecord?id=CVE-2013-7015"],"bugs":[""],"patches":{"ffmpeg":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-7014","published":"2013-12-09T16:36:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger signedness error in the add_bytes_l2_c function in\nlibavcodec/pngdsp.c in FFmpeg before 2.1 allows remote attackers to cause a\ndenial of service (out-of-bounds array access) or possibly have unspecified\nother impact via crafted PNG data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/FFmpeg/FFmpeg/commit/86736f59d6a527d8bc807d09b93f971c0fe0bb07","https://trac.ffmpeg.org/ticket/2919","http://www.openwall.com/lists/oss-security/2013/12/08","https://www.cve.org/CVERecord?id=CVE-2013-7014"],"bugs":[""],"patches":{"ffmpeg":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-7013","published":"2013-12-09T16:36:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1\nuses an incorrect ordering of arithmetic operations, which allows remote\nattackers to cause a denial of service (out-of-bounds array access) or\npossibly have unspecified other impact via crafted Go2Webinar data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/FFmpeg/FFmpeg/commit/821a5938d100458f4d09d634041b05c860554ce0","https://trac.ffmpeg.org/ticket/2922","http://www.openwall.com/lists/oss-security/2013/12/08","https://www.cve.org/CVERecord?id=CVE-2013-7013"],"bugs":[""],"patches":{"ffmpeg":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-7012","published":"2013-12-09T16:36:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe get_siz function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does\nnot prevent attempts to use non-zero image offsets, which allows remote\nattackers to cause a denial of service (out-of-bounds array access) or\npossibly have unspecified other impact via crafted JPEG2000 data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/FFmpeg/FFmpeg/commit/780669ef7c23c00836a24921fcc6b03be2b8ca4a","https://trac.ffmpeg.org/ticket/3080","http://www.openwall.com/lists/oss-security/2013/12/08","https://www.cve.org/CVERecord?id=CVE-2013-7012"],"bugs":[""],"patches":{"ffmpeg":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-7011","published":"2013-12-09T16:36:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does\nnot prevent changes to global parameters, which allows remote attackers to\ncause a denial of service (out-of-bounds array access) or possibly have\nunspecified other impact via crafted FFV1 data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/FFmpeg/FFmpeg/commit/547d690d676064069d44703a1917e0dab7e33445","https://trac.ffmpeg.org/ticket/2906","http://www.openwall.com/lists/oss-security/2013/12/08","https://www.cve.org/CVERecord?id=CVE-2013-7011"],"bugs":[""],"patches":{"ffmpeg":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-7010","published":"2013-12-09T16:36:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer signedness errors in libavcodec/dsputil.c in FFmpeg before\n2.1 allow remote attackers to cause a denial of service (out-of-bounds\narray access) or possibly have unspecified other impact via crafted data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/FFmpeg/FFmpeg/commit/454a11a1c9c686c78aa97954306fb63453299760","http://www.openwall.com/lists/oss-security/2013/12/08","https://www.cve.org/CVERecord?id=CVE-2013-7010"],"bugs":[""],"patches":{"ffmpeg":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-7009","published":"2013-12-09T16:36:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe rpza_decode_stream function in libavcodec/rpza.c in FFmpeg before 2.1\ndoes not properly maintain a pointer to pixel data, which allows remote\nattackers to cause a denial of service (out-of-bounds array access) or\npossibly have unspecified other impact via crafted Apple RPZA data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/FFmpeg/FFmpeg/commit/3819db745da2ac7fb3faacb116788c32f4753f34","https://trac.ffmpeg.org/ticket/2850","http://www.openwall.com/lists/oss-security/2013/12/08","https://www.cve.org/CVERecord?id=CVE-2013-7009"],"bugs":[""],"patches":{"ffmpeg":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":66480,"limit":20,"total_results":79316}