{"cves":[{"id":"CVE-2013-4758","published":"2013-10-04T17:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDouble free vulnerability in the writeDataError function in the\nElasticSearch plugin (omelasticsearch) in rsyslog before 7.4.2 and before\n7.5.2 devel, when errorfile is set to local logging, allows remote\nattackers to cause a denial of service (crash) and possibly execute\narbitrary code via a crafted JSON response.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"our versions don't contain the affected plugin"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-4758"],"bugs":["http://bugzilla.adiscon.com/show_bug.cgi?id=461"],"patches":{"rsyslog":["upstream: http://git.adiscon.com/?p=rsyslog.git;a=commitdiff;h=80f88242982c9c6ad6ce8628fc5b94ea74051cf4"]},"tags":{},"packages":[{"name":"rsyslog","source":"https://ubuntu.com/security/cve?package=rsyslog","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rsyslog","debian":"https://tracker.debian.org/pkg/rsyslog","statuses":[{"release_codename":"lucid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4249","published":"2013-10-04T17:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget\nin contrib/admin/widgets.py in Django 1.5.x before 1.5.2 and 1.6.x before\n1.6 beta 2 allows remote attackers to inject arbitrary web script or HTML\nvia a URLField.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"only affected 1.5.x+"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.djangoproject.com/weblog/2013/aug/13/security-releases-issued/","https://www.cve.org/CVERecord?id=CVE-2013-4249"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/python-django/+bug/1212058"],"patches":{"python-django":["upstream: https://github.com/django/django/commit/ec67af0bd609c412b76eaa4cc89968a2a8e5ad6a"]},"tags":{},"packages":[{"name":"python-django","source":"https://ubuntu.com/security/cve?package=python-django","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-django","debian":"https://tracker.debian.org/pkg/python-django","statuses":[{"release_codename":"lucid","status":"not-affected","description":"1.1.1-2ubuntu1.8","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.3.1-4ubuntu1.7","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.4.1-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.4.5-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2223","published":"2013-10-04T17:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGNU ZRTPCPP before 3.2.0 allows remote attackers to obtain sensitive\ninformation (uninitialized heap memory) or cause a denial of service\n(out-of-bounds read) via a crafted packet, as demonstrated by a truncated\nPing packet that is not properly handled by the getEpHash function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://blog.azimuthsecurity.com/2013/06/attacking-crypto-phones-weaknesses-in.html","https://www.cve.org/CVERecord?id=CVE-2013-2223"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=714650"],"patches":{"libzrtpcpp":["upstream: https://github.com/wernerd/ZRTPCPP/commit/c8617100f359b217a974938c5539a1dd8a120b0e"]},"tags":{},"packages":[{"name":"libzrtpcpp","source":"https://ubuntu.com/security/cve?package=libzrtpcpp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libzrtpcpp","debian":"https://tracker.debian.org/pkg/libzrtpcpp","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.3.4-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.3.4-1.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.3.4-1.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2222","published":"2013-10-04T17:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple stack-based buffer overflows in GNU ZRTPCPP before 3.2.0 allow\nremote attackers to cause a denial of service (crash) and possibly execute\narbitrary code via a crafted ZRTP Hello packet to the (1)\nZRtp::findBestSASType, (2) ZRtp::findBestAuthLen, (3) ZRtp::findBestCipher,\n(4) ZRtp::findBestHash, or (5) ZRtp::findBestPubKey functions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://blog.azimuthsecurity.com/2013/06/attacking-crypto-phones-weaknesses-in.html","https://www.cve.org/CVERecord?id=CVE-2013-2222"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=714650"],"patches":{"libzrtpcpp":["upstream: https://github.com/wernerd/ZRTPCPP/commit/c8617100f359b217a974938c5539a1dd8a120b0e"]},"tags":{},"packages":[{"name":"libzrtpcpp","source":"https://ubuntu.com/security/cve?package=libzrtpcpp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libzrtpcpp","debian":"https://tracker.debian.org/pkg/libzrtpcpp","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.3.4-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.3.4-1.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.3.4-1.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2221","published":"2013-10-04T17:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in the ZRtp::storeMsgTemp function in GNU\nZRTPCPP before 3.2.0 allows remote attackers to cause a denial of service\n(crash) and possibly execute arbitrary code via a large packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://blog.azimuthsecurity.com/2013/06/attacking-crypto-phones-weaknesses-in.html","https://www.cve.org/CVERecord?id=CVE-2013-2221"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=714650"],"patches":{"libzrtpcpp":["upstream: https://github.com/wernerd/ZRTPCPP/commit/c8617100f359b217a974938c5539a1dd8a120b0e"]},"tags":{},"packages":[{"name":"libzrtpcpp","source":"https://ubuntu.com/security/cve?package=libzrtpcpp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libzrtpcpp","debian":"https://tracker.debian.org/pkg/libzrtpcpp","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.3.4-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.3.4-1.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.3.4-1.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4344","published":"2013-10-04T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the SCSI implementation in QEMU, as used in Xen, when a\nSCSI controller has more than 256 attached devices, allows local users to\ngain privileges via a small transfer buffer in a REPORT LUNS command.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"needs the admin to configure more than 256 scsi devices,\ndowngrading to low"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/10/02/2","http://thread.gmane.org/gmane.comp.emulators.qemu/237161","http://osvdb.org/98028","https://ubuntu.com/security/notices/USN-2092-1","https://www.cve.org/CVERecord?id=CVE-2013-4344"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725944"],"patches":{"qemu-kvm":["upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=846424350b292f16b732b573273a5c1f195cd7a3"],"qemu":["upstream: http://article.gmane.org/gmane.comp.emulators.qemu/237163","upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=846424350b292f16b732b573273a5c1f195cd7a3"],"xen-3.3":[],"xen":[]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1.5.0+dfsg-3ubuntu5.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"lucid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.0+noroms-0ubuntu14.13","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1.2.0+noroms-0ubuntu2.12.10.6","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xen-3.3","source":"https://ubuntu.com/security/cve?package=xen-3.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen-3.3","debian":"https://tracker.debian.org/pkg/xen-3.3","statuses":[{"release_codename":"lucid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2092-1"],"notices":[{"id":"USN-2092-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2014-01-30T20:28:15.691082","description":"Asias He discovered that QEMU incorrectly handled SCSI controllers with\nmore than 256 attached devices. A local user could possibly use this flaw\nto elevate privileges. (CVE-2013-4344)\n\nIt was discovered that QEMU incorrectly handled Xen disks. A local guest\ncould possibly use this flaw to consume resources, resulting in a denial of\nservice. This issue only affected Ubuntu 12.10 and Ubuntu 13.10.\n(CVE-2013-4375)\n\nSibiao Luo discovered that QEMU incorrectly handled device hot-unplugging.\nA local user could possibly use this flaw to cause a denial of service.\nThis issue only affected Ubuntu 13.10. (CVE-2013-4377)\n","is_hidden":false,"release_packages":{"precise":[{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.13","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/1.0+noroms-0ubuntu14.13"}],"saucy":[{"name":"qemu","version":"1.5.0+dfsg-3ubuntu5.3","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system-misc","version":"1.5.0+dfsg-3ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1.5.0+dfsg-3ubuntu5.3"},{"name":"qemu-system","version":"1.5.0+dfsg-3ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1.5.0+dfsg-3ubuntu5.3"},{"name":"qemu-system-x86","version":"1.5.0+dfsg-3ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1.5.0+dfsg-3ubuntu5.3"},{"name":"qemu-system-sparc","version":"1.5.0+dfsg-3ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1.5.0+dfsg-3ubuntu5.3"},{"name":"qemu-system-arm","version":"1.5.0+dfsg-3ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1.5.0+dfsg-3ubuntu5.3"},{"name":"qemu-system-ppc","version":"1.5.0+dfsg-3ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1.5.0+dfsg-3ubuntu5.3"},{"name":"qemu-system-mips","version":"1.5.0+dfsg-3ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1.5.0+dfsg-3ubuntu5.3"}],"quantal":[{"name":"qemu-kvm","version":"1.2.0+noroms-0ubuntu2.12.10.6","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"1.2.0+noroms-0ubuntu2.12.10.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/1.2.0+noroms-0ubuntu2.12.10.6"}]},"type":"USN","cves_ids":["CVE-2013-4344","CVE-2013-4375","CVE-2013-4377"]}]},{"id":"CVE-2013-4324","published":"2013-10-03T21:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nspice-gtk 0.14, and possibly other versions, invokes the polkit authority\nusing the insecure polkit_unix_process_new API function, which allows local\nusers to bypass intended access restrictions by leveraging a\nPolkitUnixProcess PolkitSubject race condition via a (1) setuid process or\n(2) pkexec process, a related issue to CVE-2013-4288.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-4324"],"bugs":[""],"patches":{"spice-gtk":[]},"tags":{},"packages":[{"name":"spice-gtk","source":"https://ubuntu.com/security/cve?package=spice-gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=spice-gtk","debian":"https://tracker.debian.org/pkg/spice-gtk","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"0.22-0nocent2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"0.22-0nocent2","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"0.22-0nocent2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"0.22-0nocent2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"0.22-0nocent2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"0.22-0nocent2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [0.22-0nocent2]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2923","published":"2013-10-02T10:35:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in Google Chrome before 30.0.1599.66\nallow attackers to cause a denial of service or possibly have other impact\nvia unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.google.com/p/chromium/issues/detail?id=299016","https://code.google.com/p/chromium/issues/detail?id=294206","https://code.google.com/p/chromium/issues/detail?id=294202","https://code.google.com/p/chromium/issues/detail?id=294023","https://code.google.com/p/chromium/issues/detail?id=293521","https://code.google.com/p/chromium/issues/detail?id=289648","https://code.google.com/p/chromium/issues/detail?id=288771","https://code.google.com/p/chromium/issues/detail?id=288761","https://code.google.com/p/chromium/issues/detail?id=285380","https://code.google.com/p/chromium/issues/detail?id=284792","https://code.google.com/p/chromium/issues/detail?id=279286","https://code.google.com/p/chromium/issues/detail?id=278366","https://code.google.com/p/chromium/issues/detail?id=277656","https://code.google.com/p/chromium/issues/detail?id=276111","https://code.google.com/p/chromium/issues/detail?id=274020","https://code.google.com/p/chromium/issues/detail?id=269835","https://code.google.com/p/chromium/issues/detail?id=267068","https://code.google.com/p/chromium/issues/detail?id=266593","https://code.google.com/p/chromium/issues/detail?id=265731","https://code.google.com/p/chromium/issues/detail?id=265493","https://code.google.com/p/chromium/issues/detail?id=264211","https://code.google.com/p/chromium/issues/detail?id=260138","https://code.google.com/p/chromium/issues/detail?id=257852","https://code.google.com/p/chromium/issues/detail?id=254728","https://code.google.com/p/chromium/issues/detail?id=246724","https://code.google.com/p/chromium/issues/detail?id=237800","http://googlechromereleases.blogspot.com/2013/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-2923"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"30.0.1599.114-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"30.0.1599.114-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"30.0.1599.114-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"30.0.1599.114-0ubuntu0.13.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"30.0.1599.66","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2922","published":"2013-10-02T10:35:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in core/html/HTMLTemplateElement.cpp in Blink,\nas used in Google Chrome before 30.0.1599.66, allows remote attackers to\ncause a denial of service or possibly have unspecified other impact via\ncrafted JavaScript code that operates on a TEMPLATE element.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=157543&view=revision","https://code.google.com/p/chromium/issues/detail?id=286975","http://googlechromereleases.blogspot.com/2013/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-2922"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"30.0.1599.114-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"30.0.1599.114-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"30.0.1599.114-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"30.0.1599.114-0ubuntu0.13.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"30.0.1599.66","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2921","published":"2013-10-02T10:35:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDouble free vulnerability in the ResourceFetcher::didLoadResource function\nin core/fetch/ResourceFetcher.cpp in the resource loader in Blink, as used\nin Google Chrome before 30.0.1599.66, allows remote attackers to cause a\ndenial of service or possibly have unspecified other impact by triggering\ncertain callback processing during the reporting of a resource entry.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=157760&view=revision","https://code.google.com/p/chromium/issues/detail?id=286414","http://googlechromereleases.blogspot.com/2013/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-2921"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"30.0.1599.114-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"30.0.1599.114-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"30.0.1599.114-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"30.0.1599.114-0ubuntu0.13.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"30.0.1599.66","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2920","published":"2013-10-02T10:35:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe DoResolveRelativeHost function in url/url_canon_relative.cc in Google\nChrome before 30.0.1599.66 allows remote attackers to cause a denial of\nservice (out-of-bounds read) via a relative URL containing a hostname, as\ndemonstrated by a protocol-relative URL beginning with a //www.google.com/\nsubstring.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/chrome?revision=223735&view=revision","https://code.google.com/p/chromium/issues/detail?id=285742","http://googlechromereleases.blogspot.com/2013/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-2920"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"30.0.1599.114-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"30.0.1599.114-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"30.0.1599.114-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"30.0.1599.114-0ubuntu0.13.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"30.0.1599.66","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2919","published":"2013-10-02T10:35:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle V8, as used in Google Chrome before 30.0.1599.66, allows remote\nattackers to cause a denial of service (memory corruption) or possibly have\nunspecified other impact via unknown vectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qtjsbackend-opensource-src contains an embedded libv8, however\napplications using qtjsbackend-opensource-src should not process untrusted\njavascript and therefore Ubuntu will not process updates for libv8 in this\npackage. (See LP: #1157732 for details)"},{"author":"mikesalvatore","note":"The Ubuntu Security Team does not support libv8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.google.com/p/chromium/issues/detail?id=282736","http://googlechromereleases.blogspot.com/2013/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-2919"],"bugs":[""],"patches":{"chromium-browser":[],"libv8":[],"libv8-3.14":[],"qtjsbackend-opensource-src":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"artful","status":"not-affected","description":"31.0.1650.63-0ubuntu1~20131204.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"31.0.1650.63-0ubuntu1~20131204.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"31.0.1650.63-0ubuntu1~20131204.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"30.0.1599.114-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"30.0.1599.114-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"30.0.1599.114-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"30.0.1599.114-0ubuntu0.13.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"30.0.1599.66","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"31.0.1650.63-0ubuntu1~20131204.1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"31.0.1650.63-0ubuntu1~20131204.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"31.0.1650.63-0ubuntu1~20131204.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"31.0.1650.63-0ubuntu1~20131204.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"31.0.1650.63-0ubuntu1~20131204.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"31.0.1650.63-0ubuntu1~20131204.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [31.0.1650.63-0ubuntu1~20131204.1]","component":null,"pocket":"security"}]},{"name":"libv8","source":"https://ubuntu.com/security/cve?package=libv8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libv8","debian":"https://tracker.debian.org/pkg/libv8","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"libv8-3.14","source":"https://ubuntu.com/security/cve?package=libv8-3.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libv8-3.14","debian":"https://tracker.debian.org/pkg/libv8-3.14","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [libv8 not supported]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtjsbackend-opensource-src","source":"https://ubuntu.com/security/cve?package=qtjsbackend-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtjsbackend-opensource-src","debian":"https://tracker.debian.org/pkg/qtjsbackend-opensource-src","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2918","published":"2013-10-02T10:35:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the\nRenderBlock::collapseAnonymousBlockChild function in\ncore/rendering/RenderBlock.cpp in the DOM implementation in Blink, as used\nin Google Chrome before 30.0.1599.66, allows remote attackers to cause a\ndenial of service or possibly have unspecified other impact by leveraging\nincorrect handling of parent-child relationships for anonymous blocks.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=157392&view=revision","https://code.google.com/p/chromium/issues/detail?id=282088","http://googlechromereleases.blogspot.com/2013/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-2918"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"30.0.1599.114-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"30.0.1599.114-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"30.0.1599.114-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"30.0.1599.114-0ubuntu0.13.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"30.0.1599.66","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2917","published":"2013-10-02T10:35:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ReverbConvolverStage::ReverbConvolverStage function in\ncore/platform/audio/ReverbConvolverStage.cpp in the Web Audio\nimplementation in Blink, as used in Google Chrome before 30.0.1599.66,\nallows remote attackers to cause a denial of service (out-of-bounds read)\nvia vectors related to the impulseResponse array.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=157007&view=revision","https://code.google.com/p/chromium/issues/detail?id=281480","http://googlechromereleases.blogspot.com/2013/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-2917"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"30.0.1599.114-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"30.0.1599.114-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"30.0.1599.114-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"30.0.1599.114-0ubuntu0.13.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"30.0.1599.66","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2916","published":"2013-10-02T10:35:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBlink, as used in Google Chrome before 30.0.1599.66, allows remote\nattackers to spoof the address bar via vectors involving a response with a\n204 (aka No Content) status code, in conjunction with a delay in notifying\nthe user of an attempted spoof.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=157196&view=revision","https://code.google.com/p/chromium/issues/detail?id=281256","http://googlechromereleases.blogspot.com/2013/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-2916"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"30.0.1599.114-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"30.0.1599.114-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"30.0.1599.114-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"30.0.1599.114-0ubuntu0.13.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"30.0.1599.66","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2915","published":"2013-10-02T10:35:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 30.0.1599.66 preserves pending NavigationEntry objects\nin certain invalid circumstances, which allows remote attackers to spoof\nthe address bar via a URL with a malformed scheme, as demonstrated by a\nnonexistent:12121 URL.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/chrome?revision=222146&view=revision","https://code.google.com/p/chromium/issues/detail?id=280512","http://googlechromereleases.blogspot.com/2013/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-2915"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"30.0.1599.114-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"30.0.1599.114-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"30.0.1599.114-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"30.0.1599.114-0ubuntu0.13.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"30.0.1599.66","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2914","published":"2013-10-02T10:35:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the color-chooser dialog in Google Chrome\nbefore 30.0.1599.66 on Windows allows remote attackers to cause a denial of\nservice or possibly have unspecified other impact via vectors related to\ncolor_chooser_dialog.cc and color_chooser_win.cc in browser/ui/views/.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/chrome?revision=220639&view=revision","https://code.google.com/p/chromium/issues/detail?id=279263","http://googlechromereleases.blogspot.com/2013/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-2914"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"30.0.1599.114-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"30.0.1599.114-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"30.0.1599.114-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"30.0.1599.114-0ubuntu0.13.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"30.0.1599.66","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2913","published":"2013-10-02T10:35:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the XMLDocumentParser::append function in\ncore/xml/parser/XMLDocumentParser.cpp in Blink, as used in Google Chrome\nbefore 30.0.1599.66, allows remote attackers to cause a denial of service\nor possibly have unspecified other impact via vectors involving an XML\ndocument.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=157914&view=revision","https://code.google.com/p/chromium/issues/detail?id=278908","http://googlechromereleases.blogspot.com/2013/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-2913"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"30.0.1599.114-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"30.0.1599.114-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"30.0.1599.114-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"30.0.1599.114-0ubuntu0.13.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"30.0.1599.66","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2912","published":"2013-10-02T10:35:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the PepperInProcessRouter::SendToHost\nfunction in content/renderer/pepper/pepper_in_process_router.cc in the\nPepper Plug-in API (PPAPI) in Google Chrome before 30.0.1599.66 allows\nremote attackers to cause a denial of service or possibly have unspecified\nother impact via vectors involving a resource-destruction message.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/chrome?revision=222614&view=revision","https://code.google.com/p/chromium/issues/detail?id=276368","http://googlechromereleases.blogspot.com/2013/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-2912"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"30.0.1599.114-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"30.0.1599.114-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"30.0.1599.114-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"30.0.1599.114-0ubuntu0.13.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"30.0.1599.66","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2911","published":"2013-10-02T10:35:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the XSLStyleSheet::compileStyleSheet\nfunction in core/xml/XSLStyleSheetLibxslt.cpp in Blink, as used in Google\nChrome before 30.0.1599.66, allows remote attackers to cause a denial of\nservice or possibly have unspecified other impact by leveraging improper\nhandling of post-failure recompilation in unspecified libxslt versions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=156248&view=revision","https://code.google.com/p/chromium/issues/detail?id=271939","http://googlechromereleases.blogspot.com/2013/10/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-2911"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"30.0.1599.114-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"30.0.1599.114-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"30.0.1599.114-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"30.0.1599.114-0ubuntu0.13.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"30.0.1599.66","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":66880,"limit":20,"total_results":79316}