{"cves":[{"id":"CVE-2010-2231","published":"2010-06-28T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in\nreport/overview/report.php in the quiz module in Moodle before 1.8.13 and\n1.9.x before 1.9.9 allows remote attackers to hijack the authentication of\narbitrary users for requests that delete quiz attempts via the attemptid\nparameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2231"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=605809","http://tracker.moodle.org/browse/MDL-21688","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=586280"],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.9","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2230","published":"2010-06-28T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and\n1.9.x before 1.9.9 does not properly handle vbscript URIs, which allows\nremote authenticated users to conduct cross-site scripting (XSS) attacks\nvia HTML input.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2230"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=605809","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=586280","http://tracker.moodle.org/browse/MDL-22042"],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.9","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2229","published":"2010-06-28T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in blog/index.php in\nMoodle before 1.8.13 and 1.9.x before 1.9.9 allow remote attackers to\ninject arbitrary web script or HTML via unspecified parameters.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2229"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=605809","http://tracker.moodle.org/browse/MDL-22631","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=586280"],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.9","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2228","published":"2010-06-28T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the MNET access-control\ninterface in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote\nattackers to inject arbitrary web script or HTML via vectors involving\nextended characters in a username.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2228"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=605809","http://tracker.moodle.org/browse/MDL-22040","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=586280"],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.9","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1204","published":"2010-06-28T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSearch.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1\nthrough 3.6, and 3.7 allows remote attackers to obtain potentially\nsensitive time-tracking information via a crafted search URL, related to a\n\"boolean chart search.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.bugzilla.org/security/3.2.6/","http://www.vupen.com/english/advisories/2010/1595","https://www.cve.org/CVERecord?id=CVE-2010-1204"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=309952","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=587663"],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.4.7.0-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.4.7.0-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.4.7.0-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.7, 3.4.7, 3.6.1, 3.7.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0180","published":"2010-06-28T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInstall/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when\nuse_suexec is enabled, uses world-readable permissions for the localconfig\nfiles, which allows local users to read sensitive configuration fields, as\ndemonstrated by the database password field and the site_wide_secret field.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"only affects 3.5+"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0180"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=561797"],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"not-affected","description":"2.20-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"2.22.1-2.2ubuntu1.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"3.2.0.1-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3.2.4.0-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.2.5.1-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2454","published":"2010-06-25T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nApple Safari does not properly manage the address bar between the request\nto open a URL and the retrieval of the new document's content, which might\nallow remote attackers to conduct spoofing attacks via a crafted HTML\ndocument, a related issue to CVE-2010-1206.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit is a fork of khtml from kdelibs. kdelibs5 is farther from\nit, while qt4-x11 attempts to unify khtml and webkit."},{"author":"mdeslaur","note":"webkitkde is a wrapper around qt4-x11's webkit.\nsafari-specific"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lcamtuf.blogspot.com/2010/06/yeah-about-that-address-bar-thing.html","https://www.cve.org/CVERecord?id=CVE-2010-2454"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=556957"],"patches":{"webkit":[],"qt4-x11":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2444","published":"2010-06-25T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nparse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03,\ndoes not properly handle hostnames that do not end in a \".\" (dot)\ncharacter, which allows remote attackers to cause a denial of service (NULL\npointer dereference) via a crafted csv2 zone file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2444"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=584587"],"patches":{"maradns":["upstream: http://maradns.org/download/maradns-1.4.02-parse_segfault.patch"]},"tags":{},"packages":[{"name":"maradns","source":"https://ubuntu.com/security/cve?package=maradns","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=maradns","debian":"https://tracker.debian.org/pkg/maradns","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.4.03-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.4.03-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.4.03-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.4.03-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.4.03-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.4.03-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.03","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1206","published":"2010-06-25T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe startDocumentLoad function in browser/base/content/browser.js in\nMozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey\nbefore 2.0.6, does not properly implement the Same Origin Policy in certain\ncircumstances related to the about:blank document and a document that is\ncurrently loading, which allows (1) remote web servers to conduct spoofing\nattacks via vectors involving a 204 (aka No Content) status code, and\nallows (2) remote attackers to conduct spoofing attacks via vectors\ninvolving a window.stop call.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"CVEs in Firefox are tracked in the xulrunner source packages for\nbuilds that use the system xulrunner, and firefox source packages for those\nthat use a static build\nxulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS (system xul)\nxulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS (system xul)\nxulrunner-1.9: (ignored) reverse dependencies no longer process web content\nxulrunner-1.9.1: (ignored) reverese dependencies no longer process web content\nxulrunner-1.9.2: system xul for reverese dependencies that process web content\nfirefox: Ubuntu 6.06 LTS (static build)\nfirefox: Ubuntu 10.04 LTS and higher (static build of 3.6.x or higher)\nfirefox-3.0: Ubuntu 8.04 LTS, 9.04 (static build of 3.6.x)\nfirefox-3.5: Ubuntu 9.04 (ignored, uses system xul 1.9.1. Use 3.0 instead)\nfirefox-3.5: Ubuntu 9.10 (static build of 3.6.x)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-930-4","https://ubuntu.com/security/notices/USN-957-1","https://www.cve.org/CVERecord?id=CVE-2010-1206"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=556957"],"patches":{"firefox":[],"firefox-3.0":[],"firefox-3.5":[],"xulrunner-1.9.2":[],"seamonkey":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"Ubuntu source uses 3.6.x","component":null,"pocket":"security"}]},{"name":"firefox-3.5","source":"https://ubuntu.com/security/cve?package=firefox-3.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-3.5","debian":"https://tracker.debian.org/pkg/firefox-3.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"Ubuntu source uses 3.6.x","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.6","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.8.04.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-957-1","USN-930-4"],"notices":[{"id":"USN-957-1","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to run programs as your login if it opened a\nspecially crafted file or website.\n","instructions":"After a standard system update you need to restart Firefox to make all the\nnecessary changes.\n","references":[],"published":"2010-07-23T08:48:53.861034","description":"Several flaws were discovered in the browser engine of Firefox. If a user\nwere tricked into viewing a malicious site, a remote attacker could use\nthis to crash the browser or possibly run arbitrary code as the user\ninvoking the program. (CVE-2010-1208, CVE-2010-1209, CVE-2010-1211,\nCVE-2010-1212)\n\nAn integer overflow was discovered in how Firefox processed plugin\nparameters. An attacker could exploit this to crash the browser or possibly\nrun arbitrary code as the user invoking the program. (CVE-2010-1214)\n\nA flaw was discovered in the Firefox JavaScript engine. If a user were\ntricked into viewing a malicious site, a remote attacker code execute\narbitrary JavaScript with chrome privileges. (CVE-2010-1215)\n\nAn integer overflow was discovered in how Firefox processed CSS values. An\nattacker could exploit this to crash the browser or possibly run arbitrary\ncode as the user invoking the program. (CVE-2010-2752)\n\nAn integer overflow was discovered in how Firefox interpreted the XUL\n element. If a user were tricked into viewing a malicious site, a\nremote attacker could use this to crash the browser or possibly run\narbitrary code as the user invoking the program. (CVE-2010-2753)\n\nAki Helin discovered that libpng did not properly handle certain malformed\nPNG images. If a user were tricked into opening a crafted PNG file, an\nattacker could cause a denial of service or possibly execute arbitrary code\nwith the privileges of the user invoking the program. (CVE-2010-1205)\n\nYosuke Hasegawa and Vladimir Vukicevic discovered that the same-origin\ncheck in Firefox could be bypassed by utilizing the importScripts Web\nWorker method. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-1213, CVE-2010-1207)\n\nO. Andersen that Firefox did not properly map undefined positions within\ncertain 8 bit encodings. An attacker could utilize this to perform\ncross-site scripting attacks. (CVE-2010-1210)\n\nMichal Zalewski discovered flaws in how Firefox processed the HTTP 204 (no\ncontent) code. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-1206)\n\nJordi Chancel discovered that Firefox did not properly handle when a server\nresponds to an HTTPS request with plaintext and then processes JavaScript\nhistory events. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-2751)\n\nChris Evans discovered that Firefox did not properly process improper CSS\nselectors. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-0654)\n\nSoroush Dalili discovered that Firefox did not properly handle script error\noutput. An attacker could use this to access URL parameters from other\ndomains. (CVE-2010-2754)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.8.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.8.04.2","description":"XUL + XPCOM application runner","is_source":true},{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.7+build2+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.8.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.8.04.2"}],"lucid":[{"name":"firefox","version":"3.6.7+build2+nobinonly-0ubuntu0.10.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.10.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.7+build2+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.7+build2+nobinonly-0ubuntu0.10.04.1"},{"name":"firefox","version":"3.6.7+build2+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.7+build2+nobinonly-0ubuntu0.10.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2010-1208","CVE-2010-1209","CVE-2010-1211","CVE-2010-1212","CVE-2010-1214","CVE-2010-1215","CVE-2010-2752","CVE-2010-2753","CVE-2010-1205","CVE-2010-1213","CVE-2010-1207","CVE-2010-1210","CVE-2010-1206","CVE-2010-2751","CVE-2010-0654","CVE-2010-2754"]},{"id":"USN-930-4","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to run programs as your login if it opened a\nspecially crafted file or website.\n","instructions":"Mozilla has changed the support model for Firefox and they no longer\nsupport version 3.0 of the browser and will only support version 3.5 of the\nbrowser for a while longer. As a result, Ubuntu is providing an upgrade to\nFirefox 3.6 for Ubuntu 9.04 and 9.10 users, which is the most current\nstable release of Firefox supported by Mozilla. When upgrading, users\nshould be aware of the following:\n\n- Firefox 3.6 does not support version 5 of the Sun Java plugin. Please use\n icedtea6-plugin or sun-java6-plugin instead.\n- After upgrading to Firefox 3.6.6, users may be prompted to upgrade 3rd\n party Add-Ons. In some cases, an Add-On will not be compatible with\n Firefox 3.6.6 and have no update available. In these cases, Firefox will\n notify the user that it is disabling the Add-On.\n- Font configuration cannot be controlled via Gnome settings. This is a\n known issue being tracked in https://launchpad.net/bugs/559149 and will\n be fixed in a later update.\n- helix-player is not currently supported in Firefox 3.6. This is a known\n issue and may be fixed in a future update.\n- Plugins using external helpers (such as Totem) may not close when using\n the Epiphany browser. This is a known issue being tracked in\n https://launchpad.net/bugs/599796 and will be fixed in a later update.\n This issue only affects Ubuntu 9.04.\n- The OpenJDK java plugin is not available in Ubuntu 9.04 on Sparc\n hardware. This will be fixed in a future update.\n\nAfter a standard system upgrade you need to restart Firefox and any\napplications that use Xulrunner to effect the necessary changes.\n","references":[],"published":"2010-07-23T09:48:19.360663","description":"USN-930-1 fixed vulnerabilities in Firefox and Xulrunner. This update\nprovides the corresponding updates for Ubuntu 9.04 and 9.10, along with\nadditional updates affecting Firefox 3.6.6.\n\nSeveral flaws were discovered in the browser engine of Firefox. If a user\nwere tricked into viewing a malicious site, a remote attacker could use\nthis to crash the browser or possibly run arbitrary code as the user\ninvoking the program. (CVE-2010-1208, CVE-2010-1209, CVE-2010-1211,\nCVE-2010-1212)\n\nAn integer overflow was discovered in how Firefox processed plugin\nparameters. An attacker could exploit this to crash the browser or possibly\nrun arbitrary code as the user invoking the program. (CVE-2010-1214)\n\nA flaw was discovered in the Firefox JavaScript engine. If a user were\ntricked into viewing a malicious site, a remote attacker code execute\narbitrary JavaScript with chrome privileges. (CVE-2010-1215)\n\nAn integer overflow was discovered in how Firefox processed CSS values. An\nattacker could exploit this to crash the browser or possibly run arbitrary\ncode as the user invoking the program. (CVE-2010-2752)\n\nAn integer overflow was discovered in how Firefox interpreted the XUL\n element. If a user were tricked into viewing a malicious site, a\nremote attacker could use this to crash the browser or possibly run\narbitrary code as the user invoking the program. (CVE-2010-2753)\n\nAki Helin discovered that libpng did not properly handle certain malformed\nPNG images. If a user were tricked into opening a crafted PNG file, an\nattacker could cause a denial of service or possibly execute arbitrary code\nwith the privileges of the user invoking the program. (CVE-2010-1205)\n\nYosuke Hasegawa and Vladimir Vukicevic discovered that the same-origin\ncheck in Firefox could be bypassed by utilizing the importScripts Web\nWorker method. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-1213, CVE-2010-1207)\n\nO. Andersen that Firefox did not properly map undefined positions within\ncertain 8 bit encodings. An attacker could utilize this to perform\ncross-site scripting attacks. (CVE-2010-1210)\n\nMichal Zalewski discovered flaws in how Firefox processed the HTTP 204 (no\ncontent) code. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-1206)\n\nJordi Chancel discovered that Firefox did not properly handle when a server\nresponds to an HTTPS request with plaintext and then processes JavaScript\nhistory events. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-2751)\n\nChris Evans discovered that Firefox did not properly process improper CSS\nselectors. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-0654)\n\nSoroush Dalili discovered that Firefox did not properly handle script error\noutput. An attacker could use this to access URL parameters from other\ndomains. (CVE-2010-2754)\n\nOriginal advisory details:\n\n If was discovered that Firefox could be made to access freed memory. If a\n user were tricked into viewing a malicious site, a remote attacker could\n cause a denial of service or possibly execute arbitrary code with the\n privileges of the user invoking the program. (CVE-2010-1121)\n \n Several flaws were discovered in the browser engine of Firefox. If a\n user were tricked into viewing a malicious site, a remote attacker could\n cause a denial of service or possibly execute arbitrary code with the\n privileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\n CVE-2010-1202, CVE-2010-1203)\n \n A flaw was discovered in the way plugin instances interacted. An attacker\n could potentially exploit this and use one plugin to access freed memory from a\n second plugin to execute arbitrary code with the privileges of the user\n invoking the program. (CVE-2010-1198)\n \n An integer overflow was discovered in Firefox. If a user were tricked into\n viewing a malicious site, an attacker could overflow a buffer and cause a\n denial of service or possibly execute arbitrary code with the privileges of\n the user invoking the program. (CVE-2010-1196)\n \n Martin Barbella discovered an integer overflow in an XSLT node sorting\n routine. An attacker could exploit this to overflow a buffer and cause a\n denial of service or possibly execute arbitrary code with the privileges of\n the user invoking the program. (CVE-2010-1199)\n \n Michal Zalewski discovered that the focus behavior of Firefox could be\n subverted. If a user were tricked into viewing a malicious site, a remote\n attacker could use this to capture keystrokes. (CVE-2010-1125)\n \n Ilja van Sprundel discovered that the 'Content-Disposition: attachment'\n HTTP header was ignored when 'Content-Type: multipart' was also present.\n Under certain circumstances, this could potentially lead to cross-site\n scripting attacks. (CVE-2010-1197)\n \n Amit Klein discovered that Firefox did not seed its random number generator\n often enough. An attacker could exploit this to identify and track users\n across different web sites. (CVE-2008-5913)\n","is_hidden":false,"release_packages":{"jaunty":[{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.7+build2+nobinonly-0ubuntu0.9.04.1"},{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.7+build2+nobinonly-0ubuntu0.9.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2"}],"karmic":[{"name":"firefox-3.5","version":"3.6.7+build2+nobinonly-0ubuntu0.9.10.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","description":"empty transitional upgrade package for xulrunner-1.9","is_source":true},{"name":"firefox-3.5","version":"3.6.7+build2+nobinonly-0ubuntu0.9.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.6.7+build2+nobinonly-0ubuntu0.9.10.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2"}]},"type":"USN","cves_ids":["CVE-2008-5913","CVE-2010-1121","CVE-2010-1125","CVE-2010-1196","CVE-2010-1197","CVE-2010-1198","CVE-2010-1199","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1208","CVE-2010-1209","CVE-2010-1211","CVE-2010-1212","CVE-2010-1214","CVE-2010-1215","CVE-2010-2752","CVE-2010-2753","CVE-2010-1205","CVE-2010-1213","CVE-2010-1207","CVE-2010-1210","CVE-2010-1206","CVE-2010-2751","CVE-2010-0654","CVE-2010-2754"]}]},{"id":"CVE-2010-2443","published":"2010-06-24T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe OJPEGReadBufferFill function in tif_ojpeg.c in LibTIFF before 3.9.3\nallows remote attackers to cause a denial of service (NULL pointer\ndereference and application crash) via an OJPEG image with undefined strip\noffsets, related to the TIFFVGetField function.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"lucid was fixed in same patch as CVE-2010-2065"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://marc.info/?l=oss-security&m=127731610612908&w=2","https://www.cve.org/CVERecord?id=CVE-2010-2443"],"bugs":["https://bugs.launchpad.net/ubuntu/lucid/+source/tiff/+bug/589145","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2443"],"patches":{"tiff":[]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"dapper","status":"not-affected","description":"3.7.4-1ubuntu3.8","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"3.8.2-7ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3.8.2-13ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.9.2-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.9.4-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.9.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2441","published":"2010-06-24T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit does not properly restrict focus changes, which allows remote\nattackers to read keystrokes via \"cross-domain IFRAME gadgets,\" a different\nvulnerability than CVE-2010-1126, CVE-2010-1422, and CVE-2010-2295.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)\nwebkit is a fork of khtml from kdelibs. kdelibs5 is farther from\nit, while qt4-x11 attempts to unify khtml and webkit."},{"author":"mdeslaur","note":"webkitkde is a wrapper around qt4-x11's webkit.\nThis is fixed in webkit 1.2.5"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2441"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=552255","https://bugs.webkit.org/show_bug.cgi?id=26824"],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/58829"],"qt4-x11":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.2.5-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.2.5-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.2.5-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.2.5-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.5-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1625","published":"2010-06-24T12:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in LXR Cross Referencer before\n0.9.7 allows remote attackers to inject arbitrary web script or HTML via\nvectors related to the search body and the results page for a search, a\ndifferent vulnerability than CVE-2009-4497 and CVE-2010-1448.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-1625"],"bugs":[""],"patches":{"lxr-cvs":[]},"tags":{},"packages":[{"name":"lxr-cvs","source":"https://ubuntu.com/security/cve?package=lxr-cvs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lxr-cvs","debian":"https://tracker.debian.org/pkg/lxr-cvs","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.7","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1448","published":"2010-06-24T12:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in lib/LXR/Common.pm in LXR Cross\nReferencer before 0.9.8 allows remote attackers to inject arbitrary web\nscript or HTML via vectors related to a string in the search page's TITLE\nelement, a different vulnerability than CVE-2009-4497 and CVE-2010-1625.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-1448"],"bugs":[""],"patches":{"lxr-cvs":[]},"tags":{},"packages":[{"name":"lxr-cvs","source":"https://ubuntu.com/security/cve?package=lxr-cvs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lxr-cvs","debian":"https://tracker.debian.org/pkg/lxr-cvs","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.8","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-0183","published":"2010-06-24T12:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the nsCycleCollector::MarkRoots function in\nMozilla Firefox 3.5.x before 3.5.10 and SeaMonkey before 2.0.5 allows\nremote attackers to execute arbitrary code via a crafted HTML document,\nrelated to an improper frame construction process for menus.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"CVEs in Firefox are tracked in the xulrunner source packages. The\nmapping of xulrunner sources to firefox is:\nxulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS\nxulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS\nxulrunner-1.9: firefox-3.0\nxulrunner-1.9.1: firefox-3.5\nUbuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not\nthe system xulrunner-1.9.2, so it is tracked in the firefox source package."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-0183"],"bugs":[""],"patches":{"xulrunner-1.9.1":[],"seamonkey":[]},"tags":{},"packages":[{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.7+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.5","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2225","published":"2010-06-24T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the SplObjectStorage unserializer in PHP\n5.2.x and 5.3.x through 5.3.2 allows remote attackers to execute arbitrary\ncode or obtain sensitive information via serialized data, related to the\nPHP unserialize function.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"SplObjectStorage doesn't have an unserializer in php 5.1.x"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://twitter.com/i0n1c/status/16447867829","http://php-security.org/2010/06/25/mops-2010-061-php-splobjectstorage-deserialization-use-after-free-vulnerability/","http://nibbles.tuxfamily.org/?p=1837","https://ubuntu.com/security/notices/USN-989-1","https://www.cve.org/CVERecord?id=CVE-2010-2225"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=605641"],"patches":{"php5":["upstream: http://svn.php.net/viewvc?view=revision&revision=300843"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"not-affected","description":"5.1.2-1ubuntu3.18","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.2.4-2ubuntu5.12","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"5.2.6.dfsg.1-3ubuntu4.6","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"5.2.10.dfsg.1-2ubuntu6.5","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"5.3.2-1ubuntu4.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-989-1"],"notices":[{"id":"USN-989-1","title":"PHP vulnerabilities","summary":"","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-09-20T18:22:04.757285","description":"Auke van Slooten discovered that PHP incorrectly handled certain xmlrpc\nrequests. An attacker could exploit this issue to cause the PHP server to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n6.06 LTS, 8.04 LTS, 9.04 and 9.10. (CVE-2010-0397)\n\nIt was discovered that the pseudorandom number generator in PHP did not\nprovide the expected entropy. An attacker could exploit this issue to\npredict values that were intended to be random, such as session cookies.\nThis issue only affected Ubuntu 6.06 LTS, 8.04 LTS, 9.04 and 9.10.\n(CVE-2010-1128)\n\nIt was discovered that PHP did not properly handle directory pathnames that\nlacked a trailing slash character. An attacker could exploit this issue to\nbypass safe_mode restrictions. This issue only affected Ubuntu 6.06 LTS,\n8.04 LTS, 9.04 and 9.10. (CVE-2010-1129)\n\nGrzegorz Stachowiak discovered that the PHP session extension did not\nproperly handle semicolon characters. An attacker could exploit this issue\nto bypass safe_mode restrictions. This issue only affected Ubuntu 8.04 LTS,\n9.04 and 9.10. (CVE-2010-1130)\n\nStefan Esser discovered that PHP incorrectly decoded remote HTTP chunked\nencoding streams. An attacker could exploit this issue to cause the PHP\nserver to crash and possibly execute arbitrary code with application\nprivileges. This issue only affected Ubuntu 10.04 LTS. (CVE-2010-1866)\n\nMateusz Kocielski discovered that certain PHP SQLite functions incorrectly\nhandled empty SQL queries. An attacker could exploit this issue to possibly\nexecute arbitrary code with application privileges. (CVE-2010-1868)\n\nMateusz Kocielski discovered that PHP incorrectly handled certain arguments\nto the fnmatch function. An attacker could exploit this flaw and cause the\nPHP server to consume all available stack memory, resulting in a denial of\nservice. (CVE-2010-1917)\n\nStefan Esser discovered that PHP incorrectly handled certain strings in the\nphar extension. An attacker could exploit this flaw to possibly view\nsensitive information. This issue only affected Ubuntu 10.04 LTS.\n(CVE-2010-2094, CVE-2010-2950)\n\nStefan Esser discovered that PHP incorrectly handled deserialization of\nSPLObjectStorage objects. A remote attacker could exploit this issue to\nview sensitive information and possibly execute arbitrary code with\napplication privileges. This issue only affected Ubuntu 8.04 LTS, 9.04,\n9.10 and 10.04 LTS. (CVE-2010-2225)\n\nIt was discovered that PHP incorrectly filtered error messages when limits\nfor memory, execution time, or recursion were exceeded. A remote attacker\ncould exploit this issue to possibly view sensitive information.\n(CVE-2010-2531)\n\nStefan Esser discovered that the PHP session serializer incorrectly handled\nthe PS_UNDEF_MARKER marker. An attacker could exploit this issue to alter\narbitrary session variables. (CVE-2010-3065)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"php5","version":"5.2.10.dfsg.1-2ubuntu6.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"},{"name":"php5-cgi","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"},{"name":"libapache2-mod-php5","version":"5.2.10.dfsg.1-2ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.10.dfsg.1-2ubuntu6.5"}],"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.12","description":"","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.12"}],"lucid":[{"name":"php5","version":"5.3.2-1ubuntu4.5","description":"","is_source":true},{"name":"php5-cli","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"},{"name":"php5-cgi","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"},{"name":"libapache2-mod-php5","version":"5.3.2-1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.5"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.19","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.19","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.19"}],"jaunty":[{"name":"php5","version":"5.2.6.dfsg.1-3ubuntu4.6","description":"","is_source":true},{"name":"php5-cli","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"},{"name":"php5-cgi","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"},{"name":"libapache2-mod-php5","version":"5.2.6.dfsg.1-3ubuntu4.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6.dfsg.1-3ubuntu4.6"}]},"type":"USN","cves_ids":["CVE-2010-0397","CVE-2010-1128","CVE-2010-1129","CVE-2010-1130","CVE-2010-1866","CVE-2010-1868","CVE-2010-1917","CVE-2010-2094","CVE-2010-2225","CVE-2010-2531","CVE-2010-2950","CVE-2010-3065"]}]},{"id":"CVE-2010-1203","published":"2010-06-24T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remote\nattackers to cause a denial of service (memory corruption and application\ncrash) or possibly execute arbitrary code via vectors that trigger an\nassertion failure in jstracer.cpp.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"CVEs in Firefox are tracked in the xulrunner source packages. The\nmapping of xulrunner sources to firefox is:\nxulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS\nxulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS\nxulrunner-1.9: firefox-3.0\nxulrunner-1.9.1: firefox-3.5\nUbuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not\nthe system xulrunner-1.9.2, so it is tracked in the firefox source package.\nthunderbird neglibible (requires javascript be enabled)"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-930-1","https://ubuntu.com/security/notices/USN-943-1","https://ubuntu.com/security/notices/USN-930-4","https://www.cve.org/CVERecord?id=CVE-2010-1203"],"bugs":[""],"patches":{"firefox":[],"xulrunner":[],"xulrunner-1.9":[],"xulrunner-1.9.1":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.6.6+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-943-1","USN-930-4","USN-930-1"],"notices":[{"id":"USN-943-1","title":"Thunderbird vulnerabilities","summary":"","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":[],"published":"2010-07-06T13:01:19.099945","description":"Martin Barbella discovered an integer overflow in an XSLT node sorting\nroutine. An attacker could exploit this to overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1199)\n\nAn integer overflow was discovered in Thunderbird. If a user were tricked\ninto viewing malicious content, an attacker could overflow a buffer and\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1196)\n\nSeveral flaws were discovered in the browser engine of Thunderbird. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\nCVE-2010-1202, CVE-2010-1203)\n\nIf was discovered that Thunderbird could be made to access freed memory. If\na user were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1121)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"thunderbird","version":"3.0.5+build2+nobinonly-0ubuntu0.10.04.1","description":"","is_source":true},{"name":"thunderbird","version":"3.0.5+build2+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/3.0.5+build2+nobinonly-0ubuntu0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2010-1199","CVE-2010-1196","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1121"]},{"id":"USN-930-4","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to run programs as your login if it opened a\nspecially crafted file or website.\n","instructions":"Mozilla has changed the support model for Firefox and they no longer\nsupport version 3.0 of the browser and will only support version 3.5 of the\nbrowser for a while longer. As a result, Ubuntu is providing an upgrade to\nFirefox 3.6 for Ubuntu 9.04 and 9.10 users, which is the most current\nstable release of Firefox supported by Mozilla. When upgrading, users\nshould be aware of the following:\n\n- Firefox 3.6 does not support version 5 of the Sun Java plugin. Please use\n icedtea6-plugin or sun-java6-plugin instead.\n- After upgrading to Firefox 3.6.6, users may be prompted to upgrade 3rd\n party Add-Ons. In some cases, an Add-On will not be compatible with\n Firefox 3.6.6 and have no update available. In these cases, Firefox will\n notify the user that it is disabling the Add-On.\n- Font configuration cannot be controlled via Gnome settings. This is a\n known issue being tracked in https://launchpad.net/bugs/559149 and will\n be fixed in a later update.\n- helix-player is not currently supported in Firefox 3.6. This is a known\n issue and may be fixed in a future update.\n- Plugins using external helpers (such as Totem) may not close when using\n the Epiphany browser. This is a known issue being tracked in\n https://launchpad.net/bugs/599796 and will be fixed in a later update.\n This issue only affects Ubuntu 9.04.\n- The OpenJDK java plugin is not available in Ubuntu 9.04 on Sparc\n hardware. This will be fixed in a future update.\n\nAfter a standard system upgrade you need to restart Firefox and any\napplications that use Xulrunner to effect the necessary changes.\n","references":[],"published":"2010-07-23T09:48:19.360663","description":"USN-930-1 fixed vulnerabilities in Firefox and Xulrunner. This update\nprovides the corresponding updates for Ubuntu 9.04 and 9.10, along with\nadditional updates affecting Firefox 3.6.6.\n\nSeveral flaws were discovered in the browser engine of Firefox. If a user\nwere tricked into viewing a malicious site, a remote attacker could use\nthis to crash the browser or possibly run arbitrary code as the user\ninvoking the program. (CVE-2010-1208, CVE-2010-1209, CVE-2010-1211,\nCVE-2010-1212)\n\nAn integer overflow was discovered in how Firefox processed plugin\nparameters. An attacker could exploit this to crash the browser or possibly\nrun arbitrary code as the user invoking the program. (CVE-2010-1214)\n\nA flaw was discovered in the Firefox JavaScript engine. If a user were\ntricked into viewing a malicious site, a remote attacker code execute\narbitrary JavaScript with chrome privileges. (CVE-2010-1215)\n\nAn integer overflow was discovered in how Firefox processed CSS values. An\nattacker could exploit this to crash the browser or possibly run arbitrary\ncode as the user invoking the program. (CVE-2010-2752)\n\nAn integer overflow was discovered in how Firefox interpreted the XUL\n element. If a user were tricked into viewing a malicious site, a\nremote attacker could use this to crash the browser or possibly run\narbitrary code as the user invoking the program. (CVE-2010-2753)\n\nAki Helin discovered that libpng did not properly handle certain malformed\nPNG images. If a user were tricked into opening a crafted PNG file, an\nattacker could cause a denial of service or possibly execute arbitrary code\nwith the privileges of the user invoking the program. (CVE-2010-1205)\n\nYosuke Hasegawa and Vladimir Vukicevic discovered that the same-origin\ncheck in Firefox could be bypassed by utilizing the importScripts Web\nWorker method. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-1213, CVE-2010-1207)\n\nO. Andersen that Firefox did not properly map undefined positions within\ncertain 8 bit encodings. An attacker could utilize this to perform\ncross-site scripting attacks. (CVE-2010-1210)\n\nMichal Zalewski discovered flaws in how Firefox processed the HTTP 204 (no\ncontent) code. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-1206)\n\nJordi Chancel discovered that Firefox did not properly handle when a server\nresponds to an HTTPS request with plaintext and then processes JavaScript\nhistory events. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-2751)\n\nChris Evans discovered that Firefox did not properly process improper CSS\nselectors. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-0654)\n\nSoroush Dalili discovered that Firefox did not properly handle script error\noutput. An attacker could use this to access URL parameters from other\ndomains. (CVE-2010-2754)\n\nOriginal advisory details:\n\n If was discovered that Firefox could be made to access freed memory. If a\n user were tricked into viewing a malicious site, a remote attacker could\n cause a denial of service or possibly execute arbitrary code with the\n privileges of the user invoking the program. (CVE-2010-1121)\n \n Several flaws were discovered in the browser engine of Firefox. If a\n user were tricked into viewing a malicious site, a remote attacker could\n cause a denial of service or possibly execute arbitrary code with the\n privileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\n CVE-2010-1202, CVE-2010-1203)\n \n A flaw was discovered in the way plugin instances interacted. An attacker\n could potentially exploit this and use one plugin to access freed memory from a\n second plugin to execute arbitrary code with the privileges of the user\n invoking the program. (CVE-2010-1198)\n \n An integer overflow was discovered in Firefox. If a user were tricked into\n viewing a malicious site, an attacker could overflow a buffer and cause a\n denial of service or possibly execute arbitrary code with the privileges of\n the user invoking the program. (CVE-2010-1196)\n \n Martin Barbella discovered an integer overflow in an XSLT node sorting\n routine. An attacker could exploit this to overflow a buffer and cause a\n denial of service or possibly execute arbitrary code with the privileges of\n the user invoking the program. (CVE-2010-1199)\n \n Michal Zalewski discovered that the focus behavior of Firefox could be\n subverted. If a user were tricked into viewing a malicious site, a remote\n attacker could use this to capture keystrokes. (CVE-2010-1125)\n \n Ilja van Sprundel discovered that the 'Content-Disposition: attachment'\n HTTP header was ignored when 'Content-Type: multipart' was also present.\n Under certain circumstances, this could potentially lead to cross-site\n scripting attacks. (CVE-2010-1197)\n \n Amit Klein discovered that Firefox did not seed its random number generator\n often enough. An attacker could exploit this to identify and track users\n across different web sites. (CVE-2008-5913)\n","is_hidden":false,"release_packages":{"jaunty":[{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.7+build2+nobinonly-0ubuntu0.9.04.1"},{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.7+build2+nobinonly-0ubuntu0.9.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2"}],"karmic":[{"name":"firefox-3.5","version":"3.6.7+build2+nobinonly-0ubuntu0.9.10.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","description":"empty transitional upgrade package for xulrunner-1.9","is_source":true},{"name":"firefox-3.5","version":"3.6.7+build2+nobinonly-0ubuntu0.9.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.6.7+build2+nobinonly-0ubuntu0.9.10.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2"}]},"type":"USN","cves_ids":["CVE-2008-5913","CVE-2010-1121","CVE-2010-1125","CVE-2010-1196","CVE-2010-1197","CVE-2010-1198","CVE-2010-1199","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1208","CVE-2010-1209","CVE-2010-1211","CVE-2010-1212","CVE-2010-1214","CVE-2010-1215","CVE-2010-2752","CVE-2010-2753","CVE-2010-1205","CVE-2010-1213","CVE-2010-1207","CVE-2010-1210","CVE-2010-1206","CVE-2010-2751","CVE-2010-0654","CVE-2010-2754"]},{"id":"USN-930-1","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to run programs as your login if it opened a\nspecially crafted file or website.\n","instructions":"Mozilla has changed the support model for Firefox and they no longer\nsupport version 3.0 of the browser. As a result, Ubuntu is providing an\nupgrade to Firefox 3.6 for Ubuntu 8.04 LTS users, which is the most current\nstable release of Firefox supported by Mozilla. When upgrading, users\nshould be aware of the following:\n\n- Firefox 3.6 does not support version 5 of the Sun Java plugin. Please use\n icedtea-java7-plugin or sun-java6-plugin instead.\n- After upgrading to Firefox 3.6.6, users may be prompted to upgrade 3rd\n party Add-Ons. In some cases, an Add-On will not be compatible with\n Firefox 3.6.6 and have no update available. In these cases, Firefox will\n notify the user that it is disabling the Add-On.\n- Upgrades to Ubuntu 8.10 from Ubuntu 8.04 LTS may break the browser.\n Ubuntu 8.10 is no longer officially supported and users are required to\n upgrade to 9.04 to receive active security support and a functional browser.\n- Font configuration cannot be controlled via Gnome settings. This is a\n known issue being tracked in https://launchpad.net/bugs/559149 and will\n be fixed in a later update.\n- helix-player is not currently supported in Firefox 3.6. This is a known\n issue and may be fixed in a future update.\n- RealAudio via the totem plugin is no longer supported in Firefox 3.6 in\n Ubuntu 8.04 LTS. Affected users navigating to Real content will be\n prompted to install optional community supported packages.\n- In Ubuntu 8.04 LTS the xine plugin is non-functional. After upgrading to\n Firefox 3.6, the plugin may cause the browser to crash, while in Firefox\n 3.0 it would be silently ignored. Users are advised to uninstall\n xine-plugin and/or gxineplugin.\n- Plugins using external helpers (such as Totem) may not close when using\n the Epiphany browser. This is a known issue being tracked in\n https://launchpad.net/bugs/599796 and will be fixed in a later update.\n This issue only affects Ubuntu 8.04 LTS.\n\nAfter a standard system upgrade you need to restart Firefox and any\napplications that use Xulrunner to effect the necessary changes.\n","references":[],"published":"2010-06-29T20:41:25.775109","description":"If was discovered that Firefox could be made to access freed memory. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. This issue only affected\nUbuntu 8.04 LTS. (CVE-2010-1121)\n\nSeveral flaws were discovered in the browser engine of Firefox. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\nCVE-2010-1202, CVE-2010-1203)\n\nA flaw was discovered in the way plugin instances interacted. An attacker\ncould potentially exploit this and use one plugin to access freed memory from a\nsecond plugin to execute arbitrary code with the privileges of the user\ninvoking the program. (CVE-2010-1198)\n\nAn integer overflow was discovered in Firefox. If a user were tricked into\nviewing a malicious site, an attacker could overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1196)\n\nMartin Barbella discovered an integer overflow in an XSLT node sorting\nroutine. An attacker could exploit this to overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1199)\n\nMichal Zalewski discovered that the focus behavior of Firefox could be\nsubverted. If a user were tricked into viewing a malicious site, a remote\nattacker could use this to capture keystrokes. (CVE-2010-1125)\n\nIlja van Sprundel discovered that the 'Content-Disposition: attachment'\nHTTP header was ignored when 'Content-Type: multipart' was also present.\nUnder certain circumstances, this could potentially lead to cross-site\nscripting attacks. (CVE-2010-1197)\n\nAmit Klein discovered that Firefox did not seed its random number generator\noften enough. An attacker could exploit this to identify and track users\nacross different web sites. (CVE-2008-5913)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.6.6+nobinonly-0ubuntu0.8.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.6+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.6+nobinonly-0ubuntu0.8.04.1"}],"lucid":[{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.6+nobinonly-0ubuntu0.10.04.1"},{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.6+nobinonly-0ubuntu0.10.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.6+nobinonly-0ubuntu0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2010-1121","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1198","CVE-2010-1196","CVE-2010-1199","CVE-2010-1125","CVE-2010-1197","CVE-2008-5913"]}]},{"id":"CVE-2010-1202","published":"2010-06-24T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in the JavaScript engine in Mozilla\nFirefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before\n3.0.5, and SeaMonkey before 2.0.5 allow remote attackers to cause a denial\nof service (memory corruption and application crash) or possibly execute\narbitrary code via unknown vectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"CVEs in Firefox are tracked in the xulrunner source packages. The\nmapping of xulrunner sources to firefox is:\nxulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS\nxulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS\nxulrunner-1.9: firefox-3.0\nxulrunner-1.9.1: firefox-3.5\nUbuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not\nthe system xulrunner-1.9.2, so it is tracked in the firefox source package.\nthunderbird negligible (requires javascript be enabled)"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-930-1","https://ubuntu.com/security/notices/USN-943-1","https://ubuntu.com/security/notices/USN-930-4","https://www.cve.org/CVERecord?id=CVE-2010-1202"],"bugs":[""],"patches":{"firefox":[],"xulrunner":[],"xulrunner-1.9":[],"xulrunner-1.9.1":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.6.6+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-943-1","USN-930-4","USN-930-1"],"notices":[{"id":"USN-943-1","title":"Thunderbird vulnerabilities","summary":"","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":[],"published":"2010-07-06T13:01:19.099945","description":"Martin Barbella discovered an integer overflow in an XSLT node sorting\nroutine. An attacker could exploit this to overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1199)\n\nAn integer overflow was discovered in Thunderbird. If a user were tricked\ninto viewing malicious content, an attacker could overflow a buffer and\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1196)\n\nSeveral flaws were discovered in the browser engine of Thunderbird. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\nCVE-2010-1202, CVE-2010-1203)\n\nIf was discovered that Thunderbird could be made to access freed memory. If\na user were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1121)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"thunderbird","version":"3.0.5+build2+nobinonly-0ubuntu0.10.04.1","description":"","is_source":true},{"name":"thunderbird","version":"3.0.5+build2+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/3.0.5+build2+nobinonly-0ubuntu0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2010-1199","CVE-2010-1196","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1121"]},{"id":"USN-930-4","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to run programs as your login if it opened a\nspecially crafted file or website.\n","instructions":"Mozilla has changed the support model for Firefox and they no longer\nsupport version 3.0 of the browser and will only support version 3.5 of the\nbrowser for a while longer. As a result, Ubuntu is providing an upgrade to\nFirefox 3.6 for Ubuntu 9.04 and 9.10 users, which is the most current\nstable release of Firefox supported by Mozilla. When upgrading, users\nshould be aware of the following:\n\n- Firefox 3.6 does not support version 5 of the Sun Java plugin. Please use\n icedtea6-plugin or sun-java6-plugin instead.\n- After upgrading to Firefox 3.6.6, users may be prompted to upgrade 3rd\n party Add-Ons. In some cases, an Add-On will not be compatible with\n Firefox 3.6.6 and have no update available. In these cases, Firefox will\n notify the user that it is disabling the Add-On.\n- Font configuration cannot be controlled via Gnome settings. This is a\n known issue being tracked in https://launchpad.net/bugs/559149 and will\n be fixed in a later update.\n- helix-player is not currently supported in Firefox 3.6. This is a known\n issue and may be fixed in a future update.\n- Plugins using external helpers (such as Totem) may not close when using\n the Epiphany browser. This is a known issue being tracked in\n https://launchpad.net/bugs/599796 and will be fixed in a later update.\n This issue only affects Ubuntu 9.04.\n- The OpenJDK java plugin is not available in Ubuntu 9.04 on Sparc\n hardware. This will be fixed in a future update.\n\nAfter a standard system upgrade you need to restart Firefox and any\napplications that use Xulrunner to effect the necessary changes.\n","references":[],"published":"2010-07-23T09:48:19.360663","description":"USN-930-1 fixed vulnerabilities in Firefox and Xulrunner. This update\nprovides the corresponding updates for Ubuntu 9.04 and 9.10, along with\nadditional updates affecting Firefox 3.6.6.\n\nSeveral flaws were discovered in the browser engine of Firefox. If a user\nwere tricked into viewing a malicious site, a remote attacker could use\nthis to crash the browser or possibly run arbitrary code as the user\ninvoking the program. (CVE-2010-1208, CVE-2010-1209, CVE-2010-1211,\nCVE-2010-1212)\n\nAn integer overflow was discovered in how Firefox processed plugin\nparameters. An attacker could exploit this to crash the browser or possibly\nrun arbitrary code as the user invoking the program. (CVE-2010-1214)\n\nA flaw was discovered in the Firefox JavaScript engine. If a user were\ntricked into viewing a malicious site, a remote attacker code execute\narbitrary JavaScript with chrome privileges. (CVE-2010-1215)\n\nAn integer overflow was discovered in how Firefox processed CSS values. An\nattacker could exploit this to crash the browser or possibly run arbitrary\ncode as the user invoking the program. (CVE-2010-2752)\n\nAn integer overflow was discovered in how Firefox interpreted the XUL\n element. If a user were tricked into viewing a malicious site, a\nremote attacker could use this to crash the browser or possibly run\narbitrary code as the user invoking the program. (CVE-2010-2753)\n\nAki Helin discovered that libpng did not properly handle certain malformed\nPNG images. If a user were tricked into opening a crafted PNG file, an\nattacker could cause a denial of service or possibly execute arbitrary code\nwith the privileges of the user invoking the program. (CVE-2010-1205)\n\nYosuke Hasegawa and Vladimir Vukicevic discovered that the same-origin\ncheck in Firefox could be bypassed by utilizing the importScripts Web\nWorker method. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-1213, CVE-2010-1207)\n\nO. Andersen that Firefox did not properly map undefined positions within\ncertain 8 bit encodings. An attacker could utilize this to perform\ncross-site scripting attacks. (CVE-2010-1210)\n\nMichal Zalewski discovered flaws in how Firefox processed the HTTP 204 (no\ncontent) code. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-1206)\n\nJordi Chancel discovered that Firefox did not properly handle when a server\nresponds to an HTTPS request with plaintext and then processes JavaScript\nhistory events. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-2751)\n\nChris Evans discovered that Firefox did not properly process improper CSS\nselectors. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-0654)\n\nSoroush Dalili discovered that Firefox did not properly handle script error\noutput. An attacker could use this to access URL parameters from other\ndomains. (CVE-2010-2754)\n\nOriginal advisory details:\n\n If was discovered that Firefox could be made to access freed memory. If a\n user were tricked into viewing a malicious site, a remote attacker could\n cause a denial of service or possibly execute arbitrary code with the\n privileges of the user invoking the program. (CVE-2010-1121)\n \n Several flaws were discovered in the browser engine of Firefox. If a\n user were tricked into viewing a malicious site, a remote attacker could\n cause a denial of service or possibly execute arbitrary code with the\n privileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\n CVE-2010-1202, CVE-2010-1203)\n \n A flaw was discovered in the way plugin instances interacted. An attacker\n could potentially exploit this and use one plugin to access freed memory from a\n second plugin to execute arbitrary code with the privileges of the user\n invoking the program. (CVE-2010-1198)\n \n An integer overflow was discovered in Firefox. If a user were tricked into\n viewing a malicious site, an attacker could overflow a buffer and cause a\n denial of service or possibly execute arbitrary code with the privileges of\n the user invoking the program. (CVE-2010-1196)\n \n Martin Barbella discovered an integer overflow in an XSLT node sorting\n routine. An attacker could exploit this to overflow a buffer and cause a\n denial of service or possibly execute arbitrary code with the privileges of\n the user invoking the program. (CVE-2010-1199)\n \n Michal Zalewski discovered that the focus behavior of Firefox could be\n subverted. If a user were tricked into viewing a malicious site, a remote\n attacker could use this to capture keystrokes. (CVE-2010-1125)\n \n Ilja van Sprundel discovered that the 'Content-Disposition: attachment'\n HTTP header was ignored when 'Content-Type: multipart' was also present.\n Under certain circumstances, this could potentially lead to cross-site\n scripting attacks. (CVE-2010-1197)\n \n Amit Klein discovered that Firefox did not seed its random number generator\n often enough. An attacker could exploit this to identify and track users\n across different web sites. (CVE-2008-5913)\n","is_hidden":false,"release_packages":{"jaunty":[{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.7+build2+nobinonly-0ubuntu0.9.04.1"},{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.7+build2+nobinonly-0ubuntu0.9.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2"}],"karmic":[{"name":"firefox-3.5","version":"3.6.7+build2+nobinonly-0ubuntu0.9.10.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","description":"empty transitional upgrade package for xulrunner-1.9","is_source":true},{"name":"firefox-3.5","version":"3.6.7+build2+nobinonly-0ubuntu0.9.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.6.7+build2+nobinonly-0ubuntu0.9.10.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2"}]},"type":"USN","cves_ids":["CVE-2008-5913","CVE-2010-1121","CVE-2010-1125","CVE-2010-1196","CVE-2010-1197","CVE-2010-1198","CVE-2010-1199","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1208","CVE-2010-1209","CVE-2010-1211","CVE-2010-1212","CVE-2010-1214","CVE-2010-1215","CVE-2010-2752","CVE-2010-2753","CVE-2010-1205","CVE-2010-1213","CVE-2010-1207","CVE-2010-1210","CVE-2010-1206","CVE-2010-2751","CVE-2010-0654","CVE-2010-2754"]},{"id":"USN-930-1","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to run programs as your login if it opened a\nspecially crafted file or website.\n","instructions":"Mozilla has changed the support model for Firefox and they no longer\nsupport version 3.0 of the browser. As a result, Ubuntu is providing an\nupgrade to Firefox 3.6 for Ubuntu 8.04 LTS users, which is the most current\nstable release of Firefox supported by Mozilla. When upgrading, users\nshould be aware of the following:\n\n- Firefox 3.6 does not support version 5 of the Sun Java plugin. Please use\n icedtea-java7-plugin or sun-java6-plugin instead.\n- After upgrading to Firefox 3.6.6, users may be prompted to upgrade 3rd\n party Add-Ons. In some cases, an Add-On will not be compatible with\n Firefox 3.6.6 and have no update available. In these cases, Firefox will\n notify the user that it is disabling the Add-On.\n- Upgrades to Ubuntu 8.10 from Ubuntu 8.04 LTS may break the browser.\n Ubuntu 8.10 is no longer officially supported and users are required to\n upgrade to 9.04 to receive active security support and a functional browser.\n- Font configuration cannot be controlled via Gnome settings. This is a\n known issue being tracked in https://launchpad.net/bugs/559149 and will\n be fixed in a later update.\n- helix-player is not currently supported in Firefox 3.6. This is a known\n issue and may be fixed in a future update.\n- RealAudio via the totem plugin is no longer supported in Firefox 3.6 in\n Ubuntu 8.04 LTS. Affected users navigating to Real content will be\n prompted to install optional community supported packages.\n- In Ubuntu 8.04 LTS the xine plugin is non-functional. After upgrading to\n Firefox 3.6, the plugin may cause the browser to crash, while in Firefox\n 3.0 it would be silently ignored. Users are advised to uninstall\n xine-plugin and/or gxineplugin.\n- Plugins using external helpers (such as Totem) may not close when using\n the Epiphany browser. This is a known issue being tracked in\n https://launchpad.net/bugs/599796 and will be fixed in a later update.\n This issue only affects Ubuntu 8.04 LTS.\n\nAfter a standard system upgrade you need to restart Firefox and any\napplications that use Xulrunner to effect the necessary changes.\n","references":[],"published":"2010-06-29T20:41:25.775109","description":"If was discovered that Firefox could be made to access freed memory. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. This issue only affected\nUbuntu 8.04 LTS. (CVE-2010-1121)\n\nSeveral flaws were discovered in the browser engine of Firefox. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\nCVE-2010-1202, CVE-2010-1203)\n\nA flaw was discovered in the way plugin instances interacted. An attacker\ncould potentially exploit this and use one plugin to access freed memory from a\nsecond plugin to execute arbitrary code with the privileges of the user\ninvoking the program. (CVE-2010-1198)\n\nAn integer overflow was discovered in Firefox. If a user were tricked into\nviewing a malicious site, an attacker could overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1196)\n\nMartin Barbella discovered an integer overflow in an XSLT node sorting\nroutine. An attacker could exploit this to overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1199)\n\nMichal Zalewski discovered that the focus behavior of Firefox could be\nsubverted. If a user were tricked into viewing a malicious site, a remote\nattacker could use this to capture keystrokes. (CVE-2010-1125)\n\nIlja van Sprundel discovered that the 'Content-Disposition: attachment'\nHTTP header was ignored when 'Content-Type: multipart' was also present.\nUnder certain circumstances, this could potentially lead to cross-site\nscripting attacks. (CVE-2010-1197)\n\nAmit Klein discovered that Firefox did not seed its random number generator\noften enough. An attacker could exploit this to identify and track users\nacross different web sites. (CVE-2008-5913)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.6.6+nobinonly-0ubuntu0.8.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.6+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.6+nobinonly-0ubuntu0.8.04.1"}],"lucid":[{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.6+nobinonly-0ubuntu0.10.04.1"},{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.6+nobinonly-0ubuntu0.10.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.6+nobinonly-0ubuntu0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2010-1121","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1198","CVE-2010-1196","CVE-2010-1199","CVE-2010-1125","CVE-2010-1197","CVE-2008-5913"]}]},{"id":"CVE-2010-1201","published":"2010-06-24T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x\nbefore 3.5.10, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows\nremote attackers to cause a denial of service (memory corruption and\napplication crash) or possibly execute arbitrary code via unknown vectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"CVEs in Firefox are tracked in the xulrunner source packages. The\nmapping of xulrunner sources to firefox is:\nxulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS\nxulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS\nxulrunner-1.9: firefox-3.0\nxulrunner-1.9.1: firefox-3.5\nUbuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not\nthe system xulrunner-1.9.2, so it is tracked in the firefox source package."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-930-1","https://ubuntu.com/security/notices/USN-943-1","https://ubuntu.com/security/notices/USN-930-4","https://www.cve.org/CVERecord?id=CVE-2010-1201"],"bugs":[""],"patches":{"firefox":[],"xulrunner":[],"xulrunner-1.9":[],"xulrunner-1.9.1":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.6.6+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-943-1","USN-930-4","USN-930-1"],"notices":[{"id":"USN-943-1","title":"Thunderbird vulnerabilities","summary":"","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":[],"published":"2010-07-06T13:01:19.099945","description":"Martin Barbella discovered an integer overflow in an XSLT node sorting\nroutine. An attacker could exploit this to overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1199)\n\nAn integer overflow was discovered in Thunderbird. If a user were tricked\ninto viewing malicious content, an attacker could overflow a buffer and\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1196)\n\nSeveral flaws were discovered in the browser engine of Thunderbird. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\nCVE-2010-1202, CVE-2010-1203)\n\nIf was discovered that Thunderbird could be made to access freed memory. If\na user were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1121)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"thunderbird","version":"3.0.5+build2+nobinonly-0ubuntu0.10.04.1","description":"","is_source":true},{"name":"thunderbird","version":"3.0.5+build2+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/3.0.5+build2+nobinonly-0ubuntu0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2010-1199","CVE-2010-1196","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1121"]},{"id":"USN-930-4","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to run programs as your login if it opened a\nspecially crafted file or website.\n","instructions":"Mozilla has changed the support model for Firefox and they no longer\nsupport version 3.0 of the browser and will only support version 3.5 of the\nbrowser for a while longer. As a result, Ubuntu is providing an upgrade to\nFirefox 3.6 for Ubuntu 9.04 and 9.10 users, which is the most current\nstable release of Firefox supported by Mozilla. When upgrading, users\nshould be aware of the following:\n\n- Firefox 3.6 does not support version 5 of the Sun Java plugin. Please use\n icedtea6-plugin or sun-java6-plugin instead.\n- After upgrading to Firefox 3.6.6, users may be prompted to upgrade 3rd\n party Add-Ons. In some cases, an Add-On will not be compatible with\n Firefox 3.6.6 and have no update available. In these cases, Firefox will\n notify the user that it is disabling the Add-On.\n- Font configuration cannot be controlled via Gnome settings. This is a\n known issue being tracked in https://launchpad.net/bugs/559149 and will\n be fixed in a later update.\n- helix-player is not currently supported in Firefox 3.6. This is a known\n issue and may be fixed in a future update.\n- Plugins using external helpers (such as Totem) may not close when using\n the Epiphany browser. This is a known issue being tracked in\n https://launchpad.net/bugs/599796 and will be fixed in a later update.\n This issue only affects Ubuntu 9.04.\n- The OpenJDK java plugin is not available in Ubuntu 9.04 on Sparc\n hardware. This will be fixed in a future update.\n\nAfter a standard system upgrade you need to restart Firefox and any\napplications that use Xulrunner to effect the necessary changes.\n","references":[],"published":"2010-07-23T09:48:19.360663","description":"USN-930-1 fixed vulnerabilities in Firefox and Xulrunner. This update\nprovides the corresponding updates for Ubuntu 9.04 and 9.10, along with\nadditional updates affecting Firefox 3.6.6.\n\nSeveral flaws were discovered in the browser engine of Firefox. If a user\nwere tricked into viewing a malicious site, a remote attacker could use\nthis to crash the browser or possibly run arbitrary code as the user\ninvoking the program. (CVE-2010-1208, CVE-2010-1209, CVE-2010-1211,\nCVE-2010-1212)\n\nAn integer overflow was discovered in how Firefox processed plugin\nparameters. An attacker could exploit this to crash the browser or possibly\nrun arbitrary code as the user invoking the program. (CVE-2010-1214)\n\nA flaw was discovered in the Firefox JavaScript engine. If a user were\ntricked into viewing a malicious site, a remote attacker code execute\narbitrary JavaScript with chrome privileges. (CVE-2010-1215)\n\nAn integer overflow was discovered in how Firefox processed CSS values. An\nattacker could exploit this to crash the browser or possibly run arbitrary\ncode as the user invoking the program. (CVE-2010-2752)\n\nAn integer overflow was discovered in how Firefox interpreted the XUL\n element. If a user were tricked into viewing a malicious site, a\nremote attacker could use this to crash the browser or possibly run\narbitrary code as the user invoking the program. (CVE-2010-2753)\n\nAki Helin discovered that libpng did not properly handle certain malformed\nPNG images. If a user were tricked into opening a crafted PNG file, an\nattacker could cause a denial of service or possibly execute arbitrary code\nwith the privileges of the user invoking the program. (CVE-2010-1205)\n\nYosuke Hasegawa and Vladimir Vukicevic discovered that the same-origin\ncheck in Firefox could be bypassed by utilizing the importScripts Web\nWorker method. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-1213, CVE-2010-1207)\n\nO. Andersen that Firefox did not properly map undefined positions within\ncertain 8 bit encodings. An attacker could utilize this to perform\ncross-site scripting attacks. (CVE-2010-1210)\n\nMichal Zalewski discovered flaws in how Firefox processed the HTTP 204 (no\ncontent) code. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-1206)\n\nJordi Chancel discovered that Firefox did not properly handle when a server\nresponds to an HTTPS request with plaintext and then processes JavaScript\nhistory events. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-2751)\n\nChris Evans discovered that Firefox did not properly process improper CSS\nselectors. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-0654)\n\nSoroush Dalili discovered that Firefox did not properly handle script error\noutput. An attacker could use this to access URL parameters from other\ndomains. (CVE-2010-2754)\n\nOriginal advisory details:\n\n If was discovered that Firefox could be made to access freed memory. If a\n user were tricked into viewing a malicious site, a remote attacker could\n cause a denial of service or possibly execute arbitrary code with the\n privileges of the user invoking the program. (CVE-2010-1121)\n \n Several flaws were discovered in the browser engine of Firefox. If a\n user were tricked into viewing a malicious site, a remote attacker could\n cause a denial of service or possibly execute arbitrary code with the\n privileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\n CVE-2010-1202, CVE-2010-1203)\n \n A flaw was discovered in the way plugin instances interacted. An attacker\n could potentially exploit this and use one plugin to access freed memory from a\n second plugin to execute arbitrary code with the privileges of the user\n invoking the program. (CVE-2010-1198)\n \n An integer overflow was discovered in Firefox. If a user were tricked into\n viewing a malicious site, an attacker could overflow a buffer and cause a\n denial of service or possibly execute arbitrary code with the privileges of\n the user invoking the program. (CVE-2010-1196)\n \n Martin Barbella discovered an integer overflow in an XSLT node sorting\n routine. An attacker could exploit this to overflow a buffer and cause a\n denial of service or possibly execute arbitrary code with the privileges of\n the user invoking the program. (CVE-2010-1199)\n \n Michal Zalewski discovered that the focus behavior of Firefox could be\n subverted. If a user were tricked into viewing a malicious site, a remote\n attacker could use this to capture keystrokes. (CVE-2010-1125)\n \n Ilja van Sprundel discovered that the 'Content-Disposition: attachment'\n HTTP header was ignored when 'Content-Type: multipart' was also present.\n Under certain circumstances, this could potentially lead to cross-site\n scripting attacks. (CVE-2010-1197)\n \n Amit Klein discovered that Firefox did not seed its random number generator\n often enough. An attacker could exploit this to identify and track users\n across different web sites. (CVE-2008-5913)\n","is_hidden":false,"release_packages":{"jaunty":[{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.7+build2+nobinonly-0ubuntu0.9.04.1"},{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.7+build2+nobinonly-0ubuntu0.9.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2"}],"karmic":[{"name":"firefox-3.5","version":"3.6.7+build2+nobinonly-0ubuntu0.9.10.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","description":"empty transitional upgrade package for xulrunner-1.9","is_source":true},{"name":"firefox-3.5","version":"3.6.7+build2+nobinonly-0ubuntu0.9.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.6.7+build2+nobinonly-0ubuntu0.9.10.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2"}]},"type":"USN","cves_ids":["CVE-2008-5913","CVE-2010-1121","CVE-2010-1125","CVE-2010-1196","CVE-2010-1197","CVE-2010-1198","CVE-2010-1199","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1208","CVE-2010-1209","CVE-2010-1211","CVE-2010-1212","CVE-2010-1214","CVE-2010-1215","CVE-2010-2752","CVE-2010-2753","CVE-2010-1205","CVE-2010-1213","CVE-2010-1207","CVE-2010-1210","CVE-2010-1206","CVE-2010-2751","CVE-2010-0654","CVE-2010-2754"]},{"id":"USN-930-1","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to run programs as your login if it opened a\nspecially crafted file or website.\n","instructions":"Mozilla has changed the support model for Firefox and they no longer\nsupport version 3.0 of the browser. As a result, Ubuntu is providing an\nupgrade to Firefox 3.6 for Ubuntu 8.04 LTS users, which is the most current\nstable release of Firefox supported by Mozilla. When upgrading, users\nshould be aware of the following:\n\n- Firefox 3.6 does not support version 5 of the Sun Java plugin. Please use\n icedtea-java7-plugin or sun-java6-plugin instead.\n- After upgrading to Firefox 3.6.6, users may be prompted to upgrade 3rd\n party Add-Ons. In some cases, an Add-On will not be compatible with\n Firefox 3.6.6 and have no update available. In these cases, Firefox will\n notify the user that it is disabling the Add-On.\n- Upgrades to Ubuntu 8.10 from Ubuntu 8.04 LTS may break the browser.\n Ubuntu 8.10 is no longer officially supported and users are required to\n upgrade to 9.04 to receive active security support and a functional browser.\n- Font configuration cannot be controlled via Gnome settings. This is a\n known issue being tracked in https://launchpad.net/bugs/559149 and will\n be fixed in a later update.\n- helix-player is not currently supported in Firefox 3.6. This is a known\n issue and may be fixed in a future update.\n- RealAudio via the totem plugin is no longer supported in Firefox 3.6 in\n Ubuntu 8.04 LTS. Affected users navigating to Real content will be\n prompted to install optional community supported packages.\n- In Ubuntu 8.04 LTS the xine plugin is non-functional. After upgrading to\n Firefox 3.6, the plugin may cause the browser to crash, while in Firefox\n 3.0 it would be silently ignored. Users are advised to uninstall\n xine-plugin and/or gxineplugin.\n- Plugins using external helpers (such as Totem) may not close when using\n the Epiphany browser. This is a known issue being tracked in\n https://launchpad.net/bugs/599796 and will be fixed in a later update.\n This issue only affects Ubuntu 8.04 LTS.\n\nAfter a standard system upgrade you need to restart Firefox and any\napplications that use Xulrunner to effect the necessary changes.\n","references":[],"published":"2010-06-29T20:41:25.775109","description":"If was discovered that Firefox could be made to access freed memory. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. This issue only affected\nUbuntu 8.04 LTS. (CVE-2010-1121)\n\nSeveral flaws were discovered in the browser engine of Firefox. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\nCVE-2010-1202, CVE-2010-1203)\n\nA flaw was discovered in the way plugin instances interacted. An attacker\ncould potentially exploit this and use one plugin to access freed memory from a\nsecond plugin to execute arbitrary code with the privileges of the user\ninvoking the program. (CVE-2010-1198)\n\nAn integer overflow was discovered in Firefox. If a user were tricked into\nviewing a malicious site, an attacker could overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1196)\n\nMartin Barbella discovered an integer overflow in an XSLT node sorting\nroutine. An attacker could exploit this to overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1199)\n\nMichal Zalewski discovered that the focus behavior of Firefox could be\nsubverted. If a user were tricked into viewing a malicious site, a remote\nattacker could use this to capture keystrokes. (CVE-2010-1125)\n\nIlja van Sprundel discovered that the 'Content-Disposition: attachment'\nHTTP header was ignored when 'Content-Type: multipart' was also present.\nUnder certain circumstances, this could potentially lead to cross-site\nscripting attacks. (CVE-2010-1197)\n\nAmit Klein discovered that Firefox did not seed its random number generator\noften enough. An attacker could exploit this to identify and track users\nacross different web sites. (CVE-2008-5913)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.6.6+nobinonly-0ubuntu0.8.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.6+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.6+nobinonly-0ubuntu0.8.04.1"}],"lucid":[{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.6+nobinonly-0ubuntu0.10.04.1"},{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.6+nobinonly-0ubuntu0.10.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.6+nobinonly-0ubuntu0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2010-1121","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1198","CVE-2010-1196","CVE-2010-1199","CVE-2010-1125","CVE-2010-1197","CVE-2008-5913"]}]},{"id":"CVE-2010-1200","published":"2010-06-24T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in the browser engine in Mozilla\nFirefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before\n3.0.5, and SeaMonkey before 2.0.5 allow remote attackers to cause a denial\nof service (memory corruption and application crash) or possibly execute\narbitrary code via unknown vectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"CVEs in Firefox are tracked in the xulrunner source packages. The\nmapping of xulrunner sources to firefox is:\nxulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS\nxulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS\nxulrunner-1.9: firefox-3.0\nxulrunner-1.9.1: firefox-3.5\nUbuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not\nthe system xulrunner-1.9.2, so it is tracked in the firefox source package."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-930-1","https://ubuntu.com/security/notices/USN-943-1","https://ubuntu.com/security/notices/USN-930-4","https://www.cve.org/CVERecord?id=CVE-2010-1200"],"bugs":[""],"patches":{"firefox":[],"xulrunner":[],"xulrunner-1.9":[],"xulrunner-1.9.1":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.6.6+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-943-1","USN-930-4","USN-930-1"],"notices":[{"id":"USN-943-1","title":"Thunderbird vulnerabilities","summary":"","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":[],"published":"2010-07-06T13:01:19.099945","description":"Martin Barbella discovered an integer overflow in an XSLT node sorting\nroutine. An attacker could exploit this to overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1199)\n\nAn integer overflow was discovered in Thunderbird. If a user were tricked\ninto viewing malicious content, an attacker could overflow a buffer and\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1196)\n\nSeveral flaws were discovered in the browser engine of Thunderbird. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\nCVE-2010-1202, CVE-2010-1203)\n\nIf was discovered that Thunderbird could be made to access freed memory. If\na user were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1121)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"thunderbird","version":"3.0.5+build2+nobinonly-0ubuntu0.10.04.1","description":"","is_source":true},{"name":"thunderbird","version":"3.0.5+build2+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/3.0.5+build2+nobinonly-0ubuntu0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2010-1199","CVE-2010-1196","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1121"]},{"id":"USN-930-4","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to run programs as your login if it opened a\nspecially crafted file or website.\n","instructions":"Mozilla has changed the support model for Firefox and they no longer\nsupport version 3.0 of the browser and will only support version 3.5 of the\nbrowser for a while longer. As a result, Ubuntu is providing an upgrade to\nFirefox 3.6 for Ubuntu 9.04 and 9.10 users, which is the most current\nstable release of Firefox supported by Mozilla. When upgrading, users\nshould be aware of the following:\n\n- Firefox 3.6 does not support version 5 of the Sun Java plugin. Please use\n icedtea6-plugin or sun-java6-plugin instead.\n- After upgrading to Firefox 3.6.6, users may be prompted to upgrade 3rd\n party Add-Ons. In some cases, an Add-On will not be compatible with\n Firefox 3.6.6 and have no update available. In these cases, Firefox will\n notify the user that it is disabling the Add-On.\n- Font configuration cannot be controlled via Gnome settings. This is a\n known issue being tracked in https://launchpad.net/bugs/559149 and will\n be fixed in a later update.\n- helix-player is not currently supported in Firefox 3.6. This is a known\n issue and may be fixed in a future update.\n- Plugins using external helpers (such as Totem) may not close when using\n the Epiphany browser. This is a known issue being tracked in\n https://launchpad.net/bugs/599796 and will be fixed in a later update.\n This issue only affects Ubuntu 9.04.\n- The OpenJDK java plugin is not available in Ubuntu 9.04 on Sparc\n hardware. This will be fixed in a future update.\n\nAfter a standard system upgrade you need to restart Firefox and any\napplications that use Xulrunner to effect the necessary changes.\n","references":[],"published":"2010-07-23T09:48:19.360663","description":"USN-930-1 fixed vulnerabilities in Firefox and Xulrunner. This update\nprovides the corresponding updates for Ubuntu 9.04 and 9.10, along with\nadditional updates affecting Firefox 3.6.6.\n\nSeveral flaws were discovered in the browser engine of Firefox. If a user\nwere tricked into viewing a malicious site, a remote attacker could use\nthis to crash the browser or possibly run arbitrary code as the user\ninvoking the program. (CVE-2010-1208, CVE-2010-1209, CVE-2010-1211,\nCVE-2010-1212)\n\nAn integer overflow was discovered in how Firefox processed plugin\nparameters. An attacker could exploit this to crash the browser or possibly\nrun arbitrary code as the user invoking the program. (CVE-2010-1214)\n\nA flaw was discovered in the Firefox JavaScript engine. If a user were\ntricked into viewing a malicious site, a remote attacker code execute\narbitrary JavaScript with chrome privileges. (CVE-2010-1215)\n\nAn integer overflow was discovered in how Firefox processed CSS values. An\nattacker could exploit this to crash the browser or possibly run arbitrary\ncode as the user invoking the program. (CVE-2010-2752)\n\nAn integer overflow was discovered in how Firefox interpreted the XUL\n element. If a user were tricked into viewing a malicious site, a\nremote attacker could use this to crash the browser or possibly run\narbitrary code as the user invoking the program. (CVE-2010-2753)\n\nAki Helin discovered that libpng did not properly handle certain malformed\nPNG images. If a user were tricked into opening a crafted PNG file, an\nattacker could cause a denial of service or possibly execute arbitrary code\nwith the privileges of the user invoking the program. (CVE-2010-1205)\n\nYosuke Hasegawa and Vladimir Vukicevic discovered that the same-origin\ncheck in Firefox could be bypassed by utilizing the importScripts Web\nWorker method. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-1213, CVE-2010-1207)\n\nO. Andersen that Firefox did not properly map undefined positions within\ncertain 8 bit encodings. An attacker could utilize this to perform\ncross-site scripting attacks. (CVE-2010-1210)\n\nMichal Zalewski discovered flaws in how Firefox processed the HTTP 204 (no\ncontent) code. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-1206)\n\nJordi Chancel discovered that Firefox did not properly handle when a server\nresponds to an HTTPS request with plaintext and then processes JavaScript\nhistory events. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-2751)\n\nChris Evans discovered that Firefox did not properly process improper CSS\nselectors. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-0654)\n\nSoroush Dalili discovered that Firefox did not properly handle script error\noutput. An attacker could use this to access URL parameters from other\ndomains. (CVE-2010-2754)\n\nOriginal advisory details:\n\n If was discovered that Firefox could be made to access freed memory. If a\n user were tricked into viewing a malicious site, a remote attacker could\n cause a denial of service or possibly execute arbitrary code with the\n privileges of the user invoking the program. (CVE-2010-1121)\n \n Several flaws were discovered in the browser engine of Firefox. If a\n user were tricked into viewing a malicious site, a remote attacker could\n cause a denial of service or possibly execute arbitrary code with the\n privileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\n CVE-2010-1202, CVE-2010-1203)\n \n A flaw was discovered in the way plugin instances interacted. An attacker\n could potentially exploit this and use one plugin to access freed memory from a\n second plugin to execute arbitrary code with the privileges of the user\n invoking the program. (CVE-2010-1198)\n \n An integer overflow was discovered in Firefox. If a user were tricked into\n viewing a malicious site, an attacker could overflow a buffer and cause a\n denial of service or possibly execute arbitrary code with the privileges of\n the user invoking the program. (CVE-2010-1196)\n \n Martin Barbella discovered an integer overflow in an XSLT node sorting\n routine. An attacker could exploit this to overflow a buffer and cause a\n denial of service or possibly execute arbitrary code with the privileges of\n the user invoking the program. (CVE-2010-1199)\n \n Michal Zalewski discovered that the focus behavior of Firefox could be\n subverted. If a user were tricked into viewing a malicious site, a remote\n attacker could use this to capture keystrokes. (CVE-2010-1125)\n \n Ilja van Sprundel discovered that the 'Content-Disposition: attachment'\n HTTP header was ignored when 'Content-Type: multipart' was also present.\n Under certain circumstances, this could potentially lead to cross-site\n scripting attacks. (CVE-2010-1197)\n \n Amit Klein discovered that Firefox did not seed its random number generator\n often enough. An attacker could exploit this to identify and track users\n across different web sites. (CVE-2008-5913)\n","is_hidden":false,"release_packages":{"jaunty":[{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.7+build2+nobinonly-0ubuntu0.9.04.1"},{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.7+build2+nobinonly-0ubuntu0.9.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2"}],"karmic":[{"name":"firefox-3.5","version":"3.6.7+build2+nobinonly-0ubuntu0.9.10.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","description":"empty transitional upgrade package for xulrunner-1.9","is_source":true},{"name":"firefox-3.5","version":"3.6.7+build2+nobinonly-0ubuntu0.9.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.6.7+build2+nobinonly-0ubuntu0.9.10.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2"}]},"type":"USN","cves_ids":["CVE-2008-5913","CVE-2010-1121","CVE-2010-1125","CVE-2010-1196","CVE-2010-1197","CVE-2010-1198","CVE-2010-1199","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1208","CVE-2010-1209","CVE-2010-1211","CVE-2010-1212","CVE-2010-1214","CVE-2010-1215","CVE-2010-2752","CVE-2010-2753","CVE-2010-1205","CVE-2010-1213","CVE-2010-1207","CVE-2010-1210","CVE-2010-1206","CVE-2010-2751","CVE-2010-0654","CVE-2010-2754"]},{"id":"USN-930-1","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to run programs as your login if it opened a\nspecially crafted file or website.\n","instructions":"Mozilla has changed the support model for Firefox and they no longer\nsupport version 3.0 of the browser. As a result, Ubuntu is providing an\nupgrade to Firefox 3.6 for Ubuntu 8.04 LTS users, which is the most current\nstable release of Firefox supported by Mozilla. When upgrading, users\nshould be aware of the following:\n\n- Firefox 3.6 does not support version 5 of the Sun Java plugin. Please use\n icedtea-java7-plugin or sun-java6-plugin instead.\n- After upgrading to Firefox 3.6.6, users may be prompted to upgrade 3rd\n party Add-Ons. In some cases, an Add-On will not be compatible with\n Firefox 3.6.6 and have no update available. In these cases, Firefox will\n notify the user that it is disabling the Add-On.\n- Upgrades to Ubuntu 8.10 from Ubuntu 8.04 LTS may break the browser.\n Ubuntu 8.10 is no longer officially supported and users are required to\n upgrade to 9.04 to receive active security support and a functional browser.\n- Font configuration cannot be controlled via Gnome settings. This is a\n known issue being tracked in https://launchpad.net/bugs/559149 and will\n be fixed in a later update.\n- helix-player is not currently supported in Firefox 3.6. This is a known\n issue and may be fixed in a future update.\n- RealAudio via the totem plugin is no longer supported in Firefox 3.6 in\n Ubuntu 8.04 LTS. Affected users navigating to Real content will be\n prompted to install optional community supported packages.\n- In Ubuntu 8.04 LTS the xine plugin is non-functional. After upgrading to\n Firefox 3.6, the plugin may cause the browser to crash, while in Firefox\n 3.0 it would be silently ignored. Users are advised to uninstall\n xine-plugin and/or gxineplugin.\n- Plugins using external helpers (such as Totem) may not close when using\n the Epiphany browser. This is a known issue being tracked in\n https://launchpad.net/bugs/599796 and will be fixed in a later update.\n This issue only affects Ubuntu 8.04 LTS.\n\nAfter a standard system upgrade you need to restart Firefox and any\napplications that use Xulrunner to effect the necessary changes.\n","references":[],"published":"2010-06-29T20:41:25.775109","description":"If was discovered that Firefox could be made to access freed memory. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. This issue only affected\nUbuntu 8.04 LTS. (CVE-2010-1121)\n\nSeveral flaws were discovered in the browser engine of Firefox. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\nCVE-2010-1202, CVE-2010-1203)\n\nA flaw was discovered in the way plugin instances interacted. An attacker\ncould potentially exploit this and use one plugin to access freed memory from a\nsecond plugin to execute arbitrary code with the privileges of the user\ninvoking the program. (CVE-2010-1198)\n\nAn integer overflow was discovered in Firefox. If a user were tricked into\nviewing a malicious site, an attacker could overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1196)\n\nMartin Barbella discovered an integer overflow in an XSLT node sorting\nroutine. An attacker could exploit this to overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1199)\n\nMichal Zalewski discovered that the focus behavior of Firefox could be\nsubverted. If a user were tricked into viewing a malicious site, a remote\nattacker could use this to capture keystrokes. (CVE-2010-1125)\n\nIlja van Sprundel discovered that the 'Content-Disposition: attachment'\nHTTP header was ignored when 'Content-Type: multipart' was also present.\nUnder certain circumstances, this could potentially lead to cross-site\nscripting attacks. (CVE-2010-1197)\n\nAmit Klein discovered that Firefox did not seed its random number generator\noften enough. An attacker could exploit this to identify and track users\nacross different web sites. (CVE-2008-5913)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.6.6+nobinonly-0ubuntu0.8.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.6+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.6+nobinonly-0ubuntu0.8.04.1"}],"lucid":[{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.6+nobinonly-0ubuntu0.10.04.1"},{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.6+nobinonly-0ubuntu0.10.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.6+nobinonly-0ubuntu0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2010-1121","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1198","CVE-2010-1196","CVE-2010-1199","CVE-2010-1125","CVE-2010-1197","CVE-2008-5913"]}]},{"id":"CVE-2010-1199","published":"2010-06-24T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the XSLT node sorting implementation in Mozilla Firefox\n3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and\nSeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code\nvia a large text value for a node.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"CVEs in Firefox are tracked in the xulrunner source packages. The\nmapping of xulrunner sources to firefox is:\nxulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS\nxulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS\nxulrunner-1.9: firefox-3.0\nxulrunner-1.9.1: firefox-3.5\nUbuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not\nthe system xulrunner-1.9.2, so it is tracked in the firefox source package."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-930-1","https://ubuntu.com/security/notices/USN-943-1","https://ubuntu.com/security/notices/USN-930-4","https://www.cve.org/CVERecord?id=CVE-2010-1199"],"bugs":[""],"patches":{"firefox":[],"xulrunner":[],"xulrunner-1.9":[],"xulrunner-1.9.1":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.6.6+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.6.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"2.0.6+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.5+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.9.2.7+build2+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-943-1","USN-930-4","USN-930-1"],"notices":[{"id":"USN-943-1","title":"Thunderbird vulnerabilities","summary":"","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":[],"published":"2010-07-06T13:01:19.099945","description":"Martin Barbella discovered an integer overflow in an XSLT node sorting\nroutine. An attacker could exploit this to overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1199)\n\nAn integer overflow was discovered in Thunderbird. If a user were tricked\ninto viewing malicious content, an attacker could overflow a buffer and\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1196)\n\nSeveral flaws were discovered in the browser engine of Thunderbird. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\nCVE-2010-1202, CVE-2010-1203)\n\nIf was discovered that Thunderbird could be made to access freed memory. If\na user were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1121)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"thunderbird","version":"3.0.5+build2+nobinonly-0ubuntu0.10.04.1","description":"","is_source":true},{"name":"thunderbird","version":"3.0.5+build2+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/3.0.5+build2+nobinonly-0ubuntu0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2010-1199","CVE-2010-1196","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1121"]},{"id":"USN-930-4","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to run programs as your login if it opened a\nspecially crafted file or website.\n","instructions":"Mozilla has changed the support model for Firefox and they no longer\nsupport version 3.0 of the browser and will only support version 3.5 of the\nbrowser for a while longer. As a result, Ubuntu is providing an upgrade to\nFirefox 3.6 for Ubuntu 9.04 and 9.10 users, which is the most current\nstable release of Firefox supported by Mozilla. When upgrading, users\nshould be aware of the following:\n\n- Firefox 3.6 does not support version 5 of the Sun Java plugin. Please use\n icedtea6-plugin or sun-java6-plugin instead.\n- After upgrading to Firefox 3.6.6, users may be prompted to upgrade 3rd\n party Add-Ons. In some cases, an Add-On will not be compatible with\n Firefox 3.6.6 and have no update available. In these cases, Firefox will\n notify the user that it is disabling the Add-On.\n- Font configuration cannot be controlled via Gnome settings. This is a\n known issue being tracked in https://launchpad.net/bugs/559149 and will\n be fixed in a later update.\n- helix-player is not currently supported in Firefox 3.6. This is a known\n issue and may be fixed in a future update.\n- Plugins using external helpers (such as Totem) may not close when using\n the Epiphany browser. This is a known issue being tracked in\n https://launchpad.net/bugs/599796 and will be fixed in a later update.\n This issue only affects Ubuntu 9.04.\n- The OpenJDK java plugin is not available in Ubuntu 9.04 on Sparc\n hardware. This will be fixed in a future update.\n\nAfter a standard system upgrade you need to restart Firefox and any\napplications that use Xulrunner to effect the necessary changes.\n","references":[],"published":"2010-07-23T09:48:19.360663","description":"USN-930-1 fixed vulnerabilities in Firefox and Xulrunner. This update\nprovides the corresponding updates for Ubuntu 9.04 and 9.10, along with\nadditional updates affecting Firefox 3.6.6.\n\nSeveral flaws were discovered in the browser engine of Firefox. If a user\nwere tricked into viewing a malicious site, a remote attacker could use\nthis to crash the browser or possibly run arbitrary code as the user\ninvoking the program. (CVE-2010-1208, CVE-2010-1209, CVE-2010-1211,\nCVE-2010-1212)\n\nAn integer overflow was discovered in how Firefox processed plugin\nparameters. An attacker could exploit this to crash the browser or possibly\nrun arbitrary code as the user invoking the program. (CVE-2010-1214)\n\nA flaw was discovered in the Firefox JavaScript engine. If a user were\ntricked into viewing a malicious site, a remote attacker code execute\narbitrary JavaScript with chrome privileges. (CVE-2010-1215)\n\nAn integer overflow was discovered in how Firefox processed CSS values. An\nattacker could exploit this to crash the browser or possibly run arbitrary\ncode as the user invoking the program. (CVE-2010-2752)\n\nAn integer overflow was discovered in how Firefox interpreted the XUL\n element. If a user were tricked into viewing a malicious site, a\nremote attacker could use this to crash the browser or possibly run\narbitrary code as the user invoking the program. (CVE-2010-2753)\n\nAki Helin discovered that libpng did not properly handle certain malformed\nPNG images. If a user were tricked into opening a crafted PNG file, an\nattacker could cause a denial of service or possibly execute arbitrary code\nwith the privileges of the user invoking the program. (CVE-2010-1205)\n\nYosuke Hasegawa and Vladimir Vukicevic discovered that the same-origin\ncheck in Firefox could be bypassed by utilizing the importScripts Web\nWorker method. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-1213, CVE-2010-1207)\n\nO. Andersen that Firefox did not properly map undefined positions within\ncertain 8 bit encodings. An attacker could utilize this to perform\ncross-site scripting attacks. (CVE-2010-1210)\n\nMichal Zalewski discovered flaws in how Firefox processed the HTTP 204 (no\ncontent) code. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-1206)\n\nJordi Chancel discovered that Firefox did not properly handle when a server\nresponds to an HTTPS request with plaintext and then processes JavaScript\nhistory events. An attacker could exploit this to spoof the location bar,\nsuch as in a phishing attack. (CVE-2010-2751)\n\nChris Evans discovered that Firefox did not properly process improper CSS\nselectors. If a user were tricked into viewing a malicious website, an\nattacker could exploit this to read data from other domains.\n(CVE-2010-0654)\n\nSoroush Dalili discovered that Firefox did not properly handle script error\noutput. An attacker could use this to access URL parameters from other\ndomains. (CVE-2010-2754)\n\nOriginal advisory details:\n\n If was discovered that Firefox could be made to access freed memory. If a\n user were tricked into viewing a malicious site, a remote attacker could\n cause a denial of service or possibly execute arbitrary code with the\n privileges of the user invoking the program. (CVE-2010-1121)\n \n Several flaws were discovered in the browser engine of Firefox. If a\n user were tricked into viewing a malicious site, a remote attacker could\n cause a denial of service or possibly execute arbitrary code with the\n privileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\n CVE-2010-1202, CVE-2010-1203)\n \n A flaw was discovered in the way plugin instances interacted. An attacker\n could potentially exploit this and use one plugin to access freed memory from a\n second plugin to execute arbitrary code with the privileges of the user\n invoking the program. (CVE-2010-1198)\n \n An integer overflow was discovered in Firefox. If a user were tricked into\n viewing a malicious site, an attacker could overflow a buffer and cause a\n denial of service or possibly execute arbitrary code with the privileges of\n the user invoking the program. (CVE-2010-1196)\n \n Martin Barbella discovered an integer overflow in an XSLT node sorting\n routine. An attacker could exploit this to overflow a buffer and cause a\n denial of service or possibly execute arbitrary code with the privileges of\n the user invoking the program. (CVE-2010-1199)\n \n Michal Zalewski discovered that the focus behavior of Firefox could be\n subverted. If a user were tricked into viewing a malicious site, a remote\n attacker could use this to capture keystrokes. (CVE-2010-1125)\n \n Ilja van Sprundel discovered that the 'Content-Disposition: attachment'\n HTTP header was ignored when 'Content-Type: multipart' was also present.\n Under certain circumstances, this could potentially lead to cross-site\n scripting attacks. (CVE-2010-1197)\n \n Amit Klein discovered that Firefox did not seed its random number generator\n often enough. An attacker could exploit this to identify and track users\n across different web sites. (CVE-2008-5913)\n","is_hidden":false,"release_packages":{"jaunty":[{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.7+build2+nobinonly-0ubuntu0.9.04.1"},{"name":"firefox-3.0","version":"3.6.7+build2+nobinonly-0ubuntu0.9.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.7+build2+nobinonly-0ubuntu0.9.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2"}],"karmic":[{"name":"firefox-3.5","version":"3.6.7+build2+nobinonly-0ubuntu0.9.10.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","description":"empty transitional upgrade package for xulrunner-1.9","is_source":true},{"name":"firefox-3.5","version":"3.6.7+build2+nobinonly-0ubuntu0.9.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.6.7+build2+nobinonly-0ubuntu0.9.10.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2"}]},"type":"USN","cves_ids":["CVE-2008-5913","CVE-2010-1121","CVE-2010-1125","CVE-2010-1196","CVE-2010-1197","CVE-2010-1198","CVE-2010-1199","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1208","CVE-2010-1209","CVE-2010-1211","CVE-2010-1212","CVE-2010-1214","CVE-2010-1215","CVE-2010-2752","CVE-2010-2753","CVE-2010-1205","CVE-2010-1213","CVE-2010-1207","CVE-2010-1210","CVE-2010-1206","CVE-2010-2751","CVE-2010-0654","CVE-2010-2754"]},{"id":"USN-930-1","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to run programs as your login if it opened a\nspecially crafted file or website.\n","instructions":"Mozilla has changed the support model for Firefox and they no longer\nsupport version 3.0 of the browser. As a result, Ubuntu is providing an\nupgrade to Firefox 3.6 for Ubuntu 8.04 LTS users, which is the most current\nstable release of Firefox supported by Mozilla. When upgrading, users\nshould be aware of the following:\n\n- Firefox 3.6 does not support version 5 of the Sun Java plugin. Please use\n icedtea-java7-plugin or sun-java6-plugin instead.\n- After upgrading to Firefox 3.6.6, users may be prompted to upgrade 3rd\n party Add-Ons. In some cases, an Add-On will not be compatible with\n Firefox 3.6.6 and have no update available. In these cases, Firefox will\n notify the user that it is disabling the Add-On.\n- Upgrades to Ubuntu 8.10 from Ubuntu 8.04 LTS may break the browser.\n Ubuntu 8.10 is no longer officially supported and users are required to\n upgrade to 9.04 to receive active security support and a functional browser.\n- Font configuration cannot be controlled via Gnome settings. This is a\n known issue being tracked in https://launchpad.net/bugs/559149 and will\n be fixed in a later update.\n- helix-player is not currently supported in Firefox 3.6. This is a known\n issue and may be fixed in a future update.\n- RealAudio via the totem plugin is no longer supported in Firefox 3.6 in\n Ubuntu 8.04 LTS. Affected users navigating to Real content will be\n prompted to install optional community supported packages.\n- In Ubuntu 8.04 LTS the xine plugin is non-functional. After upgrading to\n Firefox 3.6, the plugin may cause the browser to crash, while in Firefox\n 3.0 it would be silently ignored. Users are advised to uninstall\n xine-plugin and/or gxineplugin.\n- Plugins using external helpers (such as Totem) may not close when using\n the Epiphany browser. This is a known issue being tracked in\n https://launchpad.net/bugs/599796 and will be fixed in a later update.\n This issue only affects Ubuntu 8.04 LTS.\n\nAfter a standard system upgrade you need to restart Firefox and any\napplications that use Xulrunner to effect the necessary changes.\n","references":[],"published":"2010-06-29T20:41:25.775109","description":"If was discovered that Firefox could be made to access freed memory. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. This issue only affected\nUbuntu 8.04 LTS. (CVE-2010-1121)\n\nSeveral flaws were discovered in the browser engine of Firefox. If a\nuser were tricked into viewing a malicious site, a remote attacker could\ncause a denial of service or possibly execute arbitrary code with the\nprivileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,\nCVE-2010-1202, CVE-2010-1203)\n\nA flaw was discovered in the way plugin instances interacted. An attacker\ncould potentially exploit this and use one plugin to access freed memory from a\nsecond plugin to execute arbitrary code with the privileges of the user\ninvoking the program. (CVE-2010-1198)\n\nAn integer overflow was discovered in Firefox. If a user were tricked into\nviewing a malicious site, an attacker could overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1196)\n\nMartin Barbella discovered an integer overflow in an XSLT node sorting\nroutine. An attacker could exploit this to overflow a buffer and cause a\ndenial of service or possibly execute arbitrary code with the privileges of\nthe user invoking the program. (CVE-2010-1199)\n\nMichal Zalewski discovered that the focus behavior of Firefox could be\nsubverted. If a user were tricked into viewing a malicious site, a remote\nattacker could use this to capture keystrokes. (CVE-2010-1125)\n\nIlja van Sprundel discovered that the 'Content-Disposition: attachment'\nHTTP header was ignored when 'Content-Type: multipart' was also present.\nUnder certain circumstances, this could potentially lead to cross-site\nscripting attacks. (CVE-2010-1197)\n\nAmit Klein discovered that Firefox did not seed its random number generator\noften enough. An attacker could exploit this to identify and track users\nacross different web sites. (CVE-2008-5913)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.6.6+nobinonly-0ubuntu0.8.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.6+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.6+nobinonly-0ubuntu0.8.04.1"}],"lucid":[{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.6+nobinonly-0ubuntu0.10.04.1"},{"name":"firefox","version":"3.6.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.6+nobinonly-0ubuntu0.10.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.6+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.6+nobinonly-0ubuntu0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2010-1121","CVE-2010-1200","CVE-2010-1201","CVE-2010-1202","CVE-2010-1203","CVE-2010-1198","CVE-2010-1196","CVE-2010-1199","CVE-2010-1125","CVE-2010-1197","CVE-2008-5913"]}]}],"offset":72660,"limit":20,"total_results":79316}