{"cves":[{"id":"CVE-2009-4298","published":"2009-12-16T01:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before\n1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields\nwithin the user table, which allows attackers to obtain user account\ninformation via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4298"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.9.9.dfsg2-3","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.9.9.dfsg2-6","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.9.9.dfsg2-6","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.9.9.dfsg2-6","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.9.9.dfsg2-6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4297","published":"2009-12-16T01:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8\nbefore 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the\nauthentication of unspecified victims via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4297"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.9.9.dfsg2-2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.9.9.dfsg2-3","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.9.9.dfsg2-6","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.9.9.dfsg2-6","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.9.9.dfsg2-6","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.9.9.dfsg2-6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-7248","published":"2009-12-16T01:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nRuby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify\ntokens for requests with certain content types, which allows remote\nattackers to bypass cross-site request forgery (CSRF) protection for\nrequests to applications that rely on this protection, as demonstrated\nusing text/plain.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-7248"],"bugs":[""],"patches":{"rails":[]},"tags":{},"packages":[{"name":"rails","source":"https://ubuntu.com/security/cve?package=rails","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rails","debian":"https://tracker.debian.org/pkg/rails","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"2.2.3-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.3, 2.2.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4138","published":"2009-12-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ndrivers/firewire/ohci.c in the Linux kernel before 2.6.32-git9, when\npacket-per-buffer mode is used, allows local users to cause a denial of\nservice (NULL pointer dereference and system crash) or possibly have\nunknown other impact via an unspecified ioctl associated with receiving an\nISO packet that contains zero in the payload-length field.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-894-1","https://www.cve.org/CVERecord?id=CVE-2009-4138"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: 8c0c0cc2d9f4c523fde04bdfe41e4380dec8ee54"]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-27.65","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.6.27-17.45","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-18.59","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-19.56","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]}],"notices_ids":["USN-894-1"],"notices":[{"id":"USN-894-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change (except for Ubuntu 6.06)\nthe kernel updates have been given a new version number, which requires\nyou to recompile and reinstall all third party kernel modules you\nmight have installed. If you use linux-restricted-modules, you have to\nupdate that package as well to get modules which work with the new kernel\nversion. Unless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-server, linux-powerpc), a standard system\nupgrade will automatically perform this as well.\n","references":[],"published":"2010-02-05T00:37:17.812607","description":"Amerigo Wang and Eric Sesterhenn discovered that the HFS and ext4\nfilesystems did not correctly check certain disk structures. If a user\nwere tricked into mounting a specially crafted filesystem, a remote\nattacker could crash the system or gain root privileges. (CVE-2009-4020,\nCVE-2009-4308)\n\nIt was discovered that FUSE did not correctly check certain requests.\nA local attacker with access to FUSE mounts could exploit this to\ncrash the system or possibly gain root privileges. Ubuntu 9.10 was not\naffected. (CVE-2009-4021)\n\nIt was discovered that KVM did not correctly decode certain guest\ninstructions. A local attacker in a guest could exploit this to\ntrigger high scheduling latency in the host, leading to a denial of\nservice. Ubuntu 6.06 was not affected. (CVE-2009-4031)\n\nIt was discovered that the OHCI fireware driver did not correctly\nhandle certain ioctls. A local attacker could exploit this to crash\nthe system, or possibly gain root privileges. Ubuntu 6.06 was not\naffected. (CVE-2009-4138)\n\nTavis Ormandy discovered that the kernel did not correctly handle\nO_ASYNC on locked files. A local attacker could exploit this to gain\nroot privileges. Only Ubuntu 9.04 and 9.10 were affected. (CVE-2009-4141)\n\nNeil Horman and Eugene Teo discovered that the e1000 and e1000e\nnetwork drivers did not correctly check the size of Ethernet frames.\nAn attacker on the local network could send specially crafted traffic\nto bypass packet filters, crash the system, or possibly gain root\nprivileges. (CVE-2009-4536, CVE-2009-4538)\n\nIt was discovered that \"print-fatal-signals\" reporting could show\narbitrary kernel memory contents. A local attacker could exploit\nthis, leading to a loss of privacy. By default this is disabled in\nUbuntu and did not affect Ubuntu 6.06. (CVE-2010-0003)\n\nOlli Jarva and Tuomo Untinen discovered that IPv6 did not correctly\nhandle jumbo frames. A remote attacker could exploit this to crash the\nsystem, leading to a denial of service. Only Ubuntu 9.04 and 9.10 were\naffected. (CVE-2010-0006)\n\nFlorian Westphal discovered that bridging netfilter rules could be\nmodified by unprivileged users. A local attacker could disrupt network\ntraffic, leading to a denial of service. (CVE-2010-0007)\n\nAl Viro discovered that certain mremap operations could leak kernel\nmemory. A local attacker could exploit this to consume all available\nmemory, leading to a denial of service. (CVE-2010-0291)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-27.65","description":"","is_source":true},{"name":"linux-image-2.6.24-27-itanium","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-sparc64","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-lpia","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-hppa32","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-powerpc","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-lpiacompat","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-powerpc-smp","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-386","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-mckinley","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-sparc64-smp","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-xen","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-generic","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-virtual","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-server","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-rt","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-openvz","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-powerpc64-smp","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"},{"name":"linux-image-2.6.24-27-hppa64","version":"2.6.24-27.65","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-27.65"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.82","description":"","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.82","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.82"}],"intrepid":[{"name":"linux","version":"2.6.27-17.45","description":"","is_source":true},{"name":"linux-image-2.6.27-17-generic","version":"2.6.27-17.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-17.45"},{"name":"linux-image-2.6.27-17-virtual","version":"2.6.27-17.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-17.45"},{"name":"linux-image-2.6.27-17-server","version":"2.6.27-17.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-17.45"}],"jaunty":[{"name":"linux","version":"2.6.28-18.59","description":"","is_source":true},{"name":"linux-image-2.6.28-18-generic","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-server","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-iop32x","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-ixp4xx","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-lpia","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-virtual","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-imx51","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"},{"name":"linux-image-2.6.28-18-versatile","version":"2.6.28-18.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-18.59"}],"karmic":[{"name":"linux-mvl-dove","version":"2.6.31-211.22","description":"","is_source":true},{"name":"linux-fsl-imx51","version":"2.6.31-108.21","description":"","is_source":true},{"name":"linux-ec2","version":"2.6.31-304.10","description":"","is_source":true},{"name":"linux","version":"2.6.31-19.56","description":"","is_source":true},{"name":"linux-image-2.6.31-304-ec2","version":"2.6.31-304.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-304.10"},{"name":"linux-image-2.6.31-19-386","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-108-imx51","version":"2.6.31-108.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-108.21"},{"name":"linux-image-2.6.31-19-powerpc-smp","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-sparc64","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-211-dove-z0","version":"2.6.31-211.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-211.22"},{"name":"linux-image-2.6.31-19-virtual","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-server","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-powerpc64-smp","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-generic-pae","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-211-dove","version":"2.6.31-211.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.31-211.22"},{"name":"linux-image-2.6.31-19-generic","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-sparc64-smp","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-powerpc","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-lpia","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"},{"name":"linux-image-2.6.31-19-ia64","version":"2.6.31-19.56","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-19.56"}]},"type":"USN","cves_ids":["CVE-2009-4031","CVE-2009-4308","CVE-2009-4536","CVE-2009-4538","CVE-2009-4021","CVE-2010-0007","CVE-2010-0291","CVE-2009-4020","CVE-2009-4138","CVE-2010-0006","CVE-2010-0003","CVE-2009-4141"]}]},{"id":"CVE-2009-3554","published":"2009-12-15T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nTwiddle in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or\nJBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 writes the JMX\npassword, and other command-line arguments, to the twiddle.log file, which\nallows local users to obtain sensitive information by reading this file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3554"],"bugs":[""],"patches":{"jbossas4":[]},"tags":{},"packages":[{"name":"jbossas4","source":"https://ubuntu.com/security/cve?package=jbossas4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jbossas4","debian":"https://tracker.debian.org/pkg/jbossas4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"4.2.2.GA-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"4.2.2.GA-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"4.2.3.GA-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"4.2.3.GA-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.2.0.CP08, 4.3.0.CP07","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2405","published":"2009-12-15T18:30:00","updated_at":"2025-08-04T19:23:31.266285+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in the Web Console in\nthe Application Server in Red Hat JBoss Enterprise Application Platform\n(aka JBoss EAP or JBEAP) 4.2.0 before 4.2.0.CP08, 4.2.2GA, 4.3 before\n4.3.0.CP07, and 5.1.0GA allow remote attackers to inject arbitrary web\nscript or HTML via the (1) monitorName, (2) objectName, (3) attribute, or\n(4) period parameter to createSnapshot.jsp, or the (5) monitorName, (6)\nobjectName, (7) attribute, (8) threshold, (9) period, or (10) enabled\nparameter to createThresholdMonitor.jsp. NOTE: some of these details are\nobtained from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2405"],"bugs":[""],"patches":{"jbossas4":[]},"tags":{},"packages":[{"name":"jbossas4","source":"https://ubuntu.com/security/cve?package=jbossas4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jbossas4","debian":"https://tracker.debian.org/pkg/jbossas4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.2.2.GA","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-1380","published":"2009-12-15T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in JMX-Console in JBossAs in Red\nHat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2\nbefore 4.2.0.CP08 and 4.3 before 4.3.0.CP07 allows remote attackers to\ninject arbitrary web script or HTML via the filter parameter, related to\nthe key property and the position of quote and colon characters.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-1380"],"bugs":[""],"patches":{"jbossas4":[]},"tags":{},"packages":[{"name":"jbossas4","source":"https://ubuntu.com/security/cve?package=jbossas4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jbossas4","debian":"https://tracker.debian.org/pkg/jbossas4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"4.2.2.GA-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"4.2.2.GA-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"4.2.3.GA-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"4.2.3.GA-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.2.0.CP08, 4.3.0.CP07","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4324","published":"2009-12-15T02:30:00","updated_at":"2025-08-25T19:51:09.955906+00:00","description":"\nUse-after-free vulnerability in the Doc.media.newPlayer method in\nMultimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before\n8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary\ncode via a crafted PDF file using ZLib compressed streams, as exploited in\nthe wild in December 2009.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-4324","https://www.cisa.gov/known-exploited-vulnerabilities-catalog"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"9.3.1-1hardy2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"9.3.1-1intrepid1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"9.3.1-1jaunty1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"9.3.1-1karmic1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-4136","published":"2009-12-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19,\n8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not\nproperly manage session-local state during execution of an index function\nby a database superuser, which allows remote authenticated users to gain\nprivileges via a table with crafted index functions, as demonstrated by\nfunctions that modify (1) search_path or (2) a prepared statement, a\nrelated issue to CVE-2007-6600 and CVE-2009-3230.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-876-1","https://www.cve.org/CVERecord?id=CVE-2009-4136"],"bugs":[""],"patches":{"postgresql-8.4":[],"postgresql-7.4":[],"postgresql-8.1":[],"postgresql-8.3":[],"postgresql-8.2":[],"postgresql-8.0":[]},"tags":{},"packages":[{"name":"postgresql-7.4","source":"https://ubuntu.com/security/cve?package=postgresql-7.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-7.4","debian":"https://tracker.debian.org/pkg/postgresql-7.4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.0","source":"https://ubuntu.com/security/cve?package=postgresql-8.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.0","debian":"https://tracker.debian.org/pkg/postgresql-8.0","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.1","source":"https://ubuntu.com/security/cve?package=postgresql-8.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.1","debian":"https://tracker.debian.org/pkg/postgresql-8.1","statuses":[{"release_codename":"dapper","status":"released","description":"8.1.19-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.2","source":"https://ubuntu.com/security/cve?package=postgresql-8.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.2","debian":"https://tracker.debian.org/pkg/postgresql-8.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.3","source":"https://ubuntu.com/security/cve?package=postgresql-8.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.3","debian":"https://tracker.debian.org/pkg/postgresql-8.3","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"8.3.9-0ubuntu8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"8.3.9-0ubuntu8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"8.3.9-0ubuntu9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.4","source":"https://ubuntu.com/security/cve?package=postgresql-8.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.4","debian":"https://tracker.debian.org/pkg/postgresql-8.4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"8.4.2-0ubuntu9.10","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-876-1"],"notices":[{"id":"USN-876-1","title":"PostgreSQL vulnerabilities","summary":"PostgreSQL vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-01-03T20:39:20.945717","description":"It was discovered that PostgreSQL did not properly handle certificates with\nNULL characters in the Common Name field of X.509 certificates. An attacker\ncould exploit this to perform a machine-in-the-middle attack to view sensitive\ninformation or alter encrypted communications. (CVE-2009-4034)\n\nIt was discovered that PostgreSQL did not properly manage session-local\nstate. A remote authenticated user could exploit this to escalate\npriviliges within PostgreSQL. (CVE-2009-4136)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"postgresql-8.1","version":"8.1.19-0ubuntu0.6.06","description":"","is_source":true},{"name":"postgresql-8.1","version":"8.1.19-0ubuntu0.6.06","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.1","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.1/8.1.19-0ubuntu0.6.06"}],"hardy":[{"name":"postgresql-8.3","version":"8.3.9-0ubuntu8.04","description":"","is_source":true},{"name":"postgresql-8.3","version":"8.3.9-0ubuntu8.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.9-0ubuntu8.04"}],"intrepid":[{"name":"postgresql-8.3","version":"8.3.9-0ubuntu8.10","description":"","is_source":true},{"name":"postgresql-8.3","version":"8.3.9-0ubuntu8.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.9-0ubuntu8.10"}],"jaunty":[{"name":"postgresql-8.3","version":"8.3.9-0ubuntu9.04","description":"","is_source":true},{"name":"postgresql-8.3","version":"8.3.9-0ubuntu9.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.9-0ubuntu9.04"}],"karmic":[{"name":"postgresql-8.4","version":"8.4.2-0ubuntu9.10","description":"","is_source":true},{"name":"postgresql-8.4","version":"8.4.2-0ubuntu9.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4/8.4.2-0ubuntu9.10"}]},"type":"USN","cves_ids":["CVE-2009-4034","CVE-2009-4136"]}]},{"id":"CVE-2009-4034","published":"2009-12-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19,\n8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not\nproperly handle a '\\0' character in a domain name in the subject's Common\nName (CN) field of an X.509 certificate, which (1) allows man-in-the-middle\nattackers to spoof arbitrary SSL-based PostgreSQL servers via a crafted\nserver certificate issued by a legitimate Certification Authority, and (2)\nallows remote attackers to bypass intended client-hostname restrictions via\na crafted client certificate issued by a legitimate Certification\nAuthority, a related issue to CVE-2009-2408.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-876-1","https://www.cve.org/CVERecord?id=CVE-2009-4034"],"bugs":[""],"patches":{"postgresql-8.4":[],"postgresql-7.4":[],"postgresql-8.1":[],"postgresql-8.3":[],"postgresql-8.2":[],"postgresql-8.0":[]},"tags":{},"packages":[{"name":"postgresql-7.4","source":"https://ubuntu.com/security/cve?package=postgresql-7.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-7.4","debian":"https://tracker.debian.org/pkg/postgresql-7.4","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.0","source":"https://ubuntu.com/security/cve?package=postgresql-8.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.0","debian":"https://tracker.debian.org/pkg/postgresql-8.0","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.1","source":"https://ubuntu.com/security/cve?package=postgresql-8.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.1","debian":"https://tracker.debian.org/pkg/postgresql-8.1","statuses":[{"release_codename":"dapper","status":"released","description":"8.1.19-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.2","source":"https://ubuntu.com/security/cve?package=postgresql-8.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.2","debian":"https://tracker.debian.org/pkg/postgresql-8.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.3","source":"https://ubuntu.com/security/cve?package=postgresql-8.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.3","debian":"https://tracker.debian.org/pkg/postgresql-8.3","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"8.3.9-0ubuntu8.04","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"8.3.9-0ubuntu8.10","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"8.3.9-0ubuntu9.04","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.4","source":"https://ubuntu.com/security/cve?package=postgresql-8.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.4","debian":"https://tracker.debian.org/pkg/postgresql-8.4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"8.4.2-0ubuntu9.10","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-876-1"],"notices":[{"id":"USN-876-1","title":"PostgreSQL vulnerabilities","summary":"PostgreSQL vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-01-03T20:39:20.945717","description":"It was discovered that PostgreSQL did not properly handle certificates with\nNULL characters in the Common Name field of X.509 certificates. An attacker\ncould exploit this to perform a machine-in-the-middle attack to view sensitive\ninformation or alter encrypted communications. (CVE-2009-4034)\n\nIt was discovered that PostgreSQL did not properly manage session-local\nstate. A remote authenticated user could exploit this to escalate\npriviliges within PostgreSQL. (CVE-2009-4136)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"postgresql-8.1","version":"8.1.19-0ubuntu0.6.06","description":"","is_source":true},{"name":"postgresql-8.1","version":"8.1.19-0ubuntu0.6.06","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.1","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.1/8.1.19-0ubuntu0.6.06"}],"hardy":[{"name":"postgresql-8.3","version":"8.3.9-0ubuntu8.04","description":"","is_source":true},{"name":"postgresql-8.3","version":"8.3.9-0ubuntu8.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.9-0ubuntu8.04"}],"intrepid":[{"name":"postgresql-8.3","version":"8.3.9-0ubuntu8.10","description":"","is_source":true},{"name":"postgresql-8.3","version":"8.3.9-0ubuntu8.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.9-0ubuntu8.10"}],"jaunty":[{"name":"postgresql-8.3","version":"8.3.9-0ubuntu9.04","description":"","is_source":true},{"name":"postgresql-8.3","version":"8.3.9-0ubuntu9.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.9-0ubuntu9.04"}],"karmic":[{"name":"postgresql-8.4","version":"8.4.2-0ubuntu9.10","description":"","is_source":true},{"name":"postgresql-8.4","version":"8.4.2-0ubuntu9.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4/8.4.2-0ubuntu9.10"}]},"type":"USN","cves_ids":["CVE-2009-4034","CVE-2009-4136"]}]},{"id":"CVE-2009-3986","published":"2009-12-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before\n2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome\nprivileges by leveraging a reference to a chrome window from a content\nwindow, related to the window.opener property.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-874-1","https://ubuntu.com/security/notices/USN-873-1","https://www.cve.org/CVERecord?id=CVE-2009-3986"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9":[],"xulrunner-1.9.1":[],"seamonkey":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.1","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.16+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.16+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.16+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.0.16","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.1.6+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-873-1","USN-874-1"],"notices":[{"id":"USN-873-1","title":"Firefox 3.0 and Xulrunner 1.9 vulnerabilities","summary":"Firefox 3.0 and Xulrunner 1.9 vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner to effect the necessary changes.\n","references":[],"published":"2009-12-18T21:52:43.805714","description":"Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and\nDavid James discovered several flaws in the browser and JavaScript engines\nof Firefox. If a user were tricked into viewing a malicious website, a\nremote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3979, CVE-2009-3981, CVE-2009-3986)\n\nTakehiro Takahashi discovered flaws in the NTLM implementation in Firefox.\nIf an NTLM authenticated user visited a malicious website, a remote\nattacker could send requests to other applications, authenticated as the\nuser. (CVE-2009-3983)\n\nJonathan Morgan discovered that Firefox did not properly display SSL\nindicators under certain circumstances. This could be used by an attacker\nto spoof an encrypted page, such as in a phishing attack. (CVE-2009-3984)\n\nJordi Chancel discovered that Firefox did not properly display invalid URLs\nfor a blank page. If a user were tricked into accessing a malicious\nwebsite, an attacker could exploit this to spoof the location bar, such as\nin a phishing attack. (CVE-2009-3985)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.16+nobinonly-0ubuntu0.8.04.1"}],"intrepid":[{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.8.10.1"},{"name":"abrowser","version":"3.0.16+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.8.10.1"},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.16+nobinonly-0ubuntu0.8.10.1"}],"jaunty":[{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.9.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.9.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.9.04.1"},{"name":"abrowser","version":"3.0.16+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.9.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.16+nobinonly-0ubuntu0.9.04.1"}]},"type":"USN","cves_ids":["CVE-2009-3979","CVE-2009-3981","CVE-2009-3986","CVE-2009-3983","CVE-2009-3984","CVE-2009-3985"]},{"id":"USN-874-1","title":"Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities","summary":"Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner to effect the necessary changes.\n","references":[],"published":"2009-12-18T22:31:03.524958","description":"Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and\nDavid James discovered several flaws in the browser and JavaScript engines\nof Firefox. If a user were tricked into viewing a malicious website, a\nremote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3979, CVE-2009-3980, CVE-2009-3982, CVE-2009-3986)\n\nTakehiro Takahashi discovered flaws in the NTLM implementation in Firefox.\nIf an NTLM authenticated user visited a malicious website, a remote\nattacker could send requests to other applications, authenticated as the\nuser. (CVE-2009-3983)\n\nJonathan Morgan discovered that Firefox did not properly display SSL\nindicators under certain circumstances. This could be used by an attacker\nto spoof an encrypted page, such as in a phishing attack. (CVE-2009-3984)\n\nJordi Chancel discovered that Firefox did not properly display invalid URLs\nfor a blank page. If a user were tricked into accessing a malicious\nwebsite, an attacker could exploit this to spoof the location bar, such as\nin a phishing attack. (CVE-2009-3985)\n\nDavid Keeler, Bob Clary, and Dan Kaminsky discovered several flaws in third\nparty media libraries. If a user were tricked into opening a crafted media\nfile, a remote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3388, CVE-2009-3389)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"xulrunner-1.9.1","version":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"firefox-3.5","version":"3.5.6+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"xulrunner-1.9.1","version":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1/1.9.1.6+nobinonly-0ubuntu0.9.10.1"},{"name":"firefox-3.5","version":"3.5.6+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.5.6+nobinonly-0ubuntu0.9.10.1"}]},"type":"USN","cves_ids":["CVE-2009-3979","CVE-2009-3982","CVE-2009-3388","CVE-2009-3986","CVE-2009-3984","CVE-2009-3985","CVE-2009-3389","CVE-2009-3980","CVE-2009-3983"]}]},{"id":"CVE-2009-3985","published":"2009-12-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before\n2.0.1, allows remote attackers to associate spoofed content with an invalid\nURL by setting document.location to this URL, and then writing arbitrary\nweb script or HTML to the associated blank document, a related issue to\nCVE-2009-2654.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-874-1","https://ubuntu.com/security/notices/USN-873-1","https://www.cve.org/CVERecord?id=CVE-2009-3985"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9":[],"xulrunner-1.9.1":[],"seamonkey":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.1","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.16+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.16+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.16+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.0.16","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.1.6+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-873-1","USN-874-1"],"notices":[{"id":"USN-873-1","title":"Firefox 3.0 and Xulrunner 1.9 vulnerabilities","summary":"Firefox 3.0 and Xulrunner 1.9 vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner to effect the necessary changes.\n","references":[],"published":"2009-12-18T21:52:43.805714","description":"Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and\nDavid James discovered several flaws in the browser and JavaScript engines\nof Firefox. If a user were tricked into viewing a malicious website, a\nremote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3979, CVE-2009-3981, CVE-2009-3986)\n\nTakehiro Takahashi discovered flaws in the NTLM implementation in Firefox.\nIf an NTLM authenticated user visited a malicious website, a remote\nattacker could send requests to other applications, authenticated as the\nuser. (CVE-2009-3983)\n\nJonathan Morgan discovered that Firefox did not properly display SSL\nindicators under certain circumstances. This could be used by an attacker\nto spoof an encrypted page, such as in a phishing attack. (CVE-2009-3984)\n\nJordi Chancel discovered that Firefox did not properly display invalid URLs\nfor a blank page. If a user were tricked into accessing a malicious\nwebsite, an attacker could exploit this to spoof the location bar, such as\nin a phishing attack. (CVE-2009-3985)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.16+nobinonly-0ubuntu0.8.04.1"}],"intrepid":[{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.8.10.1"},{"name":"abrowser","version":"3.0.16+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.8.10.1"},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.16+nobinonly-0ubuntu0.8.10.1"}],"jaunty":[{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.9.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.9.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.9.04.1"},{"name":"abrowser","version":"3.0.16+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.9.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.16+nobinonly-0ubuntu0.9.04.1"}]},"type":"USN","cves_ids":["CVE-2009-3979","CVE-2009-3981","CVE-2009-3986","CVE-2009-3983","CVE-2009-3984","CVE-2009-3985"]},{"id":"USN-874-1","title":"Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities","summary":"Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner to effect the necessary changes.\n","references":[],"published":"2009-12-18T22:31:03.524958","description":"Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and\nDavid James discovered several flaws in the browser and JavaScript engines\nof Firefox. If a user were tricked into viewing a malicious website, a\nremote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3979, CVE-2009-3980, CVE-2009-3982, CVE-2009-3986)\n\nTakehiro Takahashi discovered flaws in the NTLM implementation in Firefox.\nIf an NTLM authenticated user visited a malicious website, a remote\nattacker could send requests to other applications, authenticated as the\nuser. (CVE-2009-3983)\n\nJonathan Morgan discovered that Firefox did not properly display SSL\nindicators under certain circumstances. This could be used by an attacker\nto spoof an encrypted page, such as in a phishing attack. (CVE-2009-3984)\n\nJordi Chancel discovered that Firefox did not properly display invalid URLs\nfor a blank page. If a user were tricked into accessing a malicious\nwebsite, an attacker could exploit this to spoof the location bar, such as\nin a phishing attack. (CVE-2009-3985)\n\nDavid Keeler, Bob Clary, and Dan Kaminsky discovered several flaws in third\nparty media libraries. If a user were tricked into opening a crafted media\nfile, a remote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3388, CVE-2009-3389)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"xulrunner-1.9.1","version":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"firefox-3.5","version":"3.5.6+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"xulrunner-1.9.1","version":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1/1.9.1.6+nobinonly-0ubuntu0.9.10.1"},{"name":"firefox-3.5","version":"3.5.6+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.5.6+nobinonly-0ubuntu0.9.10.1"}]},"type":"USN","cves_ids":["CVE-2009-3979","CVE-2009-3982","CVE-2009-3388","CVE-2009-3986","CVE-2009-3984","CVE-2009-3985","CVE-2009-3389","CVE-2009-3980","CVE-2009-3983"]}]},{"id":"CVE-2009-3984","published":"2009-12-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before\n2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or\na file URL by setting document.location to an https URL corresponding to a\nsite that responds with a No Content (aka 204) status code and an empty\nbody.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-874-1","https://ubuntu.com/security/notices/USN-873-1","https://www.cve.org/CVERecord?id=CVE-2009-3984"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9":[],"xulrunner-1.9.1":[],"seamonkey":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.1","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.16+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.16+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.16+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.0.16","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.1.6+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-873-1","USN-874-1"],"notices":[{"id":"USN-873-1","title":"Firefox 3.0 and Xulrunner 1.9 vulnerabilities","summary":"Firefox 3.0 and Xulrunner 1.9 vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner to effect the necessary changes.\n","references":[],"published":"2009-12-18T21:52:43.805714","description":"Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and\nDavid James discovered several flaws in the browser and JavaScript engines\nof Firefox. If a user were tricked into viewing a malicious website, a\nremote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3979, CVE-2009-3981, CVE-2009-3986)\n\nTakehiro Takahashi discovered flaws in the NTLM implementation in Firefox.\nIf an NTLM authenticated user visited a malicious website, a remote\nattacker could send requests to other applications, authenticated as the\nuser. (CVE-2009-3983)\n\nJonathan Morgan discovered that Firefox did not properly display SSL\nindicators under certain circumstances. This could be used by an attacker\nto spoof an encrypted page, such as in a phishing attack. (CVE-2009-3984)\n\nJordi Chancel discovered that Firefox did not properly display invalid URLs\nfor a blank page. If a user were tricked into accessing a malicious\nwebsite, an attacker could exploit this to spoof the location bar, such as\nin a phishing attack. (CVE-2009-3985)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.16+nobinonly-0ubuntu0.8.04.1"}],"intrepid":[{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.8.10.1"},{"name":"abrowser","version":"3.0.16+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.8.10.1"},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.16+nobinonly-0ubuntu0.8.10.1"}],"jaunty":[{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.9.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.9.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.9.04.1"},{"name":"abrowser","version":"3.0.16+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.9.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.16+nobinonly-0ubuntu0.9.04.1"}]},"type":"USN","cves_ids":["CVE-2009-3979","CVE-2009-3981","CVE-2009-3986","CVE-2009-3983","CVE-2009-3984","CVE-2009-3985"]},{"id":"USN-874-1","title":"Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities","summary":"Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner to effect the necessary changes.\n","references":[],"published":"2009-12-18T22:31:03.524958","description":"Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and\nDavid James discovered several flaws in the browser and JavaScript engines\nof Firefox. If a user were tricked into viewing a malicious website, a\nremote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3979, CVE-2009-3980, CVE-2009-3982, CVE-2009-3986)\n\nTakehiro Takahashi discovered flaws in the NTLM implementation in Firefox.\nIf an NTLM authenticated user visited a malicious website, a remote\nattacker could send requests to other applications, authenticated as the\nuser. (CVE-2009-3983)\n\nJonathan Morgan discovered that Firefox did not properly display SSL\nindicators under certain circumstances. This could be used by an attacker\nto spoof an encrypted page, such as in a phishing attack. (CVE-2009-3984)\n\nJordi Chancel discovered that Firefox did not properly display invalid URLs\nfor a blank page. If a user were tricked into accessing a malicious\nwebsite, an attacker could exploit this to spoof the location bar, such as\nin a phishing attack. (CVE-2009-3985)\n\nDavid Keeler, Bob Clary, and Dan Kaminsky discovered several flaws in third\nparty media libraries. If a user were tricked into opening a crafted media\nfile, a remote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3388, CVE-2009-3389)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"xulrunner-1.9.1","version":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"firefox-3.5","version":"3.5.6+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"xulrunner-1.9.1","version":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1/1.9.1.6+nobinonly-0ubuntu0.9.10.1"},{"name":"firefox-3.5","version":"3.5.6+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.5.6+nobinonly-0ubuntu0.9.10.1"}]},"type":"USN","cves_ids":["CVE-2009-3979","CVE-2009-3982","CVE-2009-3388","CVE-2009-3986","CVE-2009-3984","CVE-2009-3985","CVE-2009-3389","CVE-2009-3980","CVE-2009-3983"]}]},{"id":"CVE-2009-3983","published":"2009-12-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before\n2.0.1, allows remote attackers to send authenticated requests to arbitrary\napplications by replaying the NTLM credentials of a browser user.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"CVEs in Firefox are tracked in the xulrunner source packages. The\nmapping of xulrunner sources to firefox is:\nxulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS\nxulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS\nxulrunner-1.9: firefox-3.0\nxulrunner-1.9.1: firefox-3.5\nUbuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not\nthe system xulrunner-1.9.2, so it is tracked in the firefox source package."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-874-1","https://ubuntu.com/security/notices/USN-873-1","https://ubuntu.com/security/notices/USN-915-1","https://www.cve.org/CVERecord?id=CVE-2009-3983"],"bugs":[""],"patches":{"firefox":[],"xulrunner":[],"xulrunner-1.9":[],"xulrunner-1.9.1":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.0.4+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.0.4+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.0.4+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.1","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.24+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.0.24+build1+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.0.24+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.0.24+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.0.3+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.0.3+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.0.3+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.0.3+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.24","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.16+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.16+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.16+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.0.16","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.1.6+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-873-1","USN-915-1","USN-874-1"],"notices":[{"id":"USN-873-1","title":"Firefox 3.0 and Xulrunner 1.9 vulnerabilities","summary":"Firefox 3.0 and Xulrunner 1.9 vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner to effect the necessary changes.\n","references":[],"published":"2009-12-18T21:52:43.805714","description":"Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and\nDavid James discovered several flaws in the browser and JavaScript engines\nof Firefox. If a user were tricked into viewing a malicious website, a\nremote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3979, CVE-2009-3981, CVE-2009-3986)\n\nTakehiro Takahashi discovered flaws in the NTLM implementation in Firefox.\nIf an NTLM authenticated user visited a malicious website, a remote\nattacker could send requests to other applications, authenticated as the\nuser. (CVE-2009-3983)\n\nJonathan Morgan discovered that Firefox did not properly display SSL\nindicators under certain circumstances. This could be used by an attacker\nto spoof an encrypted page, such as in a phishing attack. (CVE-2009-3984)\n\nJordi Chancel discovered that Firefox did not properly display invalid URLs\nfor a blank page. If a user were tricked into accessing a malicious\nwebsite, an attacker could exploit this to spoof the location bar, such as\nin a phishing attack. (CVE-2009-3985)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.16+nobinonly-0ubuntu0.8.04.1"}],"intrepid":[{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.8.10.1"},{"name":"abrowser","version":"3.0.16+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.8.10.1"},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.16+nobinonly-0ubuntu0.8.10.1"}],"jaunty":[{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.9.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.9.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.9.04.1"},{"name":"abrowser","version":"3.0.16+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.9.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.16+nobinonly-0ubuntu0.9.04.1"}]},"type":"USN","cves_ids":["CVE-2009-3979","CVE-2009-3981","CVE-2009-3986","CVE-2009-3983","CVE-2009-3984","CVE-2009-3985"]},{"id":"USN-915-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2010-03-18T14:08:21.930607","description":"Several flaws were discovered in the JavaScript engine of Thunderbird. If a\nuser had JavaScript enabled and were tricked into viewing malicious web\ncontent, a remote attacker could cause a denial of service or possibly\nexecute arbitrary code with the privileges of the user invoking the\nprogram. (CVE-2009-0689, CVE-2009-2463, CVE-2009-3075)\n\nJosh Soref discovered that the BinHex decoder used in Thunderbird contained\na flaw. If a user were tricked into viewing malicious content, a remote\nattacker could cause a denial of service or possibly execute arbitrary code\nwith the privileges of the user invoking the program. (CVE-2009-3072)\n\nIt was discovered that Thunderbird did not properly manage memory when\nusing XUL tree elements. If a user were tricked into viewing malicious\ncontent, a remote attacker could cause a denial of service or possibly\nexecute arbitrary code with the privileges of the user invoking the\nprogram. (CVE-2009-3077)\n\nJesse Ruderman and Sid Stamm discovered that Thunderbird did not properly\ndisplay filenames containing right-to-left (RTL) override characters. If a\nuser were tricked into opening a malicious file with a crafted filename, an\nattacker could exploit this to trick the user into opening a different file\nthan the user expected. (CVE-2009-3376)\n\nTakehiro Takahashi discovered flaws in the NTLM implementation in\nThunderbird. If an NTLM authenticated user opened content containing links\nto a malicious website, a remote attacker could send requests to other\napplications, authenticated as the user. (CVE-2009-3983)\n\nLudovic Hirlimann discovered a flaw in the way Thunderbird indexed certain\nmessages with attachments. A remote attacker could send specially crafted\ncontent and cause a denial of service or possibly execute arbitrary code\nwith the privileges of the user invoking the program. (CVE-2010-0163)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"thunderbird","version":"2.0.0.24+build1+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.24+build1+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.24+build1+nobinonly-0ubuntu0.8.04.1"}],"intrepid":[{"name":"thunderbird","version":"2.0.0.24+build1+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.24+build1+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.24+build1+nobinonly-0ubuntu0.8.10.1"}],"jaunty":[{"name":"thunderbird","version":"2.0.0.24+build1+nobinonly-0ubuntu0.9.04.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.24+build1+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.24+build1+nobinonly-0ubuntu0.9.04.1"}],"karmic":[{"name":"thunderbird","version":"2.0.0.24+build1+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.24+build1+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.24+build1+nobinonly-0ubuntu0.9.10.1"}]},"type":"USN","cves_ids":["CVE-2009-0689","CVE-2009-2463","CVE-2009-3072","CVE-2009-3075","CVE-2009-3077","CVE-2009-3376","CVE-2009-3983","CVE-2010-0163"]},{"id":"USN-874-1","title":"Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities","summary":"Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner to effect the necessary changes.\n","references":[],"published":"2009-12-18T22:31:03.524958","description":"Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and\nDavid James discovered several flaws in the browser and JavaScript engines\nof Firefox. If a user were tricked into viewing a malicious website, a\nremote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3979, CVE-2009-3980, CVE-2009-3982, CVE-2009-3986)\n\nTakehiro Takahashi discovered flaws in the NTLM implementation in Firefox.\nIf an NTLM authenticated user visited a malicious website, a remote\nattacker could send requests to other applications, authenticated as the\nuser. (CVE-2009-3983)\n\nJonathan Morgan discovered that Firefox did not properly display SSL\nindicators under certain circumstances. This could be used by an attacker\nto spoof an encrypted page, such as in a phishing attack. (CVE-2009-3984)\n\nJordi Chancel discovered that Firefox did not properly display invalid URLs\nfor a blank page. If a user were tricked into accessing a malicious\nwebsite, an attacker could exploit this to spoof the location bar, such as\nin a phishing attack. (CVE-2009-3985)\n\nDavid Keeler, Bob Clary, and Dan Kaminsky discovered several flaws in third\nparty media libraries. If a user were tricked into opening a crafted media\nfile, a remote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3388, CVE-2009-3389)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"xulrunner-1.9.1","version":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"firefox-3.5","version":"3.5.6+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"xulrunner-1.9.1","version":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1/1.9.1.6+nobinonly-0ubuntu0.9.10.1"},{"name":"firefox-3.5","version":"3.5.6+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.5.6+nobinonly-0ubuntu0.9.10.1"}]},"type":"USN","cves_ids":["CVE-2009-3979","CVE-2009-3982","CVE-2009-3388","CVE-2009-3986","CVE-2009-3984","CVE-2009-3985","CVE-2009-3389","CVE-2009-3980","CVE-2009-3983"]}]},{"id":"CVE-2009-3982","published":"2009-12-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in the JavaScript engine in Mozilla\nFirefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow\nremote attackers to cause a denial of service (memory corruption and\napplication crash) or possibly execute arbitrary code via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-874-1","https://www.cve.org/CVERecord?id=CVE-2009-3982"],"bugs":[""],"patches":{"xulrunner-1.9.1":[],"seamonkey":[]},"tags":{},"packages":[{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.1","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.1.6+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-874-1"],"notices":[{"id":"USN-874-1","title":"Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities","summary":"Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner to effect the necessary changes.\n","references":[],"published":"2009-12-18T22:31:03.524958","description":"Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and\nDavid James discovered several flaws in the browser and JavaScript engines\nof Firefox. If a user were tricked into viewing a malicious website, a\nremote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3979, CVE-2009-3980, CVE-2009-3982, CVE-2009-3986)\n\nTakehiro Takahashi discovered flaws in the NTLM implementation in Firefox.\nIf an NTLM authenticated user visited a malicious website, a remote\nattacker could send requests to other applications, authenticated as the\nuser. (CVE-2009-3983)\n\nJonathan Morgan discovered that Firefox did not properly display SSL\nindicators under certain circumstances. This could be used by an attacker\nto spoof an encrypted page, such as in a phishing attack. (CVE-2009-3984)\n\nJordi Chancel discovered that Firefox did not properly display invalid URLs\nfor a blank page. If a user were tricked into accessing a malicious\nwebsite, an attacker could exploit this to spoof the location bar, such as\nin a phishing attack. (CVE-2009-3985)\n\nDavid Keeler, Bob Clary, and Dan Kaminsky discovered several flaws in third\nparty media libraries. If a user were tricked into opening a crafted media\nfile, a remote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3388, CVE-2009-3389)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"xulrunner-1.9.1","version":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"firefox-3.5","version":"3.5.6+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"xulrunner-1.9.1","version":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1/1.9.1.6+nobinonly-0ubuntu0.9.10.1"},{"name":"firefox-3.5","version":"3.5.6+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.5.6+nobinonly-0ubuntu0.9.10.1"}]},"type":"USN","cves_ids":["CVE-2009-3979","CVE-2009-3982","CVE-2009-3388","CVE-2009-3986","CVE-2009-3984","CVE-2009-3985","CVE-2009-3389","CVE-2009-3980","CVE-2009-3983"]}]},{"id":"CVE-2009-3981","published":"2009-12-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the browser engine in Mozilla Firefox before\n3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to\ncause a denial of service (memory corruption and application crash) or\npossibly execute arbitrary code via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-873-1","https://www.cve.org/CVERecord?id=CVE-2009-3981"],"bugs":[""],"patches":{"firefox-3.0":[],"xulrunner-1.9":[]},"tags":{},"packages":[{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.16+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.0.16+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.0.16+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.16","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.16+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.16+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.16+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.0.16","component":null,"pocket":"security"}]}],"notices_ids":["USN-873-1"],"notices":[{"id":"USN-873-1","title":"Firefox 3.0 and Xulrunner 1.9 vulnerabilities","summary":"Firefox 3.0 and Xulrunner 1.9 vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner to effect the necessary changes.\n","references":[],"published":"2009-12-18T21:52:43.805714","description":"Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and\nDavid James discovered several flaws in the browser and JavaScript engines\nof Firefox. If a user were tricked into viewing a malicious website, a\nremote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3979, CVE-2009-3981, CVE-2009-3986)\n\nTakehiro Takahashi discovered flaws in the NTLM implementation in Firefox.\nIf an NTLM authenticated user visited a malicious website, a remote\nattacker could send requests to other applications, authenticated as the\nuser. (CVE-2009-3983)\n\nJonathan Morgan discovered that Firefox did not properly display SSL\nindicators under certain circumstances. This could be used by an attacker\nto spoof an encrypted page, such as in a phishing attack. (CVE-2009-3984)\n\nJordi Chancel discovered that Firefox did not properly display invalid URLs\nfor a blank page. If a user were tricked into accessing a malicious\nwebsite, an attacker could exploit this to spoof the location bar, such as\nin a phishing attack. (CVE-2009-3985)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.16+nobinonly-0ubuntu0.8.04.1"}],"intrepid":[{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.8.10.1"},{"name":"abrowser","version":"3.0.16+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.8.10.1"},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.16+nobinonly-0ubuntu0.8.10.1"}],"jaunty":[{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.9.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.9.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.9.04.1"},{"name":"abrowser","version":"3.0.16+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.9.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.16+nobinonly-0ubuntu0.9.04.1"}]},"type":"USN","cves_ids":["CVE-2009-3979","CVE-2009-3981","CVE-2009-3986","CVE-2009-3983","CVE-2009-3984","CVE-2009-3985"]}]},{"id":"CVE-2009-3980","published":"2009-12-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in the browser engine in Mozilla\nFirefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow\nremote attackers to cause a denial of service (memory corruption and\napplication crash) or possibly execute arbitrary code via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-874-1","https://www.cve.org/CVERecord?id=CVE-2009-3980"],"bugs":[""],"patches":{"xulrunner-1.9.1":[],"seamonkey":[]},"tags":{},"packages":[{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.1","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.1.6+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-874-1"],"notices":[{"id":"USN-874-1","title":"Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities","summary":"Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner to effect the necessary changes.\n","references":[],"published":"2009-12-18T22:31:03.524958","description":"Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and\nDavid James discovered several flaws in the browser and JavaScript engines\nof Firefox. If a user were tricked into viewing a malicious website, a\nremote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3979, CVE-2009-3980, CVE-2009-3982, CVE-2009-3986)\n\nTakehiro Takahashi discovered flaws in the NTLM implementation in Firefox.\nIf an NTLM authenticated user visited a malicious website, a remote\nattacker could send requests to other applications, authenticated as the\nuser. (CVE-2009-3983)\n\nJonathan Morgan discovered that Firefox did not properly display SSL\nindicators under certain circumstances. This could be used by an attacker\nto spoof an encrypted page, such as in a phishing attack. (CVE-2009-3984)\n\nJordi Chancel discovered that Firefox did not properly display invalid URLs\nfor a blank page. If a user were tricked into accessing a malicious\nwebsite, an attacker could exploit this to spoof the location bar, such as\nin a phishing attack. (CVE-2009-3985)\n\nDavid Keeler, Bob Clary, and Dan Kaminsky discovered several flaws in third\nparty media libraries. If a user were tricked into opening a crafted media\nfile, a remote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3388, CVE-2009-3389)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"xulrunner-1.9.1","version":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"firefox-3.5","version":"3.5.6+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"xulrunner-1.9.1","version":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1/1.9.1.6+nobinonly-0ubuntu0.9.10.1"},{"name":"firefox-3.5","version":"3.5.6+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.5.6+nobinonly-0ubuntu0.9.10.1"}]},"type":"USN","cves_ids":["CVE-2009-3979","CVE-2009-3982","CVE-2009-3388","CVE-2009-3986","CVE-2009-3984","CVE-2009-3985","CVE-2009-3389","CVE-2009-3980","CVE-2009-3983"]}]},{"id":"CVE-2009-3979","published":"2009-12-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in the browser engine in Mozilla\nFirefox before 3.0.16 and 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and\nThunderbird allow remote attackers to cause a denial of service (memory\ncorruption and application crash) or possibly execute arbitrary code via\nunknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-874-1","https://ubuntu.com/security/notices/USN-873-1","https://www.cve.org/CVERecord?id=CVE-2009-3979"],"bugs":[""],"patches":{"xulrunner-1.9":[],"xulrunner-1.9.1":[],"seamonkey":[]},"tags":{},"packages":[{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.1","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.16+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.16+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.16+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.0.16","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.1.6+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-873-1","USN-874-1"],"notices":[{"id":"USN-873-1","title":"Firefox 3.0 and Xulrunner 1.9 vulnerabilities","summary":"Firefox 3.0 and Xulrunner 1.9 vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner to effect the necessary changes.\n","references":[],"published":"2009-12-18T21:52:43.805714","description":"Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and\nDavid James discovered several flaws in the browser and JavaScript engines\nof Firefox. If a user were tricked into viewing a malicious website, a\nremote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3979, CVE-2009-3981, CVE-2009-3986)\n\nTakehiro Takahashi discovered flaws in the NTLM implementation in Firefox.\nIf an NTLM authenticated user visited a malicious website, a remote\nattacker could send requests to other applications, authenticated as the\nuser. (CVE-2009-3983)\n\nJonathan Morgan discovered that Firefox did not properly display SSL\nindicators under certain circumstances. This could be used by an attacker\nto spoof an encrypted page, such as in a phishing attack. (CVE-2009-3984)\n\nJordi Chancel discovered that Firefox did not properly display invalid URLs\nfor a blank page. If a user were tricked into accessing a malicious\nwebsite, an attacker could exploit this to spoof the location bar, such as\nin a phishing attack. (CVE-2009-3985)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.16+nobinonly-0ubuntu0.8.04.1"}],"intrepid":[{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.8.10.1"},{"name":"abrowser","version":"3.0.16+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.8.10.1"},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.16+nobinonly-0ubuntu0.8.10.1"}],"jaunty":[{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.9.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.9.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.16+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.9.04.1"},{"name":"abrowser","version":"3.0.16+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.16+nobinonly-0ubuntu0.9.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.16+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.16+nobinonly-0ubuntu0.9.04.1"}]},"type":"USN","cves_ids":["CVE-2009-3979","CVE-2009-3981","CVE-2009-3986","CVE-2009-3983","CVE-2009-3984","CVE-2009-3985"]},{"id":"USN-874-1","title":"Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities","summary":"Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner to effect the necessary changes.\n","references":[],"published":"2009-12-18T22:31:03.524958","description":"Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and\nDavid James discovered several flaws in the browser and JavaScript engines\nof Firefox. If a user were tricked into viewing a malicious website, a\nremote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3979, CVE-2009-3980, CVE-2009-3982, CVE-2009-3986)\n\nTakehiro Takahashi discovered flaws in the NTLM implementation in Firefox.\nIf an NTLM authenticated user visited a malicious website, a remote\nattacker could send requests to other applications, authenticated as the\nuser. (CVE-2009-3983)\n\nJonathan Morgan discovered that Firefox did not properly display SSL\nindicators under certain circumstances. This could be used by an attacker\nto spoof an encrypted page, such as in a phishing attack. (CVE-2009-3984)\n\nJordi Chancel discovered that Firefox did not properly display invalid URLs\nfor a blank page. If a user were tricked into accessing a malicious\nwebsite, an attacker could exploit this to spoof the location bar, such as\nin a phishing attack. (CVE-2009-3985)\n\nDavid Keeler, Bob Clary, and Dan Kaminsky discovered several flaws in third\nparty media libraries. If a user were tricked into opening a crafted media\nfile, a remote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3388, CVE-2009-3389)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"xulrunner-1.9.1","version":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"firefox-3.5","version":"3.5.6+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"xulrunner-1.9.1","version":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1/1.9.1.6+nobinonly-0ubuntu0.9.10.1"},{"name":"firefox-3.5","version":"3.5.6+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.5.6+nobinonly-0ubuntu0.9.10.1"}]},"type":"USN","cves_ids":["CVE-2009-3979","CVE-2009-3982","CVE-2009-3388","CVE-2009-3986","CVE-2009-3984","CVE-2009-3985","CVE-2009-3389","CVE-2009-3980","CVE-2009-3983"]}]},{"id":"CVE-2009-3389","published":"2009-12-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in libtheora in Xiph.Org Theora before 1.1, as used in\nMozilla Firefox 3.5 before 3.5.6 and SeaMonkey before 2.0.1, allows remote\nattackers to cause a denial of service (application crash) or possibly\nexecute arbitrary code via a video with large dimensions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-874-1","https://www.cve.org/CVERecord?id=CVE-2009-3389"],"bugs":[""],"patches":{"xulrunner-1.9.1":[],"seamonkey":[]},"tags":{},"packages":[{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.1","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.1.6+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-874-1"],"notices":[{"id":"USN-874-1","title":"Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities","summary":"Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner to effect the necessary changes.\n","references":[],"published":"2009-12-18T22:31:03.524958","description":"Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and\nDavid James discovered several flaws in the browser and JavaScript engines\nof Firefox. If a user were tricked into viewing a malicious website, a\nremote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3979, CVE-2009-3980, CVE-2009-3982, CVE-2009-3986)\n\nTakehiro Takahashi discovered flaws in the NTLM implementation in Firefox.\nIf an NTLM authenticated user visited a malicious website, a remote\nattacker could send requests to other applications, authenticated as the\nuser. (CVE-2009-3983)\n\nJonathan Morgan discovered that Firefox did not properly display SSL\nindicators under certain circumstances. This could be used by an attacker\nto spoof an encrypted page, such as in a phishing attack. (CVE-2009-3984)\n\nJordi Chancel discovered that Firefox did not properly display invalid URLs\nfor a blank page. If a user were tricked into accessing a malicious\nwebsite, an attacker could exploit this to spoof the location bar, such as\nin a phishing attack. (CVE-2009-3985)\n\nDavid Keeler, Bob Clary, and Dan Kaminsky discovered several flaws in third\nparty media libraries. If a user were tricked into opening a crafted media\nfile, a remote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3388, CVE-2009-3389)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"xulrunner-1.9.1","version":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"firefox-3.5","version":"3.5.6+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"xulrunner-1.9.1","version":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1/1.9.1.6+nobinonly-0ubuntu0.9.10.1"},{"name":"firefox-3.5","version":"3.5.6+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.5.6+nobinonly-0ubuntu0.9.10.1"}]},"type":"USN","cves_ids":["CVE-2009-3979","CVE-2009-3982","CVE-2009-3388","CVE-2009-3986","CVE-2009-3984","CVE-2009-3985","CVE-2009-3389","CVE-2009-3980","CVE-2009-3983"]}]},{"id":"CVE-2009-3388","published":"2009-12-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nliboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1\nmight allow context-dependent attackers to cause a denial of service\n(application crash) or execute arbitrary code via unspecified vectors,\nrelated to \"memory safety issues.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-874-1","https://www.cve.org/CVERecord?id=CVE-2009-3388"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.1":[],"seamonkey":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.1","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.1.6+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-874-1"],"notices":[{"id":"USN-874-1","title":"Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities","summary":"Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner to effect the necessary changes.\n","references":[],"published":"2009-12-18T22:31:03.524958","description":"Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and\nDavid James discovered several flaws in the browser and JavaScript engines\nof Firefox. If a user were tricked into viewing a malicious website, a\nremote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3979, CVE-2009-3980, CVE-2009-3982, CVE-2009-3986)\n\nTakehiro Takahashi discovered flaws in the NTLM implementation in Firefox.\nIf an NTLM authenticated user visited a malicious website, a remote\nattacker could send requests to other applications, authenticated as the\nuser. (CVE-2009-3983)\n\nJonathan Morgan discovered that Firefox did not properly display SSL\nindicators under certain circumstances. This could be used by an attacker\nto spoof an encrypted page, such as in a phishing attack. (CVE-2009-3984)\n\nJordi Chancel discovered that Firefox did not properly display invalid URLs\nfor a blank page. If a user were tricked into accessing a malicious\nwebsite, an attacker could exploit this to spoof the location bar, such as\nin a phishing attack. (CVE-2009-3985)\n\nDavid Keeler, Bob Clary, and Dan Kaminsky discovered several flaws in third\nparty media libraries. If a user were tricked into opening a crafted media\nfile, a remote attacker could cause a denial of service or possibly execute\narbitrary code with the privileges of the user invoking the program.\n(CVE-2009-3388, CVE-2009-3389)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"xulrunner-1.9.1","version":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"firefox-3.5","version":"3.5.6+nobinonly-0ubuntu0.9.10.1","description":"","is_source":true},{"name":"xulrunner-1.9.1","version":"1.9.1.6+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1/1.9.1.6+nobinonly-0ubuntu0.9.10.1"},{"name":"firefox-3.5","version":"3.5.6+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.5.6+nobinonly-0ubuntu0.9.10.1"}]},"type":"USN","cves_ids":["CVE-2009-3979","CVE-2009-3982","CVE-2009-3388","CVE-2009-3986","CVE-2009-3984","CVE-2009-3985","CVE-2009-3389","CVE-2009-3980","CVE-2009-3983"]}]}],"offset":73400,"limit":20,"total_results":79316}