Zeros312
cve | fips_bionic | oval:com.ubuntu.bionic:def:100 | Check that Ubuntu Pro FIPS 18.04 LTS (bionic) is installed. | {'cves': None, 'title': 'Check that Ubuntu Pro FIPS 18.04 LTS (bionic) is installed.', 'issued': None, 'release': 'fips_bionic', 'updated': None, 'affected': None, 'severity': None, 'oval_type': 'cve', 'references': None, 'description': None, 'definition_id': 'oval:com.ubuntu.bionic:def:100', 'package_criteria': []} | 72aff1fd5b2c91eeb41c3aae86f8a92d21a8dbc48793c5b49de09261e9b7ff6d | 2026-05-30 01:38:06.490971+03:00 | 2026-06-29 19:56:29.381921+03:00 | |||||||
pkg | bionic | oval:com.ubuntu.bionic:def:100 | Check that Ubuntu 18.04 LTS (bionic) is installed. | {'cves': None, 'title': 'Check that Ubuntu 18.04 LTS (bionic) is installed.', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': None, 'severity': None, 'oval_type': 'pkg', 'references': None, 'description': None, 'definition_id': 'oval:com.ubuntu.bionic:def:100', 'package_criteria': []} | 0654a2bd54663615386bd03913f586078c24cfdaca8e3b98c85e1357fd901cea | 2026-05-30 01:46:54.794516+03:00 | 2026-06-29 20:08:46.086914+03:00 | |||||||
pkg | jammy | oval:com.ubuntu.jammy:def:100 | Check that Ubuntu 22.04 LTS (jammy) is installed. | {'cves': None, 'title': 'Check that Ubuntu 22.04 LTS (jammy) is installed.', 'issued': None, 'release': 'jammy', 'updated': None, 'affected': None, 'severity': None, 'oval_type': 'pkg', 'references': None, 'description': None, 'definition_id': 'oval:com.ubuntu.jammy:def:100', 'package_criteria': []} | 6485aba2f1097af59a109fa00932d1babe00c4ab7ace6ca304bd885c2a39f5e9 | 2026-05-30 01:51:08.273583+03:00 | 2026-06-29 20:13:24.155221+03:00 | |||||||
cve | bionic | oval:com.ubuntu.bionic:def:200911800000000 | CVE-2009-1180 on Ubuntu 18.04 LTS (bionic) - medium | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier,Poppler before 0.10.6, and other products allows remote attackers toexecute arbitrary code via a crafted PDF file that triggers a free ofinvalid data.
Update Instructions:
Run `sudo pro fix CVE-2009-1180` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
gir1.2-poppler-0.18 - 0.10.5-1ubuntu2
libpoppler-cpp0v5 - 0.10.5-1ubuntu2
libpoppler-glib8 - 0.10.5-1ubuntu2
libpoppler-qt4-4 - 0.10.5-1ubuntu2
libpoppler-qt5-1 - 0.10.5-1ubuntu2
libpoppler68 - 0.10.5-1ubuntu2
poppler-utils - 0.10.5-1ubuntu2
No subscription required | Medium | ['CVE-2009-1180'] | ['Ubuntu 18.04 LTS'] | ['CVE-2009-1180', 'https://www.cve.org/CVERecord?id=CVE-2009-1180'] | {'cves': '["CVE-2009-1180"]', 'title': 'CVE-2009-1180 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2009-1180", "https://www.cve.org/CVERecord?id=CVE-2009-1180"]', 'description': 'The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier,Poppler before 0.10.6, and other products allows remote attackers toexecute arbitrary code via a crafted PDF file that triggers a free ofinvalid data.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2009-1180` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\ngir1.2-poppler-0.18 - 0.10.5-1ubuntu2\nlibpoppler-cpp0v5 - 0.10.5-1ubuntu2\nlibpoppler-glib8 - 0.10.5-1ubuntu2\nlibpoppler-qt4-4 - 0.10.5-1ubuntu2\nlibpoppler-qt5-1 - 0.10.5-1ubuntu2\nlibpoppler68 - 0.10.5-1ubuntu2\npoppler-utils - 0.10.5-1ubuntu2\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:200911800000000', 'package_criteria': [{'cve_id': 'CVE-2009-1180', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'poppler', 'fixed_version': '0.10.5-1ubuntu2', 'affected_version_range': '< 0.10.5-1ubuntu2'}, {'cve_id': 'CVE-2009-1180', 'source': 'description_fix', 'status': 'fixed', 'package': 'gir1.2-poppler-0.18', 'fixed_version': '0.10.5-1ubuntu2', 'affected_version_range': '< 0.10.5-1ubuntu2'}, {'cve_id': 'CVE-2009-1180', 'source': 'description_fix', 'status': 'fixed', 'package': 'libpoppler-cpp0v5', 'fixed_version': '0.10.5-1ubuntu2', 'affected_version_range': '< 0.10.5-1ubuntu2'}, {'cve_id': 'CVE-2009-1180', 'source': 'description_fix', 'status': 'fixed', 'package': 'libpoppler-glib8', 'fixed_version': '0.10.5-1ubuntu2', 'affected_version_range': '< 0.10.5-1ubuntu2'}, {'cve_id': 'CVE-2009-1180', 'source': 'description_fix', 'status': 'fixed', 'package': 'libpoppler-qt4-4', 'fixed_version': '0.10.5-1ubuntu2', 'affected_version_range': '< 0.10.5-1ubuntu2'}, {'cve_id': 'CVE-2009-1180', 'source': 'description_fix', 'status': 'fixed', 'package': 'libpoppler-qt5-1', 'fixed_version': '0.10.5-1ubuntu2', 'affected_version_range': '< 0.10.5-1ubuntu2'}, {'cve_id': 'CVE-2009-1180', 'source': 'description_fix', 'status': 'fixed', 'package': 'libpoppler68', 'fixed_version': '0.10.5-1ubuntu2', 'affected_version_range': '< 0.10.5-1ubuntu2'}, {'cve_id': 'CVE-2009-1180', 'source': 'description_fix', 'status': 'fixed', 'package': 'poppler-utils', 'fixed_version': '0.10.5-1ubuntu2', 'affected_version_range': '< 0.10.5-1ubuntu2'}]} | 1d12d67bbadc03b09fafab5f7304f35da6e9b16f0b741e776ac444ccdec63a26 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201127670000000 | CVE-2011-2767 on Ubuntu 18.04 LTS (bionic) - medium | mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl codeby placing it in a user-owned .htaccess file, because (contrary to thedocumentation) there is no configuration option that permits Perl code forthe administrator's control of HTTP request processing without alsopermitting unprivileged users to run Perl code in the context of the useraccount that runs Apache HTTP Server processes.
Update Instructions:
Run `sudo pro fix CVE-2011-2767` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
libapache2-mod-perl2 - 2.0.10-2ubuntu3.18.04.1
No subscription required | Medium | ['CVE-2011-2767'] | ['Ubuntu 18.04 LTS'] | ['CVE-2011-2767', 'https://www.cve.org/CVERecord?id=CVE-2011-2767'] | {'cves': '["CVE-2011-2767"]', 'title': 'CVE-2011-2767 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2011-2767", "https://www.cve.org/CVERecord?id=CVE-2011-2767"]', 'description': "mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl codeby placing it in a user-owned .htaccess file, because (contrary to thedocumentation) there is no configuration option that permits Perl code forthe administrator's control of HTTP request processing without alsopermitting unprivileged users to run Perl code in the context of the useraccount that runs Apache HTTP Server processes.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2011-2767` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nlibapache2-mod-perl2 - 2.0.10-2ubuntu3.18.04.1\nNo subscription required", 'definition_id': 'oval:com.ubuntu.bionic:def:201127670000000', 'package_criteria': [{'cve_id': 'CVE-2011-2767', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libapache2-mod-perl2', 'fixed_version': '2.0.10-2ubuntu3.18.04.1', 'affected_version_range': '< 2.0.10-2ubuntu3.18.04.1'}]} | 39f7573c1d1a90a705de8d6fafc5728bcc4a5473566163a80a9db9d8d8ff8729 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201149310000000 | CVE-2011-4931 on Ubuntu 18.04 LTS (bionic) - low | gpw generates shorter passwords than required | Low | ['CVE-2011-4931'] | ['Ubuntu 18.04 LTS'] | ['CVE-2011-4931', 'https://www.cve.org/CVERecord?id=CVE-2011-4931'] | {'cves': '["CVE-2011-4931"]', 'title': 'CVE-2011-4931 on Ubuntu 18.04 LTS (bionic) - low', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Low', 'oval_type': 'cve', 'references': '["CVE-2011-4931", "https://www.cve.org/CVERecord?id=CVE-2011-4931"]', 'description': 'gpw generates shorter passwords than required', 'definition_id': 'oval:com.ubuntu.bionic:def:201149310000000', 'package_criteria': []} | 8e90ee58ad7b59a6563ee44bb32e95e9d74710692a98652ef2bfb9c68559097b | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
pkg | fips-updates_noble | oval:com.ubuntu.noble:def:100 | Check that Ubuntu Pro FIPS-updates 24.04 LTS (noble) is installed. | {'cves': None, 'title': 'Check that Ubuntu Pro FIPS-updates 24.04 LTS (noble) is installed.', 'issued': None, 'release': 'fips-updates_noble', 'updated': None, 'affected': None, 'severity': None, 'oval_type': 'pkg', 'references': None, 'description': None, 'definition_id': 'oval:com.ubuntu.noble:def:100', 'package_criteria': []} | 6b0db10073753a9e6ebef7954c4b44f593cf7c3b7c510d5bedf8beda11f1efdd | 2026-05-30 01:49:35.735838+03:00 | 2026-06-29 20:11:42.338772+03:00 | |||||||
cve | bionic | oval:com.ubuntu.bionic:def:201342350000000 | CVE-2013-4235 on Ubuntu 18.04 LTS (bionic) - low | shadow: TOCTOU (time-of-check time-of-use) race condition when copying andremoving directory trees | Low | ['CVE-2013-4235'] | ['Ubuntu 18.04 LTS'] | ['CVE-2013-4235', 'https://www.cve.org/CVERecord?id=CVE-2013-4235'] | {'cves': '["CVE-2013-4235"]', 'title': 'CVE-2013-4235 on Ubuntu 18.04 LTS (bionic) - low', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Low', 'oval_type': 'cve', 'references': '["CVE-2013-4235", "https://www.cve.org/CVERecord?id=CVE-2013-4235"]', 'description': 'shadow: TOCTOU (time-of-check time-of-use) race condition when copying andremoving directory trees', 'definition_id': 'oval:com.ubuntu.bionic:def:201342350000000', 'package_criteria': []} | 8d6ffc215140755504eb3fd08cba76f5e95bbb75efabb7ecaf222d41d08b3bf4 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201414230000000 | CVE-2014-1423 on Ubuntu 18.04 LTS (bionic) - low | signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, didnot properly restrict applications from querying oath tokens due toincorrect checks and the missing installation of thesignon-apparmor-extension. An attacker could use this create a maliciousclick app that collects oauth tokens for other applications, exposingsensitive information.
Update Instructions:
Run `sudo pro fix CVE-2014-1423` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
libsignon-extension1 - 8.57+15.04.20141127.1-0ubuntu1
libsignon-plugins-common1 - 8.57+15.04.20141127.1-0ubuntu1
libsignon-qt5-1 - 8.57+15.04.20141127.1-0ubuntu1
signon-plugin-password - 8.57+15.04.20141127.1-0ubuntu1
signon-plugin-ssotest - 8.57+15.04.20141127.1-0ubuntu1
signond - 8.57+15.04.20141127.1-0ubuntu1
No subscription required | Low | ['CVE-2014-1423'] | ['Ubuntu 18.04 LTS'] | ['CVE-2014-1423', 'https://www.cve.org/CVERecord?id=CVE-2014-1423'] | {'cves': '["CVE-2014-1423"]', 'title': 'CVE-2014-1423 on Ubuntu 18.04 LTS (bionic) - low', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Low', 'oval_type': 'cve', 'references': '["CVE-2014-1423", "https://www.cve.org/CVERecord?id=CVE-2014-1423"]', 'description': 'signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, didnot properly restrict applications from querying oath tokens due toincorrect checks and the missing installation of thesignon-apparmor-extension. An attacker could use this create a maliciousclick app that collects oauth tokens for other applications, exposingsensitive information.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2014-1423` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nlibsignon-extension1 - 8.57+15.04.20141127.1-0ubuntu1\nlibsignon-plugins-common1 - 8.57+15.04.20141127.1-0ubuntu1\nlibsignon-qt5-1 - 8.57+15.04.20141127.1-0ubuntu1\nsignon-plugin-password - 8.57+15.04.20141127.1-0ubuntu1\nsignon-plugin-ssotest - 8.57+15.04.20141127.1-0ubuntu1\nsignond - 8.57+15.04.20141127.1-0ubuntu1\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:201414230000000', 'package_criteria': [{'cve_id': 'CVE-2014-1423', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'signon', 'fixed_version': '8.57+15.04.20141127.1-0ubuntu1', 'affected_version_range': '< 8.57+15.04.20141127.1-0ubuntu1'}, {'cve_id': 'CVE-2014-1423', 'source': 'description_fix', 'status': 'fixed', 'package': 'libsignon-extension1', 'fixed_version': '8.57+15.04.20141127.1-0ubuntu1', 'affected_version_range': '< 8.57+15.04.20141127.1-0ubuntu1'}, {'cve_id': 'CVE-2014-1423', 'source': 'description_fix', 'status': 'fixed', 'package': 'libsignon-plugins-common1', 'fixed_version': '8.57+15.04.20141127.1-0ubuntu1', 'affected_version_range': '< 8.57+15.04.20141127.1-0ubuntu1'}, {'cve_id': 'CVE-2014-1423', 'source': 'description_fix', 'status': 'fixed', 'package': 'libsignon-qt5-1', 'fixed_version': '8.57+15.04.20141127.1-0ubuntu1', 'affected_version_range': '< 8.57+15.04.20141127.1-0ubuntu1'}, {'cve_id': 'CVE-2014-1423', 'source': 'description_fix', 'status': 'fixed', 'package': 'signon-plugin-password', 'fixed_version': '8.57+15.04.20141127.1-0ubuntu1', 'affected_version_range': '< 8.57+15.04.20141127.1-0ubuntu1'}, {'cve_id': 'CVE-2014-1423', 'source': 'description_fix', 'status': 'fixed', 'package': 'signon-plugin-ssotest', 'fixed_version': '8.57+15.04.20141127.1-0ubuntu1', 'affected_version_range': '< 8.57+15.04.20141127.1-0ubuntu1'}, {'cve_id': 'CVE-2014-1423', 'source': 'description_fix', 'status': 'fixed', 'package': 'signond', 'fixed_version': '8.57+15.04.20141127.1-0ubuntu1', 'affected_version_range': '< 8.57+15.04.20141127.1-0ubuntu1'}]} | df570e98e7602a7514ceabe7b11164d3677f2afd36b5ac79c5d31a3c00e782d1 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201419350000000 | CVE-2014-1935 on Ubuntu 18.04 LTS (bionic) - low | 9base 1:6-6 and 1:6-7 insecurely creates temporary files which results inpredictable filenames. | Low | ['CVE-2014-1935'] | ['Ubuntu 18.04 LTS'] | ['CVE-2014-1935', 'https://www.cve.org/CVERecord?id=CVE-2014-1935'] | {'cves': '["CVE-2014-1935"]', 'title': 'CVE-2014-1935 on Ubuntu 18.04 LTS (bionic) - low', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Low', 'oval_type': 'cve', 'references': '["CVE-2014-1935", "https://www.cve.org/CVERecord?id=CVE-2014-1935"]', 'description': '9base 1:6-6 and 1:6-7 insecurely creates temporary files which results inpredictable filenames.', 'definition_id': 'oval:com.ubuntu.bionic:def:201419350000000', 'package_criteria': []} | 83b56254e6c0d7319f291c3bca0fc551907edaaa3ac77f4a323b0321d8e408d4 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201435080000000 | CVE-2014-3508 on Ubuntu 18.04 LTS (bionic) - medium | The OBJ_obj2txt function in crypto/objects/obj_dat.c in OpenSSL 0.9.8before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i, when prettyprinting is used, does not ensure the presence of '\0' characters, whichallows context-dependent attackers to obtain sensitive information fromprocess stack memory by reading output from X509_name_oneline,X509_name_print_ex, and unspecified other functions.
Update Instructions:
Run `sudo pro fix CVE-2014-3508` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
libssl1.0.0 - 1.0.1f-1ubuntu7
openssl - 1.0.1f-1ubuntu7
No subscription required | Medium | ['CVE-2014-3508'] | ['Ubuntu 18.04 LTS'] | ['CVE-2014-3508', 'https://www.cve.org/CVERecord?id=CVE-2014-3508'] | {'cves': '["CVE-2014-3508"]', 'title': 'CVE-2014-3508 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2014-3508", "https://www.cve.org/CVERecord?id=CVE-2014-3508"]', 'description': "The OBJ_obj2txt function in crypto/objects/obj_dat.c in OpenSSL 0.9.8before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i, when prettyprinting is used, does not ensure the presence of '\\0' characters, whichallows context-dependent attackers to obtain sensitive information fromprocess stack memory by reading output from X509_name_oneline,X509_name_print_ex, and unspecified other functions.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2014-3508` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nlibssl1.0.0 - 1.0.1f-1ubuntu7\nopenssl - 1.0.1f-1ubuntu7\nNo subscription required", 'definition_id': 'oval:com.ubuntu.bionic:def:201435080000000', 'package_criteria': [{'cve_id': 'CVE-2014-3508', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'openssl', 'fixed_version': '1.0.1f-1ubuntu7', 'affected_version_range': '< 1.0.1f-1ubuntu7'}, {'cve_id': 'CVE-2014-3508', 'source': 'description_fix', 'status': 'fixed', 'package': 'libssl1.0.0', 'fixed_version': '1.0.1f-1ubuntu7', 'affected_version_range': '< 1.0.1f-1ubuntu7'}]} | 818f01bf07e425aa41710ec76b6e7525a17b598397d538550149bc3afb011a43 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
pkg | bluefield_noble | oval:com.ubuntu.noble:def:24040000200000 | 389-ds-base | 389 Directory Server suite - server | ['CVE-2018-1054'] | ['Ubuntu Nvidia-BlueField 24.04 LTS'] | ['389-ds-base', 'https://launchpad.net/ubuntu/+source/389-ds-base'] | {'cves': '["CVE-2018-1054"]', 'title': '389-ds-base', 'issued': None, 'release': 'bluefield_noble', 'updated': None, 'affected': '["Ubuntu Nvidia-BlueField 24.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["389-ds-base", "https://launchpad.net/ubuntu/+source/389-ds-base"]', 'description': '389 Directory Server suite - server', 'definition_id': 'oval:com.ubuntu.noble:def:24040000200000', 'package_criteria': [{'cve_id': 'CVE-2018-1054', 'source': 'criterion_comment', 'status': 'fixed', 'package': '389-ds-base', 'fixed_version': '1.4.1.5-1', 'affected_version_range': '< 1.4.1.5-1'}]} | 57d6f09c0bcc16f863061fe54e88c1c1b87531ab4045033f50f141b6395da185 | 2026-05-30 01:47:40.337896+03:00 | 2026-06-29 20:09:35.415171+03:00 | |||
cve | bionic | oval:com.ubuntu.bionic:def:201497290000000 | CVE-2014-9729 on Ubuntu 18.04 LTS (bionic) - medium | The udf_read_inode function in fs/udf/inode.c in the Linux kernel before3.18.2 does not ensure a certain data-structure size consistency, whichallows local users to cause a denial of service (system crash) via acrafted UDF filesystem image. | Medium | ['CVE-2014-9729'] | ['Ubuntu 18.04 LTS'] | ['CVE-2014-9729', 'https://www.cve.org/CVERecord?id=CVE-2014-9729'] | {'cves': '["CVE-2014-9729"]', 'title': 'CVE-2014-9729 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2014-9729", "https://www.cve.org/CVERecord?id=CVE-2014-9729"]', 'description': 'The udf_read_inode function in fs/udf/inode.c in the Linux kernel before3.18.2 does not ensure a certain data-structure size consistency, whichallows local users to cause a denial of service (system crash) via acrafted UDF filesystem image.', 'definition_id': 'oval:com.ubuntu.bionic:def:201497290000000', 'package_criteria': []} | 8528c632bd0fdb69e5a45af91c30f489b402fd9294c01b4583c0f7ba59a39549 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201511930000000 | CVE-2015-1193 on Ubuntu 18.04 LTS (bionic) - low | Multiple directory traversal vulnerabilities in pax 1:20140703 allow remoteattackers to write to arbitrary files via a (1) full pathname or (2) ..(dot dot) in an archive. | Low | ['CVE-2015-1193'] | ['Ubuntu 18.04 LTS'] | ['CVE-2015-1193', 'https://www.cve.org/CVERecord?id=CVE-2015-1193'] | {'cves': '["CVE-2015-1193"]', 'title': 'CVE-2015-1193 on Ubuntu 18.04 LTS (bionic) - low', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Low', 'oval_type': 'cve', 'references': '["CVE-2015-1193", "https://www.cve.org/CVERecord?id=CVE-2015-1193"]', 'description': 'Multiple directory traversal vulnerabilities in pax 1:20140703 allow remoteattackers to write to arbitrary files via a (1) full pathname or (2) ..(dot dot) in an archive.', 'definition_id': 'oval:com.ubuntu.bionic:def:201511930000000', 'package_criteria': []} | fb5df5b03d9f7818881725f24b602b44f6ef7be90c62ebffd7534b0e343745c7 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201526740000000 | CVE-2015-2674 on Ubuntu 18.04 LTS (bionic) - medium | Restkit allows man-in-the-middle attackers to spoof TLS servers byleveraging use of the ssl.wrap_socket function in Python with the defaultCERT_NONE value for the cert_reqs argument. | Medium | ['CVE-2015-2674'] | ['Ubuntu 18.04 LTS'] | ['CVE-2015-2674', 'https://www.cve.org/CVERecord?id=CVE-2015-2674'] | {'cves': '["CVE-2015-2674"]', 'title': 'CVE-2015-2674 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2015-2674", "https://www.cve.org/CVERecord?id=CVE-2015-2674"]', 'description': 'Restkit allows man-in-the-middle attackers to spoof TLS servers byleveraging use of the ssl.wrap_socket function in Python with the defaultCERT_NONE value for the cert_reqs argument.', 'definition_id': 'oval:com.ubuntu.bionic:def:201526740000000', 'package_criteria': []} | 0bf26138eb9a814f4213228b7fc7e4110f6d88c2da559199cc938dbf1b27cea3 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201580110000000 | CVE-2015-8011 on Ubuntu 18.04 LTS (bionic) - medium | Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c inlldpd before 0.8.0 allows remote attackers to cause a denial of service(daemon crash) and possibly execute arbitrary code via vectors involvinglarge management addresses and TLV boundaries.
Update Instructions:
Run `sudo pro fix CVE-2015-8011` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
openvswitch-common - 2.9.7-0ubuntu0.18.04.2
openvswitch-pki - 2.9.7-0ubuntu0.18.04.2
openvswitch-switch - 2.9.7-0ubuntu0.18.04.2
openvswitch-switch-dpdk - 2.9.7-0ubuntu0.18.04.2
openvswitch-test - 2.9.7-0ubuntu0.18.04.2
openvswitch-testcontroller - 2.9.7-0ubuntu0.18.04.2
openvswitch-vtep - 2.9.7-0ubuntu0.18.04.2
ovn-central - 2.9.7-0ubuntu0.18.04.2
ovn-common - 2.9.7-0ubuntu0.18.04.2
ovn-controller-vtep - 2.9.7-0ubuntu0.18.04.2
ovn-host - 2.9.7-0ubuntu0.18.04.2
python-openvswitch - 2.9.7-0ubuntu0.18.04.2
python3-openvswitch - 2.9.7-0ubuntu0.18.04.2
No subscription required | Medium | ['CVE-2015-8011'] | ['Ubuntu 18.04 LTS'] | ['CVE-2015-8011', 'https://www.cve.org/CVERecord?id=CVE-2015-8011'] | {'cves': '["CVE-2015-8011"]', 'title': 'CVE-2015-8011 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2015-8011", "https://www.cve.org/CVERecord?id=CVE-2015-8011"]', 'description': 'Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c inlldpd before 0.8.0 allows remote attackers to cause a denial of service(daemon crash) and possibly execute arbitrary code via vectors involvinglarge management addresses and TLV boundaries.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2015-8011` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nopenvswitch-common - 2.9.7-0ubuntu0.18.04.2\nopenvswitch-pki - 2.9.7-0ubuntu0.18.04.2\nopenvswitch-switch - 2.9.7-0ubuntu0.18.04.2\nopenvswitch-switch-dpdk - 2.9.7-0ubuntu0.18.04.2\nopenvswitch-test - 2.9.7-0ubuntu0.18.04.2\nopenvswitch-testcontroller - 2.9.7-0ubuntu0.18.04.2\nopenvswitch-vtep - 2.9.7-0ubuntu0.18.04.2\novn-central - 2.9.7-0ubuntu0.18.04.2\novn-common - 2.9.7-0ubuntu0.18.04.2\novn-controller-vtep - 2.9.7-0ubuntu0.18.04.2\novn-host - 2.9.7-0ubuntu0.18.04.2\npython-openvswitch - 2.9.7-0ubuntu0.18.04.2\npython3-openvswitch - 2.9.7-0ubuntu0.18.04.2\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:201580110000000', 'package_criteria': [{'cve_id': 'CVE-2015-8011', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'openvswitch', 'fixed_version': '2.9.7-0ubuntu0.18.04.2', 'affected_version_range': '< 2.9.7-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2015-8011', 'source': 'description_fix', 'status': 'fixed', 'package': 'openvswitch-common', 'fixed_version': '2.9.7-0ubuntu0.18.04.2', 'affected_version_range': '< 2.9.7-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2015-8011', 'source': 'description_fix', 'status': 'fixed', 'package': 'openvswitch-pki', 'fixed_version': '2.9.7-0ubuntu0.18.04.2', 'affected_version_range': '< 2.9.7-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2015-8011', 'source': 'description_fix', 'status': 'fixed', 'package': 'openvswitch-switch', 'fixed_version': '2.9.7-0ubuntu0.18.04.2', 'affected_version_range': '< 2.9.7-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2015-8011', 'source': 'description_fix', 'status': 'fixed', 'package': 'openvswitch-switch-dpdk', 'fixed_version': '2.9.7-0ubuntu0.18.04.2', 'affected_version_range': '< 2.9.7-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2015-8011', 'source': 'description_fix', 'status': 'fixed', 'package': 'openvswitch-test', 'fixed_version': '2.9.7-0ubuntu0.18.04.2', 'affected_version_range': '< 2.9.7-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2015-8011', 'source': 'description_fix', 'status': 'fixed', 'package': 'openvswitch-testcontroller', 'fixed_version': '2.9.7-0ubuntu0.18.04.2', 'affected_version_range': '< 2.9.7-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2015-8011', 'source': 'description_fix', 'status': 'fixed', 'package': 'openvswitch-vtep', 'fixed_version': '2.9.7-0ubuntu0.18.04.2', 'affected_version_range': '< 2.9.7-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2015-8011', 'source': 'description_fix', 'status': 'fixed', 'package': 'ovn-central', 'fixed_version': '2.9.7-0ubuntu0.18.04.2', 'affected_version_range': '< 2.9.7-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2015-8011', 'source': 'description_fix', 'status': 'fixed', 'package': 'ovn-common', 'fixed_version': '2.9.7-0ubuntu0.18.04.2', 'affected_version_range': '< 2.9.7-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2015-8011', 'source': 'description_fix', 'status': 'fixed', 'package': 'ovn-controller-vtep', 'fixed_version': '2.9.7-0ubuntu0.18.04.2', 'affected_version_range': '< 2.9.7-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2015-8011', 'source': 'description_fix', 'status': 'fixed', 'package': 'ovn-host', 'fixed_version': '2.9.7-0ubuntu0.18.04.2', 'affected_version_range': '< 2.9.7-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2015-8011', 'source': 'description_fix', 'status': 'fixed', 'package': 'python-openvswitch', 'fixed_version': '2.9.7-0ubuntu0.18.04.2', 'affected_version_range': '< 2.9.7-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2015-8011', 'source': 'description_fix', 'status': 'fixed', 'package': 'python3-openvswitch', 'fixed_version': '2.9.7-0ubuntu0.18.04.2', 'affected_version_range': '< 2.9.7-0ubuntu0.18.04.2'}]} | fb1e9d92c352d25f9d1f884f38e05d39f5522e13bd2eafff56f766fcfcd6e842 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201586970000000 | CVE-2015-8697 on Ubuntu 18.04 LTS (bionic) - medium | stalin 0.11-5 allows local users to write to arbitrary files. | Medium | ['CVE-2015-8697'] | ['Ubuntu 18.04 LTS'] | ['CVE-2015-8697', 'https://www.cve.org/CVERecord?id=CVE-2015-8697'] | {'cves': '["CVE-2015-8697"]', 'title': 'CVE-2015-8697 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2015-8697", "https://www.cve.org/CVERecord?id=CVE-2015-8697"]', 'description': 'stalin 0.11-5 allows local users to write to arbitrary files.', 'definition_id': 'oval:com.ubuntu.bionic:def:201586970000000', 'package_criteria': []} | 6a34deb05d9cb3db3aaa3b213df0a95d7e919fe929d25db9ce0267dbec174faf | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2016107230000000 | CVE-2016-10723 on Ubuntu 18.04 LTS (bionic) - low | An issue was discovered in the Linux kernel through 4.17.2. Since the pageallocator does not yield CPU resources to the owner of the oom_lock mutex,a local unprivileged user can trivially lock up the system forever bywasting CPU resources from the page allocator (e.g., via concurrent pagefault events) when the global OOM killer is invoked. NOTE: the softwaremaintainer has not accepted certain proposed patches, in part because of aviewpoint that "the underlying problem is non-trivial to handle.
Update Instructions:
Run `sudo pro fix CVE-2016-10723` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
linux-image-5.0.0-23-generic - 5.0.0-23.24~18.04.1
linux-image-5.0.0-23-generic-lpae - 5.0.0-23.24~18.04.1
linux-image-5.0.0-23-lowlatency - 5.0.0-23.24~18.04.1
linux-image-unsigned-5.0.0-23-generic - 5.0.0-23.24~18.04.1
linux-image-unsigned-5.0.0-23-lowlatency - 5.0.0-23.24~18.04.1
No subscription required
linux-image-unsigned-5.0.0-1020-gcp - 5.0.0-1020.20~18.04.1
No subscription required | Low | ['CVE-2016-10723'] | ['Ubuntu 18.04 LTS'] | ['CVE-2016-10723', 'https://www.cve.org/CVERecord?id=CVE-2016-10723'] | {'cves': '["CVE-2016-10723"]', 'title': 'CVE-2016-10723 on Ubuntu 18.04 LTS (bionic) - low', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Low', 'oval_type': 'cve', 'references': '["CVE-2016-10723", "https://www.cve.org/CVERecord?id=CVE-2016-10723"]', 'description': 'An issue was discovered in the Linux kernel through 4.17.2. Since the pageallocator does not yield CPU resources to the owner of the oom_lock mutex,a local unprivileged user can trivially lock up the system forever bywasting CPU resources from the page allocator (e.g., via concurrent pagefault events) when the global OOM killer is invoked. NOTE: the softwaremaintainer has not accepted certain proposed patches, in part because of aviewpoint that "the underlying problem is non-trivial to handle.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2016-10723` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nlinux-image-5.0.0-23-generic - 5.0.0-23.24~18.04.1\nlinux-image-5.0.0-23-generic-lpae - 5.0.0-23.24~18.04.1\nlinux-image-5.0.0-23-lowlatency - 5.0.0-23.24~18.04.1\nlinux-image-unsigned-5.0.0-23-generic - 5.0.0-23.24~18.04.1\nlinux-image-unsigned-5.0.0-23-lowlatency - 5.0.0-23.24~18.04.1\nNo subscription required\n\nlinux-image-unsigned-5.0.0-1020-gcp - 5.0.0-1020.20~18.04.1\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2016107230000000', 'package_criteria': [{'cve_id': 'CVE-2016-10723', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-hwe', 'fixed_version': '5.0.0-23.24~18.04.1', 'affected_version_range': '< 5.0.0-23.24~18.04.1'}, {'cve_id': 'CVE-2016-10723', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-gcp', 'fixed_version': '5.0.0-1020.20~18.04.1', 'affected_version_range': '< 5.0.0-1020.20~18.04.1'}, {'cve_id': 'CVE-2016-10723', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-5.0.0-23-generic', 'fixed_version': '5.0.0-23.24~18.04.1', 'affected_version_range': '< 5.0.0-23.24~18.04.1'}, {'cve_id': 'CVE-2016-10723', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-5.0.0-23-generic-lpae', 'fixed_version': '5.0.0-23.24~18.04.1', 'affected_version_range': '< 5.0.0-23.24~18.04.1'}, {'cve_id': 'CVE-2016-10723', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-5.0.0-23-lowlatency', 'fixed_version': '5.0.0-23.24~18.04.1', 'affected_version_range': '< 5.0.0-23.24~18.04.1'}, {'cve_id': 'CVE-2016-10723', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-5.0.0-23-generic', 'fixed_version': '5.0.0-23.24~18.04.1', 'affected_version_range': '< 5.0.0-23.24~18.04.1'}, {'cve_id': 'CVE-2016-10723', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-5.0.0-23-lowlatency', 'fixed_version': '5.0.0-23.24~18.04.1', 'affected_version_range': '< 5.0.0-23.24~18.04.1'}, {'cve_id': 'CVE-2016-10723', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-5.0.0-1020-gcp', 'fixed_version': '5.0.0-1020.20~18.04.1', 'affected_version_range': '< 5.0.0-1020.20~18.04.1'}]} | cf772698440e4dea520cc0be4f9236034276ef1cf6fdfa31d037f3f5e7db2024 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201665120000000 | CVE-2016-6512 on Ubuntu 18.04 LTS (bionic) - low | epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits anoverflow check in the tvb_get_guintvar function, which allows remoteattackers to cause a denial of service (infinite loop) via a craftedpacket, related to the MMSE, WAP, WBXML, and WSP dissectors.
Update Instructions:
Run `sudo pro fix CVE-2016-6512` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
libwireshark-data - 2.6.3-1~ubuntu18.04.1
libwireshark11 - 2.6.3-1~ubuntu18.04.1
libwiretap8 - 2.6.3-1~ubuntu18.04.1
libwscodecs2 - 2.6.3-1~ubuntu18.04.1
libwsutil9 - 2.6.3-1~ubuntu18.04.1
tshark - 2.6.3-1~ubuntu18.04.1
wireshark - 2.6.3-1~ubuntu18.04.1
wireshark-common - 2.6.3-1~ubuntu18.04.1
wireshark-gtk - 2.6.3-1~ubuntu18.04.1
wireshark-qt - 2.6.3-1~ubuntu18.04.1
No subscription required | Low | ['CVE-2016-6512'] | ['Ubuntu 18.04 LTS'] | ['CVE-2016-6512', 'https://www.cve.org/CVERecord?id=CVE-2016-6512'] | {'cves': '["CVE-2016-6512"]', 'title': 'CVE-2016-6512 on Ubuntu 18.04 LTS (bionic) - low', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Low', 'oval_type': 'cve', 'references': '["CVE-2016-6512", "https://www.cve.org/CVERecord?id=CVE-2016-6512"]', 'description': 'epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits anoverflow check in the tvb_get_guintvar function, which allows remoteattackers to cause a denial of service (infinite loop) via a craftedpacket, related to the MMSE, WAP, WBXML, and WSP dissectors.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2016-6512` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nlibwireshark-data - 2.6.3-1~ubuntu18.04.1\nlibwireshark11 - 2.6.3-1~ubuntu18.04.1\nlibwiretap8 - 2.6.3-1~ubuntu18.04.1\nlibwscodecs2 - 2.6.3-1~ubuntu18.04.1\nlibwsutil9 - 2.6.3-1~ubuntu18.04.1\ntshark - 2.6.3-1~ubuntu18.04.1\nwireshark - 2.6.3-1~ubuntu18.04.1\nwireshark-common - 2.6.3-1~ubuntu18.04.1\nwireshark-gtk - 2.6.3-1~ubuntu18.04.1\nwireshark-qt - 2.6.3-1~ubuntu18.04.1\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:201665120000000', 'package_criteria': [{'cve_id': 'CVE-2016-6512', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wireshark', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}, {'cve_id': 'CVE-2016-6512', 'source': 'description_fix', 'status': 'fixed', 'package': 'libwireshark-data', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}, {'cve_id': 'CVE-2016-6512', 'source': 'description_fix', 'status': 'fixed', 'package': 'libwireshark11', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}, {'cve_id': 'CVE-2016-6512', 'source': 'description_fix', 'status': 'fixed', 'package': 'libwiretap8', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}, {'cve_id': 'CVE-2016-6512', 'source': 'description_fix', 'status': 'fixed', 'package': 'libwscodecs2', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}, {'cve_id': 'CVE-2016-6512', 'source': 'description_fix', 'status': 'fixed', 'package': 'libwsutil9', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}, {'cve_id': 'CVE-2016-6512', 'source': 'description_fix', 'status': 'fixed', 'package': 'tshark', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}, {'cve_id': 'CVE-2016-6512', 'source': 'description_fix', 'status': 'fixed', 'package': 'wireshark-common', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}, {'cve_id': 'CVE-2016-6512', 'source': 'description_fix', 'status': 'fixed', 'package': 'wireshark-gtk', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}, {'cve_id': 'CVE-2016-6512', 'source': 'description_fix', 'status': 'fixed', 'package': 'wireshark-qt', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}]} | c5429ebc72322159914f68a54463033ba6d2a8164f8d9831046999979a00e7e8 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201693180000000 | CVE-2016-9318 on Ubuntu 18.04 LTS (bionic) - low | libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and otherproducts, does not offer a flag directly indicating that the currentdocument may be read but other files may not be opened, which makes iteasier for remote attackers to conduct XML External Entity (XXE) attacksvia a crafted document.
Update Instructions:
Run `sudo pro fix CVE-2016-9318` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
libxml2 - 2.9.4+dfsg1-6.1ubuntu1.2
libxml2-utils - 2.9.4+dfsg1-6.1ubuntu1.2
python-libxml2 - 2.9.4+dfsg1-6.1ubuntu1.2
python3-libxml2 - 2.9.4+dfsg1-6.1ubuntu1.2
No subscription required | Low | ['CVE-2016-9318'] | ['Ubuntu 18.04 LTS'] | ['CVE-2016-9318', 'https://www.cve.org/CVERecord?id=CVE-2016-9318'] | {'cves': '["CVE-2016-9318"]', 'title': 'CVE-2016-9318 on Ubuntu 18.04 LTS (bionic) - low', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Low', 'oval_type': 'cve', 'references': '["CVE-2016-9318", "https://www.cve.org/CVERecord?id=CVE-2016-9318"]', 'description': 'libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and otherproducts, does not offer a flag directly indicating that the currentdocument may be read but other files may not be opened, which makes iteasier for remote attackers to conduct XML External Entity (XXE) attacksvia a crafted document.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2016-9318` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nlibxml2 - 2.9.4+dfsg1-6.1ubuntu1.2\nlibxml2-utils - 2.9.4+dfsg1-6.1ubuntu1.2\npython-libxml2 - 2.9.4+dfsg1-6.1ubuntu1.2\npython3-libxml2 - 2.9.4+dfsg1-6.1ubuntu1.2\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:201693180000000', 'package_criteria': [{'cve_id': 'CVE-2016-9318', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libxml2', 'fixed_version': '2.9.4+dfsg1-6.1ubuntu1.2', 'affected_version_range': '< 2.9.4+dfsg1-6.1ubuntu1.2'}, {'cve_id': 'CVE-2016-9318', 'source': 'description_fix', 'status': 'fixed', 'package': 'libxml2-utils', 'fixed_version': '2.9.4+dfsg1-6.1ubuntu1.2', 'affected_version_range': '< 2.9.4+dfsg1-6.1ubuntu1.2'}, {'cve_id': 'CVE-2016-9318', 'source': 'description_fix', 'status': 'fixed', 'package': 'python-libxml2', 'fixed_version': '2.9.4+dfsg1-6.1ubuntu1.2', 'affected_version_range': '< 2.9.4+dfsg1-6.1ubuntu1.2'}, {'cve_id': 'CVE-2016-9318', 'source': 'description_fix', 'status': 'fixed', 'package': 'python3-libxml2', 'fixed_version': '2.9.4+dfsg1-6.1ubuntu1.2', 'affected_version_range': '< 2.9.4+dfsg1-6.1ubuntu1.2'}]} | 4171239eef7be53549190321bd37a8cd6aeea386668ae89d6eaacd3d60b71061 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201698010000000 | CVE-2016-9801 on Ubuntu 18.04 LTS (bionic) - negligible | In BlueZ 5.42, a buffer overflow was observed in "set_ext_ctrl" function in"tools/parser/l2cap.c" source file when processing corrupted dump file. | Negligible | ['CVE-2016-9801'] | ['Ubuntu 18.04 LTS'] | ['CVE-2016-9801', 'https://www.cve.org/CVERecord?id=CVE-2016-9801'] | {'cves': '["CVE-2016-9801"]', 'title': 'CVE-2016-9801 on Ubuntu 18.04 LTS (bionic) - negligible', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Negligible', 'oval_type': 'cve', 'references': '["CVE-2016-9801", "https://www.cve.org/CVERecord?id=CVE-2016-9801"]', 'description': 'In BlueZ 5.42, a buffer overflow was observed in "set_ext_ctrl" function in"tools/parser/l2cap.c" source file when processing corrupted dump file.', 'definition_id': 'oval:com.ubuntu.bionic:def:201698010000000', 'package_criteria': []} | 5d636c98ec9b05f237cbadb0db67500f6fe2a91d7f80ddcad4f953a5393ea396 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201698030000000 | CVE-2016-9803 on Ubuntu 18.04 LTS (bionic) - negligible | In BlueZ 5.42, an out-of-bounds read was observed in "le_meta_ev_dump"function in "tools/parser/hci.c" source file. This issue exists because'subevent' (which is used to read correct element from 'ev_le_meta_str'array) is overflowed. | Negligible | ['CVE-2016-9803'] | ['Ubuntu 18.04 LTS'] | ['CVE-2016-9803', 'https://www.cve.org/CVERecord?id=CVE-2016-9803'] | {'cves': '["CVE-2016-9803"]', 'title': 'CVE-2016-9803 on Ubuntu 18.04 LTS (bionic) - negligible', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Negligible', 'oval_type': 'cve', 'references': '["CVE-2016-9803", "https://www.cve.org/CVERecord?id=CVE-2016-9803"]', 'description': 'In BlueZ 5.42, an out-of-bounds read was observed in "le_meta_ev_dump"function in "tools/parser/hci.c" source file. This issue exists because\'subevent\' (which is used to read correct element from \'ev_le_meta_str\'array) is overflowed.', 'definition_id': 'oval:com.ubuntu.bionic:def:201698030000000', 'package_criteria': []} | 2752f20fadffe9334e9e40543fd0c1c495bc2e64ccc8da07b977ecd8d55f3802 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2017114100000000 | CVE-2017-11410 on Ubuntu 18.04 LTS (bionic) - medium | In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the WBXML dissectorcould go into an infinite loop, triggered by packet injection or amalformed capture file. This was addressed inepan/dissectors/packet-wbxml.c by adding validation of the relationshipsbetween indexes and lengths. NOTE: this vulnerability exists because of anincomplete fix for CVE-2017-7702.
Update Instructions:
Run `sudo pro fix CVE-2017-11410` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
libwireshark-data - 2.6.3-1~ubuntu18.04.1
libwireshark11 - 2.6.3-1~ubuntu18.04.1
libwiretap8 - 2.6.3-1~ubuntu18.04.1
libwscodecs2 - 2.6.3-1~ubuntu18.04.1
libwsutil9 - 2.6.3-1~ubuntu18.04.1
tshark - 2.6.3-1~ubuntu18.04.1
wireshark - 2.6.3-1~ubuntu18.04.1
wireshark-common - 2.6.3-1~ubuntu18.04.1
wireshark-gtk - 2.6.3-1~ubuntu18.04.1
wireshark-qt - 2.6.3-1~ubuntu18.04.1
No subscription required | Medium | ['CVE-2017-11410'] | ['Ubuntu 18.04 LTS'] | ['CVE-2017-11410', 'https://www.cve.org/CVERecord?id=CVE-2017-11410'] | {'cves': '["CVE-2017-11410"]', 'title': 'CVE-2017-11410 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2017-11410", "https://www.cve.org/CVERecord?id=CVE-2017-11410"]', 'description': 'In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the WBXML dissectorcould go into an infinite loop, triggered by packet injection or amalformed capture file. This was addressed inepan/dissectors/packet-wbxml.c by adding validation of the relationshipsbetween indexes and lengths. NOTE: this vulnerability exists because of anincomplete fix for CVE-2017-7702.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2017-11410` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nlibwireshark-data - 2.6.3-1~ubuntu18.04.1\nlibwireshark11 - 2.6.3-1~ubuntu18.04.1\nlibwiretap8 - 2.6.3-1~ubuntu18.04.1\nlibwscodecs2 - 2.6.3-1~ubuntu18.04.1\nlibwsutil9 - 2.6.3-1~ubuntu18.04.1\ntshark - 2.6.3-1~ubuntu18.04.1\nwireshark - 2.6.3-1~ubuntu18.04.1\nwireshark-common - 2.6.3-1~ubuntu18.04.1\nwireshark-gtk - 2.6.3-1~ubuntu18.04.1\nwireshark-qt - 2.6.3-1~ubuntu18.04.1\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2017114100000000', 'package_criteria': [{'cve_id': 'CVE-2017-11410', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wireshark', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}, {'cve_id': 'CVE-2017-11410', 'source': 'description_fix', 'status': 'fixed', 'package': 'libwireshark-data', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}, {'cve_id': 'CVE-2017-11410', 'source': 'description_fix', 'status': 'fixed', 'package': 'libwireshark11', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}, {'cve_id': 'CVE-2017-11410', 'source': 'description_fix', 'status': 'fixed', 'package': 'libwiretap8', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}, {'cve_id': 'CVE-2017-11410', 'source': 'description_fix', 'status': 'fixed', 'package': 'libwscodecs2', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}, {'cve_id': 'CVE-2017-11410', 'source': 'description_fix', 'status': 'fixed', 'package': 'libwsutil9', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}, {'cve_id': 'CVE-2017-11410', 'source': 'description_fix', 'status': 'fixed', 'package': 'tshark', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}, {'cve_id': 'CVE-2017-11410', 'source': 'description_fix', 'status': 'fixed', 'package': 'wireshark-common', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}, {'cve_id': 'CVE-2017-11410', 'source': 'description_fix', 'status': 'fixed', 'package': 'wireshark-gtk', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}, {'cve_id': 'CVE-2017-11410', 'source': 'description_fix', 'status': 'fixed', 'package': 'wireshark-qt', 'fixed_version': '2.6.3-1~ubuntu18.04.1', 'affected_version_range': '< 2.6.3-1~ubuntu18.04.1'}]} | cab3b5a1112cb0567ffd5036c36fcd23f3df175dde748e4dd7789d061206ebea | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2017126920000000 | CVE-2017-12692 on Ubuntu 18.04 LTS (bionic) - low | The ReadVIFFImage function in coders/viff.c in ImageMagick 7.0.6-6 allowsremote attackers to cause a denial of service (memory consumption) via acrafted VIFF file.
Update Instructions:
Run `sudo pro fix CVE-2017-12692` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
imagemagick - 8:6.9.7.4+dfsg-16ubuntu6.2
imagemagick-6-common - 8:6.9.7.4+dfsg-16ubuntu6.2
imagemagick-6.q16 - 8:6.9.7.4+dfsg-16ubuntu6.2
imagemagick-6.q16hdri - 8:6.9.7.4+dfsg-16ubuntu6.2
imagemagick-common - 8:6.9.7.4+dfsg-16ubuntu6.2
libimage-magick-perl - 8:6.9.7.4+dfsg-16ubuntu6.2
libimage-magick-q16-perl - 8:6.9.7.4+dfsg-16ubuntu6.2
libimage-magick-q16hdri-perl - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagick++-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagick++-6.q16-7 - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagick++-6.q16hdri-7 - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickcore-6-arch-config - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickcore-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickcore-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickcore-6.q16-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickcore-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickcore-6.q16hdri-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickwand-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickwand-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickwand-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.2
perlmagick - 8:6.9.7.4+dfsg-16ubuntu6.2
No subscription required | Low | ['CVE-2017-12692'] | ['Ubuntu 18.04 LTS'] | ['CVE-2017-12692', 'https://www.cve.org/CVERecord?id=CVE-2017-12692'] | {'cves': '["CVE-2017-12692"]', 'title': 'CVE-2017-12692 on Ubuntu 18.04 LTS (bionic) - low', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Low', 'oval_type': 'cve', 'references': '["CVE-2017-12692", "https://www.cve.org/CVERecord?id=CVE-2017-12692"]', 'description': 'The ReadVIFFImage function in coders/viff.c in ImageMagick 7.0.6-6 allowsremote attackers to cause a denial of service (memory consumption) via acrafted VIFF file.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2017-12692` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nimagemagick - 8:6.9.7.4+dfsg-16ubuntu6.2\nimagemagick-6-common - 8:6.9.7.4+dfsg-16ubuntu6.2\nimagemagick-6.q16 - 8:6.9.7.4+dfsg-16ubuntu6.2\nimagemagick-6.q16hdri - 8:6.9.7.4+dfsg-16ubuntu6.2\nimagemagick-common - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibimage-magick-perl - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibimage-magick-q16-perl - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibimage-magick-q16hdri-perl - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagick++-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagick++-6.q16-7 - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagick++-6.q16hdri-7 - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickcore-6-arch-config - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickcore-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickcore-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickcore-6.q16-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickcore-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickcore-6.q16hdri-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickwand-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickwand-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickwand-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.2\nperlmagick - 8:6.9.7.4+dfsg-16ubuntu6.2\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2017126920000000', 'package_criteria': [{'cve_id': 'CVE-2017-12692', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'imagemagick', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-6-common', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-6.q16', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-6.q16hdri', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-common', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'libimage-magick-perl', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'libimage-magick-q16-perl', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'libimage-magick-q16hdri-perl', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagick++-6-headers', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagick++-6.q16-7', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagick++-6.q16hdri-7', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6-arch-config', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6-headers', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16-3-extra', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16hdri-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16hdri-3-extra', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickwand-6-headers', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickwand-6.q16-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickwand-6.q16hdri-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-12692', 'source': 'description_fix', 'status': 'fixed', 'package': 'perlmagick', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}]} | d9c88fd08f2b5a696eebc7298b70508233d07ddbcae92dff74cac5e44bbf45c2 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2017137680000000 | CVE-2017-13768 on Ubuntu 18.04 LTS (bionic) - medium | Null Pointer Dereference in the IdentifyImage function inMagickCore/identify.c in ImageMagick through 7.0.6-10 allows an attacker toperform denial of service by sending a crafted image file.
Update Instructions:
Run `sudo pro fix CVE-2017-13768` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
imagemagick - 8:6.9.7.4+dfsg-16ubuntu6.2
imagemagick-6-common - 8:6.9.7.4+dfsg-16ubuntu6.2
imagemagick-6.q16 - 8:6.9.7.4+dfsg-16ubuntu6.2
imagemagick-6.q16hdri - 8:6.9.7.4+dfsg-16ubuntu6.2
imagemagick-common - 8:6.9.7.4+dfsg-16ubuntu6.2
libimage-magick-perl - 8:6.9.7.4+dfsg-16ubuntu6.2
libimage-magick-q16-perl - 8:6.9.7.4+dfsg-16ubuntu6.2
libimage-magick-q16hdri-perl - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagick++-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagick++-6.q16-7 - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagick++-6.q16hdri-7 - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickcore-6-arch-config - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickcore-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickcore-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickcore-6.q16-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickcore-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickcore-6.q16hdri-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickwand-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickwand-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickwand-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.2
perlmagick - 8:6.9.7.4+dfsg-16ubuntu6.2
No subscription required | Medium | ['CVE-2017-13768'] | ['Ubuntu 18.04 LTS'] | ['CVE-2017-13768', 'https://www.cve.org/CVERecord?id=CVE-2017-13768'] | {'cves': '["CVE-2017-13768"]', 'title': 'CVE-2017-13768 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2017-13768", "https://www.cve.org/CVERecord?id=CVE-2017-13768"]', 'description': 'Null Pointer Dereference in the IdentifyImage function inMagickCore/identify.c in ImageMagick through 7.0.6-10 allows an attacker toperform denial of service by sending a crafted image file.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2017-13768` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nimagemagick - 8:6.9.7.4+dfsg-16ubuntu6.2\nimagemagick-6-common - 8:6.9.7.4+dfsg-16ubuntu6.2\nimagemagick-6.q16 - 8:6.9.7.4+dfsg-16ubuntu6.2\nimagemagick-6.q16hdri - 8:6.9.7.4+dfsg-16ubuntu6.2\nimagemagick-common - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibimage-magick-perl - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibimage-magick-q16-perl - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibimage-magick-q16hdri-perl - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagick++-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagick++-6.q16-7 - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagick++-6.q16hdri-7 - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickcore-6-arch-config - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickcore-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickcore-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickcore-6.q16-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickcore-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickcore-6.q16hdri-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickwand-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickwand-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickwand-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.2\nperlmagick - 8:6.9.7.4+dfsg-16ubuntu6.2\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2017137680000000', 'package_criteria': [{'cve_id': 'CVE-2017-13768', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'imagemagick', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-6-common', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-6.q16', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-6.q16hdri', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-common', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'libimage-magick-perl', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'libimage-magick-q16-perl', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'libimage-magick-q16hdri-perl', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagick++-6-headers', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagick++-6.q16-7', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagick++-6.q16hdri-7', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6-arch-config', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6-headers', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16-3-extra', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16hdri-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16hdri-3-extra', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickwand-6-headers', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickwand-6.q16-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickwand-6.q16hdri-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2017-13768', 'source': 'description_fix', 'status': 'fixed', 'package': 'perlmagick', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}]} | 964cda8893b064fa70d115416e71cb91c6aab43d4f40b405fbb1cbea3b91d6e8 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
pkg | bionic | oval:com.ubuntu.bionic:def:18040271500000 | node-sha.js | Streamable SHA hashes in pure javascript | ['CVE-2025-9288'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/node-sha.js', 'node-sha.js'] | {'cves': '["CVE-2025-9288"]', 'title': 'node-sha.js', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/node-sha.js", "node-sha.js"]', 'description': 'Streamable SHA hashes in pure javascript', 'definition_id': 'oval:com.ubuntu.bionic:def:18040271500000', 'package_criteria': [{'cve_id': 'CVE-2025-9288', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'node-sha.js', 'fixed_version': '2.4.9-1ubuntu0.1~esm1', 'affected_version_range': '< 2.4.9-1ubuntu0.1~esm1'}]} | 604bc21e016c75dc36b7828106b97ae48a205c23e7e1b1a740417ee47d58340d | 2026-06-15 14:51:21.224735+03:00 | 2026-06-15 14:51:21.224735+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040273100000 | pam-pkcs11 | ['CVE-2025-24032'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/pam-pkcs11', 'pam-pkcs11'] | {'cves': '["CVE-2025-24032"]', 'title': 'pam-pkcs11', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/pam-pkcs11", "pam-pkcs11"]', 'description': None, 'definition_id': 'oval:com.ubuntu.bionic:def:18040273100000', 'package_criteria': [{'cve_id': 'CVE-2025-24032', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'pam-pkcs11', 'fixed_version': '0.6.9-2ubuntu0.1~esm1', 'affected_version_range': '< 0.6.9-2ubuntu0.1~esm1'}]} | 43ef4867d691d07c4c9026f7ee3798d44468925f30c92868962be7f23d2bcd3c | 2026-06-15 14:51:21.224735+03:00 | 2026-06-15 14:51:21.224735+03:00 | ||||
pkg | bionic | oval:com.ubuntu.bionic:def:18040279700000 | simpleeval | ['CVE-2026-32640'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/simpleeval', 'simpleeval'] | {'cves': '["CVE-2026-32640"]', 'title': 'simpleeval', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/simpleeval", "simpleeval"]', 'description': None, 'definition_id': 'oval:com.ubuntu.bionic:def:18040279700000', 'package_criteria': [{'cve_id': 'CVE-2026-32640', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'simpleeval', 'fixed_version': '0.9.5-1ubuntu0.1~esm1', 'affected_version_range': '< 0.9.5-1ubuntu0.1~esm1'}]} | 53cea06ee082b22213c85dc2c76875a7070422272622dfe6da7360178ea91bd2 | 2026-06-15 14:51:21.224735+03:00 | 2026-06-15 14:51:21.224735+03:00 | ||||
pkg | bionic | oval:com.ubuntu.bionic:def:18040281500000 | wlc | Command line utility for Weblate | ['CVE-2026-22250', 'CVE-2026-22251'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/wlc', 'wlc'] | {'cves': '["CVE-2026-22250", "CVE-2026-22251"]', 'title': 'wlc', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/wlc", "wlc"]', 'description': 'Command line utility for Weblate', 'definition_id': 'oval:com.ubuntu.bionic:def:18040281500000', 'package_criteria': [{'cve_id': 'CVE-2026-22250', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wlc', 'fixed_version': '0.8-1ubuntu0.1~esm1', 'affected_version_range': '< 0.8-1ubuntu0.1~esm1'}]} | be6c20234d13ae6fdd77f3081fd40f1e2bca57c167a4d4aaf71ddc6bc9a696d9 | 2026-06-15 14:51:21.224735+03:00 | 2026-06-15 14:51:21.224735+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040283100000 | zulucrypt | A simple, feature rich and powerful solution for hard drives encryption | ['CVE-2025-53391'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/zulucrypt', 'zulucrypt'] | {'cves': '["CVE-2025-53391"]', 'title': 'zulucrypt', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/zulucrypt", "zulucrypt"]', 'description': 'A simple, feature rich and powerful solution for hard drives encryption', 'definition_id': 'oval:com.ubuntu.bionic:def:18040283100000', 'package_criteria': [{'cve_id': 'CVE-2025-53391', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'zulucrypt', 'fixed_version': '5.4.0-2ubuntu0.1~esm2', 'affected_version_range': '< 5.4.0-2ubuntu0.1~esm2'}]} | 4ba4172a9d4f51dbebd0a625dda80e57f1b5b49752ceab5396155c53658d27c8 | 2026-06-15 14:51:21.224735+03:00 | 2026-06-15 14:51:21.224735+03:00 | |||
cve | bionic | oval:com.ubuntu.bionic:def:2017141080000000 | CVE-2017-14108 on Ubuntu 18.04 LTS (bionic) - negligible | libgedit.a in GNOME gedit through 3.22.1 allows remote attackers to cause adenial of service (CPU consumption) via a file that begins with many '\0'characters. | Negligible | ['CVE-2017-14108'] | ['Ubuntu 18.04 LTS'] | ['CVE-2017-14108', 'https://www.cve.org/CVERecord?id=CVE-2017-14108'] | {'cves': '["CVE-2017-14108"]', 'title': 'CVE-2017-14108 on Ubuntu 18.04 LTS (bionic) - negligible', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Negligible', 'oval_type': 'cve', 'references': '["CVE-2017-14108", "https://www.cve.org/CVERecord?id=CVE-2017-14108"]', 'description': "libgedit.a in GNOME gedit through 3.22.1 allows remote attackers to cause adenial of service (CPU consumption) via a file that begins with many '\\0'characters.", 'definition_id': 'oval:com.ubuntu.bionic:def:2017141080000000', 'package_criteria': []} | 91d3ade4664ca578abb51a0317fe28ce64a0713d074b98125ff736c76b3d45e0 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2017165410000000 | CVE-2017-16541 on Ubuntu 18.04 LTS (bionic) - medium | Tor Browser before 7.0.9 on macOS and Linux allows remote attackers tobypass the intended anonymity feature and discover a client IP address viavectors involving a crafted web site that leverages file:// mishandling inFirefox, aka TorMoil. NOTE: Tails is unaffected.
Update Instructions:
Run `sudo pro fix CVE-2017-16541` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
firefox - 62.0+build2-0ubuntu0.18.04.3
firefox-globalmenu - 62.0+build2-0ubuntu0.18.04.3
firefox-mozsymbols - 62.0+build2-0ubuntu0.18.04.3
firefox-testsuite - 62.0+build2-0ubuntu0.18.04.3
No subscription required
thunderbird - 1:60.2.1+build1-0ubuntu0.18.04.2
thunderbird-globalmenu - 1:60.2.1+build1-0ubuntu0.18.04.2
thunderbird-gnome-support - 1:60.2.1+build1-0ubuntu0.18.04.2
thunderbird-mozsymbols - 1:60.2.1+build1-0ubuntu0.18.04.2
thunderbird-testsuite - 1:60.2.1+build1-0ubuntu0.18.04.2
xul-ext-calendar-timezones - 1:60.2.1+build1-0ubuntu0.18.04.2
xul-ext-gdata-provider - 1:60.2.1+build1-0ubuntu0.18.04.2
xul-ext-lightning - 1:60.2.1+build1-0ubuntu0.18.04.2
No subscription required | Medium | ['CVE-2017-16541'] | ['Ubuntu 18.04 LTS'] | ['CVE-2017-16541', 'https://www.cve.org/CVERecord?id=CVE-2017-16541'] | {'cves': '["CVE-2017-16541"]', 'title': 'CVE-2017-16541 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2017-16541", "https://www.cve.org/CVERecord?id=CVE-2017-16541"]', 'description': 'Tor Browser before 7.0.9 on macOS and Linux allows remote attackers tobypass the intended anonymity feature and discover a client IP address viavectors involving a crafted web site that leverages file:// mishandling inFirefox, aka TorMoil. NOTE: Tails is unaffected.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2017-16541` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nfirefox - 62.0+build2-0ubuntu0.18.04.3\nfirefox-globalmenu - 62.0+build2-0ubuntu0.18.04.3\nfirefox-mozsymbols - 62.0+build2-0ubuntu0.18.04.3\nfirefox-testsuite - 62.0+build2-0ubuntu0.18.04.3\nNo subscription required\n\nthunderbird - 1:60.2.1+build1-0ubuntu0.18.04.2\nthunderbird-globalmenu - 1:60.2.1+build1-0ubuntu0.18.04.2\nthunderbird-gnome-support - 1:60.2.1+build1-0ubuntu0.18.04.2\nthunderbird-mozsymbols - 1:60.2.1+build1-0ubuntu0.18.04.2\nthunderbird-testsuite - 1:60.2.1+build1-0ubuntu0.18.04.2\nxul-ext-calendar-timezones - 1:60.2.1+build1-0ubuntu0.18.04.2\nxul-ext-gdata-provider - 1:60.2.1+build1-0ubuntu0.18.04.2\nxul-ext-lightning - 1:60.2.1+build1-0ubuntu0.18.04.2\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2017165410000000', 'package_criteria': [{'cve_id': 'CVE-2017-16541', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'firefox', 'fixed_version': '62.0+build2-0ubuntu0.18.04.3', 'affected_version_range': '< 62.0+build2-0ubuntu0.18.04.3'}, {'cve_id': 'CVE-2017-16541', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'thunderbird', 'fixed_version': '1:60.2.1+build1-0ubuntu0.18.04.2', 'affected_version_range': '< 1:60.2.1+build1-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2017-16541', 'source': 'description_fix', 'status': 'fixed', 'package': 'firefox-globalmenu', 'fixed_version': '62.0+build2-0ubuntu0.18.04.3', 'affected_version_range': '< 62.0+build2-0ubuntu0.18.04.3'}, {'cve_id': 'CVE-2017-16541', 'source': 'description_fix', 'status': 'fixed', 'package': 'firefox-mozsymbols', 'fixed_version': '62.0+build2-0ubuntu0.18.04.3', 'affected_version_range': '< 62.0+build2-0ubuntu0.18.04.3'}, {'cve_id': 'CVE-2017-16541', 'source': 'description_fix', 'status': 'fixed', 'package': 'firefox-testsuite', 'fixed_version': '62.0+build2-0ubuntu0.18.04.3', 'affected_version_range': '< 62.0+build2-0ubuntu0.18.04.3'}, {'cve_id': 'CVE-2017-16541', 'source': 'description_fix', 'status': 'fixed', 'package': 'thunderbird-globalmenu', 'fixed_version': '1:60.2.1+build1-0ubuntu0.18.04.2', 'affected_version_range': '< 1:60.2.1+build1-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2017-16541', 'source': 'description_fix', 'status': 'fixed', 'package': 'thunderbird-gnome-support', 'fixed_version': '1:60.2.1+build1-0ubuntu0.18.04.2', 'affected_version_range': '< 1:60.2.1+build1-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2017-16541', 'source': 'description_fix', 'status': 'fixed', 'package': 'thunderbird-mozsymbols', 'fixed_version': '1:60.2.1+build1-0ubuntu0.18.04.2', 'affected_version_range': '< 1:60.2.1+build1-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2017-16541', 'source': 'description_fix', 'status': 'fixed', 'package': 'thunderbird-testsuite', 'fixed_version': '1:60.2.1+build1-0ubuntu0.18.04.2', 'affected_version_range': '< 1:60.2.1+build1-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2017-16541', 'source': 'description_fix', 'status': 'fixed', 'package': 'xul-ext-calendar-timezones', 'fixed_version': '1:60.2.1+build1-0ubuntu0.18.04.2', 'affected_version_range': '< 1:60.2.1+build1-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2017-16541', 'source': 'description_fix', 'status': 'fixed', 'package': 'xul-ext-gdata-provider', 'fixed_version': '1:60.2.1+build1-0ubuntu0.18.04.2', 'affected_version_range': '< 1:60.2.1+build1-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2017-16541', 'source': 'description_fix', 'status': 'fixed', 'package': 'xul-ext-lightning', 'fixed_version': '1:60.2.1+build1-0ubuntu0.18.04.2', 'affected_version_range': '< 1:60.2.1+build1-0ubuntu0.18.04.2'}]} | d1231573a5a213c3c8456f8d66cba63404f8bc76c54c66dc6010754168932240 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2017182660000000 | CVE-2017-18266 on Ubuntu 18.04 LTS (bionic) - medium | The open_envvar function in xdg-open in xdg-utils before 1.1.3 does notvalidate strings before launching the program specified by the BROWSERenvironment variable, which might allow remote attackers to conductargument-injection attacks via a crafted URL, as demonstrated by %s in thisenvironment variable.
Update Instructions:
Run `sudo pro fix CVE-2017-18266` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
xdg-utils - 1.1.2-1ubuntu2.2
No subscription required | Medium | ['CVE-2017-18266'] | ['Ubuntu 18.04 LTS'] | ['CVE-2017-18266', 'https://www.cve.org/CVERecord?id=CVE-2017-18266'] | {'cves': '["CVE-2017-18266"]', 'title': 'CVE-2017-18266 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2017-18266", "https://www.cve.org/CVERecord?id=CVE-2017-18266"]', 'description': 'The open_envvar function in xdg-open in xdg-utils before 1.1.3 does notvalidate strings before launching the program specified by the BROWSERenvironment variable, which might allow remote attackers to conductargument-injection attacks via a crafted URL, as demonstrated by %s in thisenvironment variable.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2017-18266` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nxdg-utils - 1.1.2-1ubuntu2.2\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2017182660000000', 'package_criteria': [{'cve_id': 'CVE-2017-18266', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'xdg-utils', 'fixed_version': '1.1.2-1ubuntu2.2', 'affected_version_range': '< 1.1.2-1ubuntu2.2'}]} | ab5e5ee77d6db7e7ba3308c8a8e55e40e108eb1d3dd4a351d2b6bc093eafe4aa | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201750940000000 | CVE-2017-5094 on Ubuntu 18.04 LTS (bionic) - medium | Type confusion in extensions JavaScript bindings in Google Chrome prior to60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attackerto potentially maliciously modify objects via a crafted HTML page.
Update Instructions:
Run `sudo pro fix CVE-2017-5094` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
chromium-browser - 60.0.3112.78-0ubuntu1.1363
chromium-browser-l10n - 60.0.3112.78-0ubuntu1.1363
chromium-chromedriver - 60.0.3112.78-0ubuntu1.1363
chromium-codecs-ffmpeg - 60.0.3112.78-0ubuntu1.1363
chromium-codecs-ffmpeg-extra - 60.0.3112.78-0ubuntu1.1363
No subscription required | Medium | ['CVE-2017-5094'] | ['Ubuntu 18.04 LTS'] | ['CVE-2017-5094', 'https://www.cve.org/CVERecord?id=CVE-2017-5094'] | {'cves': '["CVE-2017-5094"]', 'title': 'CVE-2017-5094 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2017-5094", "https://www.cve.org/CVERecord?id=CVE-2017-5094"]', 'description': 'Type confusion in extensions JavaScript bindings in Google Chrome prior to60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attackerto potentially maliciously modify objects via a crafted HTML page.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2017-5094` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nchromium-browser - 60.0.3112.78-0ubuntu1.1363\nchromium-browser-l10n - 60.0.3112.78-0ubuntu1.1363\nchromium-chromedriver - 60.0.3112.78-0ubuntu1.1363\nchromium-codecs-ffmpeg - 60.0.3112.78-0ubuntu1.1363\nchromium-codecs-ffmpeg-extra - 60.0.3112.78-0ubuntu1.1363\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:201750940000000', 'package_criteria': [{'cve_id': 'CVE-2017-5094', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'chromium-browser', 'fixed_version': '60.0.3112.78-0ubuntu1.1363', 'affected_version_range': '< 60.0.3112.78-0ubuntu1.1363'}, {'cve_id': 'CVE-2017-5094', 'source': 'description_fix', 'status': 'fixed', 'package': 'chromium-browser-l10n', 'fixed_version': '60.0.3112.78-0ubuntu1.1363', 'affected_version_range': '< 60.0.3112.78-0ubuntu1.1363'}, {'cve_id': 'CVE-2017-5094', 'source': 'description_fix', 'status': 'fixed', 'package': 'chromium-chromedriver', 'fixed_version': '60.0.3112.78-0ubuntu1.1363', 'affected_version_range': '< 60.0.3112.78-0ubuntu1.1363'}, {'cve_id': 'CVE-2017-5094', 'source': 'description_fix', 'status': 'fixed', 'package': 'chromium-codecs-ffmpeg', 'fixed_version': '60.0.3112.78-0ubuntu1.1363', 'affected_version_range': '< 60.0.3112.78-0ubuntu1.1363'}, {'cve_id': 'CVE-2017-5094', 'source': 'description_fix', 'status': 'fixed', 'package': 'chromium-codecs-ffmpeg-extra', 'fixed_version': '60.0.3112.78-0ubuntu1.1363', 'affected_version_range': '< 60.0.3112.78-0ubuntu1.1363'}]} | b96cab17d8f9e86b067dca06978bea50af8cad7f097e0d41bef9f2ff4949771a | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201769600000000 | CVE-2017-6960 on Ubuntu 18.04 LTS (bionic) - medium | An issue was discovered in apng2gif 1.7. There is an integer overflowresulting in a heap-based buffer over-read, related to the load_apngfunction and the imagesize variable. | Medium | ['CVE-2017-6960'] | ['Ubuntu 18.04 LTS'] | ['CVE-2017-6960', 'https://www.cve.org/CVERecord?id=CVE-2017-6960'] | {'cves': '["CVE-2017-6960"]', 'title': 'CVE-2017-6960 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2017-6960", "https://www.cve.org/CVERecord?id=CVE-2017-6960"]', 'description': 'An issue was discovered in apng2gif 1.7. There is an integer overflowresulting in a heap-based buffer over-read, related to the load_apngfunction and the imagesize variable.', 'definition_id': 'oval:com.ubuntu.bionic:def:201769600000000', 'package_criteria': []} | eda09464020e8caa30648ee3f08c8dc89aa0b65e009420873393f60d85e1550b | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201774750000000 | CVE-2017-7475 on Ubuntu 18.04 LTS (bionic) - low | Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related tothe FT_Load_Glyph and FT_Render_Glyph resulting in an application crash. | Low | ['CVE-2017-7475'] | ['Ubuntu 18.04 LTS'] | ['CVE-2017-7475', 'https://www.cve.org/CVERecord?id=CVE-2017-7475'] | {'cves': '["CVE-2017-7475"]', 'title': 'CVE-2017-7475 on Ubuntu 18.04 LTS (bionic) - low', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Low', 'oval_type': 'cve', 'references': '["CVE-2017-7475", "https://www.cve.org/CVERecord?id=CVE-2017-7475"]', 'description': 'Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related tothe FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.', 'definition_id': 'oval:com.ubuntu.bionic:def:201774750000000', 'package_criteria': []} | 28810bbd8a5f5b44e6000175f2ebd2109d6bbff5fafb8c8ac11faaa0615b5c52 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201775310000000 | CVE-2017-7531 on Ubuntu 18.04 LTS (bionic) - medium | In Moodle 3.3, the course overview block reveals activities in hiddencourses. | Medium | ['CVE-2017-7531'] | ['Ubuntu 18.04 LTS'] | ['CVE-2017-7531', 'https://www.cve.org/CVERecord?id=CVE-2017-7531'] | {'cves': '["CVE-2017-7531"]', 'title': 'CVE-2017-7531 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2017-7531", "https://www.cve.org/CVERecord?id=CVE-2017-7531"]', 'description': 'In Moodle 3.3, the course overview block reveals activities in hiddencourses.', 'definition_id': 'oval:com.ubuntu.bionic:def:201775310000000', 'package_criteria': []} | c64711216aee417374ad5e821ea4c990b76c11213390af63be0dcaf67442df6e | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201777790000000 | CVE-2017-7779 on Ubuntu 18.04 LTS (bionic) - medium | Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, andThunderbird 52.2. Some of these bugs showed evidence of memory corruptionand we presume that with enough effort that some of these could beexploited to run arbitrary code. This vulnerability affects Thunderbird <52.3, Firefox ESR < 52.3, and Firefox < 55.
Update Instructions:
Run `sudo pro fix CVE-2017-7779` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
firefox - 55.0.2+build1-0ubuntu4
firefox-globalmenu - 55.0.2+build1-0ubuntu4
firefox-mozsymbols - 55.0.2+build1-0ubuntu4
firefox-testsuite - 55.0.2+build1-0ubuntu4
No subscription required
thunderbird - 1:52.4.0+build1-0ubuntu2
thunderbird-globalmenu - 1:52.4.0+build1-0ubuntu2
thunderbird-gnome-support - 1:52.4.0+build1-0ubuntu2
thunderbird-mozsymbols - 1:52.4.0+build1-0ubuntu2
thunderbird-testsuite - 1:52.4.0+build1-0ubuntu2
xul-ext-calendar-timezones - 1:52.4.0+build1-0ubuntu2
xul-ext-gdata-provider - 1:52.4.0+build1-0ubuntu2
xul-ext-lightning - 1:52.4.0+build1-0ubuntu2
No subscription required | Medium | ['CVE-2017-7779'] | ['Ubuntu 18.04 LTS'] | ['CVE-2017-7779', 'https://www.cve.org/CVERecord?id=CVE-2017-7779'] | {'cves': '["CVE-2017-7779"]', 'title': 'CVE-2017-7779 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2017-7779", "https://www.cve.org/CVERecord?id=CVE-2017-7779"]', 'description': 'Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, andThunderbird 52.2. Some of these bugs showed evidence of memory corruptionand we presume that with enough effort that some of these could beexploited to run arbitrary code. This vulnerability affects Thunderbird <52.3, Firefox ESR < 52.3, and Firefox < 55.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2017-7779` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nfirefox - 55.0.2+build1-0ubuntu4\nfirefox-globalmenu - 55.0.2+build1-0ubuntu4\nfirefox-mozsymbols - 55.0.2+build1-0ubuntu4\nfirefox-testsuite - 55.0.2+build1-0ubuntu4\nNo subscription required\n\nthunderbird - 1:52.4.0+build1-0ubuntu2\nthunderbird-globalmenu - 1:52.4.0+build1-0ubuntu2\nthunderbird-gnome-support - 1:52.4.0+build1-0ubuntu2\nthunderbird-mozsymbols - 1:52.4.0+build1-0ubuntu2\nthunderbird-testsuite - 1:52.4.0+build1-0ubuntu2\nxul-ext-calendar-timezones - 1:52.4.0+build1-0ubuntu2\nxul-ext-gdata-provider - 1:52.4.0+build1-0ubuntu2\nxul-ext-lightning - 1:52.4.0+build1-0ubuntu2\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:201777790000000', 'package_criteria': [{'cve_id': 'CVE-2017-7779', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'firefox', 'fixed_version': '55.0.2+build1-0ubuntu4', 'affected_version_range': '< 55.0.2+build1-0ubuntu4'}, {'cve_id': 'CVE-2017-7779', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'thunderbird', 'fixed_version': '1:52.4.0+build1-0ubuntu2', 'affected_version_range': '< 1:52.4.0+build1-0ubuntu2'}, {'cve_id': 'CVE-2017-7779', 'source': 'description_fix', 'status': 'fixed', 'package': 'firefox-globalmenu', 'fixed_version': '55.0.2+build1-0ubuntu4', 'affected_version_range': '< 55.0.2+build1-0ubuntu4'}, {'cve_id': 'CVE-2017-7779', 'source': 'description_fix', 'status': 'fixed', 'package': 'firefox-mozsymbols', 'fixed_version': '55.0.2+build1-0ubuntu4', 'affected_version_range': '< 55.0.2+build1-0ubuntu4'}, {'cve_id': 'CVE-2017-7779', 'source': 'description_fix', 'status': 'fixed', 'package': 'firefox-testsuite', 'fixed_version': '55.0.2+build1-0ubuntu4', 'affected_version_range': '< 55.0.2+build1-0ubuntu4'}, {'cve_id': 'CVE-2017-7779', 'source': 'description_fix', 'status': 'fixed', 'package': 'thunderbird-globalmenu', 'fixed_version': '1:52.4.0+build1-0ubuntu2', 'affected_version_range': '< 1:52.4.0+build1-0ubuntu2'}, {'cve_id': 'CVE-2017-7779', 'source': 'description_fix', 'status': 'fixed', 'package': 'thunderbird-gnome-support', 'fixed_version': '1:52.4.0+build1-0ubuntu2', 'affected_version_range': '< 1:52.4.0+build1-0ubuntu2'}, {'cve_id': 'CVE-2017-7779', 'source': 'description_fix', 'status': 'fixed', 'package': 'thunderbird-mozsymbols', 'fixed_version': '1:52.4.0+build1-0ubuntu2', 'affected_version_range': '< 1:52.4.0+build1-0ubuntu2'}, {'cve_id': 'CVE-2017-7779', 'source': 'description_fix', 'status': 'fixed', 'package': 'thunderbird-testsuite', 'fixed_version': '1:52.4.0+build1-0ubuntu2', 'affected_version_range': '< 1:52.4.0+build1-0ubuntu2'}, {'cve_id': 'CVE-2017-7779', 'source': 'description_fix', 'status': 'fixed', 'package': 'xul-ext-calendar-timezones', 'fixed_version': '1:52.4.0+build1-0ubuntu2', 'affected_version_range': '< 1:52.4.0+build1-0ubuntu2'}, {'cve_id': 'CVE-2017-7779', 'source': 'description_fix', 'status': 'fixed', 'package': 'xul-ext-gdata-provider', 'fixed_version': '1:52.4.0+build1-0ubuntu2', 'affected_version_range': '< 1:52.4.0+build1-0ubuntu2'}, {'cve_id': 'CVE-2017-7779', 'source': 'description_fix', 'status': 'fixed', 'package': 'xul-ext-lightning', 'fixed_version': '1:52.4.0+build1-0ubuntu2', 'affected_version_range': '< 1:52.4.0+build1-0ubuntu2'}]} | 2c2dc83ce12bd9b75c3b8f9a6dc30825f46319d6ac7d700a90f0ec1f5c806030 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201777810000000 | CVE-2017-7781 on Ubuntu 18.04 LTS (bionic) - medium | An error occurs in the elliptic curve point addition algorithm that usesmixed Jacobian-affine coordinates where it can yield a result"POINT_AT_INFINITY" when it should not. A man-in-the-middle attacker coulduse this to interfere with a connection, resulting in an attacked partycomputing an incorrect shared secret. This vulnerability affects Firefox <55.
Update Instructions:
Run `sudo pro fix CVE-2017-7781` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
firefox - 55.0.2+build1-0ubuntu4
firefox-globalmenu - 55.0.2+build1-0ubuntu4
firefox-mozsymbols - 55.0.2+build1-0ubuntu4
firefox-testsuite - 55.0.2+build1-0ubuntu4
No subscription required | Medium | ['CVE-2017-7781'] | ['Ubuntu 18.04 LTS'] | ['CVE-2017-7781', 'https://www.cve.org/CVERecord?id=CVE-2017-7781'] | {'cves': '["CVE-2017-7781"]', 'title': 'CVE-2017-7781 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2017-7781", "https://www.cve.org/CVERecord?id=CVE-2017-7781"]', 'description': 'An error occurs in the elliptic curve point addition algorithm that usesmixed Jacobian-affine coordinates where it can yield a result"POINT_AT_INFINITY" when it should not. A man-in-the-middle attacker coulduse this to interfere with a connection, resulting in an attacked partycomputing an incorrect shared secret. This vulnerability affects Firefox <55.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2017-7781` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nfirefox - 55.0.2+build1-0ubuntu4\nfirefox-globalmenu - 55.0.2+build1-0ubuntu4\nfirefox-mozsymbols - 55.0.2+build1-0ubuntu4\nfirefox-testsuite - 55.0.2+build1-0ubuntu4\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:201777810000000', 'package_criteria': [{'cve_id': 'CVE-2017-7781', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'firefox', 'fixed_version': '55.0.2+build1-0ubuntu4', 'affected_version_range': '< 55.0.2+build1-0ubuntu4'}, {'cve_id': 'CVE-2017-7781', 'source': 'description_fix', 'status': 'fixed', 'package': 'firefox-globalmenu', 'fixed_version': '55.0.2+build1-0ubuntu4', 'affected_version_range': '< 55.0.2+build1-0ubuntu4'}, {'cve_id': 'CVE-2017-7781', 'source': 'description_fix', 'status': 'fixed', 'package': 'firefox-mozsymbols', 'fixed_version': '55.0.2+build1-0ubuntu4', 'affected_version_range': '< 55.0.2+build1-0ubuntu4'}, {'cve_id': 'CVE-2017-7781', 'source': 'description_fix', 'status': 'fixed', 'package': 'firefox-testsuite', 'fixed_version': '55.0.2+build1-0ubuntu4', 'affected_version_range': '< 55.0.2+build1-0ubuntu4'}]} | 6846a8848e84b01ff37b8d0c33cc653e2574c56129c57f5f3488f8bb435e8d76 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
pkg | bionic | oval:com.ubuntu.bionic:def:18040248600000 | libndp | Library for Neighbor Discovery Protocol | ['CVE-2024-5564'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/libndp', 'libndp'] | {'cves': '["CVE-2024-5564"]', 'title': 'libndp', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/libndp", "libndp"]', 'description': 'Library for Neighbor Discovery Protocol', 'definition_id': 'oval:com.ubuntu.bionic:def:18040248600000', 'package_criteria': [{'cve_id': 'CVE-2024-5564', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libndp', 'fixed_version': '1.6-1ubuntu0.1~esm1', 'affected_version_range': '< 1.6-1ubuntu0.1~esm1'}]} | e93f5e4be8d0cfdaa9f7e06d95e56b1a19fa969838542eadf0c4fe184cfe4870 | 2026-05-30 01:47:08.377667+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040250000000 | nano | GNU nano editor | ['CVE-2024-5742', 'CVE-2026-6842'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/nano', 'nano'] | {'cves': '["CVE-2024-5742", "CVE-2026-6842"]', 'title': 'nano', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/nano", "nano"]', 'description': 'GNU nano editor', 'definition_id': 'oval:com.ubuntu.bionic:def:18040250000000', 'package_criteria': [{'cve_id': 'CVE-2024-5742', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'nano', 'fixed_version': '2.9.3-2ubuntu0.1~esm1', 'affected_version_range': '< 2.9.3-2ubuntu0.1~esm1'}, {'cve_id': 'CVE-2026-6842', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'nano', 'fixed_version': '2.9.3-2ubuntu0.1~esm2', 'affected_version_range': '< 2.9.3-2ubuntu0.1~esm2'}]} | dee7ba5b09e731721465ecc401f5d8ed2a3386ae7ce20bf86e877a8495530297 | 2026-06-10 19:57:18.158423+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040250700000 | pymongo | Python interface to the MongoDB document-oriented database | ['CVE-2024-5629'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/pymongo', 'pymongo'] | {'cves': '["CVE-2024-5629"]', 'title': 'pymongo', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/pymongo", "pymongo"]', 'description': 'Python interface to the MongoDB document-oriented database', 'definition_id': 'oval:com.ubuntu.bionic:def:18040250700000', 'package_criteria': [{'cve_id': 'CVE-2024-5629', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'pymongo', 'fixed_version': '3.6.1+dfsg1-1ubuntu0.1~esm1', 'affected_version_range': '< 3.6.1+dfsg1-1ubuntu0.1~esm1'}]} | 20f55e6ed6a8dc2a0dbeeaff426d5dca0a9cfec28bb3fadffcf66d247d016481 | 2026-06-13 04:54:10.738166+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040251500000 | sed | GNU stream editor for filtering/transforming text | ['CVE-2026-5958'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/sed', 'sed'] | {'cves': '["CVE-2026-5958"]', 'title': 'sed', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/sed", "sed"]', 'description': 'GNU stream editor for filtering/transforming text', 'definition_id': 'oval:com.ubuntu.bionic:def:18040251500000', 'package_criteria': [{'cve_id': 'CVE-2026-5958', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'sed', 'fixed_version': '4.4-2ubuntu0.1~esm1', 'affected_version_range': '< 4.4-2ubuntu0.1~esm1'}]} | 70bc1e382e4505123bc733e4d7da24d8bbdc257240f52ebffd00a6c1a6370ebc | 2026-06-13 04:53:56.938372+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040251800000 | ubuntu-advantage-desktop-daemon | Daemon to allow access to ubuntu-advantage via D-Bus | ['CVE-2024-6388'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/ubuntu-advantage-desktop-daemon', 'ubuntu-advantage-desktop-daemon'] | {'cves': '["CVE-2024-6388"]', 'title': 'ubuntu-advantage-desktop-daemon', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/ubuntu-advantage-desktop-daemon", "ubuntu-advantage-desktop-daemon"]', 'description': 'Daemon to allow access to ubuntu-advantage via D-Bus', 'definition_id': 'oval:com.ubuntu.bionic:def:18040251800000', 'package_criteria': [{'cve_id': 'CVE-2024-6388', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'ubuntu-advantage-desktop-daemon', 'fixed_version': '1.10.ubuntu0.18.04.1~esm1', 'affected_version_range': '< 1.10.ubuntu0.18.04.1~esm1'}]} | 12bf8c016e819c43b8bee9a087bf28d3fd2074cd7966c47249db7c56dcaa38bb | 2026-05-30 01:46:54.794516+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040252500000 | anope | an open source set of IRC Services | ['CVE-2024-30187'] | ['Ubuntu 18.04 LTS'] | ['anope', 'https://launchpad.net/ubuntu/+source/anope'] | {'cves': '["CVE-2024-30187"]', 'title': 'anope', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["anope", "https://launchpad.net/ubuntu/+source/anope"]', 'description': 'an open source set of IRC Services', 'definition_id': 'oval:com.ubuntu.bionic:def:18040252500000', 'package_criteria': [{'cve_id': 'CVE-2024-30187', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'anope', 'fixed_version': '2.0.4-2ubuntu0.1~esm1', 'affected_version_range': '< 2.0.4-2ubuntu0.1~esm1'}]} | 470bfbf073113c6ab5d21411393dd7c56d1c6b0ae418e93cb4428dab80c23bdc | 2026-06-13 04:54:10.738166+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040257400000 | freeglut | Free implementation of the OpenGL Utility Toolkit (GLUT) | ['CVE-2024-24258', 'CVE-2024-24259'] | ['Ubuntu 18.04 LTS'] | ['freeglut', 'https://launchpad.net/ubuntu/+source/freeglut'] | {'cves': '["CVE-2024-24258", "CVE-2024-24259"]', 'title': 'freeglut', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["freeglut", "https://launchpad.net/ubuntu/+source/freeglut"]', 'description': 'Free implementation of the OpenGL Utility Toolkit (GLUT)', 'definition_id': 'oval:com.ubuntu.bionic:def:18040257400000', 'package_criteria': [{'cve_id': 'CVE-2024-24258', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'freeglut', 'fixed_version': '2.8.1-3ubuntu0.18.04.1~esm1', 'affected_version_range': '< 2.8.1-3ubuntu0.18.04.1~esm1'}]} | 08ac551091c3cb9e856592c4fb053a49ab79bc6fff7551e5f22b74ed61b5d67b | 2026-05-30 01:47:08.377667+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040257900000 | gimp-dds | DDS (DirectDraw Surface) plugin for GIMP | ['CVE-2023-44441'] | ['Ubuntu 18.04 LTS'] | ['gimp-dds', 'https://launchpad.net/ubuntu/+source/gimp-dds'] | {'cves': '["CVE-2023-44441"]', 'title': 'gimp-dds', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["gimp-dds", "https://launchpad.net/ubuntu/+source/gimp-dds"]', 'description': 'DDS (DirectDraw Surface) plugin for GIMP', 'definition_id': 'oval:com.ubuntu.bionic:def:18040257900000', 'package_criteria': [{'cve_id': 'CVE-2023-44441', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'gimp-dds', 'fixed_version': '3.0.1-1+deb10u1build0.18.04.1~esm1', 'affected_version_range': '< 3.0.1-1+deb10u1build0.18.04.1~esm1'}]} | 37444c15c8e3db2fd8d96fd13731d895abdf61673766008b806079070286eb71 | 2026-06-13 04:54:10.738166+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040258000000 | gobgp | BGP implementation in Go | ['CVE-2025-43970', 'CVE-2025-43972', 'CVE-2025-43973', 'CVE-2026-37461', 'CVE-2026-41643', 'CVE-2026-7735', 'CVE-2026-7736', 'CVE-2026-7737'] | ['Ubuntu 18.04 LTS'] | ['gobgp', 'https://launchpad.net/ubuntu/+source/gobgp'] | {'cves': '["CVE-2025-43970", "CVE-2025-43972", "CVE-2025-43973", "CVE-2026-37461", "CVE-2026-41643", "CVE-2026-7735", "CVE-2026-7736", "CVE-2026-7737"]', 'title': 'gobgp', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["gobgp", "https://launchpad.net/ubuntu/+source/gobgp"]', 'description': 'BGP implementation in Go', 'definition_id': 'oval:com.ubuntu.bionic:def:18040258000000', 'package_criteria': [{'cve_id': 'CVE-2025-43970', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'gobgp', 'fixed_version': '1.29-1ubuntu0.1+esm1', 'affected_version_range': '< 1.29-1ubuntu0.1+esm1'}, {'cve_id': 'CVE-2026-7735', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'gobgp', 'fixed_version': '1.29-1ubuntu0.1+esm2', 'affected_version_range': '< 1.29-1ubuntu0.1+esm2'}]} | 4a03484e3fee12b3b359a33f7447560b537905ffa3d0f787e0577683445cc63a | 2026-05-30 01:47:08.377667+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040258600000 | gross | fast and efficient greylist server with DNSBL support | ['CVE-2023-52159'] | ['Ubuntu 18.04 LTS'] | ['gross', 'https://launchpad.net/ubuntu/+source/gross'] | {'cves': '["CVE-2023-52159"]', 'title': 'gross', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["gross", "https://launchpad.net/ubuntu/+source/gross"]', 'description': 'fast and efficient greylist server with DNSBL support', 'definition_id': 'oval:com.ubuntu.bionic:def:18040258600000', 'package_criteria': [{'cve_id': 'CVE-2023-52159', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'gross', 'fixed_version': '1.0.2-4ubuntu0.18.04.1~esm1', 'affected_version_range': '< 1.0.2-4ubuntu0.18.04.1~esm1'}]} | 83068bf6104632902ccd8b8f1f5ec0634a8c793375ade9dae08a9bf5181931a3 | 2026-06-13 04:54:10.738166+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040261000000 | libcommons-lang-java | an extension of the java.lang package | ['CVE-2025-48924'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/libcommons-lang-java', 'libcommons-lang-java'] | {'cves': '["CVE-2025-48924"]', 'title': 'libcommons-lang-java', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/libcommons-lang-java", "libcommons-lang-java"]', 'description': 'an extension of the java.lang package', 'definition_id': 'oval:com.ubuntu.bionic:def:18040261000000', 'package_criteria': [{'cve_id': 'CVE-2025-48924', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libcommons-lang-java', 'fixed_version': '2.6-8ubuntu0.1~esm1', 'affected_version_range': '< 2.6-8ubuntu0.1~esm1'}]} | 4bcabb9649fc2baf6f96fdef9ce980fdf00b4d02888307bf1dc36f1c38f6490f | 2026-06-13 04:54:10.738166+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040261100000 | libcommons-lang3-java | an extension of the java.lang package | ['CVE-2025-48924'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/libcommons-lang3-java', 'libcommons-lang3-java'] | {'cves': '["CVE-2025-48924"]', 'title': 'libcommons-lang3-java', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/libcommons-lang3-java", "libcommons-lang3-java"]', 'description': 'an extension of the java.lang package', 'definition_id': 'oval:com.ubuntu.bionic:def:18040261100000', 'package_criteria': [{'cve_id': 'CVE-2025-48924', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libcommons-lang3-java', 'fixed_version': '3.8-1~18.04.2+esm1', 'affected_version_range': '< 3.8-1~18.04.2+esm1'}]} | 766a09ed82c288c1cafa07f5e22d45fbd86157ed179b9faea296e8d65c589aeb | 2026-06-13 04:54:10.738166+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040261800000 | libcrypt-saltedhash-perl | module for handling salted hashes | ['CVE-2026-47372'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/libcrypt-saltedhash-perl', 'libcrypt-saltedhash-perl'] | {'cves': '["CVE-2026-47372"]', 'title': 'libcrypt-saltedhash-perl', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/libcrypt-saltedhash-perl", "libcrypt-saltedhash-perl"]', 'description': 'module for handling salted hashes', 'definition_id': 'oval:com.ubuntu.bionic:def:18040261800000', 'package_criteria': [{'cve_id': 'CVE-2026-47372', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libcrypt-saltedhash-perl', 'fixed_version': '0.09-1ubuntu0.18.04.1~esm1', 'affected_version_range': '< 0.09-1ubuntu0.18.04.1~esm1'}]} | 81568adfc4a51a90a656cd4d369b7180d5b0a838f14822b33a84538fdc0753f9 | 2026-06-10 19:57:33.050683+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040262000000 | libcryptx-perl | Perl modules providing cryptography based on LibTomCrypt library | ['CVE-2018-25099', 'CVE-2025-40912', 'CVE-2025-40914'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/libcryptx-perl', 'libcryptx-perl'] | {'cves': '["CVE-2018-25099", "CVE-2025-40912", "CVE-2025-40914"]', 'title': 'libcryptx-perl', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/libcryptx-perl", "libcryptx-perl"]', 'description': 'Perl modules providing cryptography based on LibTomCrypt library', 'definition_id': 'oval:com.ubuntu.bionic:def:18040262000000', 'package_criteria': [{'cve_id': 'CVE-2018-25099', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libcryptx-perl', 'fixed_version': '0.056-1ubuntu0.1~esm1', 'affected_version_range': '< 0.056-1ubuntu0.1~esm1'}]} | 2ad0dccc479c85b0e52002ea34699a62f104cc5c58c6bdc536846c9e881f9d44 | 2026-06-13 04:54:10.738166+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040263600000 | libmodule-scandeps-perl | module to recursively scan Perl code for dependencies | ['CVE-2024-10224'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/libmodule-scandeps-perl', 'libmodule-scandeps-perl'] | {'cves': '["CVE-2024-10224"]', 'title': 'libmodule-scandeps-perl', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/libmodule-scandeps-perl", "libmodule-scandeps-perl"]', 'description': 'module to recursively scan Perl code for dependencies', 'definition_id': 'oval:com.ubuntu.bionic:def:18040263600000', 'package_criteria': [{'cve_id': 'CVE-2024-10224', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libmodule-scandeps-perl', 'fixed_version': '1.24-1ubuntu0.1~esm1', 'affected_version_range': '< 1.24-1ubuntu0.1~esm1'}]} | c193a675938f018997b4adfc1d2d3690506397ab69fe61a0f5f0a1c220d8ce47 | 2026-06-13 04:54:10.738166+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040265600000 | libyaml-syck-perl | Perl module providing a fast, lightweight YAML loader and dumper | ['CVE-2025-11683'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/libyaml-syck-perl', 'libyaml-syck-perl'] | {'cves': '["CVE-2025-11683"]', 'title': 'libyaml-syck-perl', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/libyaml-syck-perl", "libyaml-syck-perl"]', 'description': 'Perl module providing a fast, lightweight YAML loader and dumper', 'definition_id': 'oval:com.ubuntu.bionic:def:18040265600000', 'package_criteria': [{'cve_id': 'CVE-2025-11683', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libyaml-syck-perl', 'fixed_version': '1.29-1ubuntu0.18.04.1~esm1', 'affected_version_range': '< 1.29-1ubuntu0.18.04.1~esm1'}]} | 44915f2d25553ca3463e6afb798d034c068ec08b6f0d08b712975b1e95494bf8 | 2026-06-13 04:54:10.738166+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040267400000 | munge | authentication service to create and validate credentials | ['CVE-2026-25506'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/munge', 'munge'] | {'cves': '["CVE-2026-25506"]', 'title': 'munge', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/munge", "munge"]', 'description': 'authentication service to create and validate credentials', 'definition_id': 'oval:com.ubuntu.bionic:def:18040267400000', 'package_criteria': [{'cve_id': 'CVE-2026-25506', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'munge', 'fixed_version': '0.5.13-1ubuntu0.1~esm1', 'affected_version_range': '< 0.5.13-1ubuntu0.1~esm1'}]} | 2456b362b21a17744f2af0fc3b7a05e76ec7876db0c98ed83d4e4bb29d164bb1 | 2026-06-13 04:54:10.738166+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040268500000 | node-form-data | A library to create readable 'multipart/form-data' streams | ['CVE-2025-7783'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/node-form-data', 'node-form-data'] | {'cves': '["CVE-2025-7783"]', 'title': 'node-form-data', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/node-form-data", "node-form-data"]', 'description': "A library to create readable 'multipart/form-data' streams", 'definition_id': 'oval:com.ubuntu.bionic:def:18040268500000', 'package_criteria': [{'cve_id': 'CVE-2025-7783', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'node-form-data', 'fixed_version': '0.1.0-1ubuntu0.18.04.1~esm1', 'affected_version_range': '< 0.1.0-1ubuntu0.18.04.1~esm1'}]} | 9d66391dc8d0ad9f7a0ac3757573dc337de5132f80c7b06fff694105af32c3d2 | 2026-05-30 01:46:54.794516+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040277700000 | simpleeval | ['CVE-2026-32640'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/simpleeval', 'simpleeval'] | {'cves': '["CVE-2026-32640"]', 'title': 'simpleeval', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/simpleeval", "simpleeval"]', 'description': None, 'definition_id': 'oval:com.ubuntu.bionic:def:18040277700000', 'package_criteria': [{'cve_id': 'CVE-2026-32640', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'simpleeval', 'fixed_version': '0.9.5-1ubuntu0.1~esm1', 'affected_version_range': '< 0.9.5-1ubuntu0.1~esm1'}]} | 63d6a485a60df3ca09dd25a71b1d4c266237567d54514720e049e58faf371bd2 | 2026-06-13 04:54:10.738166+03:00 | 2026-06-15 14:51:35.496964+03:00 | ||||
pkg | bionic | oval:com.ubuntu.bionic:def:18040279500000 | wlc | Command line utility for Weblate | ['CVE-2026-22250', 'CVE-2026-22251'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/wlc', 'wlc'] | {'cves': '["CVE-2026-22250", "CVE-2026-22251"]', 'title': 'wlc', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/wlc", "wlc"]', 'description': 'Command line utility for Weblate', 'definition_id': 'oval:com.ubuntu.bionic:def:18040279500000', 'package_criteria': [{'cve_id': 'CVE-2026-22250', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wlc', 'fixed_version': '0.8-1ubuntu0.1~esm1', 'affected_version_range': '< 0.8-1ubuntu0.1~esm1'}]} | ac51836631c22a5cb9de18769d49bb1e7327fb137a7775de9e00bea69c6ee010 | 2026-06-13 04:54:10.738166+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040281100000 | zulucrypt | A simple, feature rich and powerful solution for hard drives encryption | ['CVE-2025-53391'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/zulucrypt', 'zulucrypt'] | {'cves': '["CVE-2025-53391"]', 'title': 'zulucrypt', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/zulucrypt", "zulucrypt"]', 'description': 'A simple, feature rich and powerful solution for hard drives encryption', 'definition_id': 'oval:com.ubuntu.bionic:def:18040281100000', 'package_criteria': [{'cve_id': 'CVE-2025-53391', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'zulucrypt', 'fixed_version': '5.4.0-2ubuntu0.1~esm2', 'affected_version_range': '< 5.4.0-2ubuntu0.1~esm2'}]} | 0792a7973041c51d2c30eed2bd86c448c5a027464b25d3d79ea5ebaf9c354ba2 | 2026-06-13 04:54:10.738166+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | bionic | oval:com.ubuntu.bionic:def:18040281200000 | zvbi | Vertical Blanking Interval (VBI) utilities | ['CVE-2025-2173', 'CVE-2025-2174', 'CVE-2025-2175', 'CVE-2025-2176', 'CVE-2025-2177'] | ['Ubuntu 18.04 LTS'] | ['https://launchpad.net/ubuntu/+source/zvbi', 'zvbi'] | {'cves': '["CVE-2025-2173", "CVE-2025-2174", "CVE-2025-2175", "CVE-2025-2176", "CVE-2025-2177"]', 'title': 'zvbi', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/zvbi", "zvbi"]', 'description': 'Vertical Blanking Interval (VBI) utilities', 'definition_id': 'oval:com.ubuntu.bionic:def:18040281200000', 'package_criteria': [{'cve_id': 'CVE-2025-2173', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'zvbi', 'fixed_version': '0.2.35-13ubuntu0.1~esm1', 'affected_version_range': '< 0.2.35-13ubuntu0.1~esm1'}]} | d7e1bcb45a854afa6bc7c275786209d7dc836a20990f2edb08ad2d3c5faf98aa | 2026-06-13 04:54:10.738166+03:00 | 2026-06-15 14:51:35.496964+03:00 | |||
pkg | fips-preview_jammy | oval:com.ubuntu.jammy:def:22040208900000 | python-apt | Python interface to libapt-pkg | ['CVE-2025-6966'] | ['Ubuntu Pro FIPS-preview 22.04 LTS'] | ['https://launchpad.net/ubuntu/+source/python-apt', 'python-apt'] | {'cves': '["CVE-2025-6966"]', 'title': 'python-apt', 'issued': None, 'release': 'fips-preview_jammy', 'updated': None, 'affected': '["Ubuntu Pro FIPS-preview 22.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/python-apt", "python-apt"]', 'description': 'Python interface to libapt-pkg', 'definition_id': 'oval:com.ubuntu.jammy:def:22040208900000', 'package_criteria': [{'cve_id': 'CVE-2025-6966', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'python-apt', 'fixed_version': '2.4.0ubuntu4.1', 'affected_version_range': '< 2.4.0ubuntu4.1'}]} | cf256ff75b35bf8f35a2a5f19f0a81119769ce554906a42557143c8a74a5fd87 | 2026-05-30 01:47:51.397617+03:00 | 2026-06-19 10:32:44.607612+03:00 | |||
cve | bionic | oval:com.ubuntu.bionic:def:201797810000000 | CVE-2017-9781 on Ubuntu 18.04 LTS (bionic) - medium | A cross site scripting (XSS) vulnerability exists in Check_MK versions1.4.0x prior to 1.4.0p6, allowing an unauthenticated remote attacker toinject arbitrary HTML or JavaScript via the _username parameter whenattempting authentication to webapi.py, which is returned unencoded withcontent type text/html.
Update Instructions:
Run `sudo pro fix CVE-2017-9781` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
check-mk-agent - 1.2.8p16-1ubuntu0.2
check-mk-agent-logwatch - 1.2.8p16-1ubuntu0.2
check-mk-config-icinga - 1.2.8p16-1ubuntu0.2
check-mk-livestatus - 1.2.8p16-1ubuntu0.2
check-mk-multisite - 1.2.8p16-1ubuntu0.2
check-mk-server - 1.2.8p16-1ubuntu0.2
No subscription required | Medium | ['CVE-2017-9781'] | ['Ubuntu 18.04 LTS'] | ['CVE-2017-9781', 'https://www.cve.org/CVERecord?id=CVE-2017-9781'] | {'cves': '["CVE-2017-9781"]', 'title': 'CVE-2017-9781 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2017-9781", "https://www.cve.org/CVERecord?id=CVE-2017-9781"]', 'description': 'A cross site scripting (XSS) vulnerability exists in Check_MK versions1.4.0x prior to 1.4.0p6, allowing an unauthenticated remote attacker toinject arbitrary HTML or JavaScript via the _username parameter whenattempting authentication to webapi.py, which is returned unencoded withcontent type text/html.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2017-9781` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\ncheck-mk-agent - 1.2.8p16-1ubuntu0.2\ncheck-mk-agent-logwatch - 1.2.8p16-1ubuntu0.2\ncheck-mk-config-icinga - 1.2.8p16-1ubuntu0.2\ncheck-mk-livestatus - 1.2.8p16-1ubuntu0.2\ncheck-mk-multisite - 1.2.8p16-1ubuntu0.2\ncheck-mk-server - 1.2.8p16-1ubuntu0.2\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:201797810000000', 'package_criteria': [{'cve_id': 'CVE-2017-9781', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'check-mk', 'fixed_version': '1.2.8p16-1ubuntu0.2', 'affected_version_range': '< 1.2.8p16-1ubuntu0.2'}, {'cve_id': 'CVE-2017-9781', 'source': 'description_fix', 'status': 'fixed', 'package': 'check-mk-agent', 'fixed_version': '1.2.8p16-1ubuntu0.2', 'affected_version_range': '< 1.2.8p16-1ubuntu0.2'}, {'cve_id': 'CVE-2017-9781', 'source': 'description_fix', 'status': 'fixed', 'package': 'check-mk-agent-logwatch', 'fixed_version': '1.2.8p16-1ubuntu0.2', 'affected_version_range': '< 1.2.8p16-1ubuntu0.2'}, {'cve_id': 'CVE-2017-9781', 'source': 'description_fix', 'status': 'fixed', 'package': 'check-mk-config-icinga', 'fixed_version': '1.2.8p16-1ubuntu0.2', 'affected_version_range': '< 1.2.8p16-1ubuntu0.2'}, {'cve_id': 'CVE-2017-9781', 'source': 'description_fix', 'status': 'fixed', 'package': 'check-mk-livestatus', 'fixed_version': '1.2.8p16-1ubuntu0.2', 'affected_version_range': '< 1.2.8p16-1ubuntu0.2'}, {'cve_id': 'CVE-2017-9781', 'source': 'description_fix', 'status': 'fixed', 'package': 'check-mk-multisite', 'fixed_version': '1.2.8p16-1ubuntu0.2', 'affected_version_range': '< 1.2.8p16-1ubuntu0.2'}, {'cve_id': 'CVE-2017-9781', 'source': 'description_fix', 'status': 'fixed', 'package': 'check-mk-server', 'fixed_version': '1.2.8p16-1ubuntu0.2', 'affected_version_range': '< 1.2.8p16-1ubuntu0.2'}]} | fc1ff8523e12aaf85fe160f1bbb5be7309099edcc8ed85dce38930a4250dd617 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201810003000000000 | CVE-2018-1000300 on Ubuntu 18.04 LTS (bionic) - medium | curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122:Heap-based Buffer Overflow vulnerability in denial of service and more thatcan result in curl might overflow a heap based memory buffer when closingdown an FTP connection with very long server command replies.. Thisvulnerability appears to have been fixed in curl < 7.54.1 and curl >=7.60.0.
Update Instructions:
Run `sudo pro fix CVE-2018-1000300` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
curl - 7.58.0-2ubuntu3.1
libcurl3-gnutls - 7.58.0-2ubuntu3.1
libcurl3-nss - 7.58.0-2ubuntu3.1
libcurl4 - 7.58.0-2ubuntu3.1
No subscription required | Medium | ['CVE-2018-1000300'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-1000300', 'https://www.cve.org/CVERecord?id=CVE-2018-1000300'] | {'cves': '["CVE-2018-1000300"]', 'title': 'CVE-2018-1000300 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2018-1000300", "https://www.cve.org/CVERecord?id=CVE-2018-1000300"]', 'description': 'curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122:Heap-based Buffer Overflow vulnerability in denial of service and more thatcan result in curl might overflow a heap based memory buffer when closingdown an FTP connection with very long server command replies.. Thisvulnerability appears to have been fixed in curl < 7.54.1 and curl >=7.60.0.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2018-1000300` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\ncurl - 7.58.0-2ubuntu3.1\nlibcurl3-gnutls - 7.58.0-2ubuntu3.1\nlibcurl3-nss - 7.58.0-2ubuntu3.1\nlibcurl4 - 7.58.0-2ubuntu3.1\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:201810003000000000', 'package_criteria': [{'cve_id': 'CVE-2018-1000300', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'curl', 'fixed_version': '7.58.0-2ubuntu3.1', 'affected_version_range': '< 7.58.0-2ubuntu3.1'}, {'cve_id': 'CVE-2018-1000300', 'source': 'description_fix', 'status': 'fixed', 'package': 'libcurl3-gnutls', 'fixed_version': '7.58.0-2ubuntu3.1', 'affected_version_range': '< 7.58.0-2ubuntu3.1'}, {'cve_id': 'CVE-2018-1000300', 'source': 'description_fix', 'status': 'fixed', 'package': 'libcurl3-nss', 'fixed_version': '7.58.0-2ubuntu3.1', 'affected_version_range': '< 7.58.0-2ubuntu3.1'}, {'cve_id': 'CVE-2018-1000300', 'source': 'description_fix', 'status': 'fixed', 'package': 'libcurl4', 'fixed_version': '7.58.0-2ubuntu3.1', 'affected_version_range': '< 7.58.0-2ubuntu3.1'}]} | 0566108f0c17d33ab4973bb03829467cdf4c412862120422160a57251900587b | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201810005590000000 | CVE-2018-1000559 on Ubuntu 18.04 LTS (bionic) - low | qutebrowser version introduced in v0.11.0(1179ee7a937fb31414d77d9970bac21095358449) contains a Cross Site Scripting(XSS) vulnerability in history command, qute://history page that can resultin Via injected JavaScript code, a website can steal the user's browsinghistory. This attack appear to be exploitable via the victim must open apage with a specially crafted <title> attribute, and then open thequte://history site via the :history command. This vulnerability appears tohave been fixed in fixed in v1.3.3(4c9360237f186681b1e3f2a0f30c45161cf405c7, to be released today) and v1.4.0(5a7869f2feaa346853d2a85413d6527c87ef0d9f, released later this week). | Low | ['CVE-2018-1000559'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-1000559', 'https://www.cve.org/CVERecord?id=CVE-2018-1000559'] | {'cves': '["CVE-2018-1000559"]', 'title': 'CVE-2018-1000559 on Ubuntu 18.04 LTS (bionic) - low', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Low', 'oval_type': 'cve', 'references': '["CVE-2018-1000559", "https://www.cve.org/CVERecord?id=CVE-2018-1000559"]', 'description': "qutebrowser version introduced in v0.11.0(1179ee7a937fb31414d77d9970bac21095358449) contains a Cross Site Scripting(XSS) vulnerability in history command, qute://history page that can resultin Via injected JavaScript code, a website can steal the user's browsinghistory. This attack appear to be exploitable via the victim must open apage with a specially crafted <title> attribute, and then open thequte://history site via the :history command. This vulnerability appears tohave been fixed in fixed in v1.3.3(4c9360237f186681b1e3f2a0f30c45161cf405c7, to be released today) and v1.4.0(5a7869f2feaa346853d2a85413d6527c87ef0d9f, released later this week).", 'definition_id': 'oval:com.ubuntu.bionic:def:201810005590000000', 'package_criteria': [{'cve_id': 'CVE-2018-1000559', 'source': 'criterion_comment', 'status': 'open', 'package': 'qutebrowser', 'fixed_version': None, 'affected_version_range': 'affected'}]} | 5e87d1ba2e9d60e203ca85a4cf14ec1de193e8bd42eed29f47629f460b2a1c8b | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201810021500000000 | CVE-2018-1002150 on Ubuntu 18.04 LTS (bionic) - medium | Koji version 1.12, 1.13, 1.14 and 1.15 contain an incorrect access controlvulnerability resulting in arbitrary filesystem read/write access. Thisvulnerability has been fixed in versions 1.12.1, 1.13.1, 1.14.1 and 1.15.1. | Medium | ['CVE-2018-1002150'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-1002150', 'https://www.cve.org/CVERecord?id=CVE-2018-1002150'] | {'cves': '["CVE-2018-1002150"]', 'title': 'CVE-2018-1002150 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2018-1002150", "https://www.cve.org/CVERecord?id=CVE-2018-1002150"]', 'description': 'Koji version 1.12, 1.13, 1.14 and 1.15 contain an incorrect access controlvulnerability resulting in arbitrary filesystem read/write access. Thisvulnerability has been fixed in versions 1.12.1, 1.13.1, 1.14.1 and 1.15.1.', 'definition_id': 'oval:com.ubuntu.bionic:def:201810021500000000', 'package_criteria': [{'cve_id': 'CVE-2018-1002150', 'source': 'criterion_comment', 'status': 'open', 'package': 'koji', 'fixed_version': None, 'affected_version_range': 'affected'}]} | 5fbfe3fa156c36189d10d7c1bf9d42d18769e8e15faef0140ab9c7fe61348191 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2018101130000000 | CVE-2018-10113 on Ubuntu 18.04 LTS (bionic) - low | An issue was discovered in GEGL through 0.3.32. The process function inoperations/external/ppm-load.c has unbounded memory allocation, leading toa denial of service (application crash) upon allocation failure. | Low | ['CVE-2018-10113'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-10113', 'https://www.cve.org/CVERecord?id=CVE-2018-10113'] | {'cves': '["CVE-2018-10113"]', 'title': 'CVE-2018-10113 on Ubuntu 18.04 LTS (bionic) - low', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Low', 'oval_type': 'cve', 'references': '["CVE-2018-10113", "https://www.cve.org/CVERecord?id=CVE-2018-10113"]', 'description': 'An issue was discovered in GEGL through 0.3.32. The process function inoperations/external/ppm-load.c has unbounded memory allocation, leading toa denial of service (application crash) upon allocation failure.', 'definition_id': 'oval:com.ubuntu.bionic:def:2018101130000000', 'package_criteria': []} | 358c5ed3ad621108bd976127082b0d4f42c84b1478d32e890b355650003fe1cb | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2018101940000000 | CVE-2018-10194 on Ubuntu 18.04 LTS (bionic) - medium | The set_text_distance function in devices/vector/gdevpdts.c in the pdfwritecomponent in Artifex Ghostscript through 9.22 does not prevent overflows intext-positioning calculation, which allows remote attackers to cause adenial of service (application crash) or possibly have unspecified otherimpact via a crafted PDF document.
Update Instructions:
Run `sudo pro fix CVE-2018-10194` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
ghostscript - 9.22~dfsg+1-0ubuntu1.1
ghostscript-x - 9.22~dfsg+1-0ubuntu1.1
libgs9 - 9.22~dfsg+1-0ubuntu1.1
libgs9-common - 9.22~dfsg+1-0ubuntu1.1
No subscription required | Medium | ['CVE-2018-10194'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-10194', 'https://www.cve.org/CVERecord?id=CVE-2018-10194'] | {'cves': '["CVE-2018-10194"]', 'title': 'CVE-2018-10194 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2018-10194", "https://www.cve.org/CVERecord?id=CVE-2018-10194"]', 'description': 'The set_text_distance function in devices/vector/gdevpdts.c in the pdfwritecomponent in Artifex Ghostscript through 9.22 does not prevent overflows intext-positioning calculation, which allows remote attackers to cause adenial of service (application crash) or possibly have unspecified otherimpact via a crafted PDF document.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2018-10194` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nghostscript - 9.22~dfsg+1-0ubuntu1.1\nghostscript-x - 9.22~dfsg+1-0ubuntu1.1\nlibgs9 - 9.22~dfsg+1-0ubuntu1.1\nlibgs9-common - 9.22~dfsg+1-0ubuntu1.1\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2018101940000000', 'package_criteria': [{'cve_id': 'CVE-2018-10194', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'ghostscript', 'fixed_version': '9.22~dfsg+1-0ubuntu1.1', 'affected_version_range': '< 9.22~dfsg+1-0ubuntu1.1'}, {'cve_id': 'CVE-2018-10194', 'source': 'description_fix', 'status': 'fixed', 'package': 'ghostscript-x', 'fixed_version': '9.22~dfsg+1-0ubuntu1.1', 'affected_version_range': '< 9.22~dfsg+1-0ubuntu1.1'}, {'cve_id': 'CVE-2018-10194', 'source': 'description_fix', 'status': 'fixed', 'package': 'libgs9', 'fixed_version': '9.22~dfsg+1-0ubuntu1.1', 'affected_version_range': '< 9.22~dfsg+1-0ubuntu1.1'}, {'cve_id': 'CVE-2018-10194', 'source': 'description_fix', 'status': 'fixed', 'package': 'libgs9-common', 'fixed_version': '9.22~dfsg+1-0ubuntu1.1', 'affected_version_range': '< 9.22~dfsg+1-0ubuntu1.1'}]} | 20395e43dbb2ea622d75a11ae322701d037b8df04e0e7124a6333d66ef17031e | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2018105460000000 | CVE-2018-10546 on Ubuntu 18.04 LTS (bionic) - medium | An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.xbefore 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists inext/iconv/iconv.c because the iconv stream filter does not reject invalidmultibyte sequences.
Update Instructions:
Run `sudo pro fix CVE-2018-10546` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
libapache2-mod-php7.2 - 7.2.5-0ubuntu0.18.04.1
libphp7.2-embed - 7.2.5-0ubuntu0.18.04.1
php7.2 - 7.2.5-0ubuntu0.18.04.1
php7.2-bcmath - 7.2.5-0ubuntu0.18.04.1
php7.2-bz2 - 7.2.5-0ubuntu0.18.04.1
php7.2-cgi - 7.2.5-0ubuntu0.18.04.1
php7.2-cli - 7.2.5-0ubuntu0.18.04.1
php7.2-common - 7.2.5-0ubuntu0.18.04.1
php7.2-curl - 7.2.5-0ubuntu0.18.04.1
php7.2-dba - 7.2.5-0ubuntu0.18.04.1
php7.2-enchant - 7.2.5-0ubuntu0.18.04.1
php7.2-fpm - 7.2.5-0ubuntu0.18.04.1
php7.2-gd - 7.2.5-0ubuntu0.18.04.1
php7.2-gmp - 7.2.5-0ubuntu0.18.04.1
php7.2-imap - 7.2.5-0ubuntu0.18.04.1
php7.2-interbase - 7.2.5-0ubuntu0.18.04.1
php7.2-intl - 7.2.5-0ubuntu0.18.04.1
php7.2-json - 7.2.5-0ubuntu0.18.04.1
php7.2-ldap - 7.2.5-0ubuntu0.18.04.1
php7.2-mbstring - 7.2.5-0ubuntu0.18.04.1
php7.2-mysql - 7.2.5-0ubuntu0.18.04.1
php7.2-odbc - 7.2.5-0ubuntu0.18.04.1
php7.2-opcache - 7.2.5-0ubuntu0.18.04.1
php7.2-pgsql - 7.2.5-0ubuntu0.18.04.1
php7.2-phpdbg - 7.2.5-0ubuntu0.18.04.1
php7.2-pspell - 7.2.5-0ubuntu0.18.04.1
php7.2-readline - 7.2.5-0ubuntu0.18.04.1
php7.2-recode - 7.2.5-0ubuntu0.18.04.1
php7.2-snmp - 7.2.5-0ubuntu0.18.04.1
php7.2-soap - 7.2.5-0ubuntu0.18.04.1
php7.2-sqlite3 - 7.2.5-0ubuntu0.18.04.1
php7.2-sybase - 7.2.5-0ubuntu0.18.04.1
php7.2-tidy - 7.2.5-0ubuntu0.18.04.1
php7.2-xml - 7.2.5-0ubuntu0.18.04.1
php7.2-xmlrpc - 7.2.5-0ubuntu0.18.04.1
php7.2-xsl - 7.2.5-0ubuntu0.18.04.1
php7.2-zip - 7.2.5-0ubuntu0.18.04.1
No subscription required | Medium | ['CVE-2018-10546'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-10546', 'https://www.cve.org/CVERecord?id=CVE-2018-10546'] | {'cves': '["CVE-2018-10546"]', 'title': 'CVE-2018-10546 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2018-10546", "https://www.cve.org/CVERecord?id=CVE-2018-10546"]', 'description': 'An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.xbefore 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists inext/iconv/iconv.c because the iconv stream filter does not reject invalidmultibyte sequences.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2018-10546` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nlibapache2-mod-php7.2 - 7.2.5-0ubuntu0.18.04.1\nlibphp7.2-embed - 7.2.5-0ubuntu0.18.04.1\nphp7.2 - 7.2.5-0ubuntu0.18.04.1\nphp7.2-bcmath - 7.2.5-0ubuntu0.18.04.1\nphp7.2-bz2 - 7.2.5-0ubuntu0.18.04.1\nphp7.2-cgi - 7.2.5-0ubuntu0.18.04.1\nphp7.2-cli - 7.2.5-0ubuntu0.18.04.1\nphp7.2-common - 7.2.5-0ubuntu0.18.04.1\nphp7.2-curl - 7.2.5-0ubuntu0.18.04.1\nphp7.2-dba - 7.2.5-0ubuntu0.18.04.1\nphp7.2-enchant - 7.2.5-0ubuntu0.18.04.1\nphp7.2-fpm - 7.2.5-0ubuntu0.18.04.1\nphp7.2-gd - 7.2.5-0ubuntu0.18.04.1\nphp7.2-gmp - 7.2.5-0ubuntu0.18.04.1\nphp7.2-imap - 7.2.5-0ubuntu0.18.04.1\nphp7.2-interbase - 7.2.5-0ubuntu0.18.04.1\nphp7.2-intl - 7.2.5-0ubuntu0.18.04.1\nphp7.2-json - 7.2.5-0ubuntu0.18.04.1\nphp7.2-ldap - 7.2.5-0ubuntu0.18.04.1\nphp7.2-mbstring - 7.2.5-0ubuntu0.18.04.1\nphp7.2-mysql - 7.2.5-0ubuntu0.18.04.1\nphp7.2-odbc - 7.2.5-0ubuntu0.18.04.1\nphp7.2-opcache - 7.2.5-0ubuntu0.18.04.1\nphp7.2-pgsql - 7.2.5-0ubuntu0.18.04.1\nphp7.2-phpdbg - 7.2.5-0ubuntu0.18.04.1\nphp7.2-pspell - 7.2.5-0ubuntu0.18.04.1\nphp7.2-readline - 7.2.5-0ubuntu0.18.04.1\nphp7.2-recode - 7.2.5-0ubuntu0.18.04.1\nphp7.2-snmp - 7.2.5-0ubuntu0.18.04.1\nphp7.2-soap - 7.2.5-0ubuntu0.18.04.1\nphp7.2-sqlite3 - 7.2.5-0ubuntu0.18.04.1\nphp7.2-sybase - 7.2.5-0ubuntu0.18.04.1\nphp7.2-tidy - 7.2.5-0ubuntu0.18.04.1\nphp7.2-xml - 7.2.5-0ubuntu0.18.04.1\nphp7.2-xmlrpc - 7.2.5-0ubuntu0.18.04.1\nphp7.2-xsl - 7.2.5-0ubuntu0.18.04.1\nphp7.2-zip - 7.2.5-0ubuntu0.18.04.1\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2018105460000000', 'package_criteria': [{'cve_id': 'CVE-2018-10546', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'php7.2', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'libapache2-mod-php7.2', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'libphp7.2-embed', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-bcmath', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-bz2', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-cgi', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-cli', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-common', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-curl', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-dba', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-enchant', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-fpm', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-gd', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-gmp', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-imap', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-interbase', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-intl', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-json', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-ldap', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-mbstring', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-mysql', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-odbc', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-opcache', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-pgsql', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-phpdbg', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-pspell', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-readline', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-recode', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-snmp', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-soap', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-sqlite3', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-sybase', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-tidy', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-xml', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-xmlrpc', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-xsl', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-10546', 'source': 'description_fix', 'status': 'fixed', 'package': 'php7.2-zip', 'fixed_version': '7.2.5-0ubuntu0.18.04.1', 'affected_version_range': '< 7.2.5-0ubuntu0.18.04.1'}]} | 2dc23731bb657904aaf78b019e03f5863098afafcc412e77144501908bf1ef76 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201810670000000 | CVE-2018-1067 on Ubuntu 18.04 LTS (bionic) - medium | In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fixfor CVE-2016-4993 was incomplete and Undertow web server is vulnerable tothe injection of arbitrary HTTP headers, and also response splitting, dueto insufficient sanitization and validation of user input before the inputis used as part of an HTTP header value. | Medium | ['CVE-2018-1067'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-1067', 'https://www.cve.org/CVERecord?id=CVE-2018-1067'] | {'cves': '["CVE-2018-1067"]', 'title': 'CVE-2018-1067 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2018-1067", "https://www.cve.org/CVERecord?id=CVE-2018-1067"]', 'description': 'In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fixfor CVE-2016-4993 was incomplete and Undertow web server is vulnerable tothe injection of arbitrary HTTP headers, and also response splitting, dueto insufficient sanitization and validation of user input before the inputis used as part of an HTTP header value.', 'definition_id': 'oval:com.ubuntu.bionic:def:201810670000000', 'package_criteria': []} | 79df8bbf22f5c23b5ad8b5241d37b56e918972e2504925f351bd43420d4b03ce | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2018108040000000 | CVE-2018-10804 on Ubuntu 18.04 LTS (bionic) - low | ImageMagick version 7.0.7-28 contains a memory leak in WriteTIFFImage incoders/tiff.c.
Update Instructions:
Run `sudo pro fix CVE-2018-10804` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
imagemagick - 8:6.9.7.4+dfsg-16ubuntu6.2
imagemagick-6-common - 8:6.9.7.4+dfsg-16ubuntu6.2
imagemagick-6.q16 - 8:6.9.7.4+dfsg-16ubuntu6.2
imagemagick-6.q16hdri - 8:6.9.7.4+dfsg-16ubuntu6.2
imagemagick-common - 8:6.9.7.4+dfsg-16ubuntu6.2
libimage-magick-perl - 8:6.9.7.4+dfsg-16ubuntu6.2
libimage-magick-q16-perl - 8:6.9.7.4+dfsg-16ubuntu6.2
libimage-magick-q16hdri-perl - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagick++-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagick++-6.q16-7 - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagick++-6.q16hdri-7 - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickcore-6-arch-config - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickcore-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickcore-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickcore-6.q16-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickcore-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickcore-6.q16hdri-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickwand-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickwand-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.2
libmagickwand-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.2
perlmagick - 8:6.9.7.4+dfsg-16ubuntu6.2
No subscription required | Low | ['CVE-2018-10804'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-10804', 'https://www.cve.org/CVERecord?id=CVE-2018-10804'] | {'cves': '["CVE-2018-10804"]', 'title': 'CVE-2018-10804 on Ubuntu 18.04 LTS (bionic) - low', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Low', 'oval_type': 'cve', 'references': '["CVE-2018-10804", "https://www.cve.org/CVERecord?id=CVE-2018-10804"]', 'description': 'ImageMagick version 7.0.7-28 contains a memory leak in WriteTIFFImage incoders/tiff.c.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2018-10804` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nimagemagick - 8:6.9.7.4+dfsg-16ubuntu6.2\nimagemagick-6-common - 8:6.9.7.4+dfsg-16ubuntu6.2\nimagemagick-6.q16 - 8:6.9.7.4+dfsg-16ubuntu6.2\nimagemagick-6.q16hdri - 8:6.9.7.4+dfsg-16ubuntu6.2\nimagemagick-common - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibimage-magick-perl - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibimage-magick-q16-perl - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibimage-magick-q16hdri-perl - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagick++-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagick++-6.q16-7 - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagick++-6.q16hdri-7 - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickcore-6-arch-config - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickcore-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickcore-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickcore-6.q16-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickcore-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickcore-6.q16hdri-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickwand-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickwand-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.2\nlibmagickwand-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.2\nperlmagick - 8:6.9.7.4+dfsg-16ubuntu6.2\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2018108040000000', 'package_criteria': [{'cve_id': 'CVE-2018-10804', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'imagemagick', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-6-common', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-6.q16', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-6.q16hdri', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-common', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'libimage-magick-perl', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'libimage-magick-q16-perl', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'libimage-magick-q16hdri-perl', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagick++-6-headers', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagick++-6.q16-7', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagick++-6.q16hdri-7', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6-arch-config', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6-headers', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16-3-extra', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16hdri-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16hdri-3-extra', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickwand-6-headers', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickwand-6.q16-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickwand-6.q16hdri-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}, {'cve_id': 'CVE-2018-10804', 'source': 'description_fix', 'status': 'fixed', 'package': 'perlmagick', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.2', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.2'}]} | 69e6f3f3edcbf4f4e22b5dbfd117aa73db2852d9810b6af3204b952a94726a58 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2018108820000000 | CVE-2018-10882 on Ubuntu 18.04 LTS (bionic) - low | A flaw was found in the Linux kernel's ext4 filesystem. A local user cancause an out-of-bound write in in fs/jbd2/transaction.c code, a denial ofservice, and a system crash by unmounting a crafted ext4 filesystem image.
Update Instructions:
Run `sudo pro fix CVE-2018-10882` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
linux-image-4.15.0-44-generic - 4.15.0-44.47
linux-image-4.15.0-44-generic-lpae - 4.15.0-44.47
linux-image-4.15.0-44-lowlatency - 4.15.0-44.47
linux-image-4.15.0-44-snapdragon - 4.15.0-44.47
linux-image-unsigned-4.15.0-44-generic - 4.15.0-44.47
linux-image-unsigned-4.15.0-44-lowlatency - 4.15.0-44.47
No subscription required
linux-image-4.15.0-1031-raspi2 - 4.15.0-1031.33
No subscription required
linux-image-4.15.0-1053-snapdragon - 4.15.0-1053.57
No subscription required
linux-image-4.15.0-1032-aws - 4.15.0-1032.34
No subscription required
linux-image-unsigned-4.15.0-1037-azure - 4.15.0-1037.39
No subscription required
linux-image-unsigned-4.15.0-1027-gcp - 4.15.0-1027.28
No subscription required
linux-image-4.15.0-1029-kvm - 4.15.0-1029.29
No subscription required
linux-image-unsigned-4.15.0-1033-oem - 4.15.0-1033.38
No subscription required | Low | ['CVE-2018-10882'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-10882', 'https://www.cve.org/CVERecord?id=CVE-2018-10882'] | {'cves': '["CVE-2018-10882"]', 'title': 'CVE-2018-10882 on Ubuntu 18.04 LTS (bionic) - low', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Low', 'oval_type': 'cve', 'references': '["CVE-2018-10882", "https://www.cve.org/CVERecord?id=CVE-2018-10882"]', 'description': "A flaw was found in the Linux kernel's ext4 filesystem. A local user cancause an out-of-bound write in in fs/jbd2/transaction.c code, a denial ofservice, and a system crash by unmounting a crafted ext4 filesystem image.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2018-10882` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nlinux-image-4.15.0-44-generic - 4.15.0-44.47\nlinux-image-4.15.0-44-generic-lpae - 4.15.0-44.47\nlinux-image-4.15.0-44-lowlatency - 4.15.0-44.47\nlinux-image-4.15.0-44-snapdragon - 4.15.0-44.47\nlinux-image-unsigned-4.15.0-44-generic - 4.15.0-44.47\nlinux-image-unsigned-4.15.0-44-lowlatency - 4.15.0-44.47\nNo subscription required\n\nlinux-image-4.15.0-1031-raspi2 - 4.15.0-1031.33\nNo subscription required\n\nlinux-image-4.15.0-1053-snapdragon - 4.15.0-1053.57\nNo subscription required\n\nlinux-image-4.15.0-1032-aws - 4.15.0-1032.34\nNo subscription required\n\nlinux-image-unsigned-4.15.0-1037-azure - 4.15.0-1037.39\nNo subscription required\n\nlinux-image-unsigned-4.15.0-1027-gcp - 4.15.0-1027.28\nNo subscription required\n\nlinux-image-4.15.0-1029-kvm - 4.15.0-1029.29\nNo subscription required\n\nlinux-image-unsigned-4.15.0-1033-oem - 4.15.0-1033.38\nNo subscription required", 'definition_id': 'oval:com.ubuntu.bionic:def:2018108820000000', 'package_criteria': [{'cve_id': 'CVE-2018-10882', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux', 'fixed_version': '4.15.0-44.47', 'affected_version_range': '< 4.15.0-44.47'}, {'cve_id': 'CVE-2018-10882', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-raspi2', 'fixed_version': '4.15.0-1031.33', 'affected_version_range': '< 4.15.0-1031.33'}, {'cve_id': 'CVE-2018-10882', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-snapdragon', 'fixed_version': '4.15.0-1053.57', 'affected_version_range': '< 4.15.0-1053.57'}, {'cve_id': 'CVE-2018-10882', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-aws', 'fixed_version': '4.15.0-1032.34', 'affected_version_range': '< 4.15.0-1032.34'}, {'cve_id': 'CVE-2018-10882', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-azure', 'fixed_version': '4.15.0-1037.39', 'affected_version_range': '< 4.15.0-1037.39'}, {'cve_id': 'CVE-2018-10882', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-gcp', 'fixed_version': '4.15.0-1027.28', 'affected_version_range': '< 4.15.0-1027.28'}, {'cve_id': 'CVE-2018-10882', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-kvm', 'fixed_version': '4.15.0-1029.29', 'affected_version_range': '< 4.15.0-1029.29'}, {'cve_id': 'CVE-2018-10882', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-oem', 'fixed_version': '4.15.0-1033.38', 'affected_version_range': '< 4.15.0-1033.38'}, {'cve_id': 'CVE-2018-10882', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-44-generic', 'fixed_version': '4.15.0-44.47', 'affected_version_range': '< 4.15.0-44.47'}, {'cve_id': 'CVE-2018-10882', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-44-generic-lpae', 'fixed_version': '4.15.0-44.47', 'affected_version_range': '< 4.15.0-44.47'}, {'cve_id': 'CVE-2018-10882', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-44-lowlatency', 'fixed_version': '4.15.0-44.47', 'affected_version_range': '< 4.15.0-44.47'}, {'cve_id': 'CVE-2018-10882', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-44-snapdragon', 'fixed_version': '4.15.0-44.47', 'affected_version_range': '< 4.15.0-44.47'}, {'cve_id': 'CVE-2018-10882', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-44-generic', 'fixed_version': '4.15.0-44.47', 'affected_version_range': '< 4.15.0-44.47'}, {'cve_id': 'CVE-2018-10882', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-44-lowlatency', 'fixed_version': '4.15.0-44.47', 'affected_version_range': '< 4.15.0-44.47'}, {'cve_id': 'CVE-2018-10882', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-1031-raspi2', 'fixed_version': '4.15.0-1031.33', 'affected_version_range': '< 4.15.0-1031.33'}, {'cve_id': 'CVE-2018-10882', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-1053-snapdragon', 'fixed_version': '4.15.0-1053.57', 'affected_version_range': '< 4.15.0-1053.57'}, {'cve_id': 'CVE-2018-10882', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-1032-aws', 'fixed_version': '4.15.0-1032.34', 'affected_version_range': '< 4.15.0-1032.34'}, {'cve_id': 'CVE-2018-10882', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-1037-azure', 'fixed_version': '4.15.0-1037.39', 'affected_version_range': '< 4.15.0-1037.39'}, {'cve_id': 'CVE-2018-10882', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-1027-gcp', 'fixed_version': '4.15.0-1027.28', 'affected_version_range': '< 4.15.0-1027.28'}, {'cve_id': 'CVE-2018-10882', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-1029-kvm', 'fixed_version': '4.15.0-1029.29', 'affected_version_range': '< 4.15.0-1029.29'}, {'cve_id': 'CVE-2018-10882', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-1033-oem', 'fixed_version': '4.15.0-1033.38', 'affected_version_range': '< 4.15.0-1033.38'}]} | c66e9d1885dad1f371ee96dab7d064d110083b5768526426b57d8941df6fe822 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2018113800000000 | CVE-2018-11380 on Ubuntu 18.04 LTS (bionic) - medium | The parse_import_ptr() function in radare2 2.5.0 allows remote attackers tocause a denial of service (heap-based out-of-bounds read and applicationcrash) via a crafted Mach-O file. | Medium | ['CVE-2018-11380'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-11380', 'https://www.cve.org/CVERecord?id=CVE-2018-11380'] | {'cves': '["CVE-2018-11380"]', 'title': 'CVE-2018-11380 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2018-11380", "https://www.cve.org/CVERecord?id=CVE-2018-11380"]', 'description': 'The parse_import_ptr() function in radare2 2.5.0 allows remote attackers tocause a denial of service (heap-based out-of-bounds read and applicationcrash) via a crafted Mach-O file.', 'definition_id': 'oval:com.ubuntu.bionic:def:2018113800000000', 'package_criteria': [{'cve_id': 'CVE-2018-11380', 'source': 'criterion_comment', 'status': 'open', 'package': 'radare2', 'fixed_version': None, 'affected_version_range': 'affected'}]} | 387978201f7a187c47c09ae33b403a1c9efa498becfd3595526bbbe4d4a05ec9 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2018122320000000 | CVE-2018-12232 on Ubuntu 18.04 LTS (bionic) - medium | In net/socket.c in the Linux kernel through 4.17.1, there is a racecondition between fchownat and close in cases where they target the samesocket file descriptor, related to the sock_close and sockfs_setattrfunctions. fchownat does not increment the file descriptor reference count,which allows close to set the socket to NULL during fchownat's execution,leading to a NULL pointer dereference and system crash.
Update Instructions:
Run `sudo pro fix CVE-2018-12232` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
linux-image-4.15.0-33-generic - 4.15.0-33.36
linux-image-4.15.0-33-generic-lpae - 4.15.0-33.36
linux-image-4.15.0-33-lowlatency - 4.15.0-33.36
linux-image-4.15.0-33-snapdragon - 4.15.0-33.36
linux-image-unsigned-4.15.0-33-generic - 4.15.0-33.36
linux-image-unsigned-4.15.0-33-lowlatency - 4.15.0-33.36
No subscription required
linux-image-4.15.0-1021-raspi2 - 4.15.0-1021.23
No subscription required
linux-image-4.15.0-1020-aws - 4.15.0-1020.20
No subscription required
linux-image-unsigned-4.15.0-1022-azure - 4.15.0-1022.23
No subscription required
linux-image-unsigned-4.15.0-1018-gcp - 4.15.0-1018.19
No subscription required
linux-image-4.15.0-1020-kvm - 4.15.0-1020.20
No subscription required
linux-image-unsigned-4.15.0-1017-oem - 4.15.0-1017.20
No subscription required | Medium | ['CVE-2018-12232'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-12232', 'https://www.cve.org/CVERecord?id=CVE-2018-12232'] | {'cves': '["CVE-2018-12232"]', 'title': 'CVE-2018-12232 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2018-12232", "https://www.cve.org/CVERecord?id=CVE-2018-12232"]', 'description': "In net/socket.c in the Linux kernel through 4.17.1, there is a racecondition between fchownat and close in cases where they target the samesocket file descriptor, related to the sock_close and sockfs_setattrfunctions. fchownat does not increment the file descriptor reference count,which allows close to set the socket to NULL during fchownat's execution,leading to a NULL pointer dereference and system crash.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2018-12232` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nlinux-image-4.15.0-33-generic - 4.15.0-33.36\nlinux-image-4.15.0-33-generic-lpae - 4.15.0-33.36\nlinux-image-4.15.0-33-lowlatency - 4.15.0-33.36\nlinux-image-4.15.0-33-snapdragon - 4.15.0-33.36\nlinux-image-unsigned-4.15.0-33-generic - 4.15.0-33.36\nlinux-image-unsigned-4.15.0-33-lowlatency - 4.15.0-33.36\nNo subscription required\n\nlinux-image-4.15.0-1021-raspi2 - 4.15.0-1021.23\nNo subscription required\n\nlinux-image-4.15.0-1020-aws - 4.15.0-1020.20\nNo subscription required\n\nlinux-image-unsigned-4.15.0-1022-azure - 4.15.0-1022.23\nNo subscription required\n\nlinux-image-unsigned-4.15.0-1018-gcp - 4.15.0-1018.19\nNo subscription required\n\nlinux-image-4.15.0-1020-kvm - 4.15.0-1020.20\nNo subscription required\n\nlinux-image-unsigned-4.15.0-1017-oem - 4.15.0-1017.20\nNo subscription required", 'definition_id': 'oval:com.ubuntu.bionic:def:2018122320000000', 'package_criteria': [{'cve_id': 'CVE-2018-12232', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux', 'fixed_version': '4.15.0-33.36', 'affected_version_range': '< 4.15.0-33.36'}, {'cve_id': 'CVE-2018-12232', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-raspi2', 'fixed_version': '4.15.0-1021.23', 'affected_version_range': '< 4.15.0-1021.23'}, {'cve_id': 'CVE-2018-12232', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-aws', 'fixed_version': '4.15.0-1020.20', 'affected_version_range': '< 4.15.0-1020.20'}, {'cve_id': 'CVE-2018-12232', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-azure', 'fixed_version': '4.15.0-1022.23', 'affected_version_range': '< 4.15.0-1022.23'}, {'cve_id': 'CVE-2018-12232', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-gcp', 'fixed_version': '4.15.0-1018.19', 'affected_version_range': '< 4.15.0-1018.19'}, {'cve_id': 'CVE-2018-12232', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-kvm', 'fixed_version': '4.15.0-1020.20', 'affected_version_range': '< 4.15.0-1020.20'}, {'cve_id': 'CVE-2018-12232', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-oem', 'fixed_version': '4.15.0-1017.20', 'affected_version_range': '< 4.15.0-1017.20'}, {'cve_id': 'CVE-2018-12232', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-33-generic', 'fixed_version': '4.15.0-33.36', 'affected_version_range': '< 4.15.0-33.36'}, {'cve_id': 'CVE-2018-12232', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-33-generic-lpae', 'fixed_version': '4.15.0-33.36', 'affected_version_range': '< 4.15.0-33.36'}, {'cve_id': 'CVE-2018-12232', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-33-lowlatency', 'fixed_version': '4.15.0-33.36', 'affected_version_range': '< 4.15.0-33.36'}, {'cve_id': 'CVE-2018-12232', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-33-snapdragon', 'fixed_version': '4.15.0-33.36', 'affected_version_range': '< 4.15.0-33.36'}, {'cve_id': 'CVE-2018-12232', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-33-generic', 'fixed_version': '4.15.0-33.36', 'affected_version_range': '< 4.15.0-33.36'}, {'cve_id': 'CVE-2018-12232', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-33-lowlatency', 'fixed_version': '4.15.0-33.36', 'affected_version_range': '< 4.15.0-33.36'}, {'cve_id': 'CVE-2018-12232', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-1021-raspi2', 'fixed_version': '4.15.0-1021.23', 'affected_version_range': '< 4.15.0-1021.23'}, {'cve_id': 'CVE-2018-12232', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-1020-aws', 'fixed_version': '4.15.0-1020.20', 'affected_version_range': '< 4.15.0-1020.20'}, {'cve_id': 'CVE-2018-12232', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-1022-azure', 'fixed_version': '4.15.0-1022.23', 'affected_version_range': '< 4.15.0-1022.23'}, {'cve_id': 'CVE-2018-12232', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-1018-gcp', 'fixed_version': '4.15.0-1018.19', 'affected_version_range': '< 4.15.0-1018.19'}, {'cve_id': 'CVE-2018-12232', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-1020-kvm', 'fixed_version': '4.15.0-1020.20', 'affected_version_range': '< 4.15.0-1020.20'}, {'cve_id': 'CVE-2018-12232', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-1017-oem', 'fixed_version': '4.15.0-1017.20', 'affected_version_range': '< 4.15.0-1017.20'}]} | 18f2727a928d5241d6270d85d4ea3a091c948a958b55634bdd7dc15829d545de | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2018122930000000 | CVE-2018-12293 on Ubuntu 18.04 LTS (bionic) - medium | The getImageData function in the ImageBufferCairo class inWebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used inWebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1,is vulnerable to a heap-based buffer overflow triggered by an integeroverflow, which could be abused by crafted HTML content.
Update Instructions:
Run `sudo pro fix CVE-2018-12293` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
gir1.2-javascriptcoregtk-4.0 - 2.20.3-0ubuntu0.18.04.1
gir1.2-webkit2-4.0 - 2.20.3-0ubuntu0.18.04.1
libjavascriptcoregtk-4.0-18 - 2.20.3-0ubuntu0.18.04.1
libjavascriptcoregtk-4.0-bin - 2.20.3-0ubuntu0.18.04.1
libwebkit2gtk-4.0-37 - 2.20.3-0ubuntu0.18.04.1
libwebkit2gtk-4.0-37-gtk2 - 2.20.3-0ubuntu0.18.04.1
webkit2gtk-driver - 2.20.3-0ubuntu0.18.04.1
No subscription required | Medium | ['CVE-2018-12293'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-12293', 'https://www.cve.org/CVERecord?id=CVE-2018-12293'] | {'cves': '["CVE-2018-12293"]', 'title': 'CVE-2018-12293 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2018-12293", "https://www.cve.org/CVERecord?id=CVE-2018-12293"]', 'description': 'The getImageData function in the ImageBufferCairo class inWebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used inWebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1,is vulnerable to a heap-based buffer overflow triggered by an integeroverflow, which could be abused by crafted HTML content.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2018-12293` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\ngir1.2-javascriptcoregtk-4.0 - 2.20.3-0ubuntu0.18.04.1\ngir1.2-webkit2-4.0 - 2.20.3-0ubuntu0.18.04.1\nlibjavascriptcoregtk-4.0-18 - 2.20.3-0ubuntu0.18.04.1\nlibjavascriptcoregtk-4.0-bin - 2.20.3-0ubuntu0.18.04.1\nlibwebkit2gtk-4.0-37 - 2.20.3-0ubuntu0.18.04.1\nlibwebkit2gtk-4.0-37-gtk2 - 2.20.3-0ubuntu0.18.04.1\nwebkit2gtk-driver - 2.20.3-0ubuntu0.18.04.1\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2018122930000000', 'package_criteria': [{'cve_id': 'CVE-2018-12293', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'webkit2gtk', 'fixed_version': '2.20.3-0ubuntu0.18.04.1', 'affected_version_range': '< 2.20.3-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-12293', 'source': 'description_fix', 'status': 'fixed', 'package': 'gir1.2-javascriptcoregtk-4.0', 'fixed_version': '2.20.3-0ubuntu0.18.04.1', 'affected_version_range': '< 2.20.3-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-12293', 'source': 'description_fix', 'status': 'fixed', 'package': 'gir1.2-webkit2-4.0', 'fixed_version': '2.20.3-0ubuntu0.18.04.1', 'affected_version_range': '< 2.20.3-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-12293', 'source': 'description_fix', 'status': 'fixed', 'package': 'libjavascriptcoregtk-4.0-18', 'fixed_version': '2.20.3-0ubuntu0.18.04.1', 'affected_version_range': '< 2.20.3-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-12293', 'source': 'description_fix', 'status': 'fixed', 'package': 'libjavascriptcoregtk-4.0-bin', 'fixed_version': '2.20.3-0ubuntu0.18.04.1', 'affected_version_range': '< 2.20.3-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-12293', 'source': 'description_fix', 'status': 'fixed', 'package': 'libwebkit2gtk-4.0-37', 'fixed_version': '2.20.3-0ubuntu0.18.04.1', 'affected_version_range': '< 2.20.3-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-12293', 'source': 'description_fix', 'status': 'fixed', 'package': 'libwebkit2gtk-4.0-37-gtk2', 'fixed_version': '2.20.3-0ubuntu0.18.04.1', 'affected_version_range': '< 2.20.3-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-12293', 'source': 'description_fix', 'status': 'fixed', 'package': 'webkit2gtk-driver', 'fixed_version': '2.20.3-0ubuntu0.18.04.1', 'affected_version_range': '< 2.20.3-0ubuntu0.18.04.1'}]} | 9b497ffa30dab05a3f2df700c25228f5263416c085d16a211af372fd9344bb62 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2018123760000000 | CVE-2018-12376 on Ubuntu 18.04 LTS (bionic) - medium | Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some ofthese bugs showed evidence of memory corruption and we presume that withenough effort that some of these could be exploited to run arbitrary code.This vulnerability affects Firefox < 62, Firefox ESR < 60.2, andThunderbird < 60.2.1.
Update Instructions:
Run `sudo pro fix CVE-2018-12376` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
firefox - 62.0+build2-0ubuntu0.18.04.3
firefox-globalmenu - 62.0+build2-0ubuntu0.18.04.3
firefox-mozsymbols - 62.0+build2-0ubuntu0.18.04.3
firefox-testsuite - 62.0+build2-0ubuntu0.18.04.3
No subscription required
thunderbird - 1:60.2.1+build1-0ubuntu0.18.04.2
thunderbird-globalmenu - 1:60.2.1+build1-0ubuntu0.18.04.2
thunderbird-gnome-support - 1:60.2.1+build1-0ubuntu0.18.04.2
thunderbird-mozsymbols - 1:60.2.1+build1-0ubuntu0.18.04.2
thunderbird-testsuite - 1:60.2.1+build1-0ubuntu0.18.04.2
xul-ext-calendar-timezones - 1:60.2.1+build1-0ubuntu0.18.04.2
xul-ext-gdata-provider - 1:60.2.1+build1-0ubuntu0.18.04.2
xul-ext-lightning - 1:60.2.1+build1-0ubuntu0.18.04.2
No subscription required | Medium | ['CVE-2018-12376'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-12376', 'https://www.cve.org/CVERecord?id=CVE-2018-12376'] | {'cves': '["CVE-2018-12376"]', 'title': 'CVE-2018-12376 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2018-12376", "https://www.cve.org/CVERecord?id=CVE-2018-12376"]', 'description': 'Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some ofthese bugs showed evidence of memory corruption and we presume that withenough effort that some of these could be exploited to run arbitrary code.This vulnerability affects Firefox < 62, Firefox ESR < 60.2, andThunderbird < 60.2.1.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2018-12376` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nfirefox - 62.0+build2-0ubuntu0.18.04.3\nfirefox-globalmenu - 62.0+build2-0ubuntu0.18.04.3\nfirefox-mozsymbols - 62.0+build2-0ubuntu0.18.04.3\nfirefox-testsuite - 62.0+build2-0ubuntu0.18.04.3\nNo subscription required\n\nthunderbird - 1:60.2.1+build1-0ubuntu0.18.04.2\nthunderbird-globalmenu - 1:60.2.1+build1-0ubuntu0.18.04.2\nthunderbird-gnome-support - 1:60.2.1+build1-0ubuntu0.18.04.2\nthunderbird-mozsymbols - 1:60.2.1+build1-0ubuntu0.18.04.2\nthunderbird-testsuite - 1:60.2.1+build1-0ubuntu0.18.04.2\nxul-ext-calendar-timezones - 1:60.2.1+build1-0ubuntu0.18.04.2\nxul-ext-gdata-provider - 1:60.2.1+build1-0ubuntu0.18.04.2\nxul-ext-lightning - 1:60.2.1+build1-0ubuntu0.18.04.2\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2018123760000000', 'package_criteria': [{'cve_id': 'CVE-2018-12376', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'firefox', 'fixed_version': '62.0+build2-0ubuntu0.18.04.3', 'affected_version_range': '< 62.0+build2-0ubuntu0.18.04.3'}, {'cve_id': 'CVE-2018-12376', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'thunderbird', 'fixed_version': '1:60.2.1+build1-0ubuntu0.18.04.2', 'affected_version_range': '< 1:60.2.1+build1-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2018-12376', 'source': 'description_fix', 'status': 'fixed', 'package': 'firefox-globalmenu', 'fixed_version': '62.0+build2-0ubuntu0.18.04.3', 'affected_version_range': '< 62.0+build2-0ubuntu0.18.04.3'}, {'cve_id': 'CVE-2018-12376', 'source': 'description_fix', 'status': 'fixed', 'package': 'firefox-mozsymbols', 'fixed_version': '62.0+build2-0ubuntu0.18.04.3', 'affected_version_range': '< 62.0+build2-0ubuntu0.18.04.3'}, {'cve_id': 'CVE-2018-12376', 'source': 'description_fix', 'status': 'fixed', 'package': 'firefox-testsuite', 'fixed_version': '62.0+build2-0ubuntu0.18.04.3', 'affected_version_range': '< 62.0+build2-0ubuntu0.18.04.3'}, {'cve_id': 'CVE-2018-12376', 'source': 'description_fix', 'status': 'fixed', 'package': 'thunderbird-globalmenu', 'fixed_version': '1:60.2.1+build1-0ubuntu0.18.04.2', 'affected_version_range': '< 1:60.2.1+build1-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2018-12376', 'source': 'description_fix', 'status': 'fixed', 'package': 'thunderbird-gnome-support', 'fixed_version': '1:60.2.1+build1-0ubuntu0.18.04.2', 'affected_version_range': '< 1:60.2.1+build1-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2018-12376', 'source': 'description_fix', 'status': 'fixed', 'package': 'thunderbird-mozsymbols', 'fixed_version': '1:60.2.1+build1-0ubuntu0.18.04.2', 'affected_version_range': '< 1:60.2.1+build1-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2018-12376', 'source': 'description_fix', 'status': 'fixed', 'package': 'thunderbird-testsuite', 'fixed_version': '1:60.2.1+build1-0ubuntu0.18.04.2', 'affected_version_range': '< 1:60.2.1+build1-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2018-12376', 'source': 'description_fix', 'status': 'fixed', 'package': 'xul-ext-calendar-timezones', 'fixed_version': '1:60.2.1+build1-0ubuntu0.18.04.2', 'affected_version_range': '< 1:60.2.1+build1-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2018-12376', 'source': 'description_fix', 'status': 'fixed', 'package': 'xul-ext-gdata-provider', 'fixed_version': '1:60.2.1+build1-0ubuntu0.18.04.2', 'affected_version_range': '< 1:60.2.1+build1-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2018-12376', 'source': 'description_fix', 'status': 'fixed', 'package': 'xul-ext-lightning', 'fixed_version': '1:60.2.1+build1-0ubuntu0.18.04.2', 'affected_version_range': '< 1:60.2.1+build1-0ubuntu0.18.04.2'}]} | f552b3edf6a13601cac12ef1a470e2c95bc7bcc51471fac3a10d2f0e1b19e0eb | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2018123990000000 | CVE-2018-12399 on Ubuntu 18.04 LTS (bionic) - low | When a new protocol handler is registered, the API accepts a title argumentwhich can be used to mislead users about which domain is registering thenew protocol. This may result in the user approving a protocol handler thatthey otherwise would not have. This vulnerability affects Firefox < 63.
Update Instructions:
Run `sudo pro fix CVE-2018-12399` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
firefox - 63.0+build2-0ubuntu0.18.04.2
firefox-globalmenu - 63.0+build2-0ubuntu0.18.04.2
firefox-mozsymbols - 63.0+build2-0ubuntu0.18.04.2
firefox-testsuite - 63.0+build2-0ubuntu0.18.04.2
No subscription required | Low | ['CVE-2018-12399'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-12399', 'https://www.cve.org/CVERecord?id=CVE-2018-12399'] | {'cves': '["CVE-2018-12399"]', 'title': 'CVE-2018-12399 on Ubuntu 18.04 LTS (bionic) - low', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Low', 'oval_type': 'cve', 'references': '["CVE-2018-12399", "https://www.cve.org/CVERecord?id=CVE-2018-12399"]', 'description': 'When a new protocol handler is registered, the API accepts a title argumentwhich can be used to mislead users about which domain is registering thenew protocol. This may result in the user approving a protocol handler thatthey otherwise would not have. This vulnerability affects Firefox < 63.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2018-12399` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nfirefox - 63.0+build2-0ubuntu0.18.04.2\nfirefox-globalmenu - 63.0+build2-0ubuntu0.18.04.2\nfirefox-mozsymbols - 63.0+build2-0ubuntu0.18.04.2\nfirefox-testsuite - 63.0+build2-0ubuntu0.18.04.2\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2018123990000000', 'package_criteria': [{'cve_id': 'CVE-2018-12399', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'firefox', 'fixed_version': '63.0+build2-0ubuntu0.18.04.2', 'affected_version_range': '< 63.0+build2-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2018-12399', 'source': 'description_fix', 'status': 'fixed', 'package': 'firefox-globalmenu', 'fixed_version': '63.0+build2-0ubuntu0.18.04.2', 'affected_version_range': '< 63.0+build2-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2018-12399', 'source': 'description_fix', 'status': 'fixed', 'package': 'firefox-mozsymbols', 'fixed_version': '63.0+build2-0ubuntu0.18.04.2', 'affected_version_range': '< 63.0+build2-0ubuntu0.18.04.2'}, {'cve_id': 'CVE-2018-12399', 'source': 'description_fix', 'status': 'fixed', 'package': 'firefox-testsuite', 'fixed_version': '63.0+build2-0ubuntu0.18.04.2', 'affected_version_range': '< 63.0+build2-0ubuntu0.18.04.2'}]} | 6115a540be27cc1d0a99b66ffdd4c71f8df2806c495ca4022f3317284868f46f | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2018126000000000 | CVE-2018-12600 on Ubuntu 18.04 LTS (bionic) - medium | In ImageMagick 7.0.8-3 Q16, ReadDIBImage and WriteDIBImage in coders/dib.callow attackers to cause an out of bounds write via a crafted file.
Update Instructions:
Run `sudo pro fix CVE-2018-12600` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
imagemagick - 8:6.9.7.4+dfsg-16ubuntu6.3
imagemagick-6-common - 8:6.9.7.4+dfsg-16ubuntu6.3
imagemagick-6.q16 - 8:6.9.7.4+dfsg-16ubuntu6.3
imagemagick-6.q16hdri - 8:6.9.7.4+dfsg-16ubuntu6.3
imagemagick-common - 8:6.9.7.4+dfsg-16ubuntu6.3
libimage-magick-perl - 8:6.9.7.4+dfsg-16ubuntu6.3
libimage-magick-q16-perl - 8:6.9.7.4+dfsg-16ubuntu6.3
libimage-magick-q16hdri-perl - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagick++-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagick++-6.q16-7 - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagick++-6.q16hdri-7 - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagickcore-6-arch-config - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagickcore-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagickcore-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagickcore-6.q16-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagickcore-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagickcore-6.q16hdri-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagickwand-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagickwand-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagickwand-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.3
perlmagick - 8:6.9.7.4+dfsg-16ubuntu6.3
No subscription required | Medium | ['CVE-2018-12600'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-12600', 'https://www.cve.org/CVERecord?id=CVE-2018-12600'] | {'cves': '["CVE-2018-12600"]', 'title': 'CVE-2018-12600 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2018-12600", "https://www.cve.org/CVERecord?id=CVE-2018-12600"]', 'description': 'In ImageMagick 7.0.8-3 Q16, ReadDIBImage and WriteDIBImage in coders/dib.callow attackers to cause an out of bounds write via a crafted file.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2018-12600` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nimagemagick - 8:6.9.7.4+dfsg-16ubuntu6.3\nimagemagick-6-common - 8:6.9.7.4+dfsg-16ubuntu6.3\nimagemagick-6.q16 - 8:6.9.7.4+dfsg-16ubuntu6.3\nimagemagick-6.q16hdri - 8:6.9.7.4+dfsg-16ubuntu6.3\nimagemagick-common - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibimage-magick-perl - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibimage-magick-q16-perl - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibimage-magick-q16hdri-perl - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagick++-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagick++-6.q16-7 - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagick++-6.q16hdri-7 - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagickcore-6-arch-config - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagickcore-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagickcore-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagickcore-6.q16-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagickcore-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagickcore-6.q16hdri-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagickwand-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagickwand-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagickwand-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.3\nperlmagick - 8:6.9.7.4+dfsg-16ubuntu6.3\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2018126000000000', 'package_criteria': [{'cve_id': 'CVE-2018-12600', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'imagemagick', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-6-common', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-6.q16', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-6.q16hdri', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-common', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'libimage-magick-perl', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'libimage-magick-q16-perl', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'libimage-magick-q16hdri-perl', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagick++-6-headers', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagick++-6.q16-7', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagick++-6.q16hdri-7', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6-arch-config', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6-headers', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16-3-extra', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16hdri-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16hdri-3-extra', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickwand-6-headers', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickwand-6.q16-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickwand-6.q16hdri-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-12600', 'source': 'description_fix', 'status': 'fixed', 'package': 'perlmagick', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}]} | e5f505d8e926b60fb07373351b842a1513ba336d6545dfcb2eb591623fad9875 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2018129320000000 | CVE-2018-12932 on Ubuntu 18.04 LTS (bionic) - medium | PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers tocause a denial of service (heap-based buffer overflow) or possibly haveunspecified other impact by triggering a large pAlphaBlend->cbBitsSrcvalue. | Medium | ['CVE-2018-12932'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-12932', 'https://www.cve.org/CVERecord?id=CVE-2018-12932'] | {'cves': '["CVE-2018-12932"]', 'title': 'CVE-2018-12932 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2018-12932", "https://www.cve.org/CVERecord?id=CVE-2018-12932"]', 'description': 'PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers tocause a denial of service (heap-based buffer overflow) or possibly haveunspecified other impact by triggering a large pAlphaBlend->cbBitsSrcvalue.', 'definition_id': 'oval:com.ubuntu.bionic:def:2018129320000000', 'package_criteria': [{'cve_id': 'CVE-2018-12932', 'source': 'criterion_comment', 'status': 'open', 'package': 'wine', 'fixed_version': None, 'affected_version_range': 'affected'}]} | f8ff230c1cdff3299313b5560c08632e4bf29573db002a4e8f4065eae6c1b4bf | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:201813110000000 | CVE-2018-1311 on Ubuntu 18.04 LTS (bionic) - medium | The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-freeerror triggered during the scanning of external DTDs. This flaw has notbeen addressed in the maintained version of the library and has no currentmitigation other than to disable DTD processing. This can be accomplishedvia the DOM using a standard parser feature, or via SAX using theXERCES_DISABLE_DTD environment variable.
Update Instructions:
Run `sudo pro fix CVE-2018-1311` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
libxerces-c-samples - 3.2.0+debian-2ubuntu0.1~esm2
libxerces-c3.2 - 3.2.0+debian-2ubuntu0.1~esm2
Available with Ubuntu Pro: https://ubuntu.com/pro | Medium | ['CVE-2018-1311'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-1311', 'https://www.cve.org/CVERecord?id=CVE-2018-1311'] | {'cves': '["CVE-2018-1311"]', 'title': 'CVE-2018-1311 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2018-1311", "https://www.cve.org/CVERecord?id=CVE-2018-1311"]', 'description': 'The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-freeerror triggered during the scanning of external DTDs. This flaw has notbeen addressed in the maintained version of the library and has no currentmitigation other than to disable DTD processing. This can be accomplishedvia the DOM using a standard parser feature, or via SAX using theXERCES_DISABLE_DTD environment variable.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2018-1311` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nlibxerces-c-samples - 3.2.0+debian-2ubuntu0.1~esm2\nlibxerces-c3.2 - 3.2.0+debian-2ubuntu0.1~esm2\nAvailable with Ubuntu Pro: https://ubuntu.com/pro', 'definition_id': 'oval:com.ubuntu.bionic:def:201813110000000', 'package_criteria': [{'cve_id': 'CVE-2018-1311', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'xerces-c', 'fixed_version': '3.2.0+debian-2ubuntu0.1~esm2', 'affected_version_range': '< 3.2.0+debian-2ubuntu0.1~esm2'}, {'cve_id': 'CVE-2018-1311', 'source': 'description_fix', 'status': 'fixed', 'package': 'libxerces-c-samples', 'fixed_version': '3.2.0+debian-2ubuntu0.1~esm2', 'affected_version_range': '< 3.2.0+debian-2ubuntu0.1~esm2'}, {'cve_id': 'CVE-2018-1311', 'source': 'description_fix', 'status': 'fixed', 'package': 'libxerces-c3.2', 'fixed_version': '3.2.0+debian-2ubuntu0.1~esm2', 'affected_version_range': '< 3.2.0+debian-2ubuntu0.1~esm2'}]} | 623253d4e1f434284df720cb23f4e4694ee48be2e62eadfaddd466454c1cdbeb | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2018131530000000 | CVE-2018-13153 on Ubuntu 18.04 LTS (bionic) - low | In ImageMagick 7.0.8-4, there is a memory leak in the XMagickCommandfunction in MagickCore/animate.c.
Update Instructions:
Run `sudo pro fix CVE-2018-13153` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
imagemagick - 8:6.9.7.4+dfsg-16ubuntu6.3
imagemagick-6-common - 8:6.9.7.4+dfsg-16ubuntu6.3
imagemagick-6.q16 - 8:6.9.7.4+dfsg-16ubuntu6.3
imagemagick-6.q16hdri - 8:6.9.7.4+dfsg-16ubuntu6.3
imagemagick-common - 8:6.9.7.4+dfsg-16ubuntu6.3
libimage-magick-perl - 8:6.9.7.4+dfsg-16ubuntu6.3
libimage-magick-q16-perl - 8:6.9.7.4+dfsg-16ubuntu6.3
libimage-magick-q16hdri-perl - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagick++-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagick++-6.q16-7 - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagick++-6.q16hdri-7 - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagickcore-6-arch-config - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagickcore-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagickcore-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagickcore-6.q16-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagickcore-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagickcore-6.q16hdri-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagickwand-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagickwand-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.3
libmagickwand-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.3
perlmagick - 8:6.9.7.4+dfsg-16ubuntu6.3
No subscription required | Low | ['CVE-2018-13153'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-13153', 'https://www.cve.org/CVERecord?id=CVE-2018-13153'] | {'cves': '["CVE-2018-13153"]', 'title': 'CVE-2018-13153 on Ubuntu 18.04 LTS (bionic) - low', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Low', 'oval_type': 'cve', 'references': '["CVE-2018-13153", "https://www.cve.org/CVERecord?id=CVE-2018-13153"]', 'description': 'In ImageMagick 7.0.8-4, there is a memory leak in the XMagickCommandfunction in MagickCore/animate.c.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2018-13153` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nimagemagick - 8:6.9.7.4+dfsg-16ubuntu6.3\nimagemagick-6-common - 8:6.9.7.4+dfsg-16ubuntu6.3\nimagemagick-6.q16 - 8:6.9.7.4+dfsg-16ubuntu6.3\nimagemagick-6.q16hdri - 8:6.9.7.4+dfsg-16ubuntu6.3\nimagemagick-common - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibimage-magick-perl - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibimage-magick-q16-perl - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibimage-magick-q16hdri-perl - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagick++-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagick++-6.q16-7 - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagick++-6.q16hdri-7 - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagickcore-6-arch-config - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagickcore-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagickcore-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagickcore-6.q16-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagickcore-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagickcore-6.q16hdri-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagickwand-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagickwand-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.3\nlibmagickwand-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.3\nperlmagick - 8:6.9.7.4+dfsg-16ubuntu6.3\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2018131530000000', 'package_criteria': [{'cve_id': 'CVE-2018-13153', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'imagemagick', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-6-common', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-6.q16', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-6.q16hdri', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-common', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'libimage-magick-perl', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'libimage-magick-q16-perl', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'libimage-magick-q16hdri-perl', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagick++-6-headers', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagick++-6.q16-7', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagick++-6.q16hdri-7', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6-arch-config', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6-headers', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16-3-extra', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16hdri-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16hdri-3-extra', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickwand-6-headers', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickwand-6.q16-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickwand-6.q16hdri-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}, {'cve_id': 'CVE-2018-13153', 'source': 'description_fix', 'status': 'fixed', 'package': 'perlmagick', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.3', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.3'}]} | c5ff35969eb7535d1a77a3f35b2538f70d17ff0d24b16abb42634b6e7375e2fd | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2018134050000000 | CVE-2018-13405 on Ubuntu 18.04 LTS (bionic) - medium | The inode_init_owner function in fs/inode.c in the Linux kernel through3.16 allows local users to create files with an unintended group ownership,in a scenario where a directory is SGID to a certain group and is writableby a user who is not a member of that group. Here, the non-member cantrigger creation of a plain file whose group ownership is that group. Theintended behavior was that the non-member can trigger creation of adirectory (but not a plain file) whose group ownership is that group. Thenon-member can escalate privileges by making the plain file executable andSGID.
Update Instructions:
Run `sudo pro fix CVE-2018-13405` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
linux-image-4.15.0-33-generic - 4.15.0-33.36
linux-image-4.15.0-33-generic-lpae - 4.15.0-33.36
linux-image-4.15.0-33-lowlatency - 4.15.0-33.36
linux-image-4.15.0-33-snapdragon - 4.15.0-33.36
linux-image-unsigned-4.15.0-33-generic - 4.15.0-33.36
linux-image-unsigned-4.15.0-33-lowlatency - 4.15.0-33.36
No subscription required
linux-image-4.15.0-1021-raspi2 - 4.15.0-1021.23
No subscription required
linux-image-4.15.0-1020-aws - 4.15.0-1020.20
No subscription required
linux-image-unsigned-4.15.0-1022-azure - 4.15.0-1022.23
No subscription required
linux-image-unsigned-4.15.0-1018-gcp - 4.15.0-1018.19
No subscription required
linux-image-4.15.0-1020-kvm - 4.15.0-1020.20
No subscription required
linux-image-unsigned-4.15.0-1017-oem - 4.15.0-1017.20
No subscription required | Medium | ['CVE-2018-13405'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-13405', 'https://www.cve.org/CVERecord?id=CVE-2018-13405'] | {'cves': '["CVE-2018-13405"]', 'title': 'CVE-2018-13405 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2018-13405", "https://www.cve.org/CVERecord?id=CVE-2018-13405"]', 'description': 'The inode_init_owner function in fs/inode.c in the Linux kernel through3.16 allows local users to create files with an unintended group ownership,in a scenario where a directory is SGID to a certain group and is writableby a user who is not a member of that group. Here, the non-member cantrigger creation of a plain file whose group ownership is that group. Theintended behavior was that the non-member can trigger creation of adirectory (but not a plain file) whose group ownership is that group. Thenon-member can escalate privileges by making the plain file executable andSGID.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2018-13405` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nlinux-image-4.15.0-33-generic - 4.15.0-33.36\nlinux-image-4.15.0-33-generic-lpae - 4.15.0-33.36\nlinux-image-4.15.0-33-lowlatency - 4.15.0-33.36\nlinux-image-4.15.0-33-snapdragon - 4.15.0-33.36\nlinux-image-unsigned-4.15.0-33-generic - 4.15.0-33.36\nlinux-image-unsigned-4.15.0-33-lowlatency - 4.15.0-33.36\nNo subscription required\n\nlinux-image-4.15.0-1021-raspi2 - 4.15.0-1021.23\nNo subscription required\n\nlinux-image-4.15.0-1020-aws - 4.15.0-1020.20\nNo subscription required\n\nlinux-image-unsigned-4.15.0-1022-azure - 4.15.0-1022.23\nNo subscription required\n\nlinux-image-unsigned-4.15.0-1018-gcp - 4.15.0-1018.19\nNo subscription required\n\nlinux-image-4.15.0-1020-kvm - 4.15.0-1020.20\nNo subscription required\n\nlinux-image-unsigned-4.15.0-1017-oem - 4.15.0-1017.20\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2018134050000000', 'package_criteria': [{'cve_id': 'CVE-2018-13405', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux', 'fixed_version': '4.15.0-33.36', 'affected_version_range': '< 4.15.0-33.36'}, {'cve_id': 'CVE-2018-13405', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-raspi2', 'fixed_version': '4.15.0-1021.23', 'affected_version_range': '< 4.15.0-1021.23'}, {'cve_id': 'CVE-2018-13405', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-aws', 'fixed_version': '4.15.0-1020.20', 'affected_version_range': '< 4.15.0-1020.20'}, {'cve_id': 'CVE-2018-13405', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-azure', 'fixed_version': '4.15.0-1022.23', 'affected_version_range': '< 4.15.0-1022.23'}, {'cve_id': 'CVE-2018-13405', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-gcp', 'fixed_version': '4.15.0-1018.19', 'affected_version_range': '< 4.15.0-1018.19'}, {'cve_id': 'CVE-2018-13405', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-kvm', 'fixed_version': '4.15.0-1020.20', 'affected_version_range': '< 4.15.0-1020.20'}, {'cve_id': 'CVE-2018-13405', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-oem', 'fixed_version': '4.15.0-1017.20', 'affected_version_range': '< 4.15.0-1017.20'}, {'cve_id': 'CVE-2018-13405', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-33-generic', 'fixed_version': '4.15.0-33.36', 'affected_version_range': '< 4.15.0-33.36'}, {'cve_id': 'CVE-2018-13405', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-33-generic-lpae', 'fixed_version': '4.15.0-33.36', 'affected_version_range': '< 4.15.0-33.36'}, {'cve_id': 'CVE-2018-13405', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-33-lowlatency', 'fixed_version': '4.15.0-33.36', 'affected_version_range': '< 4.15.0-33.36'}, {'cve_id': 'CVE-2018-13405', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-33-snapdragon', 'fixed_version': '4.15.0-33.36', 'affected_version_range': '< 4.15.0-33.36'}, {'cve_id': 'CVE-2018-13405', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-33-generic', 'fixed_version': '4.15.0-33.36', 'affected_version_range': '< 4.15.0-33.36'}, {'cve_id': 'CVE-2018-13405', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-33-lowlatency', 'fixed_version': '4.15.0-33.36', 'affected_version_range': '< 4.15.0-33.36'}, {'cve_id': 'CVE-2018-13405', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-1021-raspi2', 'fixed_version': '4.15.0-1021.23', 'affected_version_range': '< 4.15.0-1021.23'}, {'cve_id': 'CVE-2018-13405', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-1020-aws', 'fixed_version': '4.15.0-1020.20', 'affected_version_range': '< 4.15.0-1020.20'}, {'cve_id': 'CVE-2018-13405', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-1022-azure', 'fixed_version': '4.15.0-1022.23', 'affected_version_range': '< 4.15.0-1022.23'}, {'cve_id': 'CVE-2018-13405', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-1018-gcp', 'fixed_version': '4.15.0-1018.19', 'affected_version_range': '< 4.15.0-1018.19'}, {'cve_id': 'CVE-2018-13405', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-1020-kvm', 'fixed_version': '4.15.0-1020.20', 'affected_version_range': '< 4.15.0-1020.20'}, {'cve_id': 'CVE-2018-13405', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-1017-oem', 'fixed_version': '4.15.0-1017.20', 'affected_version_range': '< 4.15.0-1017.20'}]} | 3dbca96d8efff6252a2e76a450f230920a47e5758fc32768398bab48d906ddb5 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2018143950000000 | CVE-2018-14395 on Ubuntu 18.04 LTS (bionic) - low | libavformat/movenc.c in FFmpeg 3.2 and 4.0.2 allows attackers to cause adenial of service (application crash caused by a divide-by-zero error) witha user crafted audio file when converting to the MOV audio format.
Update Instructions:
Run `sudo pro fix CVE-2018-14395` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
ffmpeg - 7:3.4.4-0ubuntu0.18.04.1
libavcodec-extra - 7:3.4.4-0ubuntu0.18.04.1
libavcodec-extra57 - 7:3.4.4-0ubuntu0.18.04.1
libavcodec57 - 7:3.4.4-0ubuntu0.18.04.1
libavdevice57 - 7:3.4.4-0ubuntu0.18.04.1
libavfilter-extra - 7:3.4.4-0ubuntu0.18.04.1
libavfilter-extra6 - 7:3.4.4-0ubuntu0.18.04.1
libavfilter6 - 7:3.4.4-0ubuntu0.18.04.1
libavformat57 - 7:3.4.4-0ubuntu0.18.04.1
libavresample3 - 7:3.4.4-0ubuntu0.18.04.1
libavutil55 - 7:3.4.4-0ubuntu0.18.04.1
libpostproc54 - 7:3.4.4-0ubuntu0.18.04.1
libswresample2 - 7:3.4.4-0ubuntu0.18.04.1
libswscale4 - 7:3.4.4-0ubuntu0.18.04.1
No subscription required | Low | ['CVE-2018-14395'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-14395', 'https://www.cve.org/CVERecord?id=CVE-2018-14395'] | {'cves': '["CVE-2018-14395"]', 'title': 'CVE-2018-14395 on Ubuntu 18.04 LTS (bionic) - low', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Low', 'oval_type': 'cve', 'references': '["CVE-2018-14395", "https://www.cve.org/CVERecord?id=CVE-2018-14395"]', 'description': 'libavformat/movenc.c in FFmpeg 3.2 and 4.0.2 allows attackers to cause adenial of service (application crash caused by a divide-by-zero error) witha user crafted audio file when converting to the MOV audio format.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2018-14395` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nffmpeg - 7:3.4.4-0ubuntu0.18.04.1\nlibavcodec-extra - 7:3.4.4-0ubuntu0.18.04.1\nlibavcodec-extra57 - 7:3.4.4-0ubuntu0.18.04.1\nlibavcodec57 - 7:3.4.4-0ubuntu0.18.04.1\nlibavdevice57 - 7:3.4.4-0ubuntu0.18.04.1\nlibavfilter-extra - 7:3.4.4-0ubuntu0.18.04.1\nlibavfilter-extra6 - 7:3.4.4-0ubuntu0.18.04.1\nlibavfilter6 - 7:3.4.4-0ubuntu0.18.04.1\nlibavformat57 - 7:3.4.4-0ubuntu0.18.04.1\nlibavresample3 - 7:3.4.4-0ubuntu0.18.04.1\nlibavutil55 - 7:3.4.4-0ubuntu0.18.04.1\nlibpostproc54 - 7:3.4.4-0ubuntu0.18.04.1\nlibswresample2 - 7:3.4.4-0ubuntu0.18.04.1\nlibswscale4 - 7:3.4.4-0ubuntu0.18.04.1\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2018143950000000', 'package_criteria': [{'cve_id': 'CVE-2018-14395', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'ffmpeg', 'fixed_version': '7:3.4.4-0ubuntu0.18.04.1', 'affected_version_range': '< 7:3.4.4-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-14395', 'source': 'description_fix', 'status': 'fixed', 'package': 'libavcodec-extra', 'fixed_version': '7:3.4.4-0ubuntu0.18.04.1', 'affected_version_range': '< 7:3.4.4-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-14395', 'source': 'description_fix', 'status': 'fixed', 'package': 'libavcodec-extra57', 'fixed_version': '7:3.4.4-0ubuntu0.18.04.1', 'affected_version_range': '< 7:3.4.4-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-14395', 'source': 'description_fix', 'status': 'fixed', 'package': 'libavcodec57', 'fixed_version': '7:3.4.4-0ubuntu0.18.04.1', 'affected_version_range': '< 7:3.4.4-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-14395', 'source': 'description_fix', 'status': 'fixed', 'package': 'libavdevice57', 'fixed_version': '7:3.4.4-0ubuntu0.18.04.1', 'affected_version_range': '< 7:3.4.4-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-14395', 'source': 'description_fix', 'status': 'fixed', 'package': 'libavfilter-extra', 'fixed_version': '7:3.4.4-0ubuntu0.18.04.1', 'affected_version_range': '< 7:3.4.4-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-14395', 'source': 'description_fix', 'status': 'fixed', 'package': 'libavfilter-extra6', 'fixed_version': '7:3.4.4-0ubuntu0.18.04.1', 'affected_version_range': '< 7:3.4.4-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-14395', 'source': 'description_fix', 'status': 'fixed', 'package': 'libavfilter6', 'fixed_version': '7:3.4.4-0ubuntu0.18.04.1', 'affected_version_range': '< 7:3.4.4-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-14395', 'source': 'description_fix', 'status': 'fixed', 'package': 'libavformat57', 'fixed_version': '7:3.4.4-0ubuntu0.18.04.1', 'affected_version_range': '< 7:3.4.4-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-14395', 'source': 'description_fix', 'status': 'fixed', 'package': 'libavresample3', 'fixed_version': '7:3.4.4-0ubuntu0.18.04.1', 'affected_version_range': '< 7:3.4.4-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-14395', 'source': 'description_fix', 'status': 'fixed', 'package': 'libavutil55', 'fixed_version': '7:3.4.4-0ubuntu0.18.04.1', 'affected_version_range': '< 7:3.4.4-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-14395', 'source': 'description_fix', 'status': 'fixed', 'package': 'libpostproc54', 'fixed_version': '7:3.4.4-0ubuntu0.18.04.1', 'affected_version_range': '< 7:3.4.4-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-14395', 'source': 'description_fix', 'status': 'fixed', 'package': 'libswresample2', 'fixed_version': '7:3.4.4-0ubuntu0.18.04.1', 'affected_version_range': '< 7:3.4.4-0ubuntu0.18.04.1'}, {'cve_id': 'CVE-2018-14395', 'source': 'description_fix', 'status': 'fixed', 'package': 'libswscale4', 'fixed_version': '7:3.4.4-0ubuntu0.18.04.1', 'affected_version_range': '< 7:3.4.4-0ubuntu0.18.04.1'}]} | 8afcc2664017aea0c5f9481b080dbb53212718c139255c5186c1e820adf8f070 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2018144340000000 | CVE-2018-14434 on Ubuntu 18.04 LTS (bionic) - low | ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage incoders/mpc.c.
Update Instructions:
Run `sudo pro fix CVE-2018-14434` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
imagemagick - 8:6.9.7.4+dfsg-16ubuntu6.4
imagemagick-6-common - 8:6.9.7.4+dfsg-16ubuntu6.4
imagemagick-6.q16 - 8:6.9.7.4+dfsg-16ubuntu6.4
imagemagick-6.q16hdri - 8:6.9.7.4+dfsg-16ubuntu6.4
imagemagick-common - 8:6.9.7.4+dfsg-16ubuntu6.4
libimage-magick-perl - 8:6.9.7.4+dfsg-16ubuntu6.4
libimage-magick-q16-perl - 8:6.9.7.4+dfsg-16ubuntu6.4
libimage-magick-q16hdri-perl - 8:6.9.7.4+dfsg-16ubuntu6.4
libmagick++-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.4
libmagick++-6.q16-7 - 8:6.9.7.4+dfsg-16ubuntu6.4
libmagick++-6.q16hdri-7 - 8:6.9.7.4+dfsg-16ubuntu6.4
libmagickcore-6-arch-config - 8:6.9.7.4+dfsg-16ubuntu6.4
libmagickcore-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.4
libmagickcore-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.4
libmagickcore-6.q16-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.4
libmagickcore-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.4
libmagickcore-6.q16hdri-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.4
libmagickwand-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.4
libmagickwand-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.4
libmagickwand-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.4
perlmagick - 8:6.9.7.4+dfsg-16ubuntu6.4
No subscription required | Low | ['CVE-2018-14434'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-14434', 'https://www.cve.org/CVERecord?id=CVE-2018-14434'] | {'cves': '["CVE-2018-14434"]', 'title': 'CVE-2018-14434 on Ubuntu 18.04 LTS (bionic) - low', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Low', 'oval_type': 'cve', 'references': '["CVE-2018-14434", "https://www.cve.org/CVERecord?id=CVE-2018-14434"]', 'description': 'ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage incoders/mpc.c.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2018-14434` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nimagemagick - 8:6.9.7.4+dfsg-16ubuntu6.4\nimagemagick-6-common - 8:6.9.7.4+dfsg-16ubuntu6.4\nimagemagick-6.q16 - 8:6.9.7.4+dfsg-16ubuntu6.4\nimagemagick-6.q16hdri - 8:6.9.7.4+dfsg-16ubuntu6.4\nimagemagick-common - 8:6.9.7.4+dfsg-16ubuntu6.4\nlibimage-magick-perl - 8:6.9.7.4+dfsg-16ubuntu6.4\nlibimage-magick-q16-perl - 8:6.9.7.4+dfsg-16ubuntu6.4\nlibimage-magick-q16hdri-perl - 8:6.9.7.4+dfsg-16ubuntu6.4\nlibmagick++-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.4\nlibmagick++-6.q16-7 - 8:6.9.7.4+dfsg-16ubuntu6.4\nlibmagick++-6.q16hdri-7 - 8:6.9.7.4+dfsg-16ubuntu6.4\nlibmagickcore-6-arch-config - 8:6.9.7.4+dfsg-16ubuntu6.4\nlibmagickcore-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.4\nlibmagickcore-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.4\nlibmagickcore-6.q16-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.4\nlibmagickcore-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.4\nlibmagickcore-6.q16hdri-3-extra - 8:6.9.7.4+dfsg-16ubuntu6.4\nlibmagickwand-6-headers - 8:6.9.7.4+dfsg-16ubuntu6.4\nlibmagickwand-6.q16-3 - 8:6.9.7.4+dfsg-16ubuntu6.4\nlibmagickwand-6.q16hdri-3 - 8:6.9.7.4+dfsg-16ubuntu6.4\nperlmagick - 8:6.9.7.4+dfsg-16ubuntu6.4\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2018144340000000', 'package_criteria': [{'cve_id': 'CVE-2018-14434', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'imagemagick', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-6-common', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-6.q16', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-6.q16hdri', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'imagemagick-common', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'libimage-magick-perl', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'libimage-magick-q16-perl', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'libimage-magick-q16hdri-perl', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagick++-6-headers', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagick++-6.q16-7', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagick++-6.q16hdri-7', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6-arch-config', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6-headers', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16-3-extra', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16hdri-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickcore-6.q16hdri-3-extra', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickwand-6-headers', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickwand-6.q16-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'libmagickwand-6.q16hdri-3', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}, {'cve_id': 'CVE-2018-14434', 'source': 'description_fix', 'status': 'fixed', 'package': 'perlmagick', 'fixed_version': '8:6.9.7.4+dfsg-16ubuntu6.4', 'affected_version_range': '< 8:6.9.7.4+dfsg-16ubuntu6.4'}]} | 809e95352365aad28d4a86e670b559cfe421a799a6115c09e53035e7a5b6e032 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2018146250000000 | CVE-2018-14625 on Ubuntu 18.04 LTS (bionic) - medium | A flaw was found in the Linux Kernel where an attacker may be able to havean uncontrolled read to kernel-memory from within a vm guest. A racecondition between connect() and close() function may allow an attackerusing the AF_VSOCK protocol to gather a 4 byte information leak or possiblyintercept or corrupt AF_VSOCK messages destined to other clients.
Update Instructions:
Run `sudo pro fix CVE-2018-14625` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
linux-image-4.15.0-44-generic - 4.15.0-44.47
linux-image-4.15.0-44-generic-lpae - 4.15.0-44.47
linux-image-4.15.0-44-lowlatency - 4.15.0-44.47
linux-image-4.15.0-44-snapdragon - 4.15.0-44.47
linux-image-unsigned-4.15.0-44-generic - 4.15.0-44.47
linux-image-unsigned-4.15.0-44-lowlatency - 4.15.0-44.47
No subscription required
linux-image-4.15.0-1031-raspi2 - 4.15.0-1031.33
No subscription required
linux-image-4.15.0-1032-aws - 4.15.0-1032.34
No subscription required
linux-image-4.18.0-14-generic - 4.18.0-14.15~18.04.1
linux-image-4.18.0-14-generic-lpae - 4.18.0-14.15~18.04.1
linux-image-4.18.0-14-lowlatency - 4.18.0-14.15~18.04.1
linux-image-4.18.0-14-snapdragon - 4.18.0-14.15~18.04.1
linux-image-unsigned-4.18.0-14-generic - 4.18.0-14.15~18.04.1
linux-image-unsigned-4.18.0-14-lowlatency - 4.18.0-14.15~18.04.1
No subscription required
linux-image-unsigned-4.15.0-1037-azure - 4.15.0-1037.39
No subscription required
linux-image-unsigned-4.15.0-1027-gcp - 4.15.0-1027.28
No subscription required
linux-image-4.15.0-1029-kvm - 4.15.0-1029.29
No subscription required
linux-image-unsigned-4.15.0-1033-oem - 4.15.0-1033.38
No subscription required
linux-image-unsigned-4.15.0-1008-oracle - 4.15.0-1008.10
No subscription required | Medium | ['CVE-2018-14625'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-14625', 'https://www.cve.org/CVERecord?id=CVE-2018-14625'] | {'cves': '["CVE-2018-14625"]', 'title': 'CVE-2018-14625 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2018-14625", "https://www.cve.org/CVERecord?id=CVE-2018-14625"]', 'description': 'A flaw was found in the Linux Kernel where an attacker may be able to havean uncontrolled read to kernel-memory from within a vm guest. A racecondition between connect() and close() function may allow an attackerusing the AF_VSOCK protocol to gather a 4 byte information leak or possiblyintercept or corrupt AF_VSOCK messages destined to other clients.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2018-14625` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nlinux-image-4.15.0-44-generic - 4.15.0-44.47\nlinux-image-4.15.0-44-generic-lpae - 4.15.0-44.47\nlinux-image-4.15.0-44-lowlatency - 4.15.0-44.47\nlinux-image-4.15.0-44-snapdragon - 4.15.0-44.47\nlinux-image-unsigned-4.15.0-44-generic - 4.15.0-44.47\nlinux-image-unsigned-4.15.0-44-lowlatency - 4.15.0-44.47\nNo subscription required\n\nlinux-image-4.15.0-1031-raspi2 - 4.15.0-1031.33\nNo subscription required\n\nlinux-image-4.15.0-1032-aws - 4.15.0-1032.34\nNo subscription required\n\nlinux-image-4.18.0-14-generic - 4.18.0-14.15~18.04.1\nlinux-image-4.18.0-14-generic-lpae - 4.18.0-14.15~18.04.1\nlinux-image-4.18.0-14-lowlatency - 4.18.0-14.15~18.04.1\nlinux-image-4.18.0-14-snapdragon - 4.18.0-14.15~18.04.1\nlinux-image-unsigned-4.18.0-14-generic - 4.18.0-14.15~18.04.1\nlinux-image-unsigned-4.18.0-14-lowlatency - 4.18.0-14.15~18.04.1\nNo subscription required\n\nlinux-image-unsigned-4.15.0-1037-azure - 4.15.0-1037.39\nNo subscription required\n\nlinux-image-unsigned-4.15.0-1027-gcp - 4.15.0-1027.28\nNo subscription required\n\nlinux-image-4.15.0-1029-kvm - 4.15.0-1029.29\nNo subscription required\n\nlinux-image-unsigned-4.15.0-1033-oem - 4.15.0-1033.38\nNo subscription required\n\nlinux-image-unsigned-4.15.0-1008-oracle - 4.15.0-1008.10\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2018146250000000', 'package_criteria': [{'cve_id': 'CVE-2018-14625', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux', 'fixed_version': '4.15.0-44.47', 'affected_version_range': '< 4.15.0-44.47'}, {'cve_id': 'CVE-2018-14625', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-raspi2', 'fixed_version': '4.15.0-1031.33', 'affected_version_range': '< 4.15.0-1031.33'}, {'cve_id': 'CVE-2018-14625', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-aws', 'fixed_version': '4.15.0-1032.34', 'affected_version_range': '< 4.15.0-1032.34'}, {'cve_id': 'CVE-2018-14625', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-hwe', 'fixed_version': '4.18.0-14.15~18.04.1', 'affected_version_range': '< 4.18.0-14.15~18.04.1'}, {'cve_id': 'CVE-2018-14625', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-azure', 'fixed_version': '4.15.0-1037.39', 'affected_version_range': '< 4.15.0-1037.39'}, {'cve_id': 'CVE-2018-14625', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-gcp', 'fixed_version': '4.15.0-1027.28', 'affected_version_range': '< 4.15.0-1027.28'}, {'cve_id': 'CVE-2018-14625', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-kvm', 'fixed_version': '4.15.0-1029.29', 'affected_version_range': '< 4.15.0-1029.29'}, {'cve_id': 'CVE-2018-14625', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-oem', 'fixed_version': '4.15.0-1033.38', 'affected_version_range': '< 4.15.0-1033.38'}, {'cve_id': 'CVE-2018-14625', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'linux-oracle', 'fixed_version': '4.15.0-1008.10', 'affected_version_range': '< 4.15.0-1008.10'}, {'cve_id': 'CVE-2018-14625', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-44-generic', 'fixed_version': '4.15.0-44.47', 'affected_version_range': '< 4.15.0-44.47'}, {'cve_id': 'CVE-2018-14625', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-44-generic-lpae', 'fixed_version': '4.15.0-44.47', 'affected_version_range': '< 4.15.0-44.47'}, {'cve_id': 'CVE-2018-14625', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-44-lowlatency', 'fixed_version': '4.15.0-44.47', 'affected_version_range': '< 4.15.0-44.47'}, {'cve_id': 'CVE-2018-14625', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-44-snapdragon', 'fixed_version': '4.15.0-44.47', 'affected_version_range': '< 4.15.0-44.47'}, {'cve_id': 'CVE-2018-14625', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-44-generic', 'fixed_version': '4.15.0-44.47', 'affected_version_range': '< 4.15.0-44.47'}, {'cve_id': 'CVE-2018-14625', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-44-lowlatency', 'fixed_version': '4.15.0-44.47', 'affected_version_range': '< 4.15.0-44.47'}, {'cve_id': 'CVE-2018-14625', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-1031-raspi2', 'fixed_version': '4.15.0-1031.33', 'affected_version_range': '< 4.15.0-1031.33'}, {'cve_id': 'CVE-2018-14625', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-1032-aws', 'fixed_version': '4.15.0-1032.34', 'affected_version_range': '< 4.15.0-1032.34'}, {'cve_id': 'CVE-2018-14625', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.18.0-14-generic', 'fixed_version': '4.18.0-14.15~18.04.1', 'affected_version_range': '< 4.18.0-14.15~18.04.1'}, {'cve_id': 'CVE-2018-14625', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.18.0-14-generic-lpae', 'fixed_version': '4.18.0-14.15~18.04.1', 'affected_version_range': '< 4.18.0-14.15~18.04.1'}, {'cve_id': 'CVE-2018-14625', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.18.0-14-lowlatency', 'fixed_version': '4.18.0-14.15~18.04.1', 'affected_version_range': '< 4.18.0-14.15~18.04.1'}, {'cve_id': 'CVE-2018-14625', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.18.0-14-snapdragon', 'fixed_version': '4.18.0-14.15~18.04.1', 'affected_version_range': '< 4.18.0-14.15~18.04.1'}, {'cve_id': 'CVE-2018-14625', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.18.0-14-generic', 'fixed_version': '4.18.0-14.15~18.04.1', 'affected_version_range': '< 4.18.0-14.15~18.04.1'}, {'cve_id': 'CVE-2018-14625', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.18.0-14-lowlatency', 'fixed_version': '4.18.0-14.15~18.04.1', 'affected_version_range': '< 4.18.0-14.15~18.04.1'}, {'cve_id': 'CVE-2018-14625', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-1037-azure', 'fixed_version': '4.15.0-1037.39', 'affected_version_range': '< 4.15.0-1037.39'}, {'cve_id': 'CVE-2018-14625', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-1027-gcp', 'fixed_version': '4.15.0-1027.28', 'affected_version_range': '< 4.15.0-1027.28'}, {'cve_id': 'CVE-2018-14625', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-4.15.0-1029-kvm', 'fixed_version': '4.15.0-1029.29', 'affected_version_range': '< 4.15.0-1029.29'}, {'cve_id': 'CVE-2018-14625', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-1033-oem', 'fixed_version': '4.15.0-1033.38', 'affected_version_range': '< 4.15.0-1033.38'}, {'cve_id': 'CVE-2018-14625', 'source': 'description_fix', 'status': 'fixed', 'package': 'linux-image-unsigned-4.15.0-1008-oracle', 'fixed_version': '4.15.0-1008.10', 'affected_version_range': '< 4.15.0-1008.10'}]} | 5892164d5e394b651b8ab3662e3ed50316da5553b244af5ce7428cc0810a7ae9 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2018146600000000 | CVE-2018-14660 on Ubuntu 18.04 LTS (bionic) - medium | A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 whichallowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticatedattacker could use this flaw to create multiple locks for single inode byusing setxattr repetitively resulting in memory exhaustion of glusterfsserver node.
Update Instructions:
Run `sudo pro fix CVE-2018-14660` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
glusterfs-client - 3.13.2-1ubuntu1+esm1
glusterfs-common - 3.13.2-1ubuntu1+esm1
glusterfs-server - 3.13.2-1ubuntu1+esm1
Available with Ubuntu Pro: https://ubuntu.com/pro | Medium | ['CVE-2018-14660'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-14660', 'https://www.cve.org/CVERecord?id=CVE-2018-14660'] | {'cves': '["CVE-2018-14660"]', 'title': 'CVE-2018-14660 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2018-14660", "https://www.cve.org/CVERecord?id=CVE-2018-14660"]', 'description': 'A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 whichallowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticatedattacker could use this flaw to create multiple locks for single inode byusing setxattr repetitively resulting in memory exhaustion of glusterfsserver node.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2018-14660` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nglusterfs-client - 3.13.2-1ubuntu1+esm1\nglusterfs-common - 3.13.2-1ubuntu1+esm1\nglusterfs-server - 3.13.2-1ubuntu1+esm1\nAvailable with Ubuntu Pro: https://ubuntu.com/pro', 'definition_id': 'oval:com.ubuntu.bionic:def:2018146600000000', 'package_criteria': [{'cve_id': 'CVE-2018-14660', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'glusterfs', 'fixed_version': '3.13.2-1ubuntu1+esm1', 'affected_version_range': '< 3.13.2-1ubuntu1+esm1'}, {'cve_id': 'CVE-2018-14660', 'source': 'description_fix', 'status': 'fixed', 'package': 'glusterfs-client', 'fixed_version': '3.13.2-1ubuntu1+esm1', 'affected_version_range': '< 3.13.2-1ubuntu1+esm1'}, {'cve_id': 'CVE-2018-14660', 'source': 'description_fix', 'status': 'fixed', 'package': 'glusterfs-common', 'fixed_version': '3.13.2-1ubuntu1+esm1', 'affected_version_range': '< 3.13.2-1ubuntu1+esm1'}, {'cve_id': 'CVE-2018-14660', 'source': 'description_fix', 'status': 'fixed', 'package': 'glusterfs-server', 'fixed_version': '3.13.2-1ubuntu1+esm1', 'affected_version_range': '< 3.13.2-1ubuntu1+esm1'}]} | 105444802ea39bf9274f28187b5e82f0876dff5b377c35112c07f78461a9bdbf | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
cve | bionic | oval:com.ubuntu.bionic:def:2018146650000000 | CVE-2018-14665 on Ubuntu 18.04 LTS (bionic) - medium | A flaw was found in xorg-x11-server before 1.20.3. An incorrect permissioncheck for -modulepath and -logfile options when starting Xorg. X serverallows unprivileged users with the ability to log in to the system viaphysical console to escalate their privileges and run arbitrary code underroot privileges.
Update Instructions:
Run `sudo pro fix CVE-2018-14665` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
xdmx - 2:1.19.6-1ubuntu4.2
xdmx-tools - 2:1.19.6-1ubuntu4.2
xmir - 2:1.19.6-1ubuntu4.2
xnest - 2:1.19.6-1ubuntu4.2
xorg-server-source - 2:1.19.6-1ubuntu4.2
xserver-common - 2:1.19.6-1ubuntu4.2
xserver-xephyr - 2:1.19.6-1ubuntu4.2
xserver-xorg-core - 2:1.19.6-1ubuntu4.2
xserver-xorg-legacy - 2:1.19.6-1ubuntu4.2
xserver-xorg-xmir - 2:1.19.6-1ubuntu4.2
xvfb - 2:1.19.6-1ubuntu4.2
xwayland - 2:1.19.6-1ubuntu4.2
No subscription required | Medium | ['CVE-2018-14665'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-14665', 'https://www.cve.org/CVERecord?id=CVE-2018-14665'] | {'cves': '["CVE-2018-14665"]', 'title': 'CVE-2018-14665 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2018-14665", "https://www.cve.org/CVERecord?id=CVE-2018-14665"]', 'description': 'A flaw was found in xorg-x11-server before 1.20.3. An incorrect permissioncheck for -modulepath and -logfile options when starting Xorg. X serverallows unprivileged users with the ability to log in to the system viaphysical console to escalate their privileges and run arbitrary code underroot privileges.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2018-14665` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nxdmx - 2:1.19.6-1ubuntu4.2\nxdmx-tools - 2:1.19.6-1ubuntu4.2\nxmir - 2:1.19.6-1ubuntu4.2\nxnest - 2:1.19.6-1ubuntu4.2\nxorg-server-source - 2:1.19.6-1ubuntu4.2\nxserver-common - 2:1.19.6-1ubuntu4.2\nxserver-xephyr - 2:1.19.6-1ubuntu4.2\nxserver-xorg-core - 2:1.19.6-1ubuntu4.2\nxserver-xorg-legacy - 2:1.19.6-1ubuntu4.2\nxserver-xorg-xmir - 2:1.19.6-1ubuntu4.2\nxvfb - 2:1.19.6-1ubuntu4.2\nxwayland - 2:1.19.6-1ubuntu4.2\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2018146650000000', 'package_criteria': [{'cve_id': 'CVE-2018-14665', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'xorg-server', 'fixed_version': '2:1.19.6-1ubuntu4.2', 'affected_version_range': '< 2:1.19.6-1ubuntu4.2'}, {'cve_id': 'CVE-2018-14665', 'source': 'description_fix', 'status': 'fixed', 'package': 'xdmx', 'fixed_version': '2:1.19.6-1ubuntu4.2', 'affected_version_range': '< 2:1.19.6-1ubuntu4.2'}, {'cve_id': 'CVE-2018-14665', 'source': 'description_fix', 'status': 'fixed', 'package': 'xdmx-tools', 'fixed_version': '2:1.19.6-1ubuntu4.2', 'affected_version_range': '< 2:1.19.6-1ubuntu4.2'}, {'cve_id': 'CVE-2018-14665', 'source': 'description_fix', 'status': 'fixed', 'package': 'xmir', 'fixed_version': '2:1.19.6-1ubuntu4.2', 'affected_version_range': '< 2:1.19.6-1ubuntu4.2'}, {'cve_id': 'CVE-2018-14665', 'source': 'description_fix', 'status': 'fixed', 'package': 'xnest', 'fixed_version': '2:1.19.6-1ubuntu4.2', 'affected_version_range': '< 2:1.19.6-1ubuntu4.2'}, {'cve_id': 'CVE-2018-14665', 'source': 'description_fix', 'status': 'fixed', 'package': 'xorg-server-source', 'fixed_version': '2:1.19.6-1ubuntu4.2', 'affected_version_range': '< 2:1.19.6-1ubuntu4.2'}, {'cve_id': 'CVE-2018-14665', 'source': 'description_fix', 'status': 'fixed', 'package': 'xserver-common', 'fixed_version': '2:1.19.6-1ubuntu4.2', 'affected_version_range': '< 2:1.19.6-1ubuntu4.2'}, {'cve_id': 'CVE-2018-14665', 'source': 'description_fix', 'status': 'fixed', 'package': 'xserver-xephyr', 'fixed_version': '2:1.19.6-1ubuntu4.2', 'affected_version_range': '< 2:1.19.6-1ubuntu4.2'}, {'cve_id': 'CVE-2018-14665', 'source': 'description_fix', 'status': 'fixed', 'package': 'xserver-xorg-core', 'fixed_version': '2:1.19.6-1ubuntu4.2', 'affected_version_range': '< 2:1.19.6-1ubuntu4.2'}, {'cve_id': 'CVE-2018-14665', 'source': 'description_fix', 'status': 'fixed', 'package': 'xserver-xorg-legacy', 'fixed_version': '2:1.19.6-1ubuntu4.2', 'affected_version_range': '< 2:1.19.6-1ubuntu4.2'}, {'cve_id': 'CVE-2018-14665', 'source': 'description_fix', 'status': 'fixed', 'package': 'xserver-xorg-xmir', 'fixed_version': '2:1.19.6-1ubuntu4.2', 'affected_version_range': '< 2:1.19.6-1ubuntu4.2'}, {'cve_id': 'CVE-2018-14665', 'source': 'description_fix', 'status': 'fixed', 'package': 'xvfb', 'fixed_version': '2:1.19.6-1ubuntu4.2', 'affected_version_range': '< 2:1.19.6-1ubuntu4.2'}, {'cve_id': 'CVE-2018-14665', 'source': 'description_fix', 'status': 'fixed', 'package': 'xwayland', 'fixed_version': '2:1.19.6-1ubuntu4.2', 'affected_version_range': '< 2:1.19.6-1ubuntu4.2'}]} | ad28bbecf3f5496277863213afc2083594aa06fc22db6ce957feeb66d40884bf | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
pkg | bluefield_jammy | oval:com.ubuntu.jammy:def:22040101800000 | libde265 | Open H.265 video codec implementation | ['CVE-2021-35452', 'CVE-2021-36408', 'CVE-2021-36409', 'CVE-2021-36410', 'CVE-2021-36411', 'CVE-2022-1253', 'CVE-2022-43235', 'CVE-2022-43236', 'CVE-2022-43237', 'CVE-2022-43238', 'CVE-2022-43239', 'CVE-2022-43240', 'CVE-2022-43241', 'CVE-2022-43242', 'CVE-2022-43243', 'CVE-2022-43244', 'CVE-2022-43245', 'CVE-2022-43248', 'CVE-2022-43249', 'CVE-2022-43250', 'CVE-2022-43252', 'CVE-2022-43253', 'CVE-2022-47665', 'CVE-2023-24751', 'CVE-2023-24752', 'CVE-2023-24754', 'CVE-2023-24755', 'CVE-2023-24756', 'CVE-2023-24757', 'CVE-2023-24758', 'CVE-2023-25221', 'CVE-2023-27102', 'CVE-2023-27103', 'CVE-2023-43887', 'CVE-2023-47471', 'CVE-2023-49465', 'CVE-2023-49467', 'CVE-2023-49468'] | ['Ubuntu Nvidia-BlueField 22.04 LTS'] | ['https://launchpad.net/ubuntu/+source/libde265', 'libde265'] | {'cves': '["CVE-2021-35452", "CVE-2021-36408", "CVE-2021-36409", "CVE-2021-36410", "CVE-2021-36411", "CVE-2022-1253", "CVE-2022-43235", "CVE-2022-43236", "CVE-2022-43237", "CVE-2022-43238", "CVE-2022-43239", "CVE-2022-43240", "CVE-2022-43241", "CVE-2022-43242", "CVE-2022-43243", "CVE-2022-43244", "CVE-2022-43245", "CVE-2022-43248", "CVE-2022-43249", "CVE-2022-43250", "CVE-2022-43252", "CVE-2022-43253", "CVE-2022-47665", "CVE-2023-24751", "CVE-2023-24752", "CVE-2023-24754", "CVE-2023-24755", "CVE-2023-24756", "CVE-2023-24757", "CVE-2023-24758", "CVE-2023-25221", "CVE-2023-27102", "CVE-2023-27103", "CVE-2023-43887", "CVE-2023-47471", "CVE-2023-49465", "CVE-2023-49467", "CVE-2023-49468"]', 'title': 'libde265', 'issued': None, 'release': 'bluefield_jammy', 'updated': None, 'affected': '["Ubuntu Nvidia-BlueField 22.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/libde265", "libde265"]', 'description': 'Open H.265 video codec implementation', 'definition_id': 'oval:com.ubuntu.jammy:def:22040101800000', 'package_criteria': [{'cve_id': 'CVE-2021-35452', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libde265', 'fixed_version': '1.0.8-1ubuntu0.1', 'affected_version_range': '< 1.0.8-1ubuntu0.1'}, {'cve_id': 'CVE-2022-43244', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libde265', 'fixed_version': '1.0.8-1ubuntu0.2', 'affected_version_range': '< 1.0.8-1ubuntu0.2'}, {'cve_id': 'CVE-2023-27102', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libde265', 'fixed_version': '1.0.8-1ubuntu0.3', 'affected_version_range': '< 1.0.8-1ubuntu0.3'}]} | 53c20a58955e734192ac3f32ebb44dc5d5465520de910078a94783b2c854244a | 2026-06-10 19:57:35.403698+03:00 | 2026-06-15 14:52:04.971408+03:00 | |||
pkg | bluefield_jammy | oval:com.ubuntu.jammy:def:22040101900000 | libdnf | libdnf - development files | ['CVE-2021-3445'] | ['Ubuntu Nvidia-BlueField 22.04 LTS'] | ['https://launchpad.net/ubuntu/+source/libdnf', 'libdnf'] | {'cves': '["CVE-2021-3445"]', 'title': 'libdnf', 'issued': None, 'release': 'bluefield_jammy', 'updated': None, 'affected': '["Ubuntu Nvidia-BlueField 22.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/libdnf", "libdnf"]', 'description': 'libdnf - development files', 'definition_id': 'oval:com.ubuntu.jammy:def:22040101900000', 'package_criteria': [{'cve_id': 'CVE-2021-3445', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libdnf', 'fixed_version': '0.55.2-6', 'affected_version_range': '< 0.55.2-6'}]} | 2784bb4e395297b6eefdbf51f38bb4a3771f9e940bf04ec628c62fa8c6d23d18 | 2026-06-10 19:57:35.403698+03:00 | 2026-06-15 14:52:04.971408+03:00 | |||
pkg | bluefield_jammy | oval:com.ubuntu.jammy:def:22040102900000 | libetpan | Mail Framework for C Language | ['CVE-2022-4121'] | ['Ubuntu Nvidia-BlueField 22.04 LTS'] | ['https://launchpad.net/ubuntu/+source/libetpan', 'libetpan'] | {'cves': '["CVE-2022-4121"]', 'title': 'libetpan', 'issued': None, 'release': 'bluefield_jammy', 'updated': None, 'affected': '["Ubuntu Nvidia-BlueField 22.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/libetpan", "libetpan"]', 'description': 'Mail Framework for C Language', 'definition_id': 'oval:com.ubuntu.jammy:def:22040102900000', 'package_criteria': [{'cve_id': 'CVE-2022-4121', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libetpan', 'fixed_version': '1.9.4-3+deb11u1build0.22.04.1', 'affected_version_range': '< 1.9.4-3+deb11u1build0.22.04.1'}]} | 08a862a6632e4587c571fff34133eb6bc2af2a219a34603ef7c68e94c503e3cf | 2026-05-30 01:47:36.483413+03:00 | 2026-06-15 14:52:04.971408+03:00 | |||
pkg | bluefield_jammy | oval:com.ubuntu.jammy:def:22040106800000 | libhtmlcleaner-java | Java HTML Parser library | ['CVE-2023-34624'] | ['Ubuntu Nvidia-BlueField 22.04 LTS'] | ['https://launchpad.net/ubuntu/+source/libhtmlcleaner-java', 'libhtmlcleaner-java'] | {'cves': '["CVE-2023-34624"]', 'title': 'libhtmlcleaner-java', 'issued': None, 'release': 'bluefield_jammy', 'updated': None, 'affected': '["Ubuntu Nvidia-BlueField 22.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/libhtmlcleaner-java", "libhtmlcleaner-java"]', 'description': 'Java HTML Parser library', 'definition_id': 'oval:com.ubuntu.jammy:def:22040106800000', 'package_criteria': [{'cve_id': 'CVE-2023-34624', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libhtmlcleaner-java', 'fixed_version': '2.24-1+deb11u1build0.22.04.1', 'affected_version_range': '< 2.24-1+deb11u1build0.22.04.1'}]} | 3133ddd9f624a6661016548a9ef0f78ea83264ca6c1dc91f3a30c69be0b2fffb | 2026-06-10 19:58:03.235492+03:00 | 2026-06-15 14:52:04.971408+03:00 | |||
pkg | bluefield_jammy | oval:com.ubuntu.jammy:def:22040108800000 | libjettison-java | A Java library for converting XML to JSON and vice-versa | ['CVE-2022-40149', 'CVE-2022-40150', 'CVE-2022-45685', 'CVE-2022-45693'] | ['Ubuntu Nvidia-BlueField 22.04 LTS'] | ['https://launchpad.net/ubuntu/+source/libjettison-java', 'libjettison-java'] | {'cves': '["CVE-2022-40149", "CVE-2022-40150", "CVE-2022-45685", "CVE-2022-45693"]', 'title': 'libjettison-java', 'issued': None, 'release': 'bluefield_jammy', 'updated': None, 'affected': '["Ubuntu Nvidia-BlueField 22.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/libjettison-java", "libjettison-java"]', 'description': 'A Java library for converting XML to JSON and vice-versa', 'definition_id': 'oval:com.ubuntu.jammy:def:22040108800000', 'package_criteria': [{'cve_id': 'CVE-2022-40149', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libjettison-java', 'fixed_version': '1.4.1-1ubuntu0.22.04.1', 'affected_version_range': '< 1.4.1-1ubuntu0.22.04.1'}]} | 952e651fd8f89bfba7e913f685b033768763ad5efcfb64ccfc6b320a4c21b586 | 2026-06-13 04:54:39.290215+03:00 | 2026-06-15 14:52:04.971408+03:00 | |||
pkg | bluefield_jammy | oval:com.ubuntu.jammy:def:22040110100000 | libjson-xs-perl | module for manipulating JSON-formatted data | ['CVE-2025-40928'] | ['Ubuntu Nvidia-BlueField 22.04 LTS'] | ['https://launchpad.net/ubuntu/+source/libjson-xs-perl', 'libjson-xs-perl'] | {'cves': '["CVE-2025-40928"]', 'title': 'libjson-xs-perl', 'issued': None, 'release': 'bluefield_jammy', 'updated': None, 'affected': '["Ubuntu Nvidia-BlueField 22.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/libjson-xs-perl", "libjson-xs-perl"]', 'description': 'module for manipulating JSON-formatted data', 'definition_id': 'oval:com.ubuntu.jammy:def:22040110100000', 'package_criteria': [{'cve_id': 'CVE-2025-40928', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libjson-xs-perl', 'fixed_version': '4.040-0ubuntu0.22.04.1', 'affected_version_range': '< 4.040-0ubuntu0.22.04.1'}]} | f90446c95eddc2e4817b9244bb87dd015f4417d0f0b6ef42bb966808a410786e | 2026-05-30 01:47:36.483413+03:00 | 2026-06-15 14:52:04.971408+03:00 | |||
pkg | bluefield_jammy | oval:com.ubuntu.jammy:def:22040120000000 | libsndfile | Library for reading/writing audio files | ['CVE-2021-3246', 'CVE-2021-4156', 'CVE-2022-33065', 'CVE-2024-50612'] | ['Ubuntu Nvidia-BlueField 22.04 LTS'] | ['https://launchpad.net/ubuntu/+source/libsndfile', 'libsndfile'] | {'cves': '["CVE-2021-3246", "CVE-2021-4156", "CVE-2022-33065", "CVE-2024-50612"]', 'title': 'libsndfile', 'issued': None, 'release': 'bluefield_jammy', 'updated': None, 'affected': '["Ubuntu Nvidia-BlueField 22.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/libsndfile", "libsndfile"]', 'description': 'Library for reading/writing audio files', 'definition_id': 'oval:com.ubuntu.jammy:def:22040120000000', 'package_criteria': [{'cve_id': 'CVE-2021-3246', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libsndfile', 'fixed_version': '1.0.31-1ubuntu2', 'affected_version_range': '< 1.0.31-1ubuntu2'}, {'cve_id': 'CVE-2021-4156', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libsndfile', 'fixed_version': '1.0.31-2ubuntu0.2', 'affected_version_range': '< 1.0.31-2ubuntu0.2'}, {'cve_id': 'CVE-2022-33065', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libsndfile', 'fixed_version': '1.0.31-2ubuntu0.1', 'affected_version_range': '< 1.0.31-2ubuntu0.1'}]} | 12914195e09ec8bb4e97a1cd2f3c97433d8b9d705b28212be83510dcc382ed88 | 2026-06-10 19:57:35.403698+03:00 | 2026-06-15 14:52:04.971408+03:00 | |||
pkg | bluefield_jammy | oval:com.ubuntu.jammy:def:22040124000000 | libuv1 | asynchronous event notification library | ['CVE-2021-22918', 'CVE-2024-24806'] | ['Ubuntu Nvidia-BlueField 22.04 LTS'] | ['https://launchpad.net/ubuntu/+source/libuv1', 'libuv1'] | {'cves': '["CVE-2021-22918", "CVE-2024-24806"]', 'title': 'libuv1', 'issued': None, 'release': 'bluefield_jammy', 'updated': None, 'affected': '["Ubuntu Nvidia-BlueField 22.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/libuv1", "libuv1"]', 'description': 'asynchronous event notification library', 'definition_id': 'oval:com.ubuntu.jammy:def:22040124000000', 'package_criteria': [{'cve_id': 'CVE-2021-22918', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libuv1', 'fixed_version': '1.40.0-2', 'affected_version_range': '< 1.40.0-2'}, {'cve_id': 'CVE-2024-24806', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libuv1', 'fixed_version': '1.43.0-1ubuntu0.1', 'affected_version_range': '< 1.43.0-1ubuntu0.1'}]} | 92ddd7bb311a8db8ca3cbfac8a0eb447500d8da3b9db5d488a3fd7a2b9a41e7e | 2026-05-30 01:47:36.483413+03:00 | 2026-06-15 14:52:04.971408+03:00 | |||
cve | bionic | oval:com.ubuntu.bionic:def:2018156880000000 | CVE-2018-15688 on Ubuntu 18.04 LTS (bionic) - medium | A buffer overflow vulnerability in the dhcp6 client of systemd allows amalicious dhcp6 server to overwrite heap memory in systemd-networkd.Affected releases are systemd: versions up to and including 239.
Update Instructions:
Run `sudo pro fix CVE-2018-15688` to fix the vulnerability. The problem can be corrected
by updating your system to the following package versions:
libnss-myhostname - 237-3ubuntu10.4
libnss-mymachines - 237-3ubuntu10.4
libnss-resolve - 237-3ubuntu10.4
libnss-systemd - 237-3ubuntu10.4
libpam-systemd - 237-3ubuntu10.4
libsystemd0 - 237-3ubuntu10.4
libudev1 - 237-3ubuntu10.4
systemd - 237-3ubuntu10.4
systemd-container - 237-3ubuntu10.4
systemd-coredump - 237-3ubuntu10.4
systemd-journal-remote - 237-3ubuntu10.4
systemd-sysv - 237-3ubuntu10.4
systemd-tests - 237-3ubuntu10.4
udev - 237-3ubuntu10.4
No subscription required
gir1.2-networkmanager-1.0 - 1.10.6-2ubuntu1.1
gir1.2-nm-1.0 - 1.10.6-2ubuntu1.1
libnm-glib-vpn1 - 1.10.6-2ubuntu1.1
libnm-glib4 - 1.10.6-2ubuntu1.1
libnm-util2 - 1.10.6-2ubuntu1.1
libnm0 - 1.10.6-2ubuntu1.1
network-manager - 1.10.6-2ubuntu1.1
network-manager-config-connectivity-debian - 1.10.6-2ubuntu1.1
network-manager-config-connectivity-ubuntu - 1.10.6-2ubuntu1.1
No subscription required | Medium | ['CVE-2018-15688'] | ['Ubuntu 18.04 LTS'] | ['CVE-2018-15688', 'https://www.cve.org/CVERecord?id=CVE-2018-15688'] | {'cves': '["CVE-2018-15688"]', 'title': 'CVE-2018-15688 on Ubuntu 18.04 LTS (bionic) - medium', 'issued': None, 'release': 'bionic', 'updated': None, 'affected': '["Ubuntu 18.04 LTS"]', 'severity': 'Medium', 'oval_type': 'cve', 'references': '["CVE-2018-15688", "https://www.cve.org/CVERecord?id=CVE-2018-15688"]', 'description': 'A buffer overflow vulnerability in the dhcp6 client of systemd allows amalicious dhcp6 server to overwrite heap memory in systemd-networkd.Affected releases are systemd: versions up to and including 239.\n\n Update Instructions:\n\n Run `sudo pro fix CVE-2018-15688` to fix the vulnerability. The problem can be corrected\n by updating your system to the following package versions:\n\nlibnss-myhostname - 237-3ubuntu10.4\nlibnss-mymachines - 237-3ubuntu10.4\nlibnss-resolve - 237-3ubuntu10.4\nlibnss-systemd - 237-3ubuntu10.4\nlibpam-systemd - 237-3ubuntu10.4\nlibsystemd0 - 237-3ubuntu10.4\nlibudev1 - 237-3ubuntu10.4\nsystemd - 237-3ubuntu10.4\nsystemd-container - 237-3ubuntu10.4\nsystemd-coredump - 237-3ubuntu10.4\nsystemd-journal-remote - 237-3ubuntu10.4\nsystemd-sysv - 237-3ubuntu10.4\nsystemd-tests - 237-3ubuntu10.4\nudev - 237-3ubuntu10.4\nNo subscription required\n\ngir1.2-networkmanager-1.0 - 1.10.6-2ubuntu1.1\ngir1.2-nm-1.0 - 1.10.6-2ubuntu1.1\nlibnm-glib-vpn1 - 1.10.6-2ubuntu1.1\nlibnm-glib4 - 1.10.6-2ubuntu1.1\nlibnm-util2 - 1.10.6-2ubuntu1.1\nlibnm0 - 1.10.6-2ubuntu1.1\nnetwork-manager - 1.10.6-2ubuntu1.1\nnetwork-manager-config-connectivity-debian - 1.10.6-2ubuntu1.1\nnetwork-manager-config-connectivity-ubuntu - 1.10.6-2ubuntu1.1\nNo subscription required', 'definition_id': 'oval:com.ubuntu.bionic:def:2018156880000000', 'package_criteria': [{'cve_id': 'CVE-2018-15688', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'systemd', 'fixed_version': '237-3ubuntu10.4', 'affected_version_range': '< 237-3ubuntu10.4'}, {'cve_id': 'CVE-2018-15688', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'network-manager', 'fixed_version': '1.10.6-2ubuntu1.1', 'affected_version_range': '< 1.10.6-2ubuntu1.1'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'libnss-myhostname', 'fixed_version': '237-3ubuntu10.4', 'affected_version_range': '< 237-3ubuntu10.4'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'libnss-mymachines', 'fixed_version': '237-3ubuntu10.4', 'affected_version_range': '< 237-3ubuntu10.4'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'libnss-resolve', 'fixed_version': '237-3ubuntu10.4', 'affected_version_range': '< 237-3ubuntu10.4'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'libnss-systemd', 'fixed_version': '237-3ubuntu10.4', 'affected_version_range': '< 237-3ubuntu10.4'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'libpam-systemd', 'fixed_version': '237-3ubuntu10.4', 'affected_version_range': '< 237-3ubuntu10.4'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'libsystemd0', 'fixed_version': '237-3ubuntu10.4', 'affected_version_range': '< 237-3ubuntu10.4'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'libudev1', 'fixed_version': '237-3ubuntu10.4', 'affected_version_range': '< 237-3ubuntu10.4'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'systemd-container', 'fixed_version': '237-3ubuntu10.4', 'affected_version_range': '< 237-3ubuntu10.4'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'systemd-coredump', 'fixed_version': '237-3ubuntu10.4', 'affected_version_range': '< 237-3ubuntu10.4'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'systemd-journal-remote', 'fixed_version': '237-3ubuntu10.4', 'affected_version_range': '< 237-3ubuntu10.4'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'systemd-sysv', 'fixed_version': '237-3ubuntu10.4', 'affected_version_range': '< 237-3ubuntu10.4'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'systemd-tests', 'fixed_version': '237-3ubuntu10.4', 'affected_version_range': '< 237-3ubuntu10.4'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'udev', 'fixed_version': '237-3ubuntu10.4', 'affected_version_range': '< 237-3ubuntu10.4'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'gir1.2-networkmanager-1.0', 'fixed_version': '1.10.6-2ubuntu1.1', 'affected_version_range': '< 1.10.6-2ubuntu1.1'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'gir1.2-nm-1.0', 'fixed_version': '1.10.6-2ubuntu1.1', 'affected_version_range': '< 1.10.6-2ubuntu1.1'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'libnm-glib-vpn1', 'fixed_version': '1.10.6-2ubuntu1.1', 'affected_version_range': '< 1.10.6-2ubuntu1.1'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'libnm-glib4', 'fixed_version': '1.10.6-2ubuntu1.1', 'affected_version_range': '< 1.10.6-2ubuntu1.1'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'libnm-util2', 'fixed_version': '1.10.6-2ubuntu1.1', 'affected_version_range': '< 1.10.6-2ubuntu1.1'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'libnm0', 'fixed_version': '1.10.6-2ubuntu1.1', 'affected_version_range': '< 1.10.6-2ubuntu1.1'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'network-manager-config-connectivity-debian', 'fixed_version': '1.10.6-2ubuntu1.1', 'affected_version_range': '< 1.10.6-2ubuntu1.1'}, {'cve_id': 'CVE-2018-15688', 'source': 'description_fix', 'status': 'fixed', 'package': 'network-manager-config-connectivity-ubuntu', 'fixed_version': '1.10.6-2ubuntu1.1', 'affected_version_range': '< 1.10.6-2ubuntu1.1'}]} | c2094e95a0bd0eaa6afef76672427a2d050f857b0e37ded8367a18c82800e9f0 | 2026-05-30 01:29:37.443399+03:00 | 2026-06-29 19:45:50.128088+03:00 | ||
pkg | bluefield_jammy | oval:com.ubuntu.jammy:def:22040140200000 | mako | fast and lightweight templating for the Python platform | ['CVE-2022-40023', 'CVE-2026-41205'] | ['Ubuntu Nvidia-BlueField 22.04 LTS'] | ['https://launchpad.net/ubuntu/+source/mako', 'mako'] | {'cves': '["CVE-2022-40023", "CVE-2026-41205"]', 'title': 'mako', 'issued': None, 'release': 'bluefield_jammy', 'updated': None, 'affected': '["Ubuntu Nvidia-BlueField 22.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/mako", "mako"]', 'description': 'fast and lightweight templating for the Python platform', 'definition_id': 'oval:com.ubuntu.jammy:def:22040140200000', 'package_criteria': [{'cve_id': 'CVE-2022-40023', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'mako', 'fixed_version': '1.1.3+ds1-2ubuntu0.1', 'affected_version_range': '< 1.1.3+ds1-2ubuntu0.1'}, {'cve_id': 'CVE-2026-41205', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'mako', 'fixed_version': '1.1.3+ds1-2ubuntu0.2', 'affected_version_range': '< 1.1.3+ds1-2ubuntu0.2'}]} | 0e4d7075d3e82f2c41418e4dd3ca54c46e1c0e193fcda5752c451cdd619d7780 | 2026-06-13 04:54:39.290215+03:00 | 2026-06-15 14:52:04.971408+03:00 | |||
pkg | bluefield_jammy | oval:com.ubuntu.jammy:def:22040141300000 | maradns | A small open-source DNS server | ['CVE-2022-30256', 'CVE-2023-31137'] | ['Ubuntu Nvidia-BlueField 22.04 LTS'] | ['https://launchpad.net/ubuntu/+source/maradns', 'maradns'] | {'cves': '["CVE-2022-30256", "CVE-2023-31137"]', 'title': 'maradns', 'issued': None, 'release': 'bluefield_jammy', 'updated': None, 'affected': '["Ubuntu Nvidia-BlueField 22.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/maradns", "maradns"]', 'description': 'A small open-source DNS server', 'definition_id': 'oval:com.ubuntu.jammy:def:22040141300000', 'package_criteria': [{'cve_id': 'CVE-2022-30256', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'maradns', 'fixed_version': '2.0.13-1.4+deb11u1build0.22.04.1', 'affected_version_range': '< 2.0.13-1.4+deb11u1build0.22.04.1'}]} | a99c94956c6a24f82dc6d0149f2215de6e4a2164a1739451ce4b5902674ce2ff | 2026-05-30 01:47:36.483413+03:00 | 2026-06-15 14:52:04.971408+03:00 | |||
pkg | bluefield_jammy | oval:com.ubuntu.jammy:def:22040141400000 | mariadb-10.6 | MariaDB database | ['CVE-2018-25032', 'CVE-2021-46661', 'CVE-2021-46663', 'CVE-2021-46664', 'CVE-2021-46665', 'CVE-2021-46666', 'CVE-2021-46668', 'CVE-2021-46669', 'CVE-2022-21427', 'CVE-2022-27376', 'CVE-2022-27377', 'CVE-2022-27378', 'CVE-2022-27379', 'CVE-2022-27380', 'CVE-2022-27381', 'CVE-2022-27382', 'CVE-2022-27383', 'CVE-2022-27384', 'CVE-2022-27386', 'CVE-2022-27387', 'CVE-2022-27444', 'CVE-2022-27445', 'CVE-2022-27446', 'CVE-2022-27447', 'CVE-2022-27448', 'CVE-2022-27449', 'CVE-2022-27451', 'CVE-2022-27452', 'CVE-2022-27455', 'CVE-2022-27456', 'CVE-2022-27457', 'CVE-2022-27458', 'CVE-2022-32081', 'CVE-2022-32082', 'CVE-2022-32083', 'CVE-2022-32084', 'CVE-2022-32085', 'CVE-2022-32086', 'CVE-2022-32087', 'CVE-2022-32088', 'CVE-2022-32089', 'CVE-2022-32091', 'CVE-2022-38791', 'CVE-2022-47015', 'CVE-2023-22084', 'CVE-2023-52969', 'CVE-2023-52970', 'CVE-2024-21096', 'CVE-2025-21490', 'CVE-2025-30693', 'CVE-2025-30722'] | ['Ubuntu Nvidia-BlueField 22.04 LTS'] | ['https://launchpad.net/ubuntu/+source/mariadb-10.6', 'mariadb-10.6'] | {'cves': '["CVE-2018-25032", "CVE-2021-46661", "CVE-2021-46663", "CVE-2021-46664", "CVE-2021-46665", "CVE-2021-46666", "CVE-2021-46668", "CVE-2021-46669", "CVE-2022-21427", "CVE-2022-27376", "CVE-2022-27377", "CVE-2022-27378", "CVE-2022-27379", "CVE-2022-27380", "CVE-2022-27381", "CVE-2022-27382", "CVE-2022-27383", "CVE-2022-27384", "CVE-2022-27386", "CVE-2022-27387", "CVE-2022-27444", "CVE-2022-27445", "CVE-2022-27446", "CVE-2022-27447", "CVE-2022-27448", "CVE-2022-27449", "CVE-2022-27451", "CVE-2022-27452", "CVE-2022-27455", "CVE-2022-27456", "CVE-2022-27457", "CVE-2022-27458", "CVE-2022-32081", "CVE-2022-32082", "CVE-2022-32083", "CVE-2022-32084", "CVE-2022-32085", "CVE-2022-32086", "CVE-2022-32087", "CVE-2022-32088", "CVE-2022-32089", "CVE-2022-32091", "CVE-2022-38791", "CVE-2022-47015", "CVE-2023-22084", "CVE-2023-52969", "CVE-2023-52970", "CVE-2024-21096", "CVE-2025-21490", "CVE-2025-30693", "CVE-2025-30722"]', 'title': 'mariadb-10.6', 'issued': None, 'release': 'bluefield_jammy', 'updated': None, 'affected': '["Ubuntu Nvidia-BlueField 22.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/mariadb-10.6", "mariadb-10.6"]', 'description': 'MariaDB database', 'definition_id': 'oval:com.ubuntu.jammy:def:22040141400000', 'package_criteria': [{'cve_id': 'CVE-2018-25032', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'mariadb-10.6', 'fixed_version': '1:10.6.11-0ubuntu0.22.04.1', 'affected_version_range': '< 1:10.6.11-0ubuntu0.22.04.1'}, {'cve_id': 'CVE-2021-46661', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'mariadb-10.6', 'fixed_version': '1:10.6.7-2ubuntu1', 'affected_version_range': '< 1:10.6.7-2ubuntu1'}, {'cve_id': 'CVE-2022-47015', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'mariadb-10.6', 'fixed_version': '1:10.6.16-0ubuntu0.22.04.1', 'affected_version_range': '< 1:10.6.16-0ubuntu0.22.04.1'}, {'cve_id': 'CVE-2023-52969', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'mariadb-10.6', 'fixed_version': '1:10.6.22-0ubuntu0.22.04.1', 'affected_version_range': '< 1:10.6.22-0ubuntu0.22.04.1'}, {'cve_id': 'CVE-2024-21096', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'mariadb-10.6', 'fixed_version': '1:10.6.18-0ubuntu0.22.04.1', 'affected_version_range': '< 1:10.6.18-0ubuntu0.22.04.1'}, {'cve_id': 'CVE-2025-21490', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'mariadb-10.6', 'fixed_version': '1:10.6.21-0ubuntu0.22.04.2', 'affected_version_range': '< 1:10.6.21-0ubuntu0.22.04.2'}]} | 73564e03074f3849a2096116415e1ac369bd4e5864c0431701ecd3ced3e28053 | 2026-06-13 04:54:39.290215+03:00 | 2026-06-15 14:52:04.971408+03:00 | |||
pkg | bluefield_jammy | oval:com.ubuntu.jammy:def:22040148700000 | mozjs91 | SpiderMonkey JavaScript library | ['CVE-2022-28285', 'CVE-2022-31740'] | ['Ubuntu Nvidia-BlueField 22.04 LTS'] | ['https://launchpad.net/ubuntu/+source/mozjs91', 'mozjs91'] | {'cves': '["CVE-2022-28285", "CVE-2022-31740"]', 'title': 'mozjs91', 'issued': None, 'release': 'bluefield_jammy', 'updated': None, 'affected': '["Ubuntu Nvidia-BlueField 22.04 LTS"]', 'severity': None, 'oval_type': 'pkg', 'references': '["https://launchpad.net/ubuntu/+source/mozjs91", "mozjs91"]', 'description': 'SpiderMonkey JavaScript library', 'definition_id': 'oval:com.ubuntu.jammy:def:22040148700000', 'package_criteria': [{'cve_id': 'CVE-2022-28285', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'mozjs91', 'fixed_version': '91.10.0-0ubuntu1', 'affected_version_range': '< 91.10.0-0ubuntu1'}]} | ace3fef66d51ffb1c2016b47d0cb8b817bb3955b851ff527019e515d24a96539 | 2026-06-13 04:54:12.920522+03:00 | 2026-06-15 14:52:04.971408+03:00 |