Canonical Security Advisories · November 2014 — Canonical Security Advisories
218 advisories 222 CVEs 11 EXPLOITED

Ubuntu Security Notices (USN-NNNN-N) for 2014-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 11 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

UBUNTU-CVE-2014-7910

USNPoC exploitMEDIUM2014-11-19

CVEs:CVE-2014-7910

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Ubuntu:14.04:LTS chromium-browser
oxide-qt affected Ubuntu:14.04:LTS oxide-qt
Upstream advisory

USN-2397-1

USNPoC exploitCRITICAL2014-11-04

ruby1.8, ruby1.9.1, ruby2.0, ruby2.1 vulnerabilities

CVEs:CVE-2014-4975CVE-2014-8080

Affected products

ProductStatusVendorPackageEcosystem
ruby1.9.1 affected ruby
ruby1.9.1 affected Ubuntu:14.04:LTS ruby1.9.1
ruby2.0 affected Ubuntu:14.04:LTS ruby2.0
Upstream advisory

USN-2399-1

USNPoC exploitHIGH2014-11-10

curl vulnerability

CVEs:CVE-2014-3707

Affected products

ProductStatusVendorPackageEcosystem
curl affected Ubuntu
curl affected Ubuntu:14.04:LTS curl
Upstream advisory

UBUNTU-CVE-2014-7825

USNPoC exploit2014-11-10

CVEs:CVE-2014-7825

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:14.04:LTS linux
linux-azure affected Ubuntu:18.04:LTS linux-azure
linux-azure-6.11 affected Ubuntu:24.04:LTS linux-azure-6.11
linux-azure-fde affected Ubuntu:20.04:LTS linux-azure-fde
linux-azure-fde-5.15 affected Ubuntu:Pro:20.04:LTS linux-azure-fde-5.15
linux-gcp affected Ubuntu:18.04:LTS linux-gcp
linux-gcp-6.11 affected Ubuntu:24.04:LTS linux-gcp-6.11
linux-gke affected Ubuntu:20.04:LTS linux-gke
linux-gkeop affected Ubuntu:20.04:LTS linux-gkeop
linux-hwe affected Ubuntu:18.04:LTS linux-hwe
linux-hwe-6.11 affected Ubuntu:24.04:LTS linux-hwe-6.11
linux-hwe-edge affected Ubuntu:18.04:LTS linux-hwe-edge
linux-intel-iot-realtime affected Ubuntu:22.04:LTS linux-intel-iot-realtime
linux-lowlatency-hwe-6.11 affected Ubuntu:24.04:LTS linux-lowlatency-hwe-6.11
linux-lts-utopic affected Ubuntu:14.04:LTS linux-lts-utopic
linux-raspi2 affected Ubuntu:20.04:LTS linux-raspi2
linux-raspi-realtime affected Ubuntu:24.04:LTS linux-raspi-realtime
linux-realtime affected Ubuntu:24.04:LTS linux-realtime
linux-realtime affected Ubuntu:22.04:LTS linux-realtime
linux-riscv affected Ubuntu:24.04:LTS linux-riscv
linux-riscv affected Ubuntu:20.04:LTS linux-riscv
linux-riscv affected Ubuntu:22.04:LTS linux-riscv
Upstream advisory

UBUNTU-CVE-2014-7843

USNPoC exploitMEDIUM2014-11-29

CVEs:CVE-2014-7843

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:14.04:LTS linux
linux-lts-utopic affected Ubuntu:14.04:LTS linux-lts-utopic
Upstream advisory

UBUNTU-CVE-2015-0561

USNEPSS <= 49%MEDIUM2014-11-14

CVEs:CVE-2015-0561

Affected products

ProductStatusVendorPackageEcosystem
wireshark affected Ubuntu:14.04:LTS wireshark
wireshark affected Ubuntu:18.04:LTS wireshark
wireshark affected Ubuntu:16.04:LTS wireshark
Upstream advisory

USN-2412-1

USNEPSS <= 49%CRITICAL2014-11-20

ruby1.8, ruby1.9.1, ruby2.0, ruby2.1 vulnerability

CVEs:CVE-2014-8090

Affected products

ProductStatusVendorPackageEcosystem
ruby1.9.1 affected Ubuntu:14.04:LTS ruby1.9.1
ruby2.0 affected Ubuntu:14.04:LTS ruby2.0
Upstream advisory

USN-2427-1

USNEPSS <= 49%CRITICAL2014-11-27

libksba vulnerability

CVEs:CVE-2014-9087

Affected products

ProductStatusVendorPackageEcosystem
libksba affected Ubuntu:14.04:LTS libksba
Upstream advisory

USN-2398-1

USNEPSS <= 49%CRITICAL2014-11-05

libreoffice vulnerability

CVEs:CVE-2014-3693

Affected products

ProductStatusVendorPackageEcosystem
libreoffice affected Ubuntu:14.04:LTS libreoffice
Upstream advisory

UBUNTU-CVE-2015-2189

USNEPSS <= 49%MEDIUM2014-11-14

CVEs:CVE-2015-2189

Affected products

ProductStatusVendorPackageEcosystem
wireshark affected Ubuntu:14.04:LTS wireshark
wireshark affected Ubuntu:18.04:LTS wireshark
wireshark affected Ubuntu:16.04:LTS wireshark
Upstream advisory

UBUNTU-CVE-2014-4459

USNEPSS <= 49%MEDIUM2014-11-18

CVEs:CVE-2014-4459

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2015-2188

USNEPSS <= 49%MEDIUM2014-11-14

CVEs:CVE-2015-2188

Affected products

ProductStatusVendorPackageEcosystem
wireshark affected Ubuntu:14.04:LTS wireshark
wireshark affected Ubuntu:18.04:LTS wireshark
wireshark affected Ubuntu:16.04:LTS wireshark
Upstream advisory

UBUNTU-CVE-2015-2191

USNEPSS <= 49%LOW2014-11-14

CVEs:CVE-2015-2191

Affected products

ProductStatusVendorPackageEcosystem
wireshark affected Ubuntu:14.04:LTS wireshark
wireshark affected Ubuntu:18.04:LTS wireshark
wireshark affected Ubuntu:16.04:LTS wireshark
Upstream advisory

UBUNTU-CVE-2014-8713

USNEPSS <= 49%MEDIUM2014-11-13

CVEs:CVE-2014-8713

Affected products

ProductStatusVendorPackageEcosystem
wireshark affected Ubuntu:14.04:LTS wireshark
wireshark affected Ubuntu:18.04:LTS wireshark
wireshark affected Ubuntu:16.04:LTS wireshark
Upstream advisory

UBUNTU-CVE-2015-3812

USNEPSS <= 49%LOW2014-11-14

CVEs:CVE-2015-3812

Affected products

ProductStatusVendorPackageEcosystem
wireshark affected Ubuntu:14.04:LTS wireshark
wireshark affected Ubuntu:18.04:LTS wireshark
wireshark affected Ubuntu:16.04:LTS wireshark
Upstream advisory

UBUNTU-CVE-2014-8714

USNEPSS <= 49%MEDIUM2014-11-13

CVEs:CVE-2014-8714

Affected products

ProductStatusVendorPackageEcosystem
wireshark affected Ubuntu:14.04:LTS wireshark
wireshark affected Ubuntu:18.04:LTS wireshark
wireshark affected Ubuntu:16.04:LTS wireshark
Upstream advisory

UBUNTU-CVE-2014-8711

USNEPSS <= 49%MEDIUM2014-11-13

CVEs:CVE-2014-8711

Affected products

ProductStatusVendorPackageEcosystem
wireshark affected Ubuntu:14.04:LTS wireshark
wireshark affected Ubuntu:18.04:LTS wireshark
wireshark affected Ubuntu:16.04:LTS wireshark
Upstream advisory

UBUNTU-CVE-2014-8712

USNEPSS <= 49%MEDIUM2014-11-13

CVEs:CVE-2014-8712

Affected products

ProductStatusVendorPackageEcosystem
wireshark affected Ubuntu:14.04:LTS wireshark
wireshark affected Ubuntu:18.04:LTS wireshark
wireshark affected Ubuntu:16.04:LTS wireshark
Upstream advisory

UBUNTU-CVE-2015-3811

USNEPSS <= 49%LOW2014-11-14

CVEs:CVE-2015-3811

Affected products

ProductStatusVendorPackageEcosystem
wireshark affected Ubuntu:14.04:LTS wireshark
wireshark affected Ubuntu:18.04:LTS wireshark
wireshark affected Ubuntu:16.04:LTS wireshark
Upstream advisory

UBUNTU-CVE-2015-3814

USNEPSS <= 49%LOW2014-11-14

CVEs:CVE-2015-3814

Affected products

ProductStatusVendorPackageEcosystem
wireshark affected Ubuntu:14.04:LTS wireshark
wireshark affected Ubuntu:18.04:LTS wireshark
wireshark affected Ubuntu:16.04:LTS wireshark
Upstream advisory

UBUNTU-CVE-2015-0564

USNEPSS <= 49%MEDIUM2014-11-14

CVEs:CVE-2015-0564

Affected products

ProductStatusVendorPackageEcosystem
wireshark affected Ubuntu:14.04:LTS wireshark
wireshark affected Ubuntu:18.04:LTS wireshark
wireshark affected Ubuntu:16.04:LTS wireshark
Upstream advisory

UBUNTU-CVE-2015-0562

USNEPSS <= 49%MEDIUM2014-11-14

CVEs:CVE-2015-0562

Affected products

ProductStatusVendorPackageEcosystem
wireshark affected Ubuntu:14.04:LTS wireshark
wireshark affected Ubuntu:18.04:LTS wireshark
wireshark affected Ubuntu:16.04:LTS wireshark
Upstream advisory

UBUNTU-CVE-2015-0563

USNEPSS <= 49%MEDIUM2014-11-14

CVEs:CVE-2015-0563

Affected products

ProductStatusVendorPackageEcosystem
wireshark affected Ubuntu:14.04:LTS wireshark
wireshark affected Ubuntu:18.04:LTS wireshark
wireshark affected Ubuntu:16.04:LTS wireshark
Upstream advisory

UBUNTU-CVE-2014-7904

USNEPSS <= 49%MEDIUM2014-11-19

CVEs:CVE-2014-7904

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Ubuntu:14.04:LTS chromium-browser
oxide-qt affected Ubuntu:14.04:LTS oxide-qt
Upstream advisory

UBUNTU-CVE-2014-7909

USNEPSS <= 49%MEDIUM2014-11-19

CVEs:CVE-2014-7909

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Ubuntu:14.04:LTS chromium-browser
oxide-qt affected Ubuntu:14.04:LTS oxide-qt
Upstream advisory

UBUNTU-CVE-2014-7907

USNEPSS <= 49%MEDIUM2014-11-19

CVEs:CVE-2014-7907

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Ubuntu:14.04:LTS chromium-browser
oxide-qt affected Ubuntu:14.04:LTS oxide-qt
Upstream advisory

UBUNTU-CVE-2014-7908

USNEPSS <= 49%MEDIUM2014-11-19

CVEs:CVE-2014-7908

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Ubuntu:14.04:LTS chromium-browser
oxide-qt affected Ubuntu:14.04:LTS oxide-qt
Upstream advisory

UBUNTU-CVE-2015-0559

USNEPSS <= 49%MEDIUM2014-11-14

CVEs:CVE-2015-0559

Affected products

ProductStatusVendorPackageEcosystem
wireshark affected Ubuntu:14.04:LTS wireshark
wireshark affected Ubuntu:18.04:LTS wireshark
wireshark affected Ubuntu:16.04:LTS wireshark
Upstream advisory

UBUNTU-CVE-2015-0560

USNEPSS <= 49%MEDIUM2014-11-14

CVEs:CVE-2015-0560

Affected products

ProductStatusVendorPackageEcosystem
wireshark affected Ubuntu:14.04:LTS wireshark
wireshark affected Ubuntu:18.04:LTS wireshark
wireshark affected Ubuntu:16.04:LTS wireshark
Upstream advisory

USN-2413-1

USNEPSS <= 49%CRITICAL2014-11-20

apparmor vulnerability

CVEs:CVE-2014-1424

Affected products

ProductStatusVendorPackageEcosystem
apparmor affected Ubuntu:14.04:LTS apparmor
apparmor affected Ubuntu
Upstream advisory

UBUNTU-CVE-2014-4462

USNEPSS <= 49%LOW2014-11-18

CVEs:CVE-2014-4462

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2014-4452

USNEPSS <= 49%MEDIUM2014-11-18

CVEs:CVE-2014-4452

Affected products

ProductStatusVendorPackageEcosystem
qtwebkit-opensource-src affected Ubuntu:16.04:LTS qtwebkit-opensource-src
qtwebkit-source affected Ubuntu:16.04:LTS qtwebkit-source
Upstream advisory

UBUNTU-CVE-2014-4883

USNEPSS <= 49%MEDIUM2014-11-28

CVEs:CVE-2014-4883

Affected products

ProductStatusVendorPackageEcosystem
lwipv6 affected Ubuntu:16.04:LTS lwipv6
lwipv6 affected Ubuntu:22.04:LTS lwipv6
lwipv6 affected Ubuntu:18.04:LTS lwipv6
lwipv6 affected Ubuntu:24.04:LTS lwipv6
lwipv6 affected Ubuntu:20.04:LTS lwipv6
lwipv6 affected Ubuntu:25.10 lwipv6
Upstream advisory

UBUNTU-CVE-2014-8989

USNEPSS <= 49%MEDIUM2014-11-29

CVEs:CVE-2014-8989

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:14.04:LTS linux
linux-azure affected Ubuntu:18.04:LTS linux-azure
linux-azure-6.11 affected Ubuntu:24.04:LTS linux-azure-6.11
linux-azure-fde affected Ubuntu:20.04:LTS linux-azure-fde
linux-azure-fde-5.15 affected Ubuntu:Pro:20.04:LTS linux-azure-fde-5.15
linux-gcp affected Ubuntu:18.04:LTS linux-gcp
linux-gcp-6.11 affected Ubuntu:24.04:LTS linux-gcp-6.11
linux-gke affected Ubuntu:20.04:LTS linux-gke
linux-gkeop affected Ubuntu:20.04:LTS linux-gkeop
linux-hwe affected Ubuntu:18.04:LTS linux-hwe
linux-hwe-6.11 affected Ubuntu:24.04:LTS linux-hwe-6.11
linux-hwe-edge affected Ubuntu:18.04:LTS linux-hwe-edge
linux-intel-iot-realtime affected Ubuntu:22.04:LTS linux-intel-iot-realtime
linux-lowlatency-hwe-6.11 affected Ubuntu:24.04:LTS linux-lowlatency-hwe-6.11
linux-lts-utopic affected Ubuntu:14.04:LTS linux-lts-utopic
linux-raspi2 affected Ubuntu:20.04:LTS linux-raspi2
linux-raspi-realtime affected Ubuntu:24.04:LTS linux-raspi-realtime
linux-realtime affected Ubuntu:22.04:LTS linux-realtime
linux-realtime affected Ubuntu:24.04:LTS linux-realtime
linux-riscv affected Ubuntu:24.04:LTS linux-riscv
linux-riscv affected Ubuntu:22.04:LTS linux-riscv
linux-riscv affected Ubuntu:20.04:LTS linux-riscv
Upstream advisory

UBUNTU-CVE-2014-7207

USNEPSS <= 49%MEDIUM2014-11-03

CVEs:CVE-2014-7207

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:14.04:LTS linux
linux-lts-utopic affected Ubuntu:14.04:LTS linux-lts-utopic
linux-lts-vivid affected Ubuntu:14.04:LTS linux-lts-vivid
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.