Explore top 10 tips to secure your open-source projects now. Read More
×HtmlUnit could be made to run programs as your login if it opened a malicious website.. ========================================================================== Ubuntu Security Notice USN-8220-1 May 05, 2026 htmlunit vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: HtmlUnit could be made to run programs as your login if it opened a malicious website. Software Description: - htmlunit: headless web browser written in Java Details: It was discovered that HtmlUnit was vulnerable to remote code execution via XSLT when browsing an attacker-controlled webpage. An attacker could possibly use this issue to execute arbitrary code in the context of the application using HtmlUnit. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS libhtmlunit-java 2.8-3ubuntu1+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libhtmlunit-java 2.8-1ubuntu2.1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8220-1 CVE-2023-49093 . HtmlUnit in Ubuntu could execute code as your login when accessing malicious sites. Immediate updates are required.. HtmlUnit Remote Code Execution Ubuntu Security Update. . Severity: Important. LinuxSecurity.com Team
Firefox could be made to crash or run programs as your login if it opened a malicious website.. =========================================================================Ubuntu Security Notice USN-5581-1 August 24, 2022 firefox vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description: - firefox: Mozilla Open Source web browser Details: Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, spoof the contents of the addressbar, bypass security restrictions, or execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: firefox 104.0+build3-0ubuntu0.20.04.1 Ubuntu 18.04 LTS: firefox 104.0+build3-0ubuntu0.18.04.1 After a standard system update you need to restart Firefox to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5581-1 CVE-2022-38472, CVE-2022-38473, CVE-2022-38475, CVE-2022-38477, CVE-2022-38478 Package Information: https://launchpad.net/ubuntu/+source/firefox/104.0+build3-0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/firefox/104.0+build3-0ubuntu0.18.04.1 . Various Chrome vulnerabilities might result in operating system failure or allow rogue applications to run through harmful web pages.. Firefox vulnerabilities, Ubuntu security notice, Mozilla Firefox. . Severity: Important. LinuxSecurity.com Team
Firefox could be made to crash or run programs as your login if it opened a malicious website.. =========================================================================Ubuntu Security Notice USN-5411-1 May 11, 2022 firefox vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description: - firefox: Mozilla Open Source web browser Details: Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, spoof the browser UI, bypass permission prompts, obtain sensitive information, bypass security restrictions, or execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: firefox 100.0+build2-0ubuntu0.21.10.1 Ubuntu 20.04 LTS: firefox 100.0+build2-0ubuntu0.20.04.1 Ubuntu 18.04 LTS: firefox 100.0+build2-0ubuntu0.18.04.1 After a standard system update you need to restart Firefox to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5411-1 CVE-2022-29909, CVE-2022-29911, CVE-2022-29912, CVE-2022-29914, CVE-2022-29915, CVE-2022-29916, CVE-2022-29917, CVE-2022-29918 Package Information: https://launchpad.net/ubuntu/+source/firefox/100.0+build2-0ubuntu0.21.10.1 https://launchpad.net/ubuntu/+source/firefox/100.0+build2-0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/firefox/100.0+build2-0ubuntu0.18.04.1 . Ubuntu Security Notice USN-5411-1 addresses critical security flaws in Firefox that could lead to application crashes or the execution ofmalicious code.. firefox Security, Ubuntu Vulnerabilities, Firefox Crash, Malicious Websites. . Severity: Critical. LinuxSecurity.com Team
Firefox could be made to crash or run programs as your login if it opened a malicious website.. =========================================================================Ubuntu Security Notice USN-5370-1 April 07, 2022 firefox vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description: - firefox: Mozilla Open Source web browser Details: Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, execute script unexpectedly, obtain sensitive information, conduct spoofing attacks, or execute arbitrary code. (CVE-2022-1097, CVE-2022-24713, CVE-2022-28281, CVE-2022-28282, CVE-2022-28284, CVE-2022-28285, CVE-2022-28286, CVE-2022-28288, CVE-2022-28289) A security issue was discovered with the sourceMapURL feature of devtools. An attacker could potentially exploit this to include local files that should have been inaccessible. (CVE-2022-28283) It was discovered that selecting text caused Firefox to crash in some circumstances. An attacker could potentially exploit this to cause a denial of service. (CVE-2022-28287) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: firefox 99.0+build2-0ubuntu0.21.10.2 Ubuntu 20.04 LTS: firefox 99.0+build2-0ubuntu0.20.04.2 Ubuntu 18.04 LTS: firefox 99.0+build2-0ubuntu0.18.04.2 After a standard system update you need to restart Firefox to make all the necessary changes. References: CVE-2022-1097, CVE-2022-24713, CVE-2022-28281, CVE-2022-28282, CVE-2022-28283, CVE-2022-28284, CVE-2022-28285, CVE-2022-28286, CVE-2022-28287, CVE-2022-28288, CVE-2022-28289 Package Information: https://launchpad.net/ubuntu/+source/firefox/99.0+build2-0ubuntu0.21.10.2 https://launchpad.net/ubuntu/+source/firefox/99.0+build2-0ubuntu0.20.04.2 https://launchpad.net/ubuntu/+source/firefox/99.0+build2-0ubuntu0.18.04.2 . Ubuntu's Mozilla Firefox could face risks of crashes and potential execution of harmful code through compromised webpages.. browser exploits, Ubuntu security advisories, Firefox security issues. . LinuxSecurity.com Team
Sergei Glazunov discovered a security issue in Chromium, which could result in the execution of arbitrary code if a malicious website is visited. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5114-1
A security issue was discovered in Chromium, which could result in the execution of arbitrary code if a malicious website is visited. For the stable distribution (bullseye), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5110-1
Firefox could be made to crash or run programs as your login if it opened a malicious website.. =========================================================================Ubuntu Security Notice USN-5284-1 February 14, 2022 firefox vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description: - firefox: Mozilla Open Source web browser Details: Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, bypass security restrictions, obtain sensitive information, or execute arbitrary code. (CVE-2022-0511, CVE-2022-22755, CVE-2022-22759, CVE-2022-22760, CVE-2022-22761, CVE-2022-22764) It was discovered that extensions of a particular type could auto-update themselves and bypass the prompt that requests permissions. If a user were tricked into installing a specially crafted extension, an attacker could potentially exploit this to bypass security restrictions. (CVE-2022-22754) It was discovered that dragging and dropping an image into a folder could result in it being marked as executable. If a user were tricked into dragging and dropping a specially crafted image, an attacker could potentially exploit this to execute arbitrary code. (CVE-2022-22756) It was discovered that Remote Agent, used in WebDriver, did not validate Host or Origin headers. If a user were tricked into opening a specially crafted website with WebDriver enabled, an attacker could potentially exploit this to connect back to the user's browser in order to control it. (CVE-2022-22757) Update instructions: The problem can be corrected by updating your system to the following packageversions: Ubuntu 21.10: firefox 97.0+build2-0ubuntu0.21.10.1 Ubuntu 20.04 LTS: firefox 97.0+build2-0ubuntu0.20.04.1 Ubuntu 18.04 LTS: firefox 97.0+build2-0ubuntu0.18.04.1 After a standard system update you need to restart Firefox to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5284-1 CVE-2022-0511, CVE-2022-22754, CVE-2022-22755, CVE-2022-22756, CVE-2022-22757, CVE-2022-22759, CVE-2022-22760, CVE-2022-22761, CVE-2022-22764 Package Information: https://launchpad.net/ubuntu/+source/firefox/97.0+build2-0ubuntu0.21.10.1 https://launchpad.net/ubuntu/+source/firefox/97.0+build2-0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/firefox/97.0+build2-0ubuntu0.18.04.1 . Uncover the vital security vulnerabilities of Firefox on Ubuntu and find out how to defend against them through prompt updates.. Firefox Security Issues, Ubuntu 21.10 Update, Browser Vulnerabilities, Software Threats. . Severity: Critical. LinuxSecurity.com Team
Firefox could be made to crash or run programs as your login if it opened a malicious website.. =========================================================================Ubuntu Security Notice USN-5131-1 November 03, 2021 firefox vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 21.04 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description: - firefox: Mozilla Open Source web browser Details: Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, bypass security restrictions, spoof the browser UI, confuse the user, conduct phishing attacks, or execute arbitrary code. (CVE-2021-38503, CVE-2021-38504, CVE-2021-38506, CVE-2021-38507, CVE-2021-38508, CVE-2021-38509) It was discovered that the 'Copy Image Link' context menu action would copy the final image URL after redirects. If a user were tricked into copying and pasting a link for an embedded image that triggered authentication flows back to the page, an attacker could potentially exploit this to steal authentication tokens. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: firefox 94.0+build3-0ubuntu0.21.10.1 Ubuntu 21.04: firefox 94.0+build3-0ubuntu0.21.04.1 Ubuntu 20.04 LTS: firefox 94.0+build3-0ubuntu0.20.04.1 Ubuntu 18.04 LTS: firefox 94.0+build3-0ubuntu0.18.04.1 After a standard system update you need to restart Firefox to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5131-1 CVE-2021-38503,CVE-2021-38504, CVE-2021-38506, CVE-2021-38507, CVE-2021-38508, CVE-2021-38509 Package Information: https://launchpad.net/ubuntu/+source/firefox/94.0+build3-0ubuntu0.21.10.1 https://launchpad.net/ubuntu/+source/firefox/94.0+build3-0ubuntu0.21.04.1 https://launchpad.net/ubuntu/+source/firefox/94.0+build3-0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/firefox/94.0+build3-0ubuntu0.18.04.1 . The latest Ubuntu Security Announcement USN-5131-1 highlights security flaws in Firefox which could be leveraged by malicious websites.. Firefox Exploit, Ubuntu Security, Mozilla Issue, Security Update, Denial of Service. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.