{"id":"UBUNTU-CVE-2014-1869","details":"Multiple cross-site scripting (XSS) vulnerabilities in ZeroClipboard.swf in ZeroClipboard before 1.3.2, as maintained by Jon Rohan and James M. Greene, allow remote attackers to inject arbitrary web script or HTML via vectors related to certain SWF query parameters (aka loaderInfo.parameters).","modified":"2026-04-22T09:36:19.365959Z","published":"2014-02-08T00:55:00Z","upstream":["CVE-2014-1869"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-1869"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2014-1869"}],"affected":[{"package":{"name":"db4o","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/db4o@8.0.184.15484+dfsg2-3?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["8.0.184.15484+dfsg-2","8.0.184.15484+dfsg2-1","8.0.184.15484+dfsg2-2","8.0.184.15484+dfsg2-3"],"ecosystem_specific":{"binaries":[{"binary_name":"db4otool","binary_version":"8.0.184.15484+dfsg2-3"},{"binary_name":"libdb4o8.0-cil","binary_version":"8.0.184.15484+dfsg2-3"},{"binary_name":"monodoc-db4o-manual","binary_version":"8.0.184.15484+dfsg2-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-1869.json"}},{"package":{"name":"db4o","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/db4o@8.0.184.15484+dfsg2-3?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["8.0.184.15484+dfsg2-3"],"ecosystem_specific":{"binaries":[{"binary_name":"db4otool","binary_version":"8.0.184.15484+dfsg2-3"},{"binary_name":"libdb4o8.0-cil","binary_version":"8.0.184.15484+dfsg2-3"},{"binary_name":"monodoc-db4o-manual","binary_version":"8.0.184.15484+dfsg2-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-1869.json"}},{"package":{"name":"db4o","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/db4o@8.0.184.15484+dfsg2-3?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["8.0.184.15484+dfsg2-3"],"ecosystem_specific":{"binaries":[{"binary_name":"db4otool","binary_version":"8.0.184.15484+dfsg2-3"},{"binary_name":"libdb4o8.0-cil","binary_version":"8.0.184.15484+dfsg2-3"},{"binary_name":"monodoc-db4o-manual","binary_version":"8.0.184.15484+dfsg2-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-1869.json"}},{"package":{"name":"db4o","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/db4o@8.0.184.15484+dfsg2-3.1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["8.0.184.15484+dfsg2-3.1"],"ecosystem_specific":{"binaries":[{"binary_name":"db4otool","binary_version":"8.0.184.15484+dfsg2-3.1"},{"binary_name":"libdb4o8.0-cil","binary_version":"8.0.184.15484+dfsg2-3.1"},{"binary_name":"monodoc-db4o-manual","binary_version":"8.0.184.15484+dfsg2-3.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-1869.json"}}],"schema_version":"1.7.5","severity":[{"type":"Ubuntu","score":"negligible"}]}