Candidate: CVE-2014-5191 PublicDate: 2014-08-07 11:13:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5191 http://ckeditor.com/node/136981 http://secunia.com/advisories/60036 Description: Cross-site scripting (XSS) vulnerability in the Preview plugin before 4.4.3 in CKEditor allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_ckeditor: upstream_ckeditor: released (4.4.4+dfsg1-1) lucid_ckeditor: ignored (reached end-of-life) precise_ckeditor: ignored (reached end-of-life) precise/esm_ckeditor: DNE (precise was needs-triage) trusty_ckeditor: ignored (reached end-of-life) trusty/esm_ckeditor: DNE (trusty was needs-triage) utopic_ckeditor: ignored (reached end-of-life) vivid_ckeditor: ignored (reached end-of-life) vivid/stable-phone-overlay_ckeditor: DNE vivid/ubuntu-core_ckeditor: DNE wily_ckeditor: ignored (reached end-of-life) xenial_ckeditor: not-affected (4.5.7+dfsg-2) yakkety_ckeditor: ignored (reached end-of-life) zesty_ckeditor: ignored (reached end-of-life) artful_ckeditor: ignored (reached end-of-life) bionic_ckeditor: not-affected (4.5.7+dfsg-2) cosmic_ckeditor: not-affected (4.5.7+dfsg-2) disco_ckeditor: not-affected (4.5.7+dfsg-2) devel_ckeditor: not-affected (4.5.7+dfsg-2)