Vulnerabilities (CVE)

Filtered by vendor Oxide Project Subscribe
Filtered by product Oxide
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-1586 1 Oxide Project 1 Oxide 2023-12-10 5.0 MEDIUM 7.5 HIGH
A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.
CVE-2015-1332 2 Canonical, Oxide Project 2 Ubuntu Linux, Oxide 2023-12-10 6.8 MEDIUM 8.8 HIGH
The oxide::JavaScriptDialogManager function in oxide-qt before 1.9.1 as packaged in Ubuntu 15.04 and Ubuntu 14.04 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted website.
CVE-2016-1578 2 Canonical, Oxide Project 2 Ubuntu Linux, Oxide 2023-12-10 7.5 HIGH 9.8 CRITICAL
Use-after-free vulnerability in Oxide allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to responding synchronously to permission requests.
CVE-2015-1317 2 Canonical, Oxide Project 2 Ubuntu Linux, Oxide 2023-12-10 7.5 HIGH N/A
Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents while a RenderProcessHost instance still exists.
CVE-2015-1321 2 Canonical, Oxide Project 2 Ubuntu Linux, Oxide 2023-12-10 6.8 MEDIUM N/A
Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted webpage.