← Back

Oxide

oxide

Vendor: Oxide Project • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Oxide Project
1Oxide
Nov 21, 2024
Apr 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.
2Canonical
Oxide Project
2Oxide
Ubuntu Linux
May 13, 2026
Jul 25, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The oxide::JavaScriptDialogManager function in oxide-qt before 1.9.1 as packaged in Ubuntu 15.04 and Ubuntu 14.04 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a c...Show more
The oxide::JavaScriptDialogManager function in oxide-qt before 1.9.1 as packaged in Ubuntu 15.04 and Ubuntu 14.04 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted website.Show less
2Canonical
Oxide Project
2Oxide
Ubuntu Linux
May 6, 2026
May 13, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Use-after-free vulnerability in Oxide allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to responding synchronously to permission requests...Show more
Use-after-free vulnerability in Oxide allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to responding synchronously to permission requests.Show less
2Canonical
Oxide Project
2Oxide
Ubuntu Linux
May 6, 2026
Apr 29, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted webpage.
2Canonical
Oxide Project
2Oxide
Ubuntu Linux
May 6, 2026
Apr 8, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents while a RenderProcessH...Show more
Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents while a RenderProcessHost instance still exists.Show less