CVE-2015-1321

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/04/2015
Last modified:
30/04/2015

Description

Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted webpage.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.1:*:*:*:*:*:*:*
cpe:2.3:a:oxide_project:oxide:*:*:*:*:*:*:*:* 1.6.4 (including)


References to Advisories, Solutions, and Tools