Search CVE reports


Toggle filters

631 – 640 of 881 results


CVE-2015-6762

Medium priority

Some fixes available 6 of 7

The CSSFontFaceSrcValue::fetch function in core/css/CSSFontFaceSrcValue.cpp in the Cascading Style Sheets (CSS) implementation in Blink, as used in Google Chrome before 46.0.2490.71, does not use the CORS cross-origin request...

2 affected packages

chromium-browser, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
oxide-qt
Show less packages

CVE-2015-6761

Low priority

Some fixes available 17 of 20

The update_dimensions function in libavcodec/vp8.c in FFmpeg through 2.8.1, as used in Google Chrome before 46.0.2490.71 and other products, relies on a coefficient-partition count during multi-threaded operation, which...

4 affected packages

chromium-browser, ffmpeg, libav, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
ffmpeg Not affected
libav Not in release
oxide-qt Not in release
Show less packages

CVE-2015-6759

Medium priority

Some fixes available 6 of 7

The shouldTreatAsUniqueOrigin function in platform/weborigin/SecurityOrigin.cpp in Blink, as used in Google Chrome before 46.0.2490.71, does not ensure that the origin of a LocalStorage resource is considered unique, which allows...

2 affected packages

chromium-browser, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
oxide-qt
Show less packages

CVE-2015-6757

Medium priority

Some fixes available 6 of 7

Use-after-free vulnerability in content/browser/service_worker/embedded_worker_instance.cc in the ServiceWorker implementation in Google Chrome before 46.0.2490.71 allows remote attackers to cause a denial of service or possibly...

2 affected packages

chromium-browser, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
oxide-qt
Show less packages

CVE-2015-6755

Medium priority

Some fixes available 6 of 7

The ContainerNode::parserInsertBefore function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 46.0.2490.71, proceeds with a DOM tree insertion in certain cases where a parent node no longer contains a...

2 affected packages

chromium-browser, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
oxide-qt
Show less packages

CVE-2015-1304

Medium priority

Some fixes available 16 of 26

object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, which allows remote attackers to bypass the Same Origin Policy via a (1) observe or...

4 affected packages

chromium-browser, libv8, libv8-3.14, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
libv8 Not in release
libv8-3.14 Ignored
oxide-qt Not in release
Show less packages

CVE-2015-1303

Medium priority

Some fixes available 6 of 7

bindings/core/v8/V8DOMWrapper.h in Blink, as used in Google Chrome before 45.0.2454.101, does not perform a rethrow action to propagate information about a cross-context exception, which allows remote attackers to bypass the Same...

2 affected packages

chromium-browser, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
oxide-qt
Show less packages

CVE-2015-1332

Medium priority
Fixed

The oxide::JavaScriptDialogManager function in oxide-qt before 1.9.1 as packaged in Ubuntu 15.04 and Ubuntu 14.04 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted website.

1 affected package

oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
oxide-qt
Show less packages

CVE-2015-6583

Medium priority

Some fixes available 3 of 4

Google Chrome before 45.0.2454.85 does not display a location bar for a hosted app's window after navigation away from the installation site, which might make it easier for remote attackers to spoof content via a crafted app,...

2 affected packages

oxide-qt, chromium-browser

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
oxide-qt
chromium-browser
Show less packages

CVE-2015-6582

Medium priority

Some fixes available 6 of 7

The decompose function in platform/transforms/TransformationMatrix.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not verify that a matrix inversion succeeded, which allows remote attackers to cause a denial of...

2 affected packages

chromium-browser, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
oxide-qt
Show less packages