Lucene search

K
cveCanonicalCVE-2015-1317
HistoryApr 08, 2015 - 6:59 p.m.

CVE-2015-1317

2015-04-0818:59:05
canonical
web.nvd.nist.gov
44
cve-2015-1317
use-after-free vulnerability
oxide
denial of service
remote attackers
arbitrary code execution
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.1

Confidence

High

EPSS

0.018

Percentile

88.0%

Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents while a RenderProcessHost instance still exists.

Affected configurations

Nvd
Node
canonicalubuntu_linuxMatch14.04lts
OR
canonicalubuntu_linuxMatch14.10
Node
oxide_projectoxideRange1.5.5
OR
oxide_projectoxideMatch1.6.0
VendorProductVersionCPE
canonicalubuntu_linux14.04cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
canonicalubuntu_linux14.10cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*
oxide_projectoxide*cpe:2.3:a:oxide_project:oxide:*:*:*:*:*:*:*:*
oxide_projectoxide1.6.0cpe:2.3:a:oxide_project:oxide:1.6.0:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.1

Confidence

High

EPSS

0.018

Percentile

88.0%