Lucene search

K
ubuntuUbuntuUSN-2410-1
HistoryNov 19, 2014 - 12:00 a.m.

Oxide vulnerabilities

2014-11-1900:00:00
ubuntu.com
43

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

High

EPSS

0.03

Percentile

90.9%

Releases

  • Ubuntu 14.10
  • Ubuntu 14.04 ESM

Packages

  • oxide-qt - Web browser engine library for Qt (QML plugin)

Details

A buffer overflow was discovered in Skia. If a user were tricked in to
opening a specially crafted website, an attacked could potentially exploit
this to cause a denial of service via renderer crash or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-7904)

Multiple use-after-frees were discovered in Blink. If a user were tricked
in to opening a specially crafted website, an attacked could potentially
exploit these to cause a denial of service via renderer crash or execute
arbitrary code with the privileges of the sandboxed render process.
(CVE-2014-7907)

An integer overflow was discovered in media. If a user were tricked in to
opening a specially crafted website, an attacked could potentially exploit
this to cause a denial of service via renderer crash or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-7908)

An uninitialized memory read was discovered in Skia. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via renderer crash.
(CVE-2014-7909)

Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash or execute arbitrary code with the
privileges of the user invoking the program. (CVE-2014-7910)

OSVersionArchitecturePackageVersionFilename
Ubuntu14.10noarchliboxideqtcore0< 1.3.4-0ubuntu0.14.10.1UNKNOWN
Ubuntu14.10noarchliboxideqt-qmlplugin< 1.3.4-0ubuntu0.14.10.1UNKNOWN
Ubuntu14.10noarchliboxideqtquick0< 1.3.4-0ubuntu0.14.10.1UNKNOWN
Ubuntu14.10noarchoxideqmlscene< 1.3.4-0ubuntu0.14.10.1UNKNOWN
Ubuntu14.10noarchoxideqt-chromedriver< 1.3.4-0ubuntu0.14.10.1UNKNOWN
Ubuntu14.10noarchoxideqt-codecs< 1.3.4-0ubuntu0.14.10.1UNKNOWN
Ubuntu14.10noarchoxideqt-codecs-dbg< 1.3.4-0ubuntu0.14.10.1UNKNOWN
Ubuntu14.10noarchoxideqt-codecs-extra< 1.3.4-0ubuntu0.14.10.1UNKNOWN
Ubuntu14.10noarchoxideqt-codecs-extra-dbg< 1.3.4-0ubuntu0.14.10.1UNKNOWN
Ubuntu14.10noarchoxideqt-dbg< 1.3.4-0ubuntu0.14.10.1UNKNOWN
Rows per page:
1-10 of 201

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

High

EPSS

0.03

Percentile

90.9%