Search CVE reports
151 – 160 of 881 results
Some fixes available 5 of 7
Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted HTML page.
2 affected packages
chromium-browser, oxide-qt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
chromium-browser | — | — | — | Fixed |
oxide-qt | — | — | — | Not in release |
Some fixes available 5 of 7
Use after free in PDFium in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
2 affected packages
chromium-browser, oxide-qt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
chromium-browser | — | — | — | Fixed |
oxide-qt | — | — | — | Not in release |
Some fixes available 3 of 4
A service worker can send the activate event on itself periodically which allows it to run perpetually, allowing it to monitor activity by users. Affects all versions prior to Firefox 60.
2 affected packages
chromium-browser, oxide-qt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
chromium-browser | — | — | — | Fixed |
oxide-qt | — | — | — | Not in release |
FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of array access vulnerability in MXF format demuxer that can result in DoS. This attack appear to be exploitable via specially crafted MXF file which...
7 affected packages
ffmpeg, qtwebengine-opensource-src, gst-libav1.0, kino, vlc...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ffmpeg | Not affected | Not affected | Not affected | Not affected |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
kino | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
vlc | Not affected | Not affected | Not affected | Not affected |
chromium-browser | Ignored | Ignored | Not in release | Ignored |
oxide-qt | Not in release | Not in release | Not in release | Not in release |
FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vulnerability allows attacker to read heap memory. This attack appear to...
5 affected packages
gst-libav1.0, qtwebengine-opensource-src, oxide-qt, chromium-browser, ffmpeg
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
oxide-qt | Not in release | Not in release | Not in release | Not in release |
chromium-browser | Ignored | Ignored | Not in release | Ignored |
ffmpeg | Not affected | Not affected | Not affected | Not affected |
Some fixes available 1 of 60
FFmpeg before commit 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 contains a CWE-835: Infinite loop vulnerability in pva format demuxer that can result in a Vulnerability that allows attackers to consume excessive amount of resources...
8 affected packages
chromium-browser, kino, gst-libav1.0, ffmpeg, qtwebengine-opensource-src...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
chromium-browser | Ignored | Ignored | Not in release | Ignored |
kino | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
ffmpeg | Not affected | Not affected | Not affected | Not affected |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libav | Not in release | Not in release | Not in release | Not in release |
oxide-qt | Not in release | Not in release | Not in release | Not in release |
vlc | Not affected | Not affected | Not affected | Not affected |
FFmpeg before commit 2b46ebdbff1d8dec7a3d8ea280a612b91a582869 contains a Buffer Overflow vulnerability in asf_o format demuxer that can result in heap-buffer-overflow that may result in remote code execution. This attack appears...
6 affected packages
vlc, chromium-browser, ffmpeg, oxide-qt, gst-libav1.0, qtwebengine-opensource-src
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
vlc | Not affected | Not affected | Not affected | Not affected |
chromium-browser | Ignored | Ignored | Not in release | Ignored |
ffmpeg | Not affected | Not affected | Not affected | Not affected |
oxide-qt | Not in release | Not in release | Not in release | Not in release |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Some fixes available 1 of 50
FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can result in attackers accessing out of bound data. This attack appear to be exploitable...
7 affected packages
chromium-browser, ffmpeg, gst-libav1.0, oxide-qt, qtwebengine-opensource-src...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
chromium-browser | Ignored | Ignored | Not in release | Ignored |
ffmpeg | Not affected | Not affected | Not affected | Not affected |
gst-libav1.0 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
oxide-qt | Not in release | Not in release | Not in release | Not in release |
qtwebengine-opensource-src | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
vlc | Not affected | Not affected | Not affected | Not affected |
libav | Not in release | Not in release | Not in release | Not in release |
In libwebm through 2018-10-03, there is an abort caused by libwebm::Webm2Pes::InitWebmParser() that will lead to a DoS attack.
5 affected packages
android, chromium-browser, sludge, libvpx, oxide-qt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
android | Not in release | Not in release | Not in release | Not in release |
chromium-browser | Not affected | Not affected | Not in release | Not affected |
sludge | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libvpx | Not affected | Not affected | Not affected | Not affected |
oxide-qt | Not in release | Not in release | Not in release | Not in release |
Some fixes available 3 of 4
Incorrect dialog placement in Extensions in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of extension popups via a crafted HTML page.
2 affected packages
chromium-browser, oxide-qt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
chromium-browser | — | — | — | Fixed |
oxide-qt | — | — | — | Not in release |