CVE-2016-1586

A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:oxide_project:oxide:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:46

Type Values Removed Values Added
References () https://git.launchpad.net/oxide/commit/?id=29014da83e5fc358d6bff0f574e9ed45e61a35ac - Patch, Third Party Advisory () https://git.launchpad.net/oxide/commit/?id=29014da83e5fc358d6bff0f574e9ed45e61a35ac - Patch, Third Party Advisory
CVSS v2 : 5.0
v3 : 7.5
v2 : 5.0
v3 : 1.8

Information

Published : 2019-04-22 16:29

Updated : 2024-11-21 02:46


NVD link : CVE-2016-1586

Mitre link : CVE-2016-1586

CVE.ORG link : CVE-2016-1586


JSON object : View

Products Affected

oxide_project

  • oxide
CWE
CWE-20

Improper Input Validation