Search CVE reports


Toggle filters

1 – 10 of 881 results


CVE-2018-6125

Medium priority

Some fixes available 4 of 5

Insufficient policy enforcement in USB in Google Chrome on Windows prior to 67.0.3396.62 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page.

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser — — — — Fixed
oxide-qt — — — — Not in release
Show less packages

CVE-2018-6122

Medium priority

Some fixes available 4 of 5

Type confusion in WebAssembly in Google Chrome prior to 66.0.3359.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser — — — — Fixed
oxide-qt — — — — Not in release
Show less packages

CVE-2018-6059

Medium priority
Not affected

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11225. Reason: This candidate is a reservation duplicate of CVE-2017-11225. Notes: All CVE users should reference CVE-2017-11225 instead of this candidate....

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser — — — — Not affected
oxide-qt — — — — Not in release
Show less packages

CVE-2018-6058

Medium priority
Not affected

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11215. Reason: This candidate is a reservation duplicate of CVE-2017-11215. Notes: All CVE users should reference CVE-2017-11215 instead of this candidate....

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser — — — — Not affected
oxide-qt — — — — Not in release
Show less packages

CVE-2018-6044

Medium priority
Fixed

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-16064. Reason: This candidate is a reservation duplicate of CVE-2018-16064. Notes: All CVE users should reference CVE-2018-16064 instead of this candidate....

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser — — — — Fixed
oxide-qt — — — — Not in release
Show less packages

CVE-2020-15999

High priority
Fixed

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

18 affected packages

android, chromium-browser, firefox, freetype, godot...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
android — Not in release Not in release Not in release Not in release
chromium-browser — Not affected Not affected Not in release Fixed
firefox — Not affected Not affected Not in release Not affected
freetype — Fixed Fixed Fixed Fixed
godot — Not affected Not affected Not affected Not in release
graphicsmagick — Not affected Not affected Not affected Not affected
musescore — Not in release Not in release Not affected Not affected
openjdk-12 — Not in release Not in release Not in release Not in release
openjdk-13 — Not in release Not in release Not affected Not in release
openjdk-15 — Not in release Not in release Not in release Not in release
openjdk-lts — Not affected Not affected Not affected Not affected
oxide-qt — Not in release Not in release Not in release Not in release
paraview — Not affected Not affected Not affected Not affected
qtbase-opensource-src — Not affected Not affected Not affected Not affected
qtbase-opensource-src-gles — Not affected Not affected Not affected Not in release
texlive-bin — Not affected Not affected Not affected Not affected
texmaker — Not affected Not affected Not affected Not affected
thunderbird — Not affected Not affected Not in release Not affected
Show all 18 packages Show less packages

CVE-2018-6177

Low priority
Fixed

Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser — — — — Fixed
oxide-qt — — — — Not in release
Show less packages

CVE-2018-6176

Medium priority
Fixed

Insufficient file type enforcement in Extensions API in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted Chrome Extension.

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser — — — — Fixed
oxide-qt — — — — Not in release
Show less packages

CVE-2018-6171

Low priority
Fixed

Use after free in Bluetooth in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension.

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser — — — — Fixed
oxide-qt — — — — Not in release
Show less packages

CVE-2018-6168

Low priority
Fixed

Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

2 affected packages

chromium-browser, oxide-qt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser — — — — Fixed
oxide-qt — — — — Not in release
Show less packages