Search CVE reports


Toggle filters

21 – 30 of 100 results


CVE-2017-5088

Medium priority

Some fixes available 7 of 17

Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 59.0.3071.117 for Android, allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.

3 affected packages

chromium-browser, libv8-3.14, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
libv8-3.14 Ignored
oxide-qt Not in release
Show less packages

CVE-2017-5071

Low priority

Some fixes available 7 of 17

Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows and Mac, and 59.0.3071.92 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

4 affected packages

chromium-browser, libv8, libv8-3.14, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
libv8 Not in release
libv8-3.14 Ignored
oxide-qt Not in release
Show less packages

CVE-2017-5070

Medium priority

Some fixes available 7 of 17

Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

4 affected packages

chromium-browser, libv8, libv8-3.14, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
libv8 Not in release
libv8-3.14 Ignored
oxide-qt Not in release
Show less packages

CVE-2017-5054

Medium priority

Some fixes available 7 of 19

An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to obtain heap memory contents via a crafted HTML page.

4 affected packages

chromium-browser, libv8, libv8-3.14, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
libv8 Not in release
libv8-3.14 Ignored
oxide-qt Not in release
Show less packages

CVE-2017-5053

Medium priority

Some fixes available 7 of 19

An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related...

4 affected packages

chromium-browser, libv8, libv8-3.14, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
libv8 Not in release
libv8-3.14 Ignored
oxide-qt Not in release
Show less packages

CVE-2017-5040

Medium priority

Some fixes available 12 of 20

V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android was missing a neutering check, which allowed a remote attacker to read values in memory via a crafted HTML page.

4 affected packages

chromium-browser, libv8, libv8-3.14, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
libv8 Not in release
libv8-3.14 Ignored
oxide-qt Not in release
Show less packages

CVE-2017-5030

Medium priority

Some fixes available 12 of 20

Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page.

4 affected packages

chromium-browser, libv8, libv8-3.14, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
libv8 Not in release
libv8-3.14 Ignored
oxide-qt Not in release
Show less packages

CVE-2017-5012

Medium priority

Some fixes available 12 of 20

A heap buffer overflow in V8 in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

4 affected packages

chromium-browser, libv8, libv8-3.14, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
libv8 Not in release
libv8-3.14 Ignored
oxide-qt Not in release
Show less packages

CVE-2016-9651

Medium priority

Some fixes available 12 of 20

A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

4 affected packages

chromium-browser, libv8, libv8-3.14, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
libv8 Not in release
libv8-3.14 Ignored
oxide-qt Not in release
Show less packages

CVE-2016-5219

Medium priority

Some fixes available 12 of 20

A heap use after free in V8 in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

4 affected packages

chromium-browser, libv8, libv8-3.14, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Fixed
libv8 Not in release
libv8-3.14 Ignored
oxide-qt Not in release
Show less packages