Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents while a RenderProcessHost instance still exists.
| Software | From | Fixed in |
|---|---|---|
| canonical / ubuntu_linux | 14.10 | 14.10.x |
| canonical / ubuntu_linux | 14.04 | 14.04.x |
| oxide_project / oxide | 1.6.0 | 1.6.0.x |
| oxide_project / oxide | - | 1.5.5.x |