Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted webpage.
| Software | From | Fixed in |
|---|---|---|
| canonical / ubuntu_linux | 15.1 | 15.1.x |
| canonical / ubuntu_linux | 14.10 | 14.10.x |
| canonical / ubuntu_linux | 14.04 | 14.04.x |
| oxide_project / oxide | - | 1.6.4.x |