Oxide Project develops a systems-software platform with a focus on bare-metal hypervisor and infrastructure components; its small but prominent vulnerability footprint reflects the specialized and security-critical role of that codebase. The durable signal centers on memory-safety and input-validation weaknesses characteristic of systems software written in lower-level languages, with observed issues spanning buffer-boundary violations and improper input handling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oxide Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-1578CRITICAL Use-after-free vulnerability in Oxide allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to respond | May 13, 2016 | 9.8 | 29 | NO | NO |
CVE-2015-1332HIGH The oxide::JavaScriptDialogManager function in oxide-qt before 1.9.1 as packaged in Ubuntu 15.04 and Ubuntu 14.04 allows remote attackers to cause a denial of service (application | Jul 25, 2017 | 8.8 | 22 | NO | NO |
CVE-2015-1317HIGH Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deletin | Apr 8, 2015 | 7.5 | 20 | NO | NO |
CVE-2016-1586HIGH A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3. | Apr 22, 2019 | 7.5 | 19 | NO | NO |
CVE-2015-1321MEDIUM Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code | Apr 29, 2015 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oxide Project.
Media articles that mention a CVE ID that affects a product developed by Oxide Project — matched by CVE ID, not by vendor name.