Id:
CVE-2015-1321
Comment
:
Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted webpage.
CVSSv2 Score:
6.8
Access vector:
|
NETWORK
|
Access complexity:
|
MEDIUM
|
Authentication:
|
NONE
|
Confidentiality impact:
|
PARTIAL
|
Integrity impact:
|
PARTIAL
|
Availability impact:
|
PARTIAL
|
CVSSv2 Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P
References: