USN-2652-1

Advisory lineage Upstream: 8 Downstream: 0
Published: 30 Jun 2015, 11:28
Last modified:04 Feb 2026, 03:35

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Jun 2015, 11:28
Published
Vulnerability first disclosed
04 Feb 2026, 03:35
Last Modified
Vulnerability information updated

Description

oxide-qt vulnerabilities It was discovered that Chromium did not properly consider the scheme when determining whether a URL is associated with a WebUI SiteInstance. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to bypass security restrictions. (CVE-2015-1266) It was discovered that Blink did not properly restrict the creation context during creation of a DOM wrapper. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to bypass same-origin restrictions. (CVE-2015-1267, CVE-2015-1268) It was discovered that Chromium did not properly canonicalize DNS hostnames before comparing to HSTS or HPKP preload entries. An attacker could potentially exploit this to bypass intended access restrictions. (CVE-2015-1269)

Affected Systems

  • ubuntuoxide-qt

    < 1.7.9-0ubuntu0.14.04.1

References (5)