CVE-2016-1586
published 2019-04-22CVE-2016-1586: A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before…
PriorityP335high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
0.66%
48.2th percentile
A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oxide_project | oxide | < 1.18.3 | 1.18.3 |
| ubuntu | oxide | >= unspecified < 1.18.3 | 1.18.3 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_ubuntu1.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3pf3-mgqq-qmjj: A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxi
ghsa_unreviewed·2022-05-24
CVE-2016-1586 [HIGH] CWE-20 GHSA-3pf3-mgqq-qmjj: A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxi
A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.
OSV
oxide-qt vulnerabilities
osv·2016-11-02·CVSS 7.5
CVE-2016-1586 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
It was discovered that a long running unload handler could cause an
incognito profile to be reused in some circumstances. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to obtain sensitive information. (CVE-2016-1586)
Multiple security vulnerabilities were discovered in Chromium. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit these to conduct cross-site scripting (XSS) attacks,
spoof an application's URL bar, obtain sensitive information, cause a
denial of service via application crash, or execute arbitrary code.
(CVE-2016-5181, CVE-2016-5182, CVE-2016-5185, CVE-2016-5186,
CVE-2016-5187, CVE-2016-5188, CVE-2016-5189, CVE-2016-5192, CVE-2016-5194)
OSV
CVE-2016-1586: A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxi
osv·2016-11-02·CVSS 7.5
CVE-2016-1586 [HIGH] CVE-2016-1586: A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxi
A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2016-11-02·CVSS 1.8
CVE-2016-1586 [LOW] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
It was discovered that a long running unload handler could cause an
incognito profile to be reused in some circumstances. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to obtain sensitive information. (CVE-2016-1586)
Multiple security vulnerabilities were discovered in Chromium. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit these to conduct cross-site scripting (XSS) attacks,
spoof an application's URL bar, obtain sensitive information, cause a
denial of service via application crash, or execute arbitrary code.
(CVE-2016-5181, CVE-2016-5182, CVE-2016-5185, CVE-2016-5186,
CVE-2016-5187,
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-0734 activemq: Clickjacking in Web Console
bugzilla·2016-03-14·CVSS 6.1
CVE-2016-0734 [MEDIUM] CVE-2016-0734 activemq: Clickjacking in Web Console
CVE-2016-0734 activemq: Clickjacking in Web Console
It was reported that the web based administration console does not set the X-Frame-Options header in HTTP responses. This allows the console to be embedded in a frame or iframe which could then be used to cause a user to perform an unintended action in the console.
Affected versions: Apache ActiveMQ 5.0.0 - 5.13.1
External Reference:
http://activemq.apache.org/security-advisories.data/CVE-2016-0734-announcement.txt
Discussion:
Created activemq tracking bugs for this issue:
Affects: fedora-all [bug 1317522]
---
https://issues.jboss.org/browse/ENTMQ-1586 was opened to track
---
This issue has been addressed in the following products:
JBoss Fuse 6.2.1
JBoss A-MQ 6.2.1
Via RHSA-2016:1424 https://access.redhat.com/errata/RHSA-2016
Bugzilla
CVE-2016-0782 activemq: Cross-site scripting vulnerabilities in web console
bugzilla·2016-03-14·CVSS 5.4
CVE-2016-0782 [MEDIUM] CVE-2016-0782 activemq: Cross-site scripting vulnerabilities in web console
CVE-2016-0782 activemq: Cross-site scripting vulnerabilities in web console
Several instances of cross-site scripting vulnerabilities were identified to be present in the web based administration console as well as the ability to trigger a Java memory dump into an arbitrary folder. The root cause of these issues are improper user data output validation and incorrect permissions configured on Jolokia.
Affected versions: ActiveMQ 5.0.0 - 5.13.1
External Reference:
http://activemq.apache.org/security-advisories.data/CVE-2016-0782-announcement.txt
Discussion:
Created activemq tracking bugs for this issue:
Affects: fedora-all [bug 1317522]
---
https://issues.jboss.org/browse/ENTMQ-1586 was opened to track
---
This issue has been addressed in the following products:
JBoss Fuse 6.2.1
2019-04-22
Published