ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-25002
An issue was discovered in the sodiumoxide crate before 0.2.5 for Rust.

An issue was discovered in the sodiumoxide crate before 0.2.5 for Rust. generichash::Digest::eq compares itself to itself and thus has degenerate security properties.

NVD description · AI analysis pending
9.81%
  • sodiumoxide project sodiumoxide
CVE-2016-1586
A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before

A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.

NVD description · AI analysis pending
7.5<1%
  • oxide project oxide
CVE-2017-1000168
sodiumoxide 0.0.13 and older scalarmult() vulnerable to degenerate public keys

sodiumoxide 0.0.13 and older scalarmult() vulnerable to degenerate public keys

NVD description · AI analysis pending
6.51%
  • sodiumoxide project sodiumoxide
CVE-2016-1578
Use-after-free vulnerability in Oxide allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors

Use-after-free vulnerability in Oxide allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to responding synchronously to permission requests.

NVD description · AI analysis pending
9.83%
  • canonical ubuntu linux
  • canonical oxide