5
CVE-2015-1210
- EPSS 1.99%
- Veröffentlicht 06.02.2015 11:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, does not properly consider frame access restrictions during the throwing of an exception, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.10
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Eus Version 6.6
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Aus Version 6.6
Redhat ≫ Enterprise Linux Workstation Version 6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.99% | 0.78 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.html
http://security.gentoo.org/glsa/glsa-201502-13.xml
http://googlechromereleases.blogspot.com/2015/02/chrome-for-android-update.html
http://googlechromereleases.blogspot.com/2015/02/stable-channel-update.html
http://rhn.redhat.com/errata/RHSA-2015-0163.html
http://secunia.com/advisories/62670
http://secunia.com/advisories/62818
http://secunia.com/advisories/62917
http://secunia.com/advisories/62925
http://www.securityfocus.com/bid/72497
http://www.securitytracker.com/id/1031709
http://www.ubuntu.com/usn/USN-2495-1
https://code.google.com/p/chromium/issues/detail?id=453979
https://exchange.xforce.ibmcloud.com/vulnerabilities/100716
https://src.chromium.org/viewvc/blink?revision=189365&view=revision