4.3
CVE-2015-1236
- EPSS 1.5%
- Veröffentlicht 19.04.2015 10:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy and obtain sensitive audio sample values via a crafted web site containing a media element.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.10
Canonical ≫ Ubuntu Linux Version 15.04
Debian ≫ Debian Linux Version 8.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.5% | 0.716 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
http://lists.opensuse.org/opensuse-updates/2015-11/msg00024.html
https://security.gentoo.org/glsa/201506-04
http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.html
http://lists.opensuse.org/opensuse-updates/2015-04/msg00040.html
http://rhn.redhat.com/errata/RHSA-2015-0816.html
http://www.debian.org/security/2015/dsa-3238
http://www.securitytracker.com/id/1032209
http://ubuntu.com/usn/usn-2570-1
https://code.google.com/p/chromium/issues/detail?id=313939
https://src.chromium.org/viewvc/blink?revision=189527&view=revision