4.3

CVE-2015-1236

The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy and obtain sensitive audio sample values via a crafted web site containing a media element.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Chrome Version <= 42.0.2311.60
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.10
Canonical ≫ Ubuntu Linux Version 15.04
Debian ≫ Debian Linux Version 8.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.5% 0.716
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.opensuse.org/opensuse-updates/2015-11/msg00024.html
https://security.gentoo.org/glsa/201506-04
http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.html
http://lists.opensuse.org/opensuse-updates/2015-04/msg00040.html
http://rhn.redhat.com/errata/RHSA-2015-0816.html
http://www.debian.org/security/2015/dsa-3238
http://www.securitytracker.com/id/1032209
http://ubuntu.com/usn/usn-2570-1
https://code.google.com/p/chromium/issues/detail?id=313939
https://src.chromium.org/viewvc/blink?revision=189527&view=revision