CVE-2015-1230
- EPSS 1.73%
- Veröffentlicht 09.03.2015 00:59:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the AudioContext class, which allows remote attackers to cause a denial of service or possibly h...
- EPSS 0.32%
- Veröffentlicht 09.03.2015 00:59:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
net/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allows remote proxy servers to conduct cookie-injection...
CVE-2015-1228
- EPSS 1.07%
- Veröffentlicht 09.03.2015 00:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
The RenderCounter::updateCounter function in core/rendering/RenderCounter.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not force a relayout operation and consequently does not initialize memory for a data structure, which allows r...
CVE-2015-1220
- EPSS 3.07%
- Veröffentlicht 09.03.2015 00:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the GIFImageReader::parseData function in platform/image-decoders/gif/GIFImageReader.cpp in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have uns...
CVE-2015-1219
- EPSS 0.9%
- Veröffentlicht 09.03.2015 00:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the SkMallocPixelRef::NewAllocate function in core/SkMallocPixelRef.cpp in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vect...
CVE-2015-1218
- EPSS 1.07%
- Veröffentlicht 09.03.2015 00:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple use-after-free vulnerabilities in the DOM implementation in Blink, as used in Google Chrome before 41.0.2272.76, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger movement ...
CVE-2015-1217
- EPSS 1.65%
- Veröffentlicht 09.03.2015 00:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The V8LazyEventListener::prepareListenerObject function in bindings/core/v8/V8LazyEventListener.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, does not properly compile listeners, which allows remote attackers to cause...
CVE-2015-1216
- EPSS 1.07%
- Veröffentlicht 09.03.2015 00:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the V8Window::namedPropertyGetterCustom function in bindings/core/v8/custom/V8WindowCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of ser...
CVE-2015-1215
- EPSS 0.97%
- Veröffentlicht 09.03.2015 00:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation.
CVE-2015-1214
- EPSS 0.97%
- Veröffentlicht 09.03.2015 00:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified ...