CVE-2015-1249
- EPSS 1.5%
- Veröffentlicht 19.04.2015 10:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.90 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
- EPSS 1.11%
- Veröffentlicht 19.04.2015 10:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for remote attackers to obtain sen...
CVE-2015-1242
- EPSS 1.65%
- Veröffentlicht 19.04.2015 10:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service or possibly have unspecified other impact via ...
CVE-2015-1241
- EPSS 2.83%
- Veröffentlicht 19.04.2015 10:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts ...
- EPSS 1.36%
- Veröffentlicht 19.04.2015 10:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebGL program that triggers a state inconsistency.
CVE-2015-1238
- EPSS 1.83%
- Veröffentlicht 19.04.2015 10:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.
CVE-2015-1237
- EPSS 1.83%
- Veröffentlicht 19.04.2015 10:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service or possibly have unspecified other impa...
CVE-2015-1236
- EPSS 0.6%
- Veröffentlicht 19.04.2015 10:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy...
- EPSS 1.13%
- Veröffentlicht 19.04.2015 10:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy via a crafted HTML document with an IFRAME...
CVE-2015-1856
- EPSS 0.87%
- Veröffentlicht 17.04.2015 17:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.