- EPSS 0.37%
- Published 09.03.2015 00:59:02
- Last modified 12.04.2025 10:46:40
content/renderer/device_sensors/device_orientation_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate gyroscope data, which makes it easier for remote attackers to obtain speech signals from a device's p...
- EPSS 0.37%
- Published 09.03.2015 00:59:00
- Last modified 12.04.2025 10:46:40
content/renderer/device_sensors/device_motion_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate accelerometer data, which makes it easier for remote attackers to capture keystrokes via a crafted web sit...
CVE-2015-1212
- EPSS 0.62%
- Published 06.02.2015 11:59:10
- Last modified 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2015-1211
- EPSS 1.01%
- Published 06.02.2015 11:59:09
- Last modified 12.04.2025 10:46:40
The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatcher_host.cc in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android does not properly restrict the URI sc...
- EPSS 0.7%
- Published 06.02.2015 11:59:08
- Last modified 12.04.2025 10:46:40
The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, does not properly c...
CVE-2015-1209
- EPSS 1.41%
- Published 06.02.2015 11:59:07
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in the VisibleSelection::nonBoundaryShadowTreeRootNode function in core/editing/VisibleSelection.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before...
CVE-2015-1361
- EPSS 0.83%
- Published 27.01.2015 20:04:15
- Last modified 12.04.2025 10:46:40
platform/image-decoders/ImageFrame.h in Blink, as used in Google Chrome before 40.0.2214.91, does not initialize a variable that is used in calls to the Skia SkBitmap::setAlphaType function, which might allow remote attackers to cause a denial of ser...
CVE-2015-1360
- EPSS 0.89%
- Published 27.01.2015 20:04:14
- Last modified 12.04.2025 10:46:40
Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data that is improperly handled during text drawing, related to gpu/GrBi...
CVE-2015-1359
- EPSS 0.85%
- Published 27.01.2015 20:04:12
- Last modified 12.04.2025 10:46:40
Multiple off-by-one errors in fpdfapi/fpdf_font/font_int.h in PDFium, as used in Google Chrome before 40.0.2214.91, allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted PDF docu...
CVE-2014-9648
- EPSS 0.58%
- Published 27.01.2015 20:01:43
- Last modified 12.04.2025 10:46:40
components/navigation_interception/intercept_navigation_resource_throttle.cc in Google Chrome before 40.0.2214.91 on Android does not properly restrict use of intent: URLs to open an application after navigation to a web site, which allows remote att...