CVE-2015-1269
- EPSS 0.92%
- Veröffentlicht 26.06.2015 14:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The DecodeHSTSPreloadRaw function in net/http/transport_security_state.cc in Google Chrome before 43.0.2357.130 does not properly canonicalize DNS hostnames before making comparisons to HSTS or HPKP preload entries, which allows remote attackers to b...
- EPSS 0.93%
- Veröffentlicht 26.06.2015 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Blink, as used in Google Chrome before 43.0.2357.130, does not properly restrict the creation context during creation of a DOM wrapper, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that uses a Blink publi...
- EPSS 0.91%
- Veröffentlicht 26.06.2015 14:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
content/browser/webui/content_web_ui_controller_factory.cc in Google Chrome before 43.0.2357.130 does not properly consider the scheme in determining whether a URL is associated with a WebUI SiteInstance, which allows remote attackers to bypass inten...
CVE-2015-4000
- EPSS 93.9%
- Veröffentlicht 21.05.2015 00:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a Clie...
CVE-2015-3910
- EPSS 0.26%
- Veröffentlicht 20.05.2015 10:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google V8 before 4.3.61.21, as used in Google Chrome before 43.0.2357.65, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2015-1265
- EPSS 7.63%
- Veröffentlicht 20.05.2015 10:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2015-1264
- EPSS 0.49%
- Veröffentlicht 20.05.2015 10:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Google Chrome before 43.0.2357.65 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted data that is improperly handled by the Bookmarks feature.
CVE-2015-1263
- EPSS 0.69%
- Veröffentlicht 20.05.2015 10:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecifie...
CVE-2015-1262
- EPSS 1.76%
- Veröffentlicht 20.05.2015 10:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
platform/fonts/shaping/HarfBuzzShaper.cpp in Blink, as used in Google Chrome before 43.0.2357.65, does not initialize a certain width field, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via craf...
- EPSS 1.06%
- Veröffentlicht 20.05.2015 10:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use of a URL's fragment identifier during construction of a page-info popup, which allows remote attacke...