CVE-2015-1233
- EPSS 26.28%
- Veröffentlicht 01.04.2015 21:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Google Chrome before 41.0.2272.118 does not properly handle the interaction of IPC, the Gamepad API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2015-2239
- EPSS 0.36%
- Veröffentlicht 09.03.2015 00:59:29
- Zuletzt bearbeitet 12.04.2025 10:46:40
Google Chrome before 41.0.2272.76, when Instant Extended mode is used, does not properly consider the interaction between the "1993 search" features and restore-from-disk RELOAD transitions, which makes it easier for remote attackers to spoof the add...
CVE-2015-2238
- EPSS 0.11%
- Veröffentlicht 09.03.2015 00:59:28
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google V8 before 4.1.0.21, as used in Google Chrome before 41.0.2272.76, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2015-1232
- EPSS 0.71%
- Veröffentlicht 09.03.2015 00:59:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
Array index error in the MidiManagerUsb::DispatchSendMidiData function in media/midi/midi_manager_usb.cc in Google Chrome before 41.0.2272.76 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging...
CVE-2015-1231
- EPSS 1.16%
- Veröffentlicht 09.03.2015 00:59:23
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google Chrome before 41.0.2272.76 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
- EPSS 0.32%
- Veröffentlicht 09.03.2015 00:59:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
net/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allows remote proxy servers to conduct cookie-injection...
CVE-2015-1230
- EPSS 1.73%
- Veröffentlicht 09.03.2015 00:59:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the AudioContext class, which allows remote attackers to cause a denial of service or possibly h...
CVE-2015-1228
- EPSS 1.07%
- Veröffentlicht 09.03.2015 00:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
The RenderCounter::updateCounter function in core/rendering/RenderCounter.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not force a relayout operation and consequently does not initialize memory for a data structure, which allows r...
CVE-2015-1227
- EPSS 1.02%
- Veröffentlicht 09.03.2015 00:59:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
The DragImage::create function in platform/DragImage.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not initialize memory for image drawing, which allows remote attackers to have an unspecified impact by triggering a failed image de...
- EPSS 0.32%
- Veröffentlicht 09.03.2015 00:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 41.0.2272.76 does not properly restrict what URLs are available as debugger targets, which allows remote attackers to bypass inten...