CVE-2015-1236
- EPSS 0.6%
- Veröffentlicht 19.04.2015 10:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy...
- EPSS 1.13%
- Veröffentlicht 19.04.2015 10:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy via a crafted HTML document with an IFRAME...
CVE-2015-1234
- EPSS 3.16%
- Veröffentlicht 01.04.2015 21:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Race condition in gpu/command_buffer/service/gles2_cmd_decoder.cc in Google Chrome before 41.0.2272.118 allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact by manipulating OpenGL ES command...
CVE-2015-1233
- EPSS 26.28%
- Veröffentlicht 01.04.2015 21:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Google Chrome before 41.0.2272.118 does not properly handle the interaction of IPC, the Gamepad API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2015-2239
- EPSS 0.36%
- Veröffentlicht 09.03.2015 00:59:29
- Zuletzt bearbeitet 12.04.2025 10:46:40
Google Chrome before 41.0.2272.76, when Instant Extended mode is used, does not properly consider the interaction between the "1993 search" features and restore-from-disk RELOAD transitions, which makes it easier for remote attackers to spoof the add...
CVE-2015-2238
- EPSS 0.11%
- Veröffentlicht 09.03.2015 00:59:28
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google V8 before 4.1.0.21, as used in Google Chrome before 41.0.2272.76, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2015-1232
- EPSS 0.71%
- Veröffentlicht 09.03.2015 00:59:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
Array index error in the MidiManagerUsb::DispatchSendMidiData function in media/midi/midi_manager_usb.cc in Google Chrome before 41.0.2272.76 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging...
CVE-2015-1231
- EPSS 1.16%
- Veröffentlicht 09.03.2015 00:59:23
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google Chrome before 41.0.2272.76 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
- EPSS 0.32%
- Veröffentlicht 09.03.2015 00:59:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
net/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allows remote proxy servers to conduct cookie-injection...
CVE-2015-1230
- EPSS 1.73%
- Veröffentlicht 09.03.2015 00:59:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the AudioContext class, which allows remote attackers to cause a denial of service or possibly h...