Lucene search

K
cveChromeCVE-2015-1294
HistorySep 03, 2015 - 10:59 p.m.

CVE-2015-1294

2015-09-0322:59:04
Chrome
web.nvd.nist.gov
55
cve-2015-1294
vulnerability
skmatrix
skia
google chrome
denial of service
remote attackers

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.7

Confidence

High

EPSS

0.019

Percentile

88.4%

Use-after-free vulnerability in the SkMatrix::invertNonIdentity function in core/SkMatrix.cpp in Skia, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering the use of matrix elements that lead to an infinite result during an inversion calculation.

Affected configurations

Nvd
Node
googlechromeRange44.0.2403
VendorProductVersionCPE
googlechromecpe:/a:google:chrome::::

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.7

Confidence

High

EPSS

0.019

Percentile

88.4%