Lucene search

K
cve[email protected]CVE-2015-1303
HistoryOct 12, 2015 - 1:59 a.m.

CVE-2015-1303

2015-10-1201:59:15
CWE-20
web.nvd.nist.gov
55
cve
blink
google chrome
same origin policy
cross-context exception
security vulnerability
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.6 High

AI Score

Confidence

High

0.013 Low

EPSS

Percentile

85.9%

bindings/core/v8/V8DOMWrapper.h in Blink, as used in Google Chrome before 45.0.2454.101, does not perform a rethrow action to propagate information about a cross-context exception, which allows remote attackers to bypass the Same Origin Policy via a crafted HTML document containing an IFRAME element.

Affected configurations

NVD
Node
googlechromeRange45.0.2454.93

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.6 High

AI Score

Confidence

High

0.013 Low

EPSS

Percentile

85.9%