Lucene search

K
cveChromeCVE-2015-6583
HistorySep 03, 2015 - 10:59 p.m.

CVE-2015-6583

2015-09-0322:59:16
CWE-254
Chrome
web.nvd.nist.gov
43
cve-2015-6583
google chrome
security vulnerability
spoofing
remote attackers
nvd
browser.cc
hosted_app_browser_controller.cc

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.2

Confidence

Low

EPSS

0.004

Percentile

72.9%

Google Chrome before 45.0.2454.85 does not display a location bar for a hosted app’s window after navigation away from the installation site, which might make it easier for remote attackers to spoof content via a crafted app, related to browser.cc and hosted_app_browser_controller.cc.

Affected configurations

Nvd
Node
googlechromeRange44.0.2403
VendorProductVersionCPE
googlechromecpe:/a:google:chrome::::

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.2

Confidence

Low

EPSS

0.004

Percentile

72.9%