Lucene search

K
prionPRIOn knowledge basePRION:CVE-2015-1268
HistoryJun 26, 2015 - 2:59 p.m.

Design/Logic Flaw

2015-06-2614:59:00
PRIOn knowledge base
www.prio-n.com
4

6.6 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.1%

bindings/scripts/v8_types.py in Blink, as used in Google Chrome before 43.0.2357.130, does not properly select a creation context for a return value’s DOM wrapper, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code, as demonstrated by use of a data: URL.

CPENameOperatorVersion
chromele43.0.2357.81