Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-1210
HistoryFeb 06, 2015 - 12:00 a.m.

CVE-2015-1210

2015-02-0600:00:00
ubuntu.com
ubuntu.com
9

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS

0.005

Percentile

75.5%

The V8ThrowException::createDOMException function in
bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used
in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and
before 40.0.2214.109 on Android, does not properly consider frame access
restrictions during the throwing of an exception, which allows remote
attackers to bypass the Same Origin Policy via a crafted web site.

OSVersionArchitecturePackageVersionFilename
ubuntu14.04noarchchromium-browser< 40.0.2214.111-0ubuntu0.14.04.1.1069UNKNOWN
ubuntu14.10noarchchromium-browser< 40.0.2214.111-0ubuntu0.14.10.1.1111UNKNOWN
ubuntu15.04noarchchromium-browser< 40.0.2214.111-0ubuntu1.1121UNKNOWN
ubuntu15.10noarchchromium-browser< 40.0.2214.111-0ubuntu1.1121UNKNOWN
ubuntu14.04noarchoxide-qt< 1.4.3-0ubuntu0.14.04.1UNKNOWN
ubuntu14.10noarchoxide-qt< 1.4.3-0ubuntu0.14.10.1UNKNOWN
ubuntu15.04noarchoxide-qt< 1.5.3-0ubuntu2UNKNOWN
ubuntu15.10noarchoxide-qt< 1.5.3-0ubuntu2UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS

0.005

Percentile

75.5%