Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-6790
HistoryDec 14, 2015 - 12:00 a.m.

CVE-2015-6790

2015-12-1400:00:00
ubuntu.com
ubuntu.com
19

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.005

Percentile

77.2%

The WebPageSerializerImpl::openTagToString function in
WebKit/Source/web/WebPageSerializerImpl.cpp in the page serializer in
Google Chrome before 47.0.2526.80 does not properly use HTML entities,
which might allow remote attackers to inject arbitrary web script or HTML
via a crafted document, as demonstrated by a double-quote character inside
a single-quoted string.

OSVersionArchitecturePackageVersionFilename
ubuntu14.04noarchchromium-browser< 47.0.2526.106-0ubuntu0.14.04.1.1107UNKNOWN
ubuntu15.04noarchchromium-browser< 47.0.2526.106-0ubuntu0.15.04.1.1192UNKNOWN
ubuntu15.10noarchchromium-browser< 47.0.2526.106-0ubuntu0.15.10.1.1218UNKNOWN
ubuntu14.04noarchoxide-qt< 1.11.4-0ubuntu0.14.04.1UNKNOWN
ubuntu15.04noarchoxide-qt< 1.11.4-0ubuntu0.15.04.1UNKNOWN
ubuntu15.10noarchoxide-qt< 1.11.4-0ubuntu0.15.10.1UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.005

Percentile

77.2%