CVE-2015-1205
published 2015-01-22CVE-2015-1205: Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have other impact via…
PriorityP431high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.81%
76.5th percentile
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| chromium | chromium | <= 40.0.2214.94 | — |
| chrome | <= 40.0.2214.85 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8rg6-4v99-qp5v: platform/image-decoders/ImageFrame
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2015-1361 [HIGH] GHSA-8rg6-4v99-qp5v: platform/image-decoders/ImageFrame
platform/image-decoders/ImageFrame.h in Blink, as used in Google Chrome before 40.0.2214.91, does not initialize a variable that is used in calls to the Skia SkBitmap::setAlphaType function, which might allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted HTML document, a different vulnerability than CVE-2015-1205.
GHSA
GHSA-mf42-wf93-6v66: Use-after-free vulnerability in PDFium, as used in Google Chrome before 40
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2014-9647 [HIGH] GHSA-mf42-wf93-6v66: Use-after-free vulnerability in PDFium, as used in Google Chrome before 40
Use-after-free vulnerability in PDFium, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document, related to fpdfsdk/src/fpdfview.cpp and fpdfsdk/src/fsdk_mgr.cpp, a different vulnerability than CVE-2015-1205.
GHSA
GHSA-7352-jw4q-788p: Multiple unspecified vulnerabilities in Google Chrome before 40
ghsa_unreviewed·2022-05-17
CVE-2015-1205 [HIGH] GHSA-7352-jw4q-788p: Multiple unspecified vulnerabilities in Google Chrome before 40
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
GHSA
GHSA-84hc-7w5w-q3hv: Multiple off-by-one errors in fpdfapi/fpdf_font/font_int
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2015-1359 [HIGH] GHSA-84hc-7w5w-q3hv: Multiple off-by-one errors in fpdfapi/fpdf_font/font_int
Multiple off-by-one errors in fpdfapi/fpdf_font/font_int.h in PDFium, as used in Google Chrome before 40.0.2214.91, allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted PDF document, related to an "intra-object-overflow" issue, a different vulnerability than CVE-2015-1205.
GHSA
GHSA-jq3p-55hr-jqv2: Unquoted Windows search path vulnerability in the GoogleChromeDistribution::DoPostUninstallOperations function in installer/util/google_chrome_distrib
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2014-9646 [HIGH] GHSA-jq3p-55hr-jqv2: Unquoted Windows search path vulnerability in the GoogleChromeDistribution::DoPostUninstallOperations function in installer/util/google_chrome_distrib
Unquoted Windows search path vulnerability in the GoogleChromeDistribution::DoPostUninstallOperations function in installer/util/google_chrome_distribution.cc in the uninstall-survey feature in Google Chrome before 40.0.2214.91 allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% directory, as demonstrated by program.exe, a different vulnerability than CVE-2015-1205.
GHSA
GHSA-8ccr-r6v5-rj2f: components/navigation_interception/intercept_navigation_resource_throttle
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2014-9648 [HIGH] CWE-284 GHSA-8ccr-r6v5-rj2f: components/navigation_interception/intercept_navigation_resource_throttle
components/navigation_interception/intercept_navigation_resource_throttle.cc in Google Chrome before 40.0.2214.91 on Android does not properly restrict use of intent: URLs to open an application after navigation to a web site, which allows remote attackers to cause a denial of service (loss of browser access to that site) via crafted JavaScript code, as demonstrated by pandora.com and the Pandora application, a different vulnerability than CVE-2015-1205.
GHSA
GHSA-cq2x-f2q5-8gm2: Skia, as used in Google Chrome before 40
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2015-1360 [HIGH] CWE-119 GHSA-cq2x-f2q5-8gm2: Skia, as used in Google Chrome before 40
Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data that is improperly handled during text drawing, related to gpu/GrBitmapTextContext.cpp and gpu/GrDistanceFieldTextContext.cpp, a different vulnerability than CVE-2015-1205.
OSV
CVE-2015-1361: platform/image-decoders/ImageFrame
osv·2015-01-27·CVSS 7.5
CVE-2015-1361 [HIGH] CVE-2015-1361: platform/image-decoders/ImageFrame
platform/image-decoders/ImageFrame.h in Blink, as used in Google Chrome before 40.0.2214.91, does not initialize a variable that is used in calls to the Skia SkBitmap::setAlphaType function, which might allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted HTML document, a different vulnerability than CVE-2015-1205.
OSV
CVE-2015-1359: Multiple off-by-one errors in fpdfapi/fpdf_font/font_int
osv·2015-01-27·CVSS 7.5
CVE-2015-1359 [HIGH] CVE-2015-1359: Multiple off-by-one errors in fpdfapi/fpdf_font/font_int
Multiple off-by-one errors in fpdfapi/fpdf_font/font_int.h in PDFium, as used in Google Chrome before 40.0.2214.91, allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted PDF document, related to an "intra-object-overflow" issue, a different vulnerability than CVE-2015-1205.
OSV
CVE-2015-1360: Skia, as used in Google Chrome before 40
osv·2015-01-27·CVSS 7.5
CVE-2015-1360 [HIGH] CVE-2015-1360: Skia, as used in Google Chrome before 40
Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data that is improperly handled during text drawing, related to gpu/GrBitmapTextContext.cpp and gpu/GrDistanceFieldTextContext.cpp, a different vulnerability than CVE-2015-1205.
OSV
CVE-2014-9647: Use-after-free vulnerability in PDFium, as used in Google Chrome before 40
osv·2015-01-27·CVSS 6.8
CVE-2014-9647 [MEDIUM] CVE-2014-9647: Use-after-free vulnerability in PDFium, as used in Google Chrome before 40
Use-after-free vulnerability in PDFium, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document, related to fpdfsdk/src/fpdfview.cpp and fpdfsdk/src/fsdk_mgr.cpp, a different vulnerability than CVE-2015-1205.
OSV
oxide-qt vulnerabilities
osv·2015-01-26·CVSS 7.5
CVE-2014-7923 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
Several memory corruption bugs were discovered in ICU. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via renderer crash
or execute arbitrary code with the privileges of the sandboxed render
process. (CVE-2014-7923, CVE-2014-7926)
A use-after-free was discovered in the IndexedDB implementation. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via application
crash or execute arbitrary code with the privileges of the user invoking
the program. (CVE-2014-7924)
A use-after free was discovered in the WebAudio implementation in Blink.
If a user were tricked in to opening a specially crafte
OSV
CVE-2015-1205: Multiple unspecified vulnerabilities in Google Chrome before 40
osv·2015-01-22·CVSS 7.5
CVE-2015-1205 [HIGH] CVE-2015-1205: Multiple unspecified vulnerabilities in Google Chrome before 40
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2015-01-26·CVSS 7.5
CVE-2014-7923 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
Several memory corruption bugs were discovered in ICU. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via renderer crash
or execute arbitrary code with the privileges of the sandboxed render
process. (CVE-2014-7923, CVE-2014-7926)
A use-after-free was discovered in the IndexedDB implementation. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via application
crash or execute arbitrary code with the privileges of the user invoking
the program. (CVE-2014-7924)
A use-after free was discovered in the WebAudio implementation in Bli
Red Hat
chromium-browser: multiple unspecified vulnerabilities
vendor_redhat·2015-01-21·CVSS 7.5
CVE-2015-1205 [HIGH] chromium-browser: multiple unspecified vulnerabilities
chromium-browser: multiple unspecified vulnerabilities
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2150 spice: Host memory access from guest with invalid primary surface parameters
bugzilla·2016-03-01·CVSS 7.1
CVE-2016-2150 [HIGH] CVE-2016-2150 spice: Host memory access from guest with invalid primary surface parameters
CVE-2016-2150 spice: Host memory access from guest with invalid primary surface parameters
It was found that one malicious guest inside a virtual machine can take control of the corresponding Qemu process in the host using crafted primary surface parameters. This issue is similar to CVE-2015-5261, but it's using different path in the code.
Discussion:
Acknowledgments:
Name: Frediano Ziglio (Red Hat)
---
Created spice tracking bugs for this issue:
Affects: fedora-all [bug 1343135]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1205 https://access.redhat.com/errata/RHSA-2016:1205
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1204 https://access.redhat.com/errata/RHSA-
Bugzilla
CVE-2014-9654 icu: insufficient size limit checks in regular expression compiler
bugzilla·2015-02-06·CVSS 9.8
CVE-2014-9654 [CRITICAL] CVE-2014-9654 icu: insufficient size limit checks in regular expression compiler
CVE-2014-9654 icu: insufficient size limit checks in regular expression compiler
An unspecified overlow vulnerability was fixed in ICU [1] and Chrome browser [2][3].
[1]: http://bugs.icu-project.org/trac/changeset/36801
[2]: https://code.google.com/p/chromium/issues/detail?id=432209
[3]: https://chromium.googlesource.com/chromium/deps/icu/+/dd727641e190d60e4593bcb3a35c7f51eb4925c5
Discussion:
Created mingw-icu tracking bugs for this issue:
Affects: fedora-all [bug 1190132]
Affects: epel-7 [bug 1190133]
---
Created icu tracking bugs for this issue:
Affects: fedora-all [bug 1190131]
---
This issue was previously grouped with other Chrome issues under the Google Chrome CVE-2015-1205. Bug 1185282 comment 1 lists information that is currently public about this flaw:
Chrome upstream b
Bugzilla
CVE-2015-1205 chromium-browser: multiple unspecified vulnerabilities
bugzilla·2015-01-23·CVSS 9.8
CVE-2015-1205 [CRITICAL] CVE-2015-1205 chromium-browser: multiple unspecified vulnerabilities
CVE-2015-1205 chromium-browser: multiple unspecified vulnerabilities
Common Vulnerabilities and Exposures assigned an identifier CVE-2015-1205 to
the following vulnerability:
Name: CVE-2015-1205
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1205
Assigned: 20150121
Reference: https://code.google.com/p/chromium/issues/detail?id=449894
Multiple unspecified vulnerabilities in Google Chrome before
40.0.2214.91 allow attackers to cause a denial of service or possibly
have other impact via unknown vectors.
Discussion:
Upstream bug linked in comment 0 contains long list of other upstream bugs for random fixes applied in this Chrome update. One of the issues is:
https://code.google.com/p/chromium/issues/detail?id=432209
This bug is currently non-public, but it can be tracked to
http://googlechromereleases.blogspot.com/2015/01/stable-update.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.htmlhttp://secunia.com/advisories/62383http://secunia.com/advisories/62575http://security.gentoo.org/glsa/glsa-201502-13.xmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/72288http://www.securitytracker.com/id/1031623http://www.ubuntu.com/usn/USN-2476-1https://code.google.com/p/chromium/issues/detail?id=327070https://code.google.com/p/chromium/issues/detail?id=334448https://code.google.com/p/chromium/issues/detail?id=410030https://code.google.com/p/chromium/issues/detail?id=411026https://code.google.com/p/chromium/issues/detail?id=411156https://code.google.com/p/chromium/issues/detail?id=413530https://code.google.com/p/chromium/issues/detail?id=422765https://code.google.com/p/chromium/issues/detail?id=423899https://code.google.com/p/chromium/issues/detail?id=425040https://code.google.com/p/chromium/issues/detail?id=425151https://code.google.com/p/chromium/issues/detail?id=428828https://code.google.com/p/chromium/issues/detail?id=429134https://code.google.com/p/chromium/issues/detail?id=429139https://code.google.com/p/chromium/issues/detail?id=431187https://code.google.com/p/chromium/issues/detail?id=431603https://code.google.com/p/chromium/issues/detail?id=432209https://code.google.com/p/chromium/issues/detail?id=434723https://code.google.com/p/chromium/issues/detail?id=435514https://code.google.com/p/chromium/issues/detail?id=435815https://code.google.com/p/chromium/issues/detail?id=437655https://code.google.com/p/chromium/issues/detail?id=438363https://code.google.com/p/chromium/issues/detail?id=439319https://code.google.com/p/chromium/issues/detail?id=440572https://code.google.com/p/chromium/issues/detail?id=440913https://code.google.com/p/chromium/issues/detail?id=441834https://code.google.com/p/chromium/issues/detail?id=443274https://code.google.com/p/chromium/issues/detail?id=443333https://code.google.com/p/chromium/issues/detail?id=446076https://code.google.com/p/chromium/issues/detail?id=449894https://support.apple.com/HT205212https://support.apple.com/HT205221http://googlechromereleases.blogspot.com/2015/01/stable-update.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.htmlhttp://secunia.com/advisories/62383http://secunia.com/advisories/62575http://security.gentoo.org/glsa/glsa-201502-13.xmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/72288http://www.securitytracker.com/id/1031623http://www.ubuntu.com/usn/USN-2476-1https://code.google.com/p/chromium/issues/detail?id=327070https://code.google.com/p/chromium/issues/detail?id=334448https://code.google.com/p/chromium/issues/detail?id=410030https://code.google.com/p/chromium/issues/detail?id=411026https://code.google.com/p/chromium/issues/detail?id=411156https://code.google.com/p/chromium/issues/detail?id=413530https://code.google.com/p/chromium/issues/detail?id=422765https://code.google.com/p/chromium/issues/detail?id=423899https://code.google.com/p/chromium/issues/detail?id=425040https://code.google.com/p/chromium/issues/detail?id=425151https://code.google.com/p/chromium/issues/detail?id=428828https://code.google.com/p/chromium/issues/detail?id=429134https://code.google.com/p/chromium/issues/detail?id=429139https://code.google.com/p/chromium/issues/detail?id=431187https://code.google.com/p/chromium/issues/detail?id=431603https://code.google.com/p/chromium/issues/detail?id=432209https://code.google.com/p/chromium/issues/detail?id=434723https://code.google.com/p/chromium/issues/detail?id=435514https://code.google.com/p/chromium/issues/detail?id=435815https://code.google.com/p/chromium/issues/detail?id=437655https://code.google.com/p/chromium/issues/detail?id=438363https://code.google.com/p/chromium/issues/detail?id=439319https://code.google.com/p/chromium/issues/detail?id=440572https://code.google.com/p/chromium/issues/detail?id=440913https://code.google.com/p/chromium/issues/detail?id=441834https://code.google.com/p/chromium/issues/detail?id=443274https://code.google.com/p/chromium/issues/detail?id=443333https://code.google.com/p/chromium/issues/detail?id=446076https://code.google.com/p/chromium/issues/detail?id=449894https://support.apple.com/HT205212https://support.apple.com/HT205221
2015-01-22
Published