CVE-2015-1209
published 2015-02-06CVE-2015-1209: Use-after-free vulnerability in the VisibleSelection::nonBoundaryShadowTreeRootNode function in core/editing/VisibleSelection.cpp in the DOM implementation in…
PriorityP433high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.85%
85.1th percentile
Use-after-free vulnerability in the VisibleSelection::nonBoundaryShadowTreeRootNode function in core/editing/VisibleSelection.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers improper handling of a shadow-root anchor.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| chrome | < 40.0.2214.109 | 40.0.2214.109 | |
| chrome | < 40.0.2214.111 | 40.0.2214.111 | |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w534-6frw-3r76: Use-after-free vulnerability in the VisibleSelection::nonBoundaryShadowTreeRootNode function in core/editing/VisibleSelection
ghsa_unreviewed·2022-05-13
CVE-2015-1209 [HIGH] CWE-416 GHSA-w534-6frw-3r76: Use-after-free vulnerability in the VisibleSelection::nonBoundaryShadowTreeRootNode function in core/editing/VisibleSelection
Use-after-free vulnerability in the VisibleSelection::nonBoundaryShadowTreeRootNode function in core/editing/VisibleSelection.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers improper handling of a shadow-root anchor.
OSV
oxide-qt vulnerabilities
osv·2015-02-10·CVSS 7.5
CVE-2015-1209 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
A use-after-free bug was discovered in the DOM implementation in Blink. If
a user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via renderer
crash or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2015-1209)
It was discovered that V8 did not properly consider frame access
restrictions when throwing exceptions in some circumstances. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same origin restrictions.
(CVE-2015-1210)
It was discovered that Chromium did not properly restrict the URI scheme
during ServiceWorker registration. If a user were tricked in to
downloading and opening
OSV
CVE-2015-1209: Use-after-free vulnerability in the VisibleSelection::nonBoundaryShadowTreeRootNode function in core/editing/VisibleSelection
osv·2015-02-06·CVSS 7.5
CVE-2015-1209 [HIGH] CVE-2015-1209: Use-after-free vulnerability in the VisibleSelection::nonBoundaryShadowTreeRootNode function in core/editing/VisibleSelection
Use-after-free vulnerability in the VisibleSelection::nonBoundaryShadowTreeRootNode function in core/editing/VisibleSelection.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers improper handling of a shadow-root anchor.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2015-02-10·CVSS 7.5
CVE-2015-1209 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
A use-after-free bug was discovered in the DOM implementation in Blink. If
a user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via renderer
crash or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2015-1209)
It was discovered that V8 did not properly consider frame access
restrictions when throwing exceptions in some circumstances. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same origin restrictions.
(CVE-2015-1210)
It was discovered that Chromium did not properly restrict the URI scheme
during ServiceWorker registra
Red Hat
chromium-browser: use-after-free in DOM
vendor_redhat·2015-02-04·CVSS 7.5
CVE-2015-1209 [HIGH] CWE-416 chromium-browser: use-after-free in DOM
chromium-browser: use-after-free in DOM
Use-after-free vulnerability in the VisibleSelection::nonBoundaryShadowTreeRootNode function in core/editing/VisibleSelection.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers improper handling of a shadow-root anchor.
Statement: This issue affects the versions of webkitgtk and webkitgtk3 as shipped with Red Hat Enterprise Linux 6 and 7 respectively.
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional
No detection rules found.
No public exploits indexed.
Talos
Research Spotlight: Exploiting Use-After-Free Vulnerabilities
blogs_talos·2015-03-17·CVSS 9.3
[CRITICAL] Research Spotlight: Exploiting Use-After-Free Vulnerabilities
This blog post was authored by Earl Carter & Yves Younan.
Talos is constantly researching the ways in which threat actors take advantage of security weaknesses to exploit systems. Yves Younan of Talos will be presenting at CanSecWest on Friday March 20th. The topic of his talk will be FreeSentry, a software-based mitigation technique developed by Talos to protect against exploitation of use-after-free vulnerabilities. Use-after-free vulnerabilities have become an important class of security problems due to the existence of mitigations that protect against other types of vulnerabilities, such as buffer overflows.
Just examining the CVE entries for 2015, you can already see over 20 use-after-free vulnerabilities that have already been identified, impacting various common software applicati
Talos
Research Spotlight: Exploiting Use-After-Free Vulnerabilities
blogs_talos·2015-03-17·CVSS 9.3
[CRITICAL] Research Spotlight: Exploiting Use-After-Free Vulnerabilities
## Research Spotlight: Exploiting Use-After-Free Vulnerabilities
This blog post was authored by Earl Carter & Yves Younan .
Talos is constantly researching the ways in which threat actors take advantage of security weaknesses to exploit systems. Yves Younan of Talos will be presenting at CanSecWest on Friday March 20th. The topic of his talk will be FreeSentry , a software-based mitigation technique developed by Talos to protect against exploitation of use-after-free vulnerabilities. Use-after-free vulnerabilities have become an important class of security problems due to the existence of mitigations that protect against other types of vulnerabilities, such as buffer overflows.
Just examining the CVE entries for 2015, you can already see over 20 use-after-free vulnerabilities that have
Bugzilla
CVE-2015-1209 chromium-browser: use-after-free in DOM
bugzilla·2015-02-06·CVSS 7.5
CVE-2015-1209 [HIGH] CVE-2015-1209 chromium-browser: use-after-free in DOM
CVE-2015-1209 chromium-browser: use-after-free in DOM
An unspecified use-after-free flaw was found in the DOM component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/02/stable-channel-update.html
Discussion:
Currently private upstream bug:
https://code.google.com/p/chromium/issues/detail?id=447906
---
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0163 https://rhn.redhat.com/errata/RHSA-2015-0163.html
---
Statement:
This issue affects the versions of webkitgtk and webkitgtk3 as shipped with Red Hat Enterprise Linux 6 and 7 respectively.
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addr
http://googlechromereleases.blogspot.com/2015/02/chrome-for-android-update.htmlhttp://googlechromereleases.blogspot.com/2015/02/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0163.htmlhttp://secunia.com/advisories/62670http://secunia.com/advisories/62818http://secunia.com/advisories/62917http://secunia.com/advisories/62925http://security.gentoo.org/glsa/glsa-201502-13.xmlhttp://www.securityfocus.com/bid/72497http://www.securitytracker.com/id/1031709http://www.ubuntu.com/usn/USN-2495-1https://code.google.com/p/chromium/issues/detail?id=447906https://exchange.xforce.ibmcloud.com/vulnerabilities/100715https://src.chromium.org/viewvc/blink?revision=188788&view=revisionhttp://googlechromereleases.blogspot.com/2015/02/chrome-for-android-update.htmlhttp://googlechromereleases.blogspot.com/2015/02/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0163.htmlhttp://secunia.com/advisories/62670http://secunia.com/advisories/62818http://secunia.com/advisories/62917http://secunia.com/advisories/62925http://security.gentoo.org/glsa/glsa-201502-13.xmlhttp://www.securityfocus.com/bid/72497http://www.securitytracker.com/id/1031709http://www.ubuntu.com/usn/USN-2495-1https://code.google.com/p/chromium/issues/detail?id=447906https://exchange.xforce.ibmcloud.com/vulnerabilities/100715https://src.chromium.org/viewvc/blink?revision=188788&view=revision
2015-02-06
Published