CVE-2015-1210
published 2015-02-06CVE-2015-1210: The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before…
PriorityP424medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.98%
78.4th percentile
The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, does not properly consider frame access restrictions during the throwing of an exception, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| chrome | < 40.0.2214.109 | 40.0.2214.109 | |
| chrome | < 40.0.2214.111 | 40.0.2214.111 | |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-96r3-2685-3jhv: The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException
ghsa_unreviewed·2022-05-13
CVE-2015-1210 [MEDIUM] GHSA-96r3-2685-3jhv: The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException
The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, does not properly consider frame access restrictions during the throwing of an exception, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
OSV
oxide-qt vulnerabilities
osv·2015-02-10·CVSS 7.5
CVE-2015-1209 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
A use-after-free bug was discovered in the DOM implementation in Blink. If
a user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via renderer
crash or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2015-1209)
It was discovered that V8 did not properly consider frame access
restrictions when throwing exceptions in some circumstances. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same origin restrictions.
(CVE-2015-1210)
It was discovered that Chromium did not properly restrict the URI scheme
during ServiceWorker registration. If a user were tricked in to
downloading and opening
OSV
CVE-2015-1210: The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException
osv·2015-02-06·CVSS 5.0
CVE-2015-1210 [MEDIUM] CVE-2015-1210: The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException
The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, does not properly consider frame access restrictions during the throwing of an exception, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2015-02-10·CVSS 7.5
CVE-2015-1209 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
A use-after-free bug was discovered in the DOM implementation in Blink. If
a user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via renderer
crash or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2015-1209)
It was discovered that V8 did not properly consider frame access
restrictions when throwing exceptions in some circumstances. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same origin restrictions.
(CVE-2015-1210)
It was discovered that Chromium did not properly restrict the URI scheme
during ServiceWorker registra
Red Hat
chromium-browser: cross-origin-bypass in V8 bindings
vendor_redhat·2015-02-04·CVSS 5.0
CVE-2015-1210 [MEDIUM] chromium-browser: cross-origin-bypass in V8 bindings
chromium-browser: cross-origin-bypass in V8 bindings
The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, does not properly consider frame access restrictions during the throwing of an exception, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2015/02/chrome-for-android-update.htmlhttp://googlechromereleases.blogspot.com/2015/02/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0163.htmlhttp://secunia.com/advisories/62670http://secunia.com/advisories/62818http://secunia.com/advisories/62917http://secunia.com/advisories/62925http://security.gentoo.org/glsa/glsa-201502-13.xmlhttp://www.securityfocus.com/bid/72497http://www.securitytracker.com/id/1031709http://www.ubuntu.com/usn/USN-2495-1https://code.google.com/p/chromium/issues/detail?id=453979https://exchange.xforce.ibmcloud.com/vulnerabilities/100716https://src.chromium.org/viewvc/blink?revision=189365&view=revisionhttp://googlechromereleases.blogspot.com/2015/02/chrome-for-android-update.htmlhttp://googlechromereleases.blogspot.com/2015/02/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0163.htmlhttp://secunia.com/advisories/62670http://secunia.com/advisories/62818http://secunia.com/advisories/62917http://secunia.com/advisories/62925http://security.gentoo.org/glsa/glsa-201502-13.xmlhttp://www.securityfocus.com/bid/72497http://www.securitytracker.com/id/1031709http://www.ubuntu.com/usn/USN-2495-1https://code.google.com/p/chromium/issues/detail?id=453979https://exchange.xforce.ibmcloud.com/vulnerabilities/100716https://src.chromium.org/viewvc/blink?revision=189365&view=revision
2015-02-06
Published