CVE-2015-1212
published 2015-02-06CVE-2015-1212: Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android allow attackers to…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.16%
80.1th percentile
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| chrome | < 40.0.2214.109 | 40.0.2214.109 | |
| chrome | < 40.0.2214.111 | 40.0.2214.111 | |
| chrome | <= 40.0.2214.115 | — | |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: Out-of-bounds write in media
vendor_redhat·2015-03-03·CVSS 7.5
CVE-2015-1232 [HIGH] CWE-787 chromium-browser: Out-of-bounds write in media
chromium-browser: Out-of-bounds write in media
Array index error in the MidiManagerUsb::DispatchSendMidiData function in media/midi/midi_manager_usb.cc in Google Chrome before 41.0.2272.76 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging renderer access to provide an invalid port index that triggers an out-of-bounds write operation, a different vulnerability than CVE-2015-1212.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2015-02-10·CVSS 7.5
CVE-2015-1209 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
A use-after-free bug was discovered in the DOM implementation in Blink. If
a user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via renderer
crash or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2015-1209)
It was discovered that V8 did not properly consider frame access
restrictions when throwing exceptions in some circumstances. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same origin restrictions.
(CVE-2015-1210)
It was discovered that Chromium did not properly restrict the URI scheme
during ServiceWorker registra
Red Hat
chromium-browser: various security fixes in Chrome 40.0.2214.111
vendor_redhat·2015-02-04·CVSS 7.5
CVE-2015-1212 [HIGH] chromium-browser: various security fixes in Chrome 40.0.2214.111
chromium-browser: various security fixes in Chrome 40.0.2214.111
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Statement: This issue affects the versions of webkitgtk and webkitgtk3 as shipped with Red Hat Enterprise Linux 6 and 7 respectively.
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webki
GHSA
GHSA-f6r4-gh32-pq92: Array index error in the MidiManagerUsb::DispatchSendMidiData function in media/midi/midi_manager_usb
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2015-1232 [HIGH] CWE-119 GHSA-f6r4-gh32-pq92: Array index error in the MidiManagerUsb::DispatchSendMidiData function in media/midi/midi_manager_usb
Array index error in the MidiManagerUsb::DispatchSendMidiData function in media/midi/midi_manager_usb.cc in Google Chrome before 41.0.2272.76 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging renderer access to provide an invalid port index that triggers an out-of-bounds write operation, a different vulnerability than CVE-2015-1212.
GHSA
GHSA-j93m-fj9q-jg26: Multiple unspecified vulnerabilities in Google Chrome before 40
ghsa_unreviewed·2022-05-13
CVE-2015-1212 [HIGH] GHSA-j93m-fj9q-jg26: Multiple unspecified vulnerabilities in Google Chrome before 40
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
OSV
CVE-2015-1232: Array index error in the MidiManagerUsb::DispatchSendMidiData function in media/midi/midi_manager_usb
osv·2015-03-09·CVSS 7.5
CVE-2015-1232 [HIGH] CVE-2015-1232: Array index error in the MidiManagerUsb::DispatchSendMidiData function in media/midi/midi_manager_usb
Array index error in the MidiManagerUsb::DispatchSendMidiData function in media/midi/midi_manager_usb.cc in Google Chrome before 41.0.2272.76 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging renderer access to provide an invalid port index that triggers an out-of-bounds write operation, a different vulnerability than CVE-2015-1212.
OSV
oxide-qt vulnerabilities
osv·2015-02-10·CVSS 7.5
CVE-2015-1209 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
A use-after-free bug was discovered in the DOM implementation in Blink. If
a user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via renderer
crash or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2015-1209)
It was discovered that V8 did not properly consider frame access
restrictions when throwing exceptions in some circumstances. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same origin restrictions.
(CVE-2015-1210)
It was discovered that Chromium did not properly restrict the URI scheme
during ServiceWorker registration. If a user were tricked in to
downloading and opening
OSV
CVE-2015-1212: Multiple unspecified vulnerabilities in Google Chrome before 40
osv·2015-02-06·CVSS 7.5
CVE-2015-1212 [HIGH] CVE-2015-1212: Multiple unspecified vulnerabilities in Google Chrome before 40
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
No detection rules found.
http://googlechromereleases.blogspot.com/2015/02/chrome-for-android-update.htmlhttp://googlechromereleases.blogspot.com/2015/02/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0163.htmlhttp://secunia.com/advisories/62670http://secunia.com/advisories/62818http://secunia.com/advisories/62917http://secunia.com/advisories/62925http://security.gentoo.org/glsa/glsa-201502-13.xmlhttp://www.securityfocus.com/bid/72497http://www.securitytracker.com/id/1031709http://www.ubuntu.com/usn/USN-2495-1https://code.google.com/p/chromium/issues/detail?id=427303https://code.google.com/p/chromium/issues/detail?id=438365https://code.google.com/p/chromium/issues/detail?id=445679https://code.google.com/p/chromium/issues/detail?id=446459https://code.google.com/p/chromium/issues/detail?id=451684https://code.google.com/p/chromium/issues/detail?id=451918https://code.google.com/p/chromium/issues/detail?id=455225https://exchange.xforce.ibmcloud.com/vulnerabilities/100718http://googlechromereleases.blogspot.com/2015/02/chrome-for-android-update.htmlhttp://googlechromereleases.blogspot.com/2015/02/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0163.htmlhttp://secunia.com/advisories/62670http://secunia.com/advisories/62818http://secunia.com/advisories/62917http://secunia.com/advisories/62925http://security.gentoo.org/glsa/glsa-201502-13.xmlhttp://www.securityfocus.com/bid/72497http://www.securitytracker.com/id/1031709http://www.ubuntu.com/usn/USN-2495-1https://code.google.com/p/chromium/issues/detail?id=427303https://code.google.com/p/chromium/issues/detail?id=438365https://code.google.com/p/chromium/issues/detail?id=445679https://code.google.com/p/chromium/issues/detail?id=446459https://code.google.com/p/chromium/issues/detail?id=451684https://code.google.com/p/chromium/issues/detail?id=451918https://code.google.com/p/chromium/issues/detail?id=455225https://exchange.xforce.ibmcloud.com/vulnerabilities/100718
2015-02-06
Published