CVE-2015-1230
published 2015-03-09CVE-2015-1230: The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the…
PriorityP431high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.12%
80.0th percentile
The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the AudioContext class, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via JavaScript code that adds an AudioContext event listener and triggers "type confusion."
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| chrome | <= 40.0.2214.115 | — | |
| redhat | enterprise_linux_desktop_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary_eus | — | — |
| redhat | enterprise_linux_workstation_supplementary | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2015-03-10·CVSS 7.5
CVE-2015-1213 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
Several out-of-bounds write bugs were discovered in Skia. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash or execute arbitrary code with the privileges of the user invoking
the program. (CVE-2015-1213, CVE-2015-1214, CVE-2015-1215)
A use-after-free was discovered in the V8 bindings in Blink. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via renderer crash,
or execute arbitrary code with the privileges of the sandboxed render
process. (CVE-2015-1216)
Multiple type confusion bugs were discovered in the V8
Red Hat
chromium-browser: Type confusion in v8
vendor_redhat·2015-03-03·CVSS 7.5
CVE-2015-1230 [HIGH] CWE-843 chromium-browser: Type confusion in v8
chromium-browser: Type confusion in v8
The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the AudioContext class, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via JavaScript code that adds an AudioContext event listener and triggers "type confusion."
GHSA
GHSA-qvf7-37f3-pvmw: The getHiddenProperty function in bindings/core/v8/V8EventListenerList
ghsa_unreviewed·2022-05-17
CVE-2015-1230 [HIGH] GHSA-qvf7-37f3-pvmw: The getHiddenProperty function in bindings/core/v8/V8EventListenerList
The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the AudioContext class, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via JavaScript code that adds an AudioContext event listener and triggers "type confusion."
OSV
oxide-qt vulnerabilities
osv·2015-03-10·CVSS 7.5
CVE-2015-1213 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
Several out-of-bounds write bugs were discovered in Skia. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash or execute arbitrary code with the privileges of the user invoking
the program. (CVE-2015-1213, CVE-2015-1214, CVE-2015-1215)
A use-after-free was discovered in the V8 bindings in Blink. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via renderer crash,
or execute arbitrary code with the privileges of the sandboxed render
process. (CVE-2015-1216)
Multiple type confusion bugs were discovered in the V8 bindings in Blink.
If a user were tricked in to opening a
OSV
CVE-2015-1230: The getHiddenProperty function in bindings/core/v8/V8EventListenerList
osv·2015-03-08·CVSS 7.5
CVE-2015-1230 [HIGH] CVE-2015-1230: The getHiddenProperty function in bindings/core/v8/V8EventListenerList
The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the AudioContext class, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via JavaScript code that adds an AudioContext event listener and triggers "type confusion."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-2621 OpenJDK: incorrect code permission checks in RMIConnectionImpl (JMX, 8075853)
bugzilla·2015-07-13·CVSS 5.0
CVE-2015-2621 [MEDIUM] CVE-2015-2621 OpenJDK: incorrect code permission checks in RMIConnectionImpl (JMX, 8075853)
CVE-2015-2621 OpenJDK: incorrect code permission checks in RMIConnectionImpl (JMX, 8075853)
It was discovered that the RMIConnectionImpl class in the JMX component of OpenJDK failed to properly check code permissions when creating repository class loaders. An untrusted Java application or applet could use this flaw to read information access to which should be restricted by the Java sandbox, partially bypassing sandbox restrictions.
Discussion:
Public now via Oracle Critical Patch Update - July 2015. Fixed in Oracle Java SE 6u101, 7u85, and 8u51.
External References:
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html#AppendixJAVA
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Via RHSA-2015:1230 https://rhn.redhat.com/
Bugzilla
CVE-2015-4732 OpenJDK: insufficient context checks during object deserialization (Libraries, 8076405)
bugzilla·2015-07-12·CVSS 10.0
CVE-2015-4732 [CRITICAL] CVE-2015-4732 OpenJDK: insufficient context checks during object deserialization (Libraries, 8076405)
CVE-2015-4732 OpenJDK: insufficient context checks during object deserialization (Libraries, 8076405)
It was discovered that the Libraries component of OpenJDK failed to check current context / thread while performing object deserialization, possibly leading to incorrect input deserialization. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions.
Discussion:
Public now via Oracle Critical Patch Update - July 2015. Fixed in Oracle Java SE 6u101, 7u85, and 8u51.
External References:
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html#AppendixJAVA
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Via RHSA-2015:1230 https://rhn.redhat.com/errata/RHSA-2015-1230.html
---
This issue h
Bugzilla
CVE-2015-1230 chromium-browser: Type confusion in v8
bugzilla·2015-03-04·CVSS 7.5
CVE-2015-1230 [HIGH] CVE-2015-1230 chromium-browser: Type confusion in v8
CVE-2015-1230 chromium-browser: Type confusion in v8
An unspecified type confusion flaw was found in the v8 component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0627 https://rhn.redhat.com/errata/RHSA-2015-0627.html
http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0627.htmlhttp://www.securityfocus.com/bid/72901http://www.ubuntu.com/usn/USN-2521-1https://code.google.com/p/chromium/issues/detail?id=449610https://security.gentoo.org/glsa/201503-12https://src.chromium.org/viewvc/blink?revision=189006&view=revisionhttp://googlechromereleases.blogspot.com/2015/03/stable-channel-update.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0627.htmlhttp://www.securityfocus.com/bid/72901http://www.ubuntu.com/usn/USN-2521-1https://code.google.com/p/chromium/issues/detail?id=449610https://security.gentoo.org/glsa/201503-12https://src.chromium.org/viewvc/blink?revision=189006&view=revision
2015-03-09
Published