CVE-2015-1233
published 2015-04-01CVE-2015-1233: Google Chrome before 41.0.2272.118 does not properly handle the interaction of IPC, the Gamepad API, and Google V8, which allows remote attackers to execute…
PriorityP347high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.30%
91.8th percentile
Google Chrome before 41.0.2272.118 does not properly handle the interaction of IPC, the Gamepad API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 41.0.2272.102 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f88w-w382-896c: Google Chrome before 41
ghsa_unreviewed·2022-05-13
CVE-2015-1233 [HIGH] GHSA-f88w-w382-896c: Google Chrome before 41
Google Chrome before 41.0.2272.118 does not properly handle the interaction of IPC, the Gamepad API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors.
OSV
oxide-qt vulnerabilities
osv·2015-04-07·CVSS 7.5
CVE-2015-1233 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
It was discovered that Chromium did not properly handle the interaction
of IPC, the gamepad API and V8. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
execute arbitrary code with the privileges of the user invoking the
program. (CVE-2015-1233)
A buffer overflow was discovered in the GPU service. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via application
crash. (CVE-2015-1234)
It was discovered that Oxide did not correctly manage the lifetime of
BrowserContext, resulting in a potential use-after-free in some
circumstances. If a user were tricked in to opening a specially crafted
website, an attacker could
OSV
CVE-2015-1233: Google Chrome before 41
osv·2015-04-01·CVSS 7.5
CVE-2015-1233 [HIGH] CVE-2015-1233: Google Chrome before 41
Google Chrome before 41.0.2272.118 does not properly handle the interaction of IPC, the Gamepad API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2015-04-07·CVSS 7.5
CVE-2015-1233 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
It was discovered that Chromium did not properly handle the interaction
of IPC, the gamepad API and V8. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
execute arbitrary code with the privileges of the user invoking the
program. (CVE-2015-1233)
A buffer overflow was discovered in the GPU service. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via application
crash. (CVE-2015-1234)
It was discovered that Oxide did not correctly manage the lifetime of
BrowserContext, resulting in a potential use-after-free in some
circumstances. If a user were tricked in
Red Hat
chromium-browser: combination of V8, Gamepad and IPC bugs that can lead to remote code execution
vendor_redhat·2015-04-02·CVSS 7.5
CVE-2015-1233 [HIGH] CWE-122 chromium-browser: combination of V8, Gamepad and IPC bugs that can lead to remote code execution
chromium-browser: combination of V8, Gamepad and IPC bugs that can lead to remote code execution
Google Chrome before 41.0.2272.118 does not properly handle the interaction of IPC, the Gamepad API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2015/04/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00024.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0778.htmlhttp://www.securityfocus.com/bid/73484http://www.securitytracker.com/id/1032012http://www.ubuntu.com/usn/USN-2556-1https://code.google.com/p/chromium/issues/detail?id=469058https://security.gentoo.org/glsa/201506-04http://googlechromereleases.blogspot.com/2015/04/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00024.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0778.htmlhttp://www.securityfocus.com/bid/73484http://www.securitytracker.com/id/1032012http://www.ubuntu.com/usn/USN-2556-1https://code.google.com/p/chromium/issues/detail?id=469058https://security.gentoo.org/glsa/201506-04
2015-04-01
Published