CVE-2015-1234
published 2015-04-01CVE-2015-1234: Race condition in gpu/command_buffer/service/gles2_cmd_decoder.cc in Google Chrome before 41.0.2272.118 allows remote attackers to cause a denial of service…
PriorityP429medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.45%
70.8th percentile
Race condition in gpu/command_buffer/service/gles2_cmd_decoder.cc in Google Chrome before 41.0.2272.118 allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact by manipulating OpenGL ES commands.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 41.0.2272.102 | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9w5w-83r2-23xw: Race condition in gpu/command_buffer/service/gles2_cmd_decoder
ghsa_unreviewed·2022-05-13
CVE-2015-1234 [MEDIUM] CWE-362 GHSA-9w5w-83r2-23xw: Race condition in gpu/command_buffer/service/gles2_cmd_decoder
Race condition in gpu/command_buffer/service/gles2_cmd_decoder.cc in Google Chrome before 41.0.2272.118 allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact by manipulating OpenGL ES commands.
OSV
oxide-qt vulnerabilities
osv·2015-04-07·CVSS 7.5
CVE-2015-1233 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
It was discovered that Chromium did not properly handle the interaction
of IPC, the gamepad API and V8. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
execute arbitrary code with the privileges of the user invoking the
program. (CVE-2015-1233)
A buffer overflow was discovered in the GPU service. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via application
crash. (CVE-2015-1234)
It was discovered that Oxide did not correctly manage the lifetime of
BrowserContext, resulting in a potential use-after-free in some
circumstances. If a user were tricked in to opening a specially crafted
website, an attacker could
OSV
CVE-2015-1234: Race condition in gpu/command_buffer/service/gles2_cmd_decoder
osv·2015-04-01·CVSS 6.8
CVE-2015-1234 [MEDIUM] CVE-2015-1234: Race condition in gpu/command_buffer/service/gles2_cmd_decoder
Race condition in gpu/command_buffer/service/gles2_cmd_decoder.cc in Google Chrome before 41.0.2272.118 allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact by manipulating OpenGL ES commands.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2015-04-07·CVSS 7.5
CVE-2015-1233 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
It was discovered that Chromium did not properly handle the interaction
of IPC, the gamepad API and V8. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
execute arbitrary code with the privileges of the user invoking the
program. (CVE-2015-1233)
A buffer overflow was discovered in the GPU service. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via application
crash. (CVE-2015-1234)
It was discovered that Oxide did not correctly manage the lifetime of
BrowserContext, resulting in a potential use-after-free in some
circumstances. If a user were tricked in
Red Hat
chromium-browser: buffer overflow via race condition in GPU
vendor_redhat·2015-04-02·CVSS 6.8
CVE-2015-1234 [MEDIUM] CWE-122 chromium-browser: buffer overflow via race condition in GPU
chromium-browser: buffer overflow via race condition in GPU
Race condition in gpu/command_buffer/service/gles2_cmd_decoder.cc in Google Chrome before 41.0.2272.118 allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact by manipulating OpenGL ES commands.
No detection rules found.
No public exploits indexed.
arXiv
SOK: On the Analysis of Web Browser Security
arxiv_fulltext·2021-12-31
SOK: On the Analysis of Web Browser Security
: On the Analysis of Web Browser Security
fancyplain
Rev.
\ of LastPage
Jungwon Lim*,\;
Yonghwi Jin*^ ,\;
Mansour Alharthi,\;
Xiaokuan Zhang,\;
Jinho Jung,\;
Rajat Gupta,\;
Kuilin Li,\;
Daehee Jang^ ,\;
Taesoo Kim\;
Georgia Institute of Technology ^ Theori Inc. ^ Sungshin Women's University
## Abstract
Web browsers are integral parts of everyone's daily life.
They are commonly used
for security-critical and privacy sensitive tasks,
like banking transactions and checking medical records.
Unfortunately,
modern web browsers are
too complex to be bug free
( , 25 million lines of code in Chrome),
and their role as an interface to the cyberspace
makes them an attractive target for attacks.
Accordingly,
web browsers naturally
become an arena for demonstrating
advanced exploitation techni
arXiv
Rethinking Misalignment to Raise the Bar for Heap Pointer Corruption
arxiv_fulltext·2018-08-08
Rethinking Misalignment to Raise the Bar for Heap Pointer Corruption
Rethinking Misalignment to Raise the Bar for Heap Pointer Corruption
Daehee Jang
KAIST
[email protected]
Hojoon Lee
KAIST
[email protected]
Brent Byunghoon Kang
KAIST
[email protected]
Michael Shell
Georgia Institute of Technology
[email protected]
Homer Simpson
Twentieth Century Fox
[email protected]
James Kirk
and Montgomery Scott
Starfleet Academy
[email protected]
\@IEEEpubidpullup9
Permission to freely reproduce all or part
of this paper for noncommercial purposes is granted provided that
copies bear this notice and the full citation on the first
page. Reproduction for commercial purposes is strictly prohibited
without the prior written consent of the Internet Society, the
first-named author (for reproduction of an entire paper only), and
the
Bugzilla
CVE-2015-1234 chromium-browser: buffer overflow via race condition in GPU
bugzilla·2015-04-02·CVSS 6.8
CVE-2015-1234 [MEDIUM] CVE-2015-1234 chromium-browser: buffer overflow via race condition in GPU
CVE-2015-1234 chromium-browser: buffer overflow via race condition in GPU
An unspecified flaws was found in the GPU component of the Chromium browser that leads to buffer overflow:
https://code.google.com/p/chromium/issues/detail?id=468936
External References:
http://googlechromereleases.blogspot.com/2015/04/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0778 https://rhn.redhat.com/errata/RHSA-2015-0778.html
http://googlechromereleases.blogspot.com/2015/04/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00024.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0778.htmlhttp://www.securityfocus.com/bid/73486http://www.securitytracker.com/id/1032012http://www.ubuntu.com/usn/USN-2556-1https://code.google.com/p/chromium/issues/detail?id=468936https://codereview.chromium.org/1016193003https://security.gentoo.org/glsa/201506-04http://googlechromereleases.blogspot.com/2015/04/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00024.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0778.htmlhttp://www.securityfocus.com/bid/73486http://www.securitytracker.com/id/1032012http://www.ubuntu.com/usn/USN-2556-1https://code.google.com/p/chromium/issues/detail?id=468936https://codereview.chromium.org/1016193003https://security.gentoo.org/glsa/201506-04
2015-04-01
Published