CVE-2015-1237
published 2015-04-19CVE-2015-1237: Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0.2311.90…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.68%
74.7th percentile
Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger renderer IPC messages during a detach operation.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| chrome | <= 42.0.2311.60 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2015-04-27·CVSS 5.0
CVE-2015-1235 [MEDIUM] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
An issue was discovered in the HTML parser in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2015-1235)
An issue was discovered in the Web Audio API implementation in Blink. If
a user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to bypass same-origin restrictions.
(CVE-2015-1236)
A use-after-free was discovered in Chromium. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed re
Red Hat
chromium-browser: Use-after-free in IPC
vendor_redhat·2015-04-14·CVSS 7.5
CVE-2015-1237 [HIGH] CWE-416 chromium-browser: Use-after-free in IPC
chromium-browser: Use-after-free in IPC
Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger renderer IPC messages during a detach operation.
GHSA
GHSA-79m3-pjgp-p5fq: Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl
ghsa_unreviewed·2022-05-17
CVE-2015-1237 [HIGH] GHSA-79m3-pjgp-p5fq: Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl
Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger renderer IPC messages during a detach operation.
OSV
oxide-qt vulnerabilities
osv·2015-04-27·CVSS 5.0
CVE-2015-1235 [MEDIUM] oxide-qt vulnerabilities
oxide-qt vulnerabilities
An issue was discovered in the HTML parser in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2015-1235)
An issue was discovered in the Web Audio API implementation in Blink. If
a user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to bypass same-origin restrictions.
(CVE-2015-1236)
A use-after-free was discovered in Chromium. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2015-1237)
An out-of-bounds write was d
OSV
CVE-2015-1237: Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl
osv·2015-04-19·CVSS 7.5
CVE-2015-1237 [HIGH] CVE-2015-1237: Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl
Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger renderer IPC messages during a detach operation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8898 ImageMagick: Prevent NULL pointer access in magick/constitute.c
bugzilla·2016-06-09·CVSS 5.5
CVE-2015-8898 [MEDIUM] CVE-2015-8898 ImageMagick: Prevent NULL pointer access in magick/constitute.c
CVE-2015-8898 ImageMagick: Prevent NULL pointer access in magick/constitute.c
A null pointer dereference flaw has been discovered in the constitute image
functionality, which could lead to an application crash.
External references:
https://github.com/ImageMagick/ImageMagick/pull/34
http://seclists.org/oss-sec/2016/q2/459
Patch:
https://github.com/ImageMagick/ImageMagick/pull/34/commits/aa785715d46f2b18b60c652a177c57bc8f0a0a68
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1344266]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:1237 https://access.redhat.com/errata/RHSA-2016:1237
Bugzilla
CVE-2015-8897 ImageMagick: Crash due to out of bounds error in SpliceImage
bugzilla·2016-06-09·CVSS 5.5
CVE-2015-8897 [MEDIUM] CVE-2015-8897 ImageMagick: Crash due to out of bounds error in SpliceImage
CVE-2015-8897 ImageMagick: Crash due to out of bounds error in SpliceImage
An error was discovered in the ImageMagick -split functionality. Processing
a specially crafted image using this functionality could lead to an application crash.
External references:
http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=28466
http://seclists.org/oss-sec/2016/q2/459
Patch:
http://git.imagemagick.org/repos/ImageMagick/commit/e00cf211070e7f150a3da77932b8620c89bb9225
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1344273]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:1237 https://access.redhat.com/errata/RHSA-2016:1237
Bugzilla
CVE-2015-1237 chromium-browser: Use-after-free in IPC
bugzilla·2015-04-15·CVSS 7.5
CVE-2015-1237 [HIGH] CVE-2015-1237 chromium-browser: Use-after-free in IPC
CVE-2015-1237 chromium-browser: Use-after-free in IPC
An unspecified use-after-free flaw was found in the IPC component of the Chromium browser.
Upstream bug: https://code.google.com/p/chromium/issues/detail?id=461191
External References:
http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0816 https://rhn.redhat.com/errata/RHSA-2015-0816.html
http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00040.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00024.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0816.htmlhttp://ubuntu.com/usn/usn-2570-1http://www.debian.org/security/2015/dsa-3238http://www.securitytracker.com/id/1032209https://code.google.com/p/chromium/issues/detail?id=461191https://codereview.chromium.org/1007123003https://security.gentoo.org/glsa/201506-04http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00040.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00024.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0816.htmlhttp://ubuntu.com/usn/usn-2570-1http://www.debian.org/security/2015/dsa-3238http://www.securitytracker.com/id/1032209https://code.google.com/p/chromium/issues/detail?id=461191https://codereview.chromium.org/1007123003https://security.gentoo.org/glsa/201506-04
2015-04-19
Published