CVE-2015-1242
published 2015-04-19CVE-2015-1242: The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows…
PriorityP431high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.70%
84.2th percentile
The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that leverages "type confusion" in the check-elimination optimization.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| chrome | <= 42.0.2311.60 | — | |
| v8 | <= 4.2.77.7 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2015-04-27·CVSS 5.0
CVE-2015-1235 [MEDIUM] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
An issue was discovered in the HTML parser in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2015-1235)
An issue was discovered in the Web Audio API implementation in Blink. If
a user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to bypass same-origin restrictions.
(CVE-2015-1236)
A use-after-free was discovered in Chromium. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed re
Red Hat
chromium-browser: Type confusion in V8
vendor_redhat·2015-04-14·CVSS 7.5
CVE-2015-1242 [HIGH] CWE-704 chromium-browser: Type confusion in V8
chromium-browser: Type confusion in V8
The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that leverages "type confusion" in the check-elimination optimization.
GHSA
GHSA-cxw8-xrj2-2xqm: The ReduceTransitionElementsKind function in hydrogen-check-elimination
ghsa_unreviewed·2022-05-17
CVE-2015-1242 [HIGH] GHSA-cxw8-xrj2-2xqm: The ReduceTransitionElementsKind function in hydrogen-check-elimination
The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that leverages "type confusion" in the check-elimination optimization.
OSV
oxide-qt vulnerabilities
osv·2015-04-27·CVSS 5.0
CVE-2015-1235 [MEDIUM] oxide-qt vulnerabilities
oxide-qt vulnerabilities
An issue was discovered in the HTML parser in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2015-1235)
An issue was discovered in the Web Audio API implementation in Blink. If
a user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to bypass same-origin restrictions.
(CVE-2015-1236)
A use-after-free was discovered in Chromium. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2015-1237)
An out-of-bounds write was d
OSV
CVE-2015-1242: The ReduceTransitionElementsKind function in hydrogen-check-elimination
osv·2015-04-19·CVSS 7.5
CVE-2015-1242 [HIGH] CVE-2015-1242: The ReduceTransitionElementsKind function in hydrogen-check-elimination
The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that leverages "type confusion" in the check-elimination optimization.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-4729 Oracle JDK: unspecified vulnerability fixed in 7u85 and 8u51 (Deployment)
bugzilla·2015-07-15·CVSS 4.0
CVE-2015-4729 [MEDIUM] CVE-2015-4729 Oracle JDK: unspecified vulnerability fixed in 7u85 and 8u51 (Deployment)
CVE-2015-4729 Oracle JDK: unspecified vulnerability fixed in 7u85 and 8u51 (Deployment)
Oracle Java SE 7u85 and 8u51 fixes an unspecified vulnerability in the Deployment component (CVE-2015-4729). Upstream has CVSSv2 scored this issue as: 4.0/AV:N/AC:H/Au:N/C:P/I:P/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html#AppendixJAVA
Discussion:
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 6
Oracle Java for Red Hat Enterprise Linux 7
Oracle Java for Red Hat Enterprise Linux 5
Via RHSA-2015:1242 https://rhn.redhat.com/errata/RHSA-2015-1242.html
---
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 6
Oracle Java for Red Hat Enterprise Linux 7
Bugzilla
CVE-2015-2619 Oracle JDK: unspecified vulnerability fixed in 7u85 and 8u51 (2D)
bugzilla·2015-07-15·CVSS 5.0
CVE-2015-2619 [MEDIUM] CVE-2015-2619 Oracle JDK: unspecified vulnerability fixed in 7u85 and 8u51 (2D)
CVE-2015-2619 Oracle JDK: unspecified vulnerability fixed in 7u85 and 8u51 (2D)
Oracle Java SE 7u85 and 8u51 fixes an unspecified vulnerability in the 2D component (CVE-2015-2619). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html#AppendixJAVA
Discussion:
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 6
Oracle Java for Red Hat Enterprise Linux 7
Oracle Java for Red Hat Enterprise Linux 5
Via RHSA-2015:1242 https://rhn.redhat.com/errata/RHSA-2015-1242.html
---
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 6
Oracle Java for Red Hat Enterprise Linux 7
Via RHSA-2015:
Bugzilla
CVE-2015-2596 Oracle JDK: unspecified vulnerability fixed in 7u85 (Hotspot)
bugzilla·2015-07-15·CVSS 4.3
CVE-2015-2596 [MEDIUM] CVE-2015-2596 Oracle JDK: unspecified vulnerability fixed in 7u85 (Hotspot)
CVE-2015-2596 Oracle JDK: unspecified vulnerability fixed in 7u85 (Hotspot)
Oracle Java SE 7u85 fixes an unspecified vulnerability in the Hotspot component (CVE-2015-2596). Upstream has CVSSv2 scored this issue as: 4.3/AV:N/AC:M/Au:N/C:N/I:P/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html#AppendixJAVA
Discussion:
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 6
Oracle Java for Red Hat Enterprise Linux 7
Oracle Java for Red Hat Enterprise Linux 5
Via RHSA-2015:1242 https://rhn.redhat.com/errata/RHSA-2015-1242.html
Bugzilla
CVE-2015-4736 Oracle JDK: unspecified vulnerability fixed in 7u85 and 8u51 (Deployment)
bugzilla·2015-07-15·CVSS 9.3
CVE-2015-4736 [CRITICAL] CVE-2015-4736 Oracle JDK: unspecified vulnerability fixed in 7u85 and 8u51 (Deployment)
CVE-2015-4736 Oracle JDK: unspecified vulnerability fixed in 7u85 and 8u51 (Deployment)
Oracle Java SE 7u85 and 8u51 fixes an unspecified vulnerability in the Deployment component (CVE-2015-4736). Upstream has CVSSv2 scored this issue as: 9.3/AV:N/AC:M/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html#AppendixJAVA
Discussion:
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 6
Oracle Java for Red Hat Enterprise Linux 7
Oracle Java for Red Hat Enterprise Linux 5
Via RHSA-2015:1242 https://rhn.redhat.com/errata/RHSA-2015-1242.html
---
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 6
Oracle Java for Red Hat Enterprise Linux 7
Bugzilla
CVE-2015-1242 chromium-browser: Type confusion in V8
bugzilla·2015-04-15·CVSS 7.5
CVE-2015-1242 [HIGH] CVE-2015-1242 chromium-browser: Type confusion in V8
CVE-2015-1242 chromium-browser: Type confusion in V8
An unspecified type confusion flaw was found in the V8 component of the Chromium browser.
Upstream bug: https://code.google.com/p/chromium/issues/detail?id=460917
External References:
http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0816 https://rhn.redhat.com/errata/RHSA-2015-0816.html
http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00040.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00024.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0816.htmlhttp://ubuntu.com/usn/usn-2570-1http://www.debian.org/security/2015/dsa-3238http://www.securitytracker.com/id/1032209https://code.google.com/p/chromium/issues/detail?id=460917https://codereview.chromium.org/1000893003https://codereview.chromium.org/1019033004https://security.gentoo.org/glsa/201506-04http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00040.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00024.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0816.htmlhttp://ubuntu.com/usn/usn-2570-1http://www.debian.org/security/2015/dsa-3238http://www.securitytracker.com/id/1032209https://code.google.com/p/chromium/issues/detail?id=460917https://codereview.chromium.org/1000893003https://codereview.chromium.org/1019033004https://security.gentoo.org/glsa/201506-04
2015-04-19
Published