CVE-2015-1246
published 2015-04-19CVE-2015-1246: Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
PriorityP420medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.58%
73.0th percentile
Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| chrome | <= 42.0.2311.60 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv9.8CRITICAL
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2015-04-27·CVSS 5.0
CVE-2015-1235 [MEDIUM] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
An issue was discovered in the HTML parser in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2015-1235)
An issue was discovered in the Web Audio API implementation in Blink. If
a user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to bypass same-origin restrictions.
(CVE-2015-1236)
A use-after-free was discovered in Chromium. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed re
Red Hat
chromium-browser: Out-of-bounds read in Blink
vendor_redhat·2015-04-14·CVSS 5.0
CVE-2015-1246 [MEDIUM] CWE-125 chromium-browser: Out-of-bounds read in Blink
chromium-browser: Out-of-bounds read in Blink
Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
GHSA
GHSA-cj69-qv22-52jw: Blink, as used in Google Chrome before 42
ghsa_unreviewed·2022-05-17
CVE-2015-1246 [MEDIUM] CWE-119 GHSA-cj69-qv22-52jw: Blink, as used in Google Chrome before 42
Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
OSV
libdbd-mysql-perl vulnerabilities
osv·2016-10-13·CVSS 9.8
CVE-2014-9906 libdbd-mysql-perl vulnerabilities
libdbd-mysql-perl vulnerabilities
It was discovered that DBD::mysql incorrectly handled certain memory
operations. A remote attacker could use this issue to cause DBD::mysql to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2014-9906)
Hanno Böck discovered that DBD::mysql incorrectly handled certain memory
operations. A remote attacker could use this issue to cause DBD::mysql to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2015-8949)
Pali Rohár discovered that DBD::mysql incorrectly handled certain user
supplied data. A remote attacker could use this issue to cause DBD::mysql
to crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2016-1246)
OSV
oxide-qt vulnerabilities
osv·2015-04-27·CVSS 5.0
CVE-2015-1235 [MEDIUM] oxide-qt vulnerabilities
oxide-qt vulnerabilities
An issue was discovered in the HTML parser in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2015-1235)
An issue was discovered in the Web Audio API implementation in Blink. If
a user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to bypass same-origin restrictions.
(CVE-2015-1236)
A use-after-free was discovered in Chromium. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2015-1237)
An out-of-bounds write was d
OSV
CVE-2015-1246: Blink, as used in Google Chrome before 42
osv·2015-04-19·CVSS 5.0
CVE-2015-1246 [MEDIUM] CVE-2015-1246: Blink, as used in Google Chrome before 42
Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00040.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00024.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0816.htmlhttp://ubuntu.com/usn/usn-2570-1http://www.debian.org/security/2015/dsa-3238http://www.securitytracker.com/id/1032209https://code.google.com/p/chromium/issues/detail?id=437399https://security.gentoo.org/glsa/201506-04http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00040.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00024.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0816.htmlhttp://ubuntu.com/usn/usn-2570-1http://www.debian.org/security/2015/dsa-3238http://www.securitytracker.com/id/1032209https://code.google.com/p/chromium/issues/detail?id=437399https://security.gentoo.org/glsa/201506-04
2015-04-19
Published