CVE-2015-1252
published 2015-05-20CVE-2015-1252: common/partial_circular_buffer.cc in Google Chrome before 43.0.2357.65 does not properly handle wraps, which allows remote attackers to bypass a sandbox…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.70%
75.0th percentile
common/partial_circular_buffer.cc in Google Chrome before 43.0.2357.65 does not properly handle wraps, which allows remote attackers to bypass a sandbox protection mechanism or cause a denial of service (out-of-bounds write) via vectors that trigger a write operation with a large amount of data, related to the PartialCircularBuffer::Write and PartialCircularBuffer::DoWrite functions.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| chrome | <= 42.0.2311.152 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: Sandbox escape in Chrome.
vendor_redhat·2015-05-19·CVSS 7.5
CVE-2015-1252 [HIGH] chromium-browser: Sandbox escape in Chrome.
chromium-browser: Sandbox escape in Chrome.
common/partial_circular_buffer.cc in Google Chrome before 43.0.2357.65 does not properly handle wraps, which allows remote attackers to bypass a sandbox protection mechanism or cause a denial of service (out-of-bounds write) via vectors that trigger a write operation with a large amount of data, related to the PartialCircularBuffer::Write and PartialCircularBuffer::DoWrite functions.
GHSA
GHSA-9qfw-82fr-g926: common/partial_circular_buffer
ghsa_unreviewed·2022-05-17
CVE-2015-1252 [HIGH] CWE-119 GHSA-9qfw-82fr-g926: common/partial_circular_buffer
common/partial_circular_buffer.cc in Google Chrome before 43.0.2357.65 does not properly handle wraps, which allows remote attackers to bypass a sandbox protection mechanism or cause a denial of service (out-of-bounds write) via vectors that trigger a write operation with a large amount of data, related to the PartialCircularBuffer::Write and PartialCircularBuffer::DoWrite functions.
OSV
CVE-2015-1252: common/partial_circular_buffer
osv·2015-05-20·CVSS 7.5
CVE-2015-1252 [HIGH] CVE-2015-1252: common/partial_circular_buffer
common/partial_circular_buffer.cc in Google Chrome before 43.0.2357.65 does not properly handle wraps, which allows remote attackers to bypass a sandbox protection mechanism or cause a denial of service (out-of-bounds write) via vectors that trigger a write operation with a large amount of data, related to the PartialCircularBuffer::Write and PartialCircularBuffer::DoWrite functions.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2015/05/stable-channel-update_19.htmlhttp://lists.opensuse.org/opensuse-updates/2015-05/msg00091.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00015.htmlhttp://www.debian.org/security/2015/dsa-3267http://www.securityfocus.com/bid/74723http://www.securitytracker.com/id/1032375https://code.google.com/p/chromium/issues/detail?id=474029https://codereview.chromium.org/1061053002https://security.gentoo.org/glsa/201506-04http://googlechromereleases.blogspot.com/2015/05/stable-channel-update_19.htmlhttp://lists.opensuse.org/opensuse-updates/2015-05/msg00091.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00015.htmlhttp://www.debian.org/security/2015/dsa-3267http://www.securityfocus.com/bid/74723http://www.securitytracker.com/id/1032375https://code.google.com/p/chromium/issues/detail?id=474029https://codereview.chromium.org/1061053002https://security.gentoo.org/glsa/201506-04
2015-05-20
Published