CVE-2015-1255
published 2015-05-20CVE-2015-1255: Use-after-free vulnerability in content/renderer/media/webaudio_capturer_source.cc in the WebAudio implementation in Google Chrome before 43.0.2357.65 allows…
PriorityP425medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.45%
70.8th percentile
Use-after-free vulnerability in content/renderer/media/webaudio_capturer_source.cc in the WebAudio implementation in Google Chrome before 43.0.2357.65 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by leveraging improper handling of a stop action for an audio track.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| chrome | <= 42.0.2311.152 | — | |
| openstack | keystone | >= 0 < 0.3.16 | 0.3.16 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p4ff-c7wr-66j3: Use-after-free vulnerability in content/renderer/media/webaudio_capturer_source
ghsa_unreviewed·2022-05-17
CVE-2015-1255 [MEDIUM] GHSA-p4ff-c7wr-66j3: Use-after-free vulnerability in content/renderer/media/webaudio_capturer_source
Use-after-free vulnerability in content/renderer/media/webaudio_capturer_source.cc in the WebAudio implementation in Google Chrome before 43.0.2357.65 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by leveraging improper handling of a stop action for an audio track.
GHSA
Authentication Weakness in keystone
ghsa·2018-06-07
CVE-2015-9240 [HIGH] CWE-1255 Authentication Weakness in keystone
Authentication Weakness in keystone
Versions of `keystone` prior to 0.3.16 are affected by a partial authentication bypass vulnerability. In the default sign in functionality, if an attacker provides a full and correct password, yet only provides part of the associated email address, authentication will be granted.
## Recommendation
Update to version 0.3.16 or later.
OSV
oxide-qt vulnerabilities
osv·2015-05-21·CVSS 7.5
CVE-2015-1253 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
Several security issues were discovered in the DOM implementation in
Blink. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit these to bypass Same Origin Policy
restrictions. (CVE-2015-1253, CVE-2015-1254)
A use-after-free was discovered in the WebAudio implementation in
Chromium. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to cause a denial of
service via renderer crash, or execute arbitrary code with the privileges
of the sandboxed render process. (CVE-2015-1255)
A use-after-free was discovered in the SVG implementation in Blink. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cau
OSV
CVE-2015-1255: Use-after-free vulnerability in content/renderer/media/webaudio_capturer_source
osv·2015-05-20·CVSS 6.8
CVE-2015-1255 [MEDIUM] CVE-2015-1255: Use-after-free vulnerability in content/renderer/media/webaudio_capturer_source
Use-after-free vulnerability in content/renderer/media/webaudio_capturer_source.cc in the WebAudio implementation in Google Chrome before 43.0.2357.65 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by leveraging improper handling of a stop action for an audio track.
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2015-05-21·CVSS 7.5
CVE-2015-1253 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
Several security issues were discovered in the DOM implementation in
Blink. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit these to bypass Same Origin Policy
restrictions. (CVE-2015-1253, CVE-2015-1254)
A use-after-free was discovered in the WebAudio implementation in
Chromium. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to cause a denial of
service via renderer crash, or execute arbitrary code with the privileges
of the sandboxed render process. (CVE-2015-1255)
A use-after-free was discovered in the SVG implementation in Blink. If a
user were tricked in to opening a specially crafted
Red Hat
chromium-browser: Use-after-free in WebAudio.
vendor_redhat·2015-05-19·CVSS 6.8
CVE-2015-1255 [MEDIUM] CWE-416 chromium-browser: Use-after-free in WebAudio.
chromium-browser: Use-after-free in WebAudio.
Use-after-free vulnerability in content/renderer/media/webaudio_capturer_source.cc in the WebAudio implementation in Google Chrome before 43.0.2357.65 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by leveraging improper handling of a stop action for an audio track.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2015/05/stable-channel-update_19.htmlhttp://lists.opensuse.org/opensuse-updates/2015-05/msg00091.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00015.htmlhttp://www.debian.org/security/2015/dsa-3267http://www.securityfocus.com/bid/74723http://www.securitytracker.com/id/1032375https://code.google.com/p/chromium/issues/detail?id=473253https://codereview.chromium.org/1071063005https://security.gentoo.org/glsa/201506-04http://googlechromereleases.blogspot.com/2015/05/stable-channel-update_19.htmlhttp://lists.opensuse.org/opensuse-updates/2015-05/msg00091.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00015.htmlhttp://www.debian.org/security/2015/dsa-3267http://www.securityfocus.com/bid/74723http://www.securitytracker.com/id/1032375https://code.google.com/p/chromium/issues/detail?id=473253https://codereview.chromium.org/1071063005https://security.gentoo.org/glsa/201506-04
2015-05-20
Published