CVE-2015-1263Google Chrome vulnerability

CWE-179 documents5 sources
Severity
6.8MEDIUMNVD
NVD4.3OSV4.3
EPSS
0.7%
top 28.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 20
Latest updateMay 17

Description

The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages4 packages

Also affects: Debian Linux 8.0, Enterprise Linux 6.0, 6.7z

🔴Vulnerability Details

4
GHSA
GHSA-78h8-qhmw-gr92: The Spellcheck API implementation in Google Chrome before 432022-05-17
GHSA
GHSA-gg9q-x7v7-56vv: The Spellcheck API implementation in Google Chrome before 442022-05-14
OSV
CVE-2015-1288: The Spellcheck API implementation in Google Chrome before 442015-07-23
OSV
CVE-2015-1263: The Spellcheck API implementation in Google Chrome before 432015-05-20

📋Vendor Advisories

2
Red Hat
chromium-browser: Spell checking dictionaries fetched over HTTP in unspecified2015-07-21
Red Hat
chromium-browser: insecure download of spellcheck dictionary in unspecified component2015-05-19

💬Community

1
Bugzilla
CVE-2015-1263 chromium-browser: insecure download of spellcheck dictionary in unspecified component2015-05-20