CVE-2015-1263
published 2015-05-20CVE-2015-1263: The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.99%
59.1th percentile
The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| chrome | <= 43.0.2357.134 | — | |
| chrome | <= 42.0.2311.152 | — | |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary_eus | — | — |
| redhat | enterprise_linux_workstation_supplementary | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-78h8-qhmw-gr92: The Spellcheck API implementation in Google Chrome before 43
ghsa_unreviewed·2022-05-17
CVE-2015-1263 [MEDIUM] GHSA-78h8-qhmw-gr92: The Spellcheck API implementation in Google Chrome before 43
The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.
GHSA
GHSA-gg9q-x7v7-56vv: The Spellcheck API implementation in Google Chrome before 44
ghsa_unreviewed·2022-05-14·CVSS 4.3
CVE-2015-1288 [MEDIUM] GHSA-gg9q-x7v7-56vv: The Spellcheck API implementation in Google Chrome before 44
The Spellcheck API implementation in Google Chrome before 44.0.2403.89 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file, a related issue to CVE-2015-1263.
OSV
CVE-2015-1288: The Spellcheck API implementation in Google Chrome before 44
osv·2015-07-23·CVSS 4.3
CVE-2015-1288 [MEDIUM] CVE-2015-1288: The Spellcheck API implementation in Google Chrome before 44
The Spellcheck API implementation in Google Chrome before 44.0.2403.89 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file, a related issue to CVE-2015-1263.
OSV
CVE-2015-1263: The Spellcheck API implementation in Google Chrome before 43
osv·2015-05-20·CVSS 4.3
CVE-2015-1263 [MEDIUM] CVE-2015-1263: The Spellcheck API implementation in Google Chrome before 43
The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.
Red Hat
chromium-browser: Spell checking dictionaries fetched over HTTP in unspecified
vendor_redhat·2015-07-21·CVSS 4.3
CVE-2015-1288 [MEDIUM] chromium-browser: Spell checking dictionaries fetched over HTTP in unspecified
chromium-browser: Spell checking dictionaries fetched over HTTP in unspecified
The Spellcheck API implementation in Google Chrome before 44.0.2403.89 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file, a related issue to CVE-2015-1263.
Red Hat
chromium-browser: insecure download of spellcheck dictionary in unspecified component
vendor_redhat·2015-05-19·CVSS 4.3
CVE-2015-1263 [MEDIUM] chromium-browser: insecure download of spellcheck dictionary in unspecified component
chromium-browser: insecure download of spellcheck dictionary in unspecified component
The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2015/05/stable-channel-update_19.htmlhttp://lists.opensuse.org/opensuse-updates/2015-05/msg00091.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00015.htmlhttp://www.debian.org/security/2015/dsa-3267http://www.securityfocus.com/bid/74723http://www.securitytracker.com/id/1032375https://code.google.com/p/chromium/issues/detail?id=479162https://codereview.chromium.org/1056103005https://security.gentoo.org/glsa/201506-04http://googlechromereleases.blogspot.com/2015/05/stable-channel-update_19.htmlhttp://lists.opensuse.org/opensuse-updates/2015-05/msg00091.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00015.htmlhttp://www.debian.org/security/2015/dsa-3267http://www.securityfocus.com/bid/74723http://www.securitytracker.com/id/1032375https://code.google.com/p/chromium/issues/detail?id=479162https://codereview.chromium.org/1056103005https://security.gentoo.org/glsa/201506-04
2015-05-20
Published