CVE-2015-1271Improper Restriction of Operations within the Bounds of a Memory Buffer in Google Chrome

Severity
6.8MEDIUMNVD
EPSS
2.9%
top 13.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateMay 14

Description

PDFium, as used in Google Chrome before 44.0.2403.89, does not properly handle certain out-of-memory conditions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted PDF document that triggers a large memory allocation.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages4 packages

Also affects: Debian Linux 8.0, Enterprise Linux 6.0, 6.7z

🔴Vulnerability Details

3
GHSA
GHSA-ghfv-3fj8-h7jx: PDFium, as used in Google Chrome before 442022-05-14
OSV
CVE-2015-1271: PDFium, as used in Google Chrome before 442015-07-23
CVEList
CVE-2015-1271: PDFium, as used in Google Chrome before 442015-07-23

📋Vendor Advisories

2
Juniper
CVE-2016-1271: Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D25, 13.2 before 13.2R8, 13.3 before 13.32016-04-15
Red Hat
chromium-browser: Heap-buffer-overflow in pdfium2015-07-21

💬Community

1
Bugzilla
CVE-2015-1271 chromium-browser: Heap-buffer-overflow in pdfium2015-07-22
CVE-2015-1271 — Google Chrome vulnerability | cvebase