CVE-2015-1274
Severity
6.8MEDIUM
EPSS
2.3%
top 15.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 23
Latest updateMay 14
Description
Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it easier for remote attackers to execute arbitrary code by providing a crafted file and leveraging a user's previous "Always open files of this type" choice, related to download_commands.cc and download_prefs.cc.
CVSS vector
AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4
Affected Packages5 packages
Also affects: Debian Linux 8.0, Enterprise Linux 6.0, 6.7.z
🔴Vulnerability Details
3📋Vendor Advisories
1Red Hat▶
chromium-browser: Settings allowed executable files to run immediately after download in unsepcified↗2015-07-21
💬Community
1Bugzilla▶
CVE-2015-1274 chromium-browser: Settings allowed executable files to run immediately after download in unsepcified↗2015-07-22