cbcvebase.
CVE-2015-1274
published 2015-07-23

CVE-2015-1274: Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it easier for remote attackers to execute…

medium6.8CVSS 3.1
AVNACMAuNCPIPAP
Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it easier for remote attackers to execute arbitrary code by providing a crafted file and leveraging a user's previous "Always open files of this type" choice, related to download_commands.cc and download_prefs.cc.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
googlechrome<= 43.0.2357.134
opensuseopensuse
opensuseopensuse
redhatenterprise_linux_desktop_supplementary
redhatenterprise_linux_server_supplementary
redhatenterprise_linux_server_supplementary
redhatenterprise_linux_workstation_supplementary

CVSS provenance

nvd6.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM