CVE-2015-1276

CWE-416Use After Free7 documents7 sources
Severity
9.8CRITICAL
EPSS
2.8%
top 13.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateMay 14

Description

Use-after-free vulnerability in content/browser/indexed_db/indexed_db_backing_store.cc in the IndexedDB implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging an abort action before a certain write operation.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages6 packages

NVDgoogle/chrome43.0.2357.134
Ubuntuchromium-browser< 44.0.2403.89-0ubuntu0.14.04.1.1095
Ubuntuoxide-qt< 1.8.4-0ubuntu0.14.04.2
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Debian Linux 8.0, Enterprise Linux 6.0, 6.7z

🔴Vulnerability Details

3
GHSA
GHSA-x6jq-g95p-hjc3: Use-after-free vulnerability in content/browser/indexed_db/indexed_db_backing_store2022-05-14
CVEList
CVE-2015-1276: Use-after-free vulnerability in content/browser/indexed_db/indexed_db_backing_store2015-07-23
OSV
CVE-2015-1276: Use-after-free vulnerability in content/browser/indexed_db/indexed_db_backing_store2015-07-22

📋Vendor Advisories

2
Ubuntu
Oxide vulnerabilities2015-08-04
Red Hat
chromium-browser: Use-after-free in IndexedDB.2015-07-21

💬Community

1
Bugzilla
CVE-2015-1276 chromium-browser: Use-after-free in IndexedDB.2015-07-22
CVE-2015-1276 (CRITICAL CVSS 9.8) | Use-after-free vulnerability in con | cvebase.io