cbcvebase.
CVE-2015-1276
published 2015-07-23

CVE-2015-1276: Use-after-free vulnerability in content/browser/indexed_db/indexed_db_backing_store.cc in the IndexedDB implementation in Google Chrome before 44.0.2403.89…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
Use-after-free vulnerability in content/browser/indexed_db/indexed_db_backing_store.cc in the IndexedDB implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging an abort action before a certain write operation.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
googlechrome<= 43.0.2357.134
opensuseopensuse
opensuseopensuse
redhatenterprise_linux_desktop_supplementary
redhatenterprise_linux_server_supplementary
redhatenterprise_linux_server_supplementary_eus
redhatenterprise_linux_workstation_supplementary

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL