CVE-2015-1280

CWE-119Buffer Overflow7 documents7 sources
Severity
7.5HIGH
EPSS
2.2%
top 15.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateMay 14

Description

SkPictureShader.cpp in Skia, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging access to a renderer process and providing crafted serialized data.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages6 packages

NVDgoogle/chrome43.0.2357.134
Ubuntuoxide-qt< 1.8.4-0ubuntu0.14.04.2
Ubuntuchromium-browser< 44.0.2403.89-0ubuntu0.14.04.1.1095
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Debian Linux 8.0, Enterprise Linux 6.0, 6.7z

🔴Vulnerability Details

3
GHSA
GHSA-48wh-29xq-96fm: SkPictureShader2022-05-14
CVEList
CVE-2015-1280: SkPictureShader2015-07-23
OSV
CVE-2015-1280: SkPictureShader2015-07-22

📋Vendor Advisories

2
Ubuntu
Oxide vulnerabilities2015-08-04
Red Hat
chromium-browser: Memory corruption in skia2015-07-21

💬Community

1
Bugzilla
CVE-2015-1280 chromium-browser: Memory corruption in skia2015-07-22
CVE-2015-1280 (HIGH CVSS 7.5) | SkPictureShader.cpp in Skia | cvebase.io