cbcvebase.
CVE-2015-1283
published 2015-07-23

CVE-2015-1283: Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote…

PriorityP340medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
19.07%
97.0th percentile
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.

Affected

57 ranges· showing 25
VendorProductVersion rangeFixed in
appleitunes
appleitunes_12.6_for_windows
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianexpat< expat 2.1.1-2 (bookworm)expat 2.1.1-2 (bookworm)
debianexpat< expat 2.1.0-7 (bookworm)expat 2.1.0-7 (bookworm)
debianlibxmltok< expat 2.1.1-2 (bookworm)expat 2.1.1-2 (bookworm)
debianlibxmltok< expat 2.1.0-7 (bookworm)expat 2.1.0-7 (bookworm)
googleandroid
googlechrome<= 43.0.2357.134
libexpat_projectlibexpat<= 2.1.0
libexpat_projectlibexpat<= 2.1.1
mcafeepolicy_auditor< 6.5.16.5.1
mozillafirefox<= 37.0.2
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.