CVE-2015-1285
Severity
5.0MEDIUM
EPSS
1.1%
top 21.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 23
Latest updateMay 14
Description
The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for remote attackers to obtain sensitive information via an unspecified linear-time attack.
CVSS vector
AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9
Affected Packages6 packages
Also affects: Debian Linux 8.0, Enterprise Linux 6.0, 6.7z
🔴Vulnerability Details
3GHSA▶
GHSA-86pj-mwrp-p73h: The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor↗2022-05-14
CVEList
▶