CVE-2015-1289
published 2015-07-23CVE-2015-1289: Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via…
PriorityP429high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.34%
68.4th percentile
Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| chrome | <= 43.0.2357.134 | — | |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary_eus | — | — |
| redhat | enterprise_linux_workstation_supplementary | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-22w2-qhqg-5898: Multiple unspecified vulnerabilities in Google Chrome before 44
ghsa_unreviewed·2022-05-14
CVE-2015-1289 [HIGH] GHSA-22w2-qhqg-5898: Multiple unspecified vulnerabilities in Google Chrome before 44
Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
OSV
oxide-qt vulnerabilities
osv·2015-08-04·CVSS 6.8
CVE-2015-1270 [MEDIUM] oxide-qt vulnerabilities
oxide-qt vulnerabilities
An uninitialized value issue was discovered in ICU. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service. (CVE-2015-1270)
A use-after-free was discovered in the GPU process implementation in
Chromium. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to cause a denial of
service via application crash, or execute arbitrary code with the
privileges of the user invoking the program. (CVE-2015-1272)
A use-after-free was discovered in the IndexedDB implementation in
Chromium. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to cause a denial of
service via applicatio
OSV
CVE-2015-1289: Multiple unspecified vulnerabilities in Google Chrome before 44
osv·2015-07-22·CVSS 7.5
CVE-2015-1289 [HIGH] CVE-2015-1289: Multiple unspecified vulnerabilities in Google Chrome before 44
Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2015-08-04·CVSS 6.8
CVE-2015-1270 [MEDIUM] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
An uninitialized value issue was discovered in ICU. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service. (CVE-2015-1270)
A use-after-free was discovered in the GPU process implementation in
Chromium. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to cause a denial of
service via application crash, or execute arbitrary code with the
privileges of the user invoking the program. (CVE-2015-1272)
A use-after-free was discovered in the IndexedDB implementation in
Chromium. If a user were tricked in to opening a specially crafted
website, an attacker could potential
Red Hat
chromium-browser: Various fixes from internal audits, fuzzing and other initiatives
vendor_redhat·2015-07-21·CVSS 7.5
CVE-2015-1289 [HIGH] chromium-browser: Various fixes from internal audits, fuzzing and other initiatives
chromium-browser: Various fixes from internal audits, fuzzing and other initiatives
Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Red Hat
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
vendor_redhat·2015-01-26·CVSS 6.8
CVE-2014-1292 [MEDIUM] webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1293, and CVE-2014-1294.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1289 chromium-browser: Various fixes from internal audits, fuzzing and other initiatives
bugzilla·2015-07-22·CVSS 7.5
CVE-2015-1289 [HIGH] CVE-2015-1289 chromium-browser: Various fixes from internal audits, fuzzing and other initiatives
CVE-2015-1289 chromium-browser: Various fixes from internal audits, fuzzing and other initiatives
An unspecified various fixes from internal audits, fuzzing and other initiatives
flawis were found in the unpsecified component of the Chromium browser.
Upstream bug: https://code.google.com/p/chromium/issues/detail?id=512110
External References:
http://googlechromereleases.blogspot.com/2015/07/stable-channel-update_21.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:1499 https://rhn.redhat.com/errata/RHSA-2015-1499.html
Bugzilla
CVE-2014-1292 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
bugzilla·2015-01-27·CVSS 6.8
CVE-2014-1292 [MEDIUM] CVE-2014-1292 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
CVE-2014-1292 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
Following vulnerability was discovered on the 2.4 stable series of WebKitGTK+:
CVE-2014-1292
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1293, and CVE-2014-1294
External References:
http://webkitgtk.org/security/WSA-2015-0001.html
Discussion:
Created webkitgtk4 tracking bugs for this issue:
Affects: fedora-all [bug 1186276]
---
Created webkitgtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1181092]
---
Statement
http://googlechromereleases.blogspot.com/2015/07/stable-channel-update_21.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00038.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1499.htmlhttp://www.debian.org/security/2015/dsa-3315http://www.securityfocus.com/bid/75973http://www.securitytracker.com/id/1033031https://code.google.com/p/chromium/issues/detail?id=512110https://crbug.com/398235https://crbug.com/401995https://crbug.com/404462https://crbug.com/458024https://crbug.com/459898https://crbug.com/460938https://crbug.com/471990https://crbug.com/477713https://crbug.com/478575https://crbug.com/484432https://crbug.com/485855https://crbug.com/486004https://crbug.com/487286https://crbug.com/491216https://crbug.com/492448https://crbug.com/492981https://crbug.com/495682https://crbug.com/504692https://crbug.com/506749https://crbug.com/507821https://security.gentoo.org/glsa/201603-09http://googlechromereleases.blogspot.com/2015/07/stable-channel-update_21.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00038.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1499.htmlhttp://www.debian.org/security/2015/dsa-3315http://www.securityfocus.com/bid/75973http://www.securitytracker.com/id/1033031https://code.google.com/p/chromium/issues/detail?id=512110https://crbug.com/398235https://crbug.com/401995https://crbug.com/404462https://crbug.com/458024https://crbug.com/459898https://crbug.com/460938https://crbug.com/471990https://crbug.com/477713https://crbug.com/478575https://crbug.com/484432https://crbug.com/485855https://crbug.com/486004https://crbug.com/487286https://crbug.com/491216https://crbug.com/492448https://crbug.com/492981https://crbug.com/495682https://crbug.com/504692https://crbug.com/506749https://crbug.com/507821https://security.gentoo.org/glsa/201603-09
2015-07-23
Published