CVE-2015-1291
published 2015-09-03CVE-2015-1291: The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not check whether a…
PriorityP425medium6.4CVSS 2.0
AVNACLAuNCPINAP
EPSS
1.71%
75.2th percentile
The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not check whether a node is expected, which allows remote attackers to bypass the Same Origin Policy or cause a denial of service (DOM tree corruption) via a web site with crafted JavaScript code and IFRAME elements.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 44.0.2403 | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv6.4MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h2q2-7w6q-hq6j: The ContainerNode::parserRemoveChild function in core/dom/ContainerNode
ghsa_unreviewed·2022-05-17
CVE-2015-1291 [MEDIUM] GHSA-h2q2-7w6q-hq6j: The ContainerNode::parserRemoveChild function in core/dom/ContainerNode
The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not check whether a node is expected, which allows remote attackers to bypass the Same Origin Policy or cause a denial of service (DOM tree corruption) via a web site with crafted JavaScript code and IFRAME elements.
OSV
oxide-qt vulnerabilities
osv·2015-09-08·CVSS 6.4
CVE-2015-1291 [MEDIUM] oxide-qt vulnerabilities
oxide-qt vulnerabilities
It was discovered that the DOM tree could be corrupted during parsing in
some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit this to bypass
same-origin restrictions or cause a denial of service. (CVE-2015-1291)
An issue was discovered in NavigatorServiceWorker::serviceWorker in Blink.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to bypass same-origin
restrictions. (CVE-2015-1292)
An issue was discovered in the DOM implementation in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2015-1293)
A use-after-free was discovered
OSV
CVE-2015-1291: The ContainerNode::parserRemoveChild function in core/dom/ContainerNode
osv·2015-09-02·CVSS 6.4
CVE-2015-1291 [MEDIUM] CVE-2015-1291: The ContainerNode::parserRemoveChild function in core/dom/ContainerNode
The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not check whether a node is expected, which allows remote attackers to bypass the Same Origin Policy or cause a denial of service (DOM tree corruption) via a web site with crafted JavaScript code and IFRAME elements.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2015-09-08·CVSS 6.4
CVE-2015-1291 [MEDIUM] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
It was discovered that the DOM tree could be corrupted during parsing in
some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit this to bypass
same-origin restrictions or cause a denial of service. (CVE-2015-1291)
An issue was discovered in NavigatorServiceWorker::serviceWorker in Blink.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to bypass same-origin
restrictions. (CVE-2015-1292)
An issue was discovered in the DOM implementation in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin res
Red Hat
chromium-browser: Cross-origin bypass in DOM
vendor_redhat·2015-09-01·CVSS 6.4
CVE-2015-1291 [MEDIUM] chromium-browser: Cross-origin bypass in DOM
chromium-browser: Cross-origin bypass in DOM
The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not check whether a node is expected, which allows remote attackers to bypass the Same Origin Policy or cause a denial of service (DOM tree corruption) via a web site with crafted JavaScript code and IFRAME elements.
Red Hat
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
vendor_redhat·2015-01-26·CVSS 6.8
CVE-2014-1292 [MEDIUM] webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1293, and CVE-2014-1294.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1291 chromium-browser: Cross-origin bypass in DOM
bugzilla·2015-09-02·CVSS 6.4
CVE-2015-1291 [MEDIUM] CVE-2015-1291 chromium-browser: Cross-origin bypass in DOM
CVE-2015-1291 chromium-browser: Cross-origin bypass in DOM
Cross-origin bypass in DOM
Upstream bug: https://code.google.com/p/chromium/issues/detail?id=516377 (private)
External References:
http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:1712 https://rhn.redhat.com/errata/RHSA-2015-1712.html
Bugzilla
CVE-2014-1292 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
bugzilla·2015-01-27·CVSS 6.8
CVE-2014-1292 [MEDIUM] CVE-2014-1292 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
CVE-2014-1292 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
Following vulnerability was discovered on the 2.4 stable series of WebKitGTK+:
CVE-2014-1292
WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1293, and CVE-2014-1294
External References:
http://webkitgtk.org/security/WSA-2015-0001.html
Discussion:
Created webkitgtk4 tracking bugs for this issue:
Affects: fedora-all [bug 1186276]
---
Created webkitgtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1181092]
---
Statement
http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1712.htmlhttp://www.debian.org/security/2015/dsa-3351http://www.securitytracker.com/id/1033472https://code.google.com/p/chromium/issues/detail?id=516377https://security.gentoo.org/glsa/201603-09https://src.chromium.org/viewvc/blink?revision=200098&view=revisionhttp://googlechromereleases.blogspot.com/2015/09/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1712.htmlhttp://www.debian.org/security/2015/dsa-3351http://www.securitytracker.com/id/1033472https://code.google.com/p/chromium/issues/detail?id=516377https://security.gentoo.org/glsa/201603-09https://src.chromium.org/viewvc/blink?revision=200098&view=revision
2015-09-03
Published