Description
Use-after-free vulnerability in the shared-timer implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging erroneous timer firing, related to ThreadTimers.cpp and Timer.cpp.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4 Affected Packages1 packages
🔴Vulnerability Details
3GHSAGHSA-cr9h-qgj5-h762: Use-after-free vulnerability in the shared-timer implementation in Blink, as used in Google Chrome before 45↗2022-05-17 ▶ OSVoxide-qt vulnerabilities↗2015-09-08 ▶ OSVCVE-2015-1299: Use-after-free vulnerability in the shared-timer implementation in Blink, as used in Google Chrome before 45↗2015-09-02 ▶ 💥Exploits & PoCs
1Exploit-DBWireshark - 'infer_pkt_encap' Heap Out-of-Bounds Read↗2015-12-22 ▶ 📋Vendor Advisories
3UbuntuOxide vulnerabilities↗2015-09-08 ▶ Red Hatchromium-browser: Use-after-free in Blink↗2015-09-01 ▶ Red Hatwebkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)↗2015-01-26 ▶ 💬Community
2BugzillaCVE-2015-1299 chromium-browser: Use-after-free in Blink↗2015-09-02 ▶ BugzillaCVE-2014-1299 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)↗2015-01-27 ▶