cbcvebase.
CVE-2015-1300
published 2015-09-03

CVE-2015-1300: The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before…

PriorityP424medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.75%
75.6th percentile
The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to obtain sensitive information via crafted JavaScript code that leverages a history.back call.

Affected

8 ranges
VendorProductVersion rangeFixed in
fedoraprojectfedora
fedoraprojectfedora
googlechrome<= 44.0.2403
mozillafirefox<= 42.0
mozillafirefox>= 0 < 43.0+build1-0ubuntu0.14.04.143.0+build1-0ubuntu0.14.04.1
opensuseleap
opensuseopensuse
opensuseopensuse

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv6.4MEDIUM
vendor_redhat10.0CRITICAL
vendor_ubuntu6.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.