CVE-2015-1300
published 2015-09-03CVE-2015-1300: The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before…
PriorityP424medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.75%
75.6th percentile
The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to obtain sensitive information via crafted JavaScript code that leverages a history.back call.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | <= 44.0.2403 | — | |
| mozilla | firefox | <= 42.0 | — |
| mozilla | firefox | >= 0 < 43.0+build1-0ubuntu0.14.04.1 | 43.0+build1-0ubuntu0.14.04.1 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv6.4MEDIUM
vendor_redhat10.0CRITICAL
vendor_ubuntu6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3xvg-65vh-g47p: The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext
ghsa_unreviewed·2022-05-17
CVE-2015-1300 [MEDIUM] GHSA-3xvg-65vh-g47p: The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext
The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to obtain sensitive information via crafted JavaScript code that leverages a history.back call.
GHSA
GHSA-5845-x3vj-jgw8: Mozilla Firefox before 43
ghsa_unreviewed·2022-05-14·CVSS 5.0
CVE-2015-7207 [MEDIUM] CWE-200 GHSA-5845-x3vj-jgw8: Mozilla Firefox before 43
Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.
OSV
CVE-2015-7207: Mozilla Firefox before 43
osv·2015-12-15·CVSS 5.0
CVE-2015-7207 [MEDIUM] CVE-2015-7207: Mozilla Firefox before 43
Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.
OSV
oxide-qt vulnerabilities
osv·2015-09-08·CVSS 6.4
CVE-2015-1291 [MEDIUM] oxide-qt vulnerabilities
oxide-qt vulnerabilities
It was discovered that the DOM tree could be corrupted during parsing in
some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit this to bypass
same-origin restrictions or cause a denial of service. (CVE-2015-1291)
An issue was discovered in NavigatorServiceWorker::serviceWorker in Blink.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to bypass same-origin
restrictions. (CVE-2015-1292)
An issue was discovered in the DOM implementation in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2015-1293)
A use-after-free was discovered
OSV
CVE-2015-1300: The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext
osv·2015-09-02·CVSS 5.0
CVE-2015-1300 [MEDIUM] CVE-2015-1300: The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext
The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to obtain sensitive information via crafted JavaScript code that leverages a history.back call.
Red Hat
Mozilla: Same-origin policy violation using perfomance.getEntries and history navigation (MFSA 2015-136)
vendor_redhat·2015-12-16·CVSS 5.0
CVE-2015-7207 [MEDIUM] Mozilla: Same-origin policy violation using perfomance.getEntries and history navigation (MFSA 2015-136)
Mozilla: Same-origin policy violation using perfomance.getEntries and history navigation (MFSA 2015-136)
Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Li
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2015-09-08·CVSS 6.4
CVE-2015-1291 [MEDIUM] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
It was discovered that the DOM tree could be corrupted during parsing in
some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit this to bypass
same-origin restrictions or cause a denial of service. (CVE-2015-1291)
An issue was discovered in NavigatorServiceWorker::serviceWorker in Blink.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to bypass same-origin
restrictions. (CVE-2015-1292)
An issue was discovered in the DOM implementation in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin res
Red Hat
chromium-browser: Information leak in Blink
vendor_redhat·2015-09-01·CVSS 5.0
CVE-2015-1300 [MEDIUM] CWE-200 chromium-browser: Information leak in Blink
chromium-browser: Information leak in Blink
The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to obtain sensitive information via crafted JavaScript code that leverages a history.back call.
Red Hat
webkitgtk: arbitrary code execution with root privileges (WSA-2015-0001)
vendor_redhat·2015-01-26·CVSS 10.0
CVE-2014-1300 [CRITICAL] webkitgtk: arbitrary code execution with root privileges (WSA-2015-0001)
webkitgtk: arbitrary code execution with root privileges (WSA-2015-0001)
Unspecified vulnerability in Apple Safari 7.0.2 on OS X allows remote attackers to execute arbitrary code with root privileges via unknown vectors, as demonstrated by Google during a Pwn4Fun competition at CanSecWest 2014.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Will not fix
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1300 chromium-browser: Information leak in Blink
bugzilla·2015-09-02·CVSS 5.0
CVE-2015-1300 [MEDIUM] CVE-2015-1300 chromium-browser: Information leak in Blink
CVE-2015-1300 chromium-browser: Information leak in Blink
An unspecified information leak flaw was found in the Blink component of the Chromium browser.
Upstream bug: https://code.google.com/p/chromium/issues/detail?id=511616
External References:
http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:1712 https://rhn.redhat.com/errata/RHSA-2015-1712.html
Bugzilla
CVE-2014-1300 webkitgtk: arbitrary code execution with root privileges (WSA-2015-0001)
bugzilla·2015-01-27·CVSS 10.0
CVE-2014-1300 [CRITICAL] CVE-2014-1300 webkitgtk: arbitrary code execution with root privileges (WSA-2015-0001)
CVE-2014-1300 webkitgtk: arbitrary code execution with root privileges (WSA-2015-0001)
Following vulnerability was discovered on the 2.4 stable series of WebKitGTK+:
CVE-2014-1300
Unspecified vulnerability in Apple Safari 7.0.2 on OS X allows remote attackers to execute arbitrary code with root privileges via unknown vectors, as demonstrated by Google during a Pwn4Fun competition at CanSecWest 2014.
External References:
http://webkitgtk.org/security/WSA-2015-0001.html
Discussion:
Statement:
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1712.htmlhttp://www.debian.org/security/2015/dsa-3351http://www.securitytracker.com/id/1033472https://code.google.com/p/chromium/issues/detail?id=511616https://github.com/w3c/resource-timing/issues/29https://security.gentoo.org/glsa/201603-09https://src.chromium.org/viewvc/blink?revision=199553&view=revisionhttp://googlechromereleases.blogspot.com/2015/09/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1712.htmlhttp://www.debian.org/security/2015/dsa-3351http://www.securitytracker.com/id/1033472https://code.google.com/p/chromium/issues/detail?id=511616https://github.com/w3c/resource-timing/issues/29https://security.gentoo.org/glsa/201603-09https://src.chromium.org/viewvc/blink?revision=199553&view=revision
2015-09-03
Published