CVE-2015-1302
published 2015-11-11CVE-2015-1302: The PDF viewer in Google Chrome before 46.0.2490.86 does not properly restrict scripting messages and API exposure, which allows remote attackers to bypass the…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.86%
77.2th percentile
The PDF viewer in Google Chrome before 46.0.2490.86 does not properly restrict scripting messages and API exposure, which allows remote attackers to bypass the Same Origin Policy via an unintended embedder or unintended plugin loading, related to pdf.js and out_of_process_instance.cc.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | netscaler_adc_gateway | — | — |
| chrome | <= 46.0.2490.80 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5f5g-9jr3-xpmv: The PDF viewer in Google Chrome before 46
ghsa_unreviewed·2022-05-14
CVE-2015-1302 [HIGH] CWE-20 GHSA-5f5g-9jr3-xpmv: The PDF viewer in Google Chrome before 46
The PDF viewer in Google Chrome before 46.0.2490.86 does not properly restrict scripting messages and API exposure, which allows remote attackers to bypass the Same Origin Policy via an unintended embedder or unintended plugin loading, related to pdf.js and out_of_process_instance.cc.
OSV
CVE-2015-1302: The PDF viewer in Google Chrome before 46
osv·2015-11-11·CVSS 7.5
CVE-2015-1302 [HIGH] CVE-2015-1302: The PDF viewer in Google Chrome before 46
The PDF viewer in Google Chrome before 46.0.2490.86 does not properly restrict scripting messages and API exposure, which allows remote attackers to bypass the Same Origin Policy via an unintended embedder or unintended plugin loading, related to pdf.js and out_of_process_instance.cc.
Citrix
CVE-2015-3642: The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices with firmware 9.x be
vendor_citrix·2017-08-02·CVSS 5.9
CVE-2015-3642 [LOW] CWE-200 CVE-2015-3642: The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices with firmware 9.x be
CVE-2015-3642: The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices with firmware 9.x before 9.3 Build 68.5, 10.0 through Build 78.6, 10.1 before Build 130.13, 10.1.e before Build 130.1302.e, 10.5 before Build 55.8, and 10.5.e before Build 55.8007.e makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).
Red Hat
chromium-browser: information leak in PDF viewer
vendor_redhat·2015-11-10·CVSS 7.5
CVE-2015-1302 [HIGH] CWE-200 chromium-browser: information leak in PDF viewer
chromium-browser: information leak in PDF viewer
The PDF viewer in Google Chrome before 46.0.2490.86 does not properly restrict scripting messages and API exposure, which allows remote attackers to bypass the Same Origin Policy via an unintended embedder or unintended plugin loading, related to pdf.js and out_of_process_instance.cc.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1302 chromium-browser: information leak in PDF viewer
bugzilla·2015-11-11·CVSS 7.5
CVE-2015-1302 [HIGH] CVE-2015-1302 chromium-browser: information leak in PDF viewer
CVE-2015-1302 chromium-browser: information leak in PDF viewer
An unspecified information leak flaw was found in the PDF viewer component of the Chromium browser.
Upstream bug:
https://code.google.com/p/chromium/issues/detail?id=520422
External References:
http://googlechromereleases.blogspot.com/2015/11/stable-channel-update.html
Discussion:
Search using the id of the private upstream bug finds this upstream commit:
https://chromium.googlesource.com/chromium/src/+/a42545fa19dcbdca14c7e53e214b05b3d9356af5
---
The above patch is included in the chromium-browser packages as shipped with Red Hat Enterprise Linux 6 Supplementary as of RHSA-2015:1841 updating packages to version 45.0.2454.101.
https://rhn.redhat.com/errata/RHSA-2015-1841.html
Upstream confirmed this issue was not fi
Bugzilla
CVE-2014-9447 elfutils: directory traversal in read_long_names()
bugzilla·2015-01-05·CVSS 6.4
CVE-2014-9447 [MEDIUM] CVE-2014-9447 elfutils: directory traversal in read_long_names()
CVE-2014-9447 elfutils: directory traversal in read_long_names()
Directory traversal vulnerability was reported in elfutils [1] 'ar' utility.
Upstream commit with the analysis:
https://git.fedorahosted.org/cgit/elfutils.git/commit/?id=147018e729e7c22eeabf15b82d26e4bf68a0d18e
[1]: https://lists.fedorahosted.org/pipermail/elfutils-devel/2014-December/004499.html
Discussion:
Created elfutils tracking bugs for this issue:
Affects: fedora-all [bug 1181525]
---
elfutils-0.161-2.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report.
---
elfutils-0.161-2.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
---
Fixed in RHEL6 via RHEA-2015:1302
http://googlechromereleases.blogspot.com/2015/11/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00120.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00121.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1841.htmlhttp://www.debian.org/security/2015/dsa-3415http://www.securityfocus.com/bid/77537http://www.securitytracker.com/id/1034132https://code.google.com/p/chromium/issues/detail?id=520422https://codereview.chromium.org/1316803003https://security.gentoo.org/glsa/201603-09http://googlechromereleases.blogspot.com/2015/11/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00120.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00121.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1841.htmlhttp://www.debian.org/security/2015/dsa-3415http://www.securityfocus.com/bid/77537http://www.securitytracker.com/id/1034132https://code.google.com/p/chromium/issues/detail?id=520422https://codereview.chromium.org/1316803003https://security.gentoo.org/glsa/201603-09
2015-11-11
Published