CVE-2015-2454
published 2015-08-15CVE-2015-2454: The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and…
PriorityP414low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
2.10%
79.6th percentile
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows KMD Security Feature Bypass Vulnerability."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jrc5-254w-5vfw: The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8
ghsa_unreviewed·2022-05-14
CVE-2015-2454 [LOW] GHSA-jrc5-254w-5vfw: The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows KMD Security Feature Bypass Vulnerability."
Red Hat
chromium-browser: Cross-origin bypass in V8
vendor_redhat·2015-09-24·CVSS 7.5
CVE-2015-1304 [HIGH] CWE-284 chromium-browser: Cross-origin bypass in V8
chromium-browser: Cross-origin bypass in V8
object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, which allows remote attackers to bypass the Same Origin Policy via a (1) observe or (2) getNotifier call.
Red Hat
chromium-browser: Cross-origin bypass in DOM
vendor_redhat·2015-09-24·CVSS 7.5
CVE-2015-1303 [HIGH] CWE-284 chromium-browser: Cross-origin bypass in DOM
chromium-browser: Cross-origin bypass in DOM
bindings/core/v8/V8DOMWrapper.h in Blink, as used in Google Chrome before 45.0.2454.101, does not perform a rethrow action to propagate information about a cross-context exception, which allows remote attackers to bypass the Same Origin Policy via a crafted HTML document containing an IFRAME element.
Red Hat
chromium-browser: Use-after-free in Blink
vendor_redhat·2015-09-01·CVSS 7.5
CVE-2015-1299 [HIGH] CWE-416 chromium-browser: Use-after-free in Blink
chromium-browser: Use-after-free in Blink
Use-after-free vulnerability in the shared-timer implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging erroneous timer firing, related to ThreadTimers.cpp and Timer.cpp.
Red Hat
chromium-browser: Use-after-free in Printing
vendor_redhat·2015-09-01·CVSS 7.5
CVE-2015-1295 [HIGH] CWE-416 chromium-browser: Use-after-free in Printing
chromium-browser: Use-after-free in Printing
Multiple use-after-free vulnerabilities in the PrintWebViewHelper class in components/printing/renderer/print_web_view_helper.cc in Google Chrome before 45.0.2454.85 allow user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact by triggering nested IPC messages during preparation for printing, as demonstrated by messages associated with PDF documents in conjunction with messages about printer capabilities.
Red Hat
chromium-browser: various fixes from internal audits
vendor_redhat·2015-09-01·CVSS 7.5
CVE-2015-1301 [HIGH] chromium-browser: various fixes from internal audits
chromium-browser: various fixes from internal audits
Multiple unspecified vulnerabilities in Google Chrome before 45.0.2454.85 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Red Hat
chromium-browser: Character spoofing in omnibox
vendor_redhat·2015-09-01·CVSS 5.0
CVE-2015-1296 [MEDIUM] chromium-browser: Character spoofing in omnibox
chromium-browser: Character spoofing in omnibox
The UnescapeURLWithAdjustmentsImpl implementation in net/base/escape.cc in Google Chrome before 45.0.2454.85 does not prevent display of Unicode LOCK characters in the omnibox, which makes it easier for remote attackers to spoof the SSL lock icon by placing one of these characters at the end of a URL, as demonstrated by the omnibox in localizations for right-to-left languages.
Red Hat
chromium-browser: Cross-origin bypass in ServiceWorker
vendor_redhat·2015-09-01·CVSS 5.0
CVE-2015-1292 [MEDIUM] chromium-browser: Cross-origin bypass in ServiceWorker
chromium-browser: Cross-origin bypass in ServiceWorker
The NavigatorServiceWorker::serviceWorker function in modules/serviceworkers/NavigatorServiceWorker.cpp in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy by accessing a Service Worker.
Red Hat
chromium-browser: Cross-origin bypass in DOM
vendor_redhat·2015-09-01·CVSS 7.5
CVE-2015-1293 [HIGH] chromium-browser: Cross-origin bypass in DOM
chromium-browser: Cross-origin bypass in DOM
The DOM implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
Red Hat
chromium-browser: Use-after-free in Skia
vendor_redhat·2015-09-01·CVSS 7.5
CVE-2015-1294 [HIGH] CWE-416 chromium-browser: Use-after-free in Skia
chromium-browser: Use-after-free in Skia
Use-after-free vulnerability in the SkMatrix::invertNonIdentity function in core/SkMatrix.cpp in Skia, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering the use of matrix elements that lead to an infinite result during an inversion calculation.
Red Hat
chromium-browser: URL validation error in extensions
vendor_redhat·2015-09-01·CVSS 4.3
CVE-2015-1298 [MEDIUM] chromium-browser: URL validation error in extensions
chromium-browser: URL validation error in extensions
The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api.cc in Google Chrome before 45.0.2454.85 does not ensure that the setUninstallURL preference corresponds to the URL of a web site, which allows user-assisted remote attackers to trigger access to an arbitrary URL via a crafted extension that is uninstalled.
Red Hat
chromium-browser: Permission scoping error in WebRequest
vendor_redhat·2015-09-01·CVSS 7.5
CVE-2015-1297 [HIGH] chromium-browser: Permission scoping error in WebRequest
chromium-browser: Permission scoping error in WebRequest
The WebRequest API implementation in extensions/browser/api/web_request/web_request_api.cc in Google Chrome before 45.0.2454.85 does not properly consider a request's source before accepting the request, which allows remote attackers to bypass intended access restrictions via a crafted (1) app or (2) extension.
Red Hat
chromium-browser: Cross-origin bypass in DOM
vendor_redhat·2015-09-01·CVSS 6.4
CVE-2015-1291 [MEDIUM] chromium-browser: Cross-origin bypass in DOM
chromium-browser: Cross-origin bypass in DOM
The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not check whether a node is expected, which allows remote attackers to bypass the Same Origin Policy or cause a denial of service (DOM tree corruption) via a web site with crafted JavaScript code and IFRAME elements.
Red Hat
chromium-browser: Information leak in Blink
vendor_redhat·2015-09-01·CVSS 5.0
CVE-2015-1300 [MEDIUM] CWE-200 chromium-browser: Information leak in Blink
chromium-browser: Information leak in Blink
The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to obtain sensitive information via crafted JavaScript code that leverages a history.back call.
Red Hat
openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd
vendor_redhat·2015-05-19·CVSS 7.5
CVE-2015-6581 [HIGH] openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd
openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd
Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 45.0.2454.85, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering a memory-allocation failure.
Statement: Not vulnerable. This issue did not affect the versions of openjpeg as shipped
with Red Hat Enterprise Linux 6 and 7.
Package: chromium-browser (Red Hat Enterprise Linux 6) - Not affected
Package: openjpeg (Red Hat Enterprise Linux 6) - Not affected
Package: openjpeg (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1302 chromium-browser: information leak in PDF viewer
bugzilla·2015-11-11·CVSS 7.5
CVE-2015-1302 [HIGH] CVE-2015-1302 chromium-browser: information leak in PDF viewer
CVE-2015-1302 chromium-browser: information leak in PDF viewer
An unspecified information leak flaw was found in the PDF viewer component of the Chromium browser.
Upstream bug:
https://code.google.com/p/chromium/issues/detail?id=520422
External References:
http://googlechromereleases.blogspot.com/2015/11/stable-channel-update.html
Discussion:
Search using the id of the private upstream bug finds this upstream commit:
https://chromium.googlesource.com/chromium/src/+/a42545fa19dcbdca14c7e53e214b05b3d9356af5
---
The above patch is included in the chromium-browser packages as shipped with Red Hat Enterprise Linux 6 Supplementary as of RHSA-2015:1841 updating packages to version 45.0.2454.101.
https://rhn.redhat.com/errata/RHSA-2015-1841.html
Upstream confirmed this issue was not fi
Bugzilla
CVE-2015-6581 openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd
bugzilla·2015-10-01·CVSS 7.5
CVE-2015-6581 [HIGH] CVE-2015-6581 openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd
CVE-2015-6581 openjpeg: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd
Double-free vulnerability was found in opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 45.0.2454.85, allowing remote attacker to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering a memory-allocation failure.
The opj_j2k_copy_default_tcp_and_create_tcp() function memcpy's a top-level
struct and then replaces pointers to memory owned by the original struct
with new blocks of memory. Unfortunately, an early return can leave the
copy with pointers to memory it doesn't own, which causes problems when
cleaning up the partially-initialized struct.
Upstream bug:
https://code.google.com
2015-08-15
Published