CVE-2015-2526
published 2015-09-09CVE-2015-2526: Microsoft .NET Framework 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to cause a denial of service to an ASP.NET web site via crafted requests, aka "MVC…
PriorityP430medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
23.87%
97.6th percentile
Microsoft .NET Framework 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to cause a denial of service to an ASP.NET web site via crafted requests, aka "MVC Denial of Service Vulnerability."
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pc33-hpmh-68rj: Microsoft
ghsa_unreviewed·2022-05-14
CVE-2015-2526 [MEDIUM] GHSA-pc33-hpmh-68rj: Microsoft
Microsoft .NET Framework 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to cause a denial of service to an ASP.NET web site via crafted requests, aka "MVC Denial of Service Vulnerability."
Red Hat
chromium-browser: Use-After-free in MidiHost
vendor_redhat·2015-12-23·CVSS 9.8
CVE-2015-8664 [CRITICAL] CWE-416 chromium-browser: Use-After-free in MidiHost
chromium-browser: Use-After-free in MidiHost
Integer overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Google Chrome before 47.0.2526.106 allows remote attackers to cause a denial of service or possibly have unspecified other impact via an RGBA pixel array with crafted dimensions, a different vulnerability than CVE-2015-6792.
Red Hat
chromium-browser: Fixes from internal audits and fuzzing
vendor_redhat·2015-12-15·CVSS 9.8
CVE-2015-6792 [CRITICAL] chromium-browser: Fixes from internal audits and fuzzing
chromium-browser: Fixes from internal audits and fuzzing
The MIDI subsystem in Google Chrome before 47.0.2526.106 does not properly handle the sending of data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, related to midi_manager.cc, midi_manager_alsa.cc, and midi_manager_mac.cc, a different vulnerability than CVE-2015-8664.
Red Hat
v8: multiple vulnerabilities fixed in 4.7.80.23
vendor_redhat·2015-12-14·CVSS 7.5
CVE-2015-8548 [HIGH] v8: multiple vulnerabilities fixed in 4.7.80.23
v8: multiple vulnerabilities fixed in 4.7.80.23
Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before 47.0.2526.80, allow attackers to cause a denial of service or possibly have other impact via unknown vectors, a different issue than CVE-2015-8478.
Red Hat
chromium-browser: Use-after free in Blink
vendor_redhat·2015-12-08·CVSS 9.3
CVE-2015-6789 [CRITICAL] CWE-416 chromium-browser: Use-after free in Blink
chromium-browser: Use-after free in Blink
Race condition in the MutationObserver implementation in Blink, as used in Google Chrome before 47.0.2526.80, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact by leveraging unanticipated object deletion.
Red Hat
chromium-browser: Escaping issue in saved pages
vendor_redhat·2015-12-08·CVSS 4.3
CVE-2015-6790 [MEDIUM] chromium-browser: Escaping issue in saved pages
chromium-browser: Escaping issue in saved pages
The WebPageSerializerImpl::openTagToString function in WebKit/Source/web/WebPageSerializerImpl.cpp in the page serializer in Google Chrome before 47.0.2526.80 does not properly use HTML entities, which might allow remote attackers to inject arbitrary web script or HTML via a crafted document, as demonstrated by a double-quote character inside a single-quoted string.
Red Hat
chromium-browser: Type confusion in extensions
vendor_redhat·2015-12-08·CVSS 10.0
CVE-2015-6788 [CRITICAL] CWE-843 chromium-browser: Type confusion in extensions
chromium-browser: Type confusion in extensions
The ObjectBackedNativeHandler class in extensions/renderer/object_backed_native_handler.cc in the extensions subsystem in Google Chrome before 47.0.2526.80 improperly implements handler functions, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."
Red Hat
chromium-browser: Various fixes from internal audits, fuzzing and other initiatives
vendor_redhat·2015-12-08·CVSS 10.0
CVE-2015-6791 [CRITICAL] chromium-browser: Various fixes from internal audits, fuzzing and other initiatives
chromium-browser: Various fixes from internal audits, fuzzing and other initiatives
Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.80 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Red Hat
chromium-browser: Out of bounds access in v8
vendor_redhat·2015-12-01·CVSS 7.5
CVE-2015-6771 [HIGH] CWE-119 chromium-browser: Out of bounds access in v8
chromium-browser: Out of bounds access in v8
js/array.js in Google V8, as used in Google Chrome before 47.0.2526.73, improperly implements certain map and filter operations for arrays, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.
Red Hat
chromium-browser: Use-after-free in AppCache
vendor_redhat·2015-12-01·CVSS 7.5
CVE-2015-6766 [HIGH] CWE-416 chromium-browser: Use-after-free in AppCache
chromium-browser: Use-after-free in AppCache
Use-after-free vulnerability in the AppCache implementation in Google Chrome before 47.0.2526.73 allows remote attackers with renderer access to cause a denial of service or possibly have unspecified other impact by leveraging incorrect AppCacheUpdateJob behavior associated with duplicate cache selection.
Red Hat
chromium-browser: Various fixes from internal audits
vendor_redhat·2015-12-01·CVSS 10.0
CVE-2015-8480 [CRITICAL] chromium-browser: Various fixes from internal audits
chromium-browser: Various fixes from internal audits
The VideoFramePool::PoolImpl::CreateFrame function in media/base/video_frame_pool.cc in Google Chrome before 47.0.2526.73 does not initialize memory for a video-frame data structure, which might allow remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact by leveraging improper interaction with the vp3_h_loop_filter_c function in libavcodec/vp3dsp.c in FFmpeg.
Red Hat
chromium-browser: Scheme bypass in CSP
vendor_redhat·2015-12-01·CVSS 4.3
CVE-2015-6786 [MEDIUM] chromium-browser: Scheme bypass in CSP
chromium-browser: Scheme bypass in CSP
The CSPSourceList::matches function in WebKit/Source/core/frame/csp/CSPSourceList.cpp in the Content Security Policy (CSP) implementation in Google Chrome before 47.0.2526.73 accepts a blob:, data:, or filesystem: URL as a match for a * pattern, which allows remote attackers to bypass intended scheme restrictions in opportunistic circumstances by leveraging a policy that relies on this pattern.
Red Hat
chromium-browser: Integer overflow in Sfntly
vendor_redhat·2015-12-01·CVSS 7.5
CVE-2015-6781 [HIGH] CWE-190 chromium-browser: Integer overflow in Sfntly
chromium-browser: Integer overflow in Sfntly
Integer overflow in the FontData::Bound function in data/font_data.cc in Google sfntly, as used in Google Chrome before 47.0.2526.73, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted offset or length value within font data in an SFNT container.
Red Hat
chromium-browser: Escaping issue in saved pages
vendor_redhat·2015-12-01·CVSS 4.3
CVE-2015-6784 [MEDIUM] chromium-browser: Escaping issue in saved pages
chromium-browser: Escaping issue in saved pages
The page serializer in Google Chrome before 47.0.2526.73 mishandles Mark of the Web (MOTW) comments for URLs containing a "--" sequence, which might allow remote attackers to inject HTML via a crafted URL, as demonstrated by an initial http://example.com?-- substring.
Red Hat
chromium-browser: Wildcard matching issue in CSP
vendor_redhat·2015-12-01·CVSS 4.3
CVE-2015-6785 [MEDIUM] chromium-browser: Wildcard matching issue in CSP
chromium-browser: Wildcard matching issue in CSP
The CSPSource::hostMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Google Chrome before 47.0.2526.73 accepts an x.y hostname as a match for a *.x.y pattern, which might allow remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging a policy that was intended to be specific to subdomains.
Red Hat
chromium-browser: Use-after-free in DOM
vendor_redhat·2015-12-01·CVSS 7.5
CVE-2015-6777 [HIGH] CWE-416 chromium-browser: Use-after-free in DOM
chromium-browser: Use-after-free in DOM
Use-after-free vulnerability in the ContainerNode::notifyNodeInsertedInternal function in WebKit/Source/core/dom/ContainerNode.cpp in the DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to DOMCharacterDataModified events for certain detached-subtree insertions.
Red Hat
chromium-browser: Use-after-free in Infobars
vendor_redhat·2015-12-01·CVSS 6.8
CVE-2015-6780 [MEDIUM] CWE-416 chromium-browser: Use-after-free in Infobars
chromium-browser: Use-after-free in Infobars
Use-after-free vulnerability in the Infobars implementation in Google Chrome before 47.0.2526.73 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site, related to browser/ui/views/website_settings/website_settings_popup_view.cc.
Red Hat
chromium-browser: Out of bounds access in PDFium
vendor_redhat·2015-12-01·CVSS 6.8
CVE-2015-6776 [MEDIUM] CWE-119 chromium-browser: Out of bounds access in PDFium
chromium-browser: Out of bounds access in PDFium
The opj_dwt_decode_1* functions in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 47.0.2526.73, allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG 2000 data that is mishandled during a discrete wavelet transform.
Red Hat
chromium-browser: Out of bounds access in Skia
vendor_redhat·2015-12-01·CVSS 7.5
CVE-2015-6773 [HIGH] CWE-119 chromium-browser: Out of bounds access in Skia
chromium-browser: Out of bounds access in Skia
The convolution implementation in Skia, as used in Google Chrome before 47.0.2526.73, does not properly constrain row lengths, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted graphics data.
Red Hat
chromium-browser: Content spoofing in Omnibox
vendor_redhat·2015-12-01·CVSS 4.3
CVE-2015-6782 [MEDIUM] chromium-browser: Content spoofing in Omnibox
chromium-browser: Content spoofing in Omnibox
The Document::open function in WebKit/Source/core/dom/Document.cpp in Google Chrome before 47.0.2526.73 does not ensure that page-dismissal event handling is compatible with modal-dialog blocking, which makes it easier for remote attackers to spoof Omnibox content via a crafted web site.
Red Hat
chromium-browser: Cross-origin bypass in core
vendor_redhat·2015-12-01·CVSS 7.5
CVE-2015-6769 [HIGH] chromium-browser: Cross-origin bypass in core
chromium-browser: Cross-origin bypass in core
The provisional-load commit implementation in WebKit/Source/bindings/core/v8/WindowProxy.cpp in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy by leveraging a delay in window proxy clearing.
Red Hat
chromium-browser: Type confusion in PDFium
vendor_redhat·2015-12-01·CVSS 7.5
CVE-2015-6775 [HIGH] CWE-843 chromium-browser: Type confusion in PDFium
chromium-browser: Type confusion in PDFium
fpdfsdk/src/jsapi/fxjs_v8.cpp in PDFium, as used in Google Chrome before 47.0.2526.73, does not use signatures, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."
Red Hat
chromium-browser: Cross-origin bypass in DOM
vendor_redhat·2015-12-01·CVSS 7.5
CVE-2015-6772 [HIGH] chromium-browser: Cross-origin bypass in DOM
chromium-browser: Cross-origin bypass in DOM
The DOM implementation in Blink, as used in Google Chrome before 47.0.2526.73, does not prevent javascript: URL navigation while a document is being detached, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that improperly interacts with a plugin.
Red Hat
chromium-browser: Cross-origin bypass in DOM
vendor_redhat·2015-12-01·CVSS 7.5
CVE-2015-6768 [HIGH] chromium-browser: Cross-origin bypass in DOM
chromium-browser: Cross-origin bypass in DOM
The DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, a different vulnerability than CVE-2015-6770.
Red Hat
chromium-browser: Signature validation issue in Android Crazy Linker
vendor_redhat·2015-12-01·CVSS 4.3
CVE-2015-6783 [MEDIUM] chromium-browser: Signature validation issue in Android Crazy Linker
chromium-browser: Signature validation issue in Android Crazy Linker
The FindStartOffsetOfFileInZipFile function in crazy_linker_zip.cpp in crazy_linker (aka Crazy Linker) in Android 5.x and 6.x, as used in Google Chrome before 47.0.2526.73, improperly searches for an EOCD record, which allows attackers to bypass a signature-validation requirement via a crafted ZIP archive.
Package: chromium-browser (Red Hat Enterprise Linux 6) - Not affected
Red Hat
chromium-browser: Various fixes from internal audits
vendor_redhat·2015-12-01·CVSS 10.0
CVE-2015-6787 [CRITICAL] chromium-browser: Various fixes from internal audits
chromium-browser: Various fixes from internal audits
Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Red Hat
chromium-browser: Use-after-free in AppCache
vendor_redhat·2015-12-01·CVSS 10.0
CVE-2015-6765 [CRITICAL] CWE-416 chromium-browser: Use-after-free in AppCache
chromium-browser: Use-after-free in AppCache
Use-after-free vulnerability in content/browser/appcache/appcache_update_job.cc in Google Chrome before 47.0.2526.73 allows remote attackers to execute arbitrary code or cause a denial of service by leveraging the mishandling of AppCache update jobs.
Red Hat
chromium-browser: Cross-origin bypass in DOM
vendor_redhat·2015-12-01·CVSS 7.5
CVE-2015-6770 [HIGH] chromium-browser: Cross-origin bypass in DOM
chromium-browser: Cross-origin bypass in DOM
The DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, a different vulnerability than CVE-2015-6768.
Red Hat
chromium-browser: Out of bounds access in PDFium
vendor_redhat·2015-12-01·CVSS 7.5
CVE-2015-6778 [HIGH] CWE-119 chromium-browser: Out of bounds access in PDFium
chromium-browser: Out of bounds access in PDFium
The CJBig2_SymbolDict class in fxcodec/jbig2/JBig2_SymbolDict.cpp in PDFium, as used in Google Chrome before 47.0.2526.73, allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via a PDF document containing crafted data with JBIG2 compression.
Red Hat
chromium-browser: Use-after-free in Extensions
vendor_redhat·2015-12-01·CVSS 7.5
CVE-2015-6774 [HIGH] CWE-416 chromium-browser: Use-after-free in Extensions
chromium-browser: Use-after-free in Extensions
Use-after-free vulnerability in the GetLoadTimes function in renderer/loadtimes_extension_bindings.cc in the Extensions implementation in Google Chrome before 47.0.2526.73 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that modifies a pointer used for reporting loadTimes data.
Red Hat
chromium-browser: Scheme bypass in PDFium
vendor_redhat·2015-12-01·CVSS 4.3
CVE-2015-6779 [MEDIUM] chromium-browser: Scheme bypass in PDFium
chromium-browser: Scheme bypass in PDFium
PDFium, as used in Google Chrome before 47.0.2526.73, does not properly restrict use of chrome: URLs, which allows remote attackers to bypass intended scheme restrictions via a crafted PDF document, as demonstrated by a document with a link to a chrome://settings URL.
Red Hat
chromium-browser: Use-after-free in AppCache
vendor_redhat·2015-12-01·CVSS 7.5
CVE-2015-6767 [HIGH] CWE-416 chromium-browser: Use-after-free in AppCache
chromium-browser: Use-after-free in AppCache
Use-after-free vulnerability in content/browser/appcache/appcache_dispatcher_host.cc in the AppCache implementation in Google Chrome before 47.0.2526.73 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect pointer maintenance associated with certain callbacks.
Red Hat
chromium-browser: Various fixes from internal audits
vendor_redhat·2015-12-01·CVSS 7.5
CVE-2015-8479 [HIGH] chromium-browser: Various fixes from internal audits
chromium-browser: Various fixes from internal audits
Use-after-free vulnerability in the AudioOutputDevice::OnDeviceAuthorized function in media/audio/audio_output_device.cc in Google Chrome before 47.0.2526.73 allows attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by triggering access to an unauthorized audio output device.
Red Hat
v8: unspecified out-of-bounds access vulnerability
vendor_redhat·2015-11-25·CVSS 9.8
CVE-2015-6764 [CRITICAL] v8: unspecified out-of-bounds access vulnerability
v8: unspecified out-of-bounds access vulnerability
The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.
Statement: This issue did not affect the versions of nodejs as shipped with Red Hat Enterprise Software Collections version 2, Red Hat OpenStack Platform and Red Hat Openshift Enterprise and Openshift Online as they do not include the vulnerable version of nodejs.
Package: nodejs (OpenShift Enterprise 1) - Not affected
Package: nodejs (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Ope
Red Hat
v8: multiple vulnerabilities fixed in 4.7.80.23
vendor_redhat·2015-01-21·CVSS 7.5
CVE-2015-8478 [HIGH] v8: multiple vulnerabilities fixed in 4.7.80.23
v8: multiple vulnerabilities fixed in 4.7.80.23
Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before 47.0.2526.73, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - September 2015
blogs_talos·2015-09-08·CVSS 9.3
[CRITICAL] Microsoft Patch Tuesday - September 2015
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release sees a total of 12 bulletins released which address 55 CVEs. Five bulletins are rated "Critical" this month and address vulnerabilities in Edge, Graphics Component, Internet Explorer, Journal, and Office. The other seven bulletins are rated "Important" and address vulnerabilities in the .NET Framework, Active Directory, Exchange, Hyper-V, Media Center, Skype for Business, and Task Management.
## Bulletins Rated CriticalMS15-094, MS15-095, MS15-097, MS-098, and MS15-099 are rated "Critical".
MS15-094 is this month's Internet Explorer security bulletin. Seventeen CVEs are addressed this month which affected Internet Explorer versions
Talos
Microsoft Patch Tuesday - September 2015
blogs_talos·2015-09-08·CVSS 9.3
[CRITICAL] Microsoft Patch Tuesday - September 2015
## Microsoft Patch Tuesday - September 2015
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release sees a total of 12 bulletins released which address 55 CVEs. Five bulletins are rated "Critical" this month and address vulnerabilities in Edge, Graphics Component, Internet Explorer, Journal, and Office. The other seven bulletins are rated "Important" and address vulnerabilities in the .NET Framework, Active Directory, Exchange, Hyper-V, Media Center, Skype for Business, and Task Management.
## Bulletins Rated Critical MS15-094, MS15-095, MS15-097, MS-098, and MS15-099 are rated "Critical".
MS15-094 is this month's Internet Explorer security bulletin. Seventeen CVEs are addressed this m
Bugzilla
CVE-2015-8664 chromium-browser: Use-After-free in MidiHost
bugzilla·2015-12-30·CVSS 9.8
CVE-2015-8664 [CRITICAL] CVE-2015-8664 chromium-browser: Use-After-free in MidiHost
CVE-2015-8664 chromium-browser: Use-After-free in MidiHost
Common Vulnerabilities and Exposures assigned an identifier CVE-2015-8664 to
the following vulnerability:
Name: CVE-2015-8664
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8664
Assigned: 20151223
Reference: CONFIRM:http://googlechromereleases.blogspot.com/2015/12/stable-channel-update_15.html
Reference: CONFIRM:https://code.google.com/p/chromium/issues/detail?id=565023
Reference: CONFIRM:https://code.google.com/p/chromium/issues/detail?id=569486
Reference: CONFIRM:https://codereview.chromium.org/1498903003
Integer overflow in the WebCursor::Deserialize function in
content/common/cursors/webcursor.cc in Google Chrome before
47.0.2526.106 allows remote attackers to cause a denial of service or
possibly have unspecifi
Bugzilla
CVE-2015-6792 chromium-browser: Fixes from internal audits and fuzzing
bugzilla·2015-12-16·CVSS 9.8
CVE-2015-6792 [CRITICAL] CVE-2015-6792 chromium-browser: Fixes from internal audits and fuzzing
CVE-2015-6792 chromium-browser: Fixes from internal audits and fuzzing
As per chromium upstream security advisory:
The stable channel has been updated to 47.0.2526.106 for Windows, Mac, and Linux.
This update includes 2 security fixes as part of our ongoing internal security work:
[569486] CVE-2015-6792: Fixes from internal audits and fuzzing.
Upstream bug:
https://code.google.com/p/chromium/issues/detail?id=569486
External References:
http://googlechromereleases.blogspot.com/2015/12/stable-channel-update_15.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:2665 https://rhn.redhat.com/errata/RHSA-2015-2665.html
---
As per:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6792
This issue
Bugzilla
CVE-2015-8548 v8: multiple vulnerabilities fixed in 4.7.80.23
bugzilla·2015-12-14·CVSS 7.5
CVE-2015-8548 [HIGH] CVE-2015-8548 v8: multiple vulnerabilities fixed in 4.7.80.23
CVE-2015-8548 v8: multiple vulnerabilities fixed in 4.7.80.23
Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before 47.0.2526.80, allow attackers to cause a denial of service or possibly have other impact via unknown vectors, a different issue than CVE-2015-8478.
External References:
http://googlechromereleases.blogspot.com/2015/12/stable-channel-update_8.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:2618 https://rhn.redhat.com/errata/RHSA-2015-2618.html
Bugzilla
CVE-2015-8478 v8: multiple vulnerabilities fixed in 4.7.80.23
bugzilla·2015-12-08·CVSS 7.5
CVE-2015-8478 [HIGH] CVE-2015-8478 v8: multiple vulnerabilities fixed in 4.7.80.23
CVE-2015-8478 v8: multiple vulnerabilities fixed in 4.7.80.23
Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before 47.0.2526.73, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
External References:
http://googlechromereleases.blogspot.com/2015/12/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:2545 https://rhn.redhat.com/errata/RHSA-2015-2545.html
---
New CVE was added to cover additional V8 fixes:
Name: CVE-2015-8548
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8548
Assigned: 20151213
Reference: http://googlechromereleases.blogspot.com/2015/12/stable-channel-update_
http://www.securityfocus.com/bid/76567http://www.securitytracker.com/id/1033493https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-101http://www.securityfocus.com/bid/76567http://www.securitytracker.com/id/1033493https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-101
2015-09-09
Published