CVE-2015-3333
published 2015-04-19CVE-2015-3333: Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before 42.0.2311.90, allow attackers to cause a denial of service…
PriorityP429high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
0.94%
56.9th percentile
Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before 42.0.2311.90, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| chrome | <= 42.0.2311.60 | — | |
| v8 | <= 4.2.77.7 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c999-q72h-34xc: Multiple unspecified vulnerabilities in Google V8 before 4
ghsa_unreviewed·2022-05-17
CVE-2015-3333 [HIGH] GHSA-c999-q72h-34xc: Multiple unspecified vulnerabilities in Google V8 before 4
Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before 42.0.2311.90, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
OSV
oxide-qt vulnerabilities
osv·2015-04-27·CVSS 5.0
CVE-2015-1235 [MEDIUM] oxide-qt vulnerabilities
oxide-qt vulnerabilities
An issue was discovered in the HTML parser in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2015-1235)
An issue was discovered in the Web Audio API implementation in Blink. If
a user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to bypass same-origin restrictions.
(CVE-2015-1236)
A use-after-free was discovered in Chromium. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2015-1237)
An out-of-bounds write was d
OSV
CVE-2015-3333: Multiple unspecified vulnerabilities in Google V8 before 4
osv·2015-04-19·CVSS 7.5
CVE-2015-3333 [HIGH] CVE-2015-3333: Multiple unspecified vulnerabilities in Google V8 before 4
Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before 42.0.2311.90, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2015-04-27·CVSS 5.0
CVE-2015-1235 [MEDIUM] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
An issue was discovered in the HTML parser in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2015-1235)
An issue was discovered in the Web Audio API implementation in Blink. If
a user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to bypass same-origin restrictions.
(CVE-2015-1236)
A use-after-free was discovered in Chromium. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed re
Suricata
ET WEB_CLIENT Microsoft Office RTF Stack Buffer Overflow
suricata·2015-03-16
CVE-2010-3333 ET WEB_CLIENT Microsoft Office RTF Stack Buffer Overflow
ET WEB_CLIENT Microsoft Office RTF Stack Buffer Overflow
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Microsoft Office RTF Stack Buffer Overflow"; flow:established,to_client; flowbits:set,ETPRO.RTF; flowbits:noalert; file.data; content:"|7b 5c|rt"; within:4; reference:cve,2010-3333; classtype:misc-activity; sid:2020699; rev:7; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2015_03_16, cve CVE_2010_3333, deployment Perimeter, confidence High, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_03_14;)
No public exploits indexed.
No writeups or analysis indexed.
http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00040.htmlhttp://ubuntu.com/usn/usn-2570-1http://www.debian.org/security/2015/dsa-3238http://www.securityfocus.com/bid/74221http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00040.htmlhttp://ubuntu.com/usn/usn-2570-1http://www.debian.org/security/2015/dsa-3238http://www.securityfocus.com/bid/74221
2015-04-19
Published