CVE-2015-6789
published 2015-12-14CVE-2015-6789: Race condition in the MutationObserver implementation in Blink, as used in Google Chrome before 47.0.2526.80, allows remote attackers to cause a denial of…
PriorityP336critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
1.71%
75.0th percentile
Race condition in the MutationObserver implementation in Blink, as used in Google Chrome before 47.0.2526.80, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact by leveraging unanticipated object deletion.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 47.0.2526.73 | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h35f-7gwh-g2rm: Race condition in the MutationObserver implementation in Blink, as used in Google Chrome before 47
ghsa_unreviewed·2022-05-17
CVE-2015-6789 [HIGH] CWE-362 GHSA-h35f-7gwh-g2rm: Race condition in the MutationObserver implementation in Blink, as used in Google Chrome before 47
Race condition in the MutationObserver implementation in Blink, as used in Google Chrome before 47.0.2526.80, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact by leveraging unanticipated object deletion.
OSV
oxide-qt vulnerabilities
osv·2016-01-11·CVSS 9.3
CVE-2015-6789 [CRITICAL] oxide-qt vulnerabilities
oxide-qt vulnerabilities
A race condition was discovered in the MutationObserver implementation in
Blink. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit this to cause a denial of service
via renderer crash, or execute arbitrary code with the privileges of the
sandboxed render process. (CVE-2015-6789)
An issue was discovered with the page serializer in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to inject arbitrary script or HTML.
(CVE-2015-6790)
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial
of servic
OSV
CVE-2015-6789: Race condition in the MutationObserver implementation in Blink, as used in Google Chrome before 47
osv·2015-12-14·CVSS 9.3
CVE-2015-6789 [CRITICAL] CVE-2015-6789: Race condition in the MutationObserver implementation in Blink, as used in Google Chrome before 47
Race condition in the MutationObserver implementation in Blink, as used in Google Chrome before 47.0.2526.80, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact by leveraging unanticipated object deletion.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2016-01-11·CVSS 9.3
CVE-2015-6789 [CRITICAL] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
A race condition was discovered in the MutationObserver implementation in
Blink. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit this to cause a denial of service
via renderer crash, or execute arbitrary code with the privileges of the
sandboxed render process. (CVE-2015-6789)
An issue was discovered with the page serializer in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to inject arbitrary script or HTML.
(CVE-2015-6790)
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit t
Red Hat
chromium-browser: Use-after free in Blink
vendor_redhat·2015-12-08·CVSS 9.3
CVE-2015-6789 [CRITICAL] CWE-416 chromium-browser: Use-after free in Blink
chromium-browser: Use-after free in Blink
Race condition in the MutationObserver implementation in Blink, as used in Google Chrome before 47.0.2526.80, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact by leveraging unanticipated object deletion.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2015/12/stable-channel-update_8.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00017.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2618.htmlhttp://www.debian.org/security/2015/dsa-3418http://www.securityfocus.com/bid/78734http://www.ubuntu.com/usn/USN-2860-1https://code.google.com/p/chromium/issues/detail?id=557981https://codereview.chromium.org/1463433002/https://security.gentoo.org/glsa/201603-09http://googlechromereleases.blogspot.com/2015/12/stable-channel-update_8.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00017.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2618.htmlhttp://www.debian.org/security/2015/dsa-3418http://www.securityfocus.com/bid/78734http://www.ubuntu.com/usn/USN-2860-1https://code.google.com/p/chromium/issues/detail?id=557981https://codereview.chromium.org/1463433002/https://security.gentoo.org/glsa/201603-09
2015-12-14
Published