Show filters
83 Total Results
Displaying 71-80 of 83
Sort by:
Attacker Value
Unknown
CVE-2015-1270
Disclosure Date: July 23, 2015 (last updated October 05, 2023)
The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names with initial x- substrings, which allows remote attackers to cause a denial of service (read of uninitialized memory) or possibly have unspecified other impact via a crafted file.
0
Attacker Value
Unknown
CVE-2015-1271
Disclosure Date: July 23, 2015 (last updated October 05, 2023)
PDFium, as used in Google Chrome before 44.0.2403.89, does not properly handle certain out-of-memory conditions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted PDF document that triggers a large memory allocation.
0
Attacker Value
Unknown
CVE-2015-1282
Disclosure Date: July 23, 2015 (last updated October 05, 2023)
Multiple use-after-free vulnerabilities in fpdfsdk/src/javascript/Document.cpp in PDFium, as used in Google Chrome before 44.0.2403.89, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document, related to the (1) Document::delay and (2) Document::DoFieldDelay functions.
0
Attacker Value
Unknown
CVE-2015-1278
Disclosure Date: July 23, 2015 (last updated October 05, 2023)
content/browser/web_contents/web_contents_impl.cc in Google Chrome before 44.0.2403.89 does not ensure that a PDF document's modal dialog is closed upon navigation to an interstitial page, which allows remote attackers to spoof URLs via a crafted document, as demonstrated by the alert_dialog.pdf document.
0
Attacker Value
Unknown
CVE-2015-1276
Disclosure Date: July 23, 2015 (last updated November 08, 2023)
Use-after-free vulnerability in content/browser/indexed_db/indexed_db_backing_store.cc in the IndexedDB implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging an abort action before a certain write operation.
0
Attacker Value
Unknown
CVE-2015-1289
Disclosure Date: July 23, 2015 (last updated October 05, 2023)
Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
0
Attacker Value
Unknown
CVE-2015-1273
Disclosure Date: July 23, 2015 (last updated October 05, 2023)
Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid JPEG2000 data in a PDF document.
0
Attacker Value
Unknown
CVE-2015-1280
Disclosure Date: July 23, 2015 (last updated October 05, 2023)
SkPictureShader.cpp in Skia, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging access to a renderer process and providing crafted serialized data.
0
Attacker Value
Unknown
CVE-2015-1281
Disclosure Date: July 23, 2015 (last updated October 05, 2023)
core/loader/ImageLoader.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly determine the V8 context of a microtask, which allows remote attackers to bypass Content Security Policy (CSP) restrictions by providing an image from an unintended source.
0
Attacker Value
Unknown
CVE-2015-1285
Disclosure Date: July 23, 2015 (last updated October 05, 2023)
The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for remote attackers to obtain sensitive information via an unspecified linear-time attack.
0