Date published: 2015-03-19
Date published: 2015-03-19 (High)
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
Date published: 2015-03-19 (High)
The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrome before 40.0.2214.91, calculates certain values without ensuring that they can be represented in a 24-bit field, which al...
CVEs:CVE-2014-9654
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| international_components_for_unicode | affected | icu-project | — | — |
Use-after-free vulnerability in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect ordering of operations in the Web SQL Database t...
CVEs:CVE-2015-1221
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
The BestWebSoft Google Captcha (aka reCAPTCHA) plugin before 1.13 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.
CVEs:CVE-2015-0890
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_captcha | affected | bestwebsoft | — | — |
The V8LazyEventListener::prepareListenerObject function in bindings/core/v8/V8LazyEventListener.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, does not properly compile listeners, which allows remote attackers to cause a...
CVEs:CVE-2015-1217
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| enterprise_linux_desktop_supplementary | affected | redhat | — | — |
| enterprise_linux_server_supplementary | affected | redhat | — | — |
| enterprise_linux_server_supplementary_eus | affected | redhat | — | — |
| enterprise_linux_workstation_supplementary | affected | redhat | — | — |
| ubuntu_linux | affected | canonical | — | — |
The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the AudioContext class, which allows remote attackers to cause a denial of service or possibly hav...
CVEs:CVE-2015-1230
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| enterprise_linux_desktop_supplementary | affected | redhat | — | — |
| enterprise_linux_server_supplementary | affected | redhat | — | — |
| enterprise_linux_server_supplementary_eus | affected | redhat | — | — |
| enterprise_linux_workstation_supplementary | affected | redhat | — | — |
| ubuntu_linux | affected | canonical | — | — |
Use-after-free vulnerability in the GIFImageReader::parseData function in platform/image-decoders/gif/GIFImageReader.cpp in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspe...
CVEs:CVE-2015-1220
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| enterprise_linux_desktop_supplementary | affected | redhat | — | — |
| enterprise_linux_server_supplementary | affected | redhat | — | — |
| enterprise_linux_server_supplementary_eus | affected | redhat | — | — |
| enterprise_linux_workstation_supplementary | affected | redhat | — | — |
| ubuntu_linux | affected | canonical | — | — |
Multiple use-after-free vulnerabilities in core/html/HTMLInputElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 41.0.2272.76, allow remote attackers to cause a denial of service or possibly have unspecified other impact vi...
CVEs:CVE-2015-1223
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
The VpxVideoDecoder::VpxDecode function in media/filters/vpx_video_decoder.cc in the vpxdecoder implementation in Google Chrome before 41.0.2272.76 does not ensure that alpha-plane dimensions are identical to image dimensions, which allows remote attac...
CVEs:CVE-2015-1224
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
The filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation.
CVEs:CVE-2015-1215
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| enterprise_linux_desktop_supplementary | affected | redhat | — | — |
| enterprise_linux_server_supplementary | affected | redhat | — | — |
| enterprise_linux_server_supplementary_eus | affected | redhat | — | — |
| enterprise_linux_workstation_supplementary | affected | redhat | — | — |
| ubuntu_linux | affected | canonical | — | — |
The SkBitmap::ReadRawPixels function in core/SkBitmap.cpp in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors th...
CVEs:CVE-2015-1213
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified ot...
CVEs:CVE-2015-1214
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| enterprise_linux_desktop_supplementary | affected | redhat | — | — |
| enterprise_linux_server_supplementary | affected | redhat | — | — |
| enterprise_linux_server_supplementary_eus | affected | redhat | — | — |
| enterprise_linux_workstation_supplementary | affected | redhat | — | — |
| ubuntu_linux | affected | canonical | — | — |
The DragImage::create function in platform/DragImage.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not initialize memory for image drawing, which allows remote attackers to have an unspecified impact by triggering a failed image deco...
CVEs:CVE-2015-1227
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Use-after-free vulnerability in the V8Window::namedPropertyGetterCustom function in bindings/core/v8/custom/V8WindowCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of servi...
CVEs:CVE-2015-1216
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| enterprise_linux_desktop_supplementary | affected | redhat | — | — |
| enterprise_linux_server_supplementary | affected | redhat | — | — |
| enterprise_linux_server_supplementary_eus | affected | redhat | — | — |
| enterprise_linux_workstation_supplementary | affected | redhat | — | — |
| ubuntu_linux | affected | canonical | — | — |
Multiple use-after-free vulnerabilities in the DOM implementation in Blink, as used in Google Chrome before 41.0.2272.76, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger movement of...
CVEs:CVE-2015-1218
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| enterprise_linux_desktop_supplementary | affected | redhat | — | — |
| enterprise_linux_server_supplementary | affected | redhat | — | — |
| enterprise_linux_server_supplementary_eus | affected | redhat | — | — |
| enterprise_linux_workstation_supplementary | affected | redhat | — | — |
| ubuntu_linux | affected | canonical | — | — |
Integer overflow in the SkMallocPixelRef::NewAllocate function in core/SkMallocPixelRef.cpp in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vector...
CVEs:CVE-2015-1219
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| enterprise_linux_desktop_supplementary | affected | redhat | — | — |
| enterprise_linux_server_supplementary | affected | redhat | — | — |
| enterprise_linux_server_supplementary_eus | affected | redhat | — | — |
| enterprise_linux_workstation_supplementary | affected | redhat | — | — |
| ubuntu_linux | affected | canonical | — | — |
Multiple use-after-free vulnerabilities in the ServiceWorkerScriptCacheMap implementation in content/browser/service_worker/service_worker_script_cache_map.cc in Google Chrome before 41.0.2272.76 allow remote attackers to cause a denial of service or p...
CVEs:CVE-2015-1222
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
The RenderCounter::updateCounter function in core/rendering/RenderCounter.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not force a relayout operation and consequently does not initialize memory for a data structure, which allows rem...
CVEs:CVE-2015-1228
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| enterprise_linux_desktop_supplementary | affected | redhat | — | — |
| enterprise_linux_server | affected | redhat | — | — |
| enterprise_linux_server_supplementary_eus | affected | redhat | — | — |
| enterprise_linux_workstation_supplementary | affected | redhat | — | — |
| ubuntu_linux | affected | canonical | — | — |
Multiple unspecified vulnerabilities in Google Chrome before 41.0.2272.76 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2015-1231
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| enterprise_linux_desktop_supplementary | affected | redhat | — | — |
| enterprise_linux_server | affected | redhat | — | — |
| enterprise_linux_server_supplementary_eus | affected | redhat | — | — |
| enterprise_linux_workstation_supplementary | affected | redhat | — | — |
| ubuntu_linux | affected | canonical | — | — |
PDFium, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
CVEs:CVE-2015-1225
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 41.0.2272.76 does not properly restrict what URLs are available as debugger targets, which allows remote attackers to bypass intende...
CVEs:CVE-2015-1226
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
content/renderer/device_sensors/device_orientation_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate gyroscope data, which makes it easier for remote attackers to obtain speech signals from a device's phy...
CVEs:CVE-2014-9689
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Google Chrome before 41.0.2272.76, when Instant Extended mode is used, does not properly consider the interaction between the "1993 search" features and restore-from-disk RELOAD transitions, which makes it easier for remote attackers to spoof the addre...
CVEs:CVE-2015-2239
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Array index error in the MidiManagerUsb::DispatchSendMidiData function in media/midi/midi_manager_usb.cc in Google Chrome before 41.0.2272.76 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging r...
CVEs:CVE-2015-1232
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
content/renderer/device_sensors/device_motion_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate accelerometer data, which makes it easier for remote attackers to capture keystrokes via a crafted web site ...
CVEs:CVE-2011-5319
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
net/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allows remote proxy servers to conduct cookie-injection a...
CVEs:CVE-2015-1229
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| enterprise_linux_desktop_supplementary | affected | redhat | — | — |
| enterprise_linux_server | affected | redhat | — | — |
| enterprise_linux_server_supplementary_eus | affected | redhat | — | — |
| enterprise_linux_workstation_supplementary | affected | redhat | — | — |
| ubuntu_linux | affected | canonical | — | — |
Multiple unspecified vulnerabilities in Google V8 before 4.1.0.21, as used in Google Chrome before 41.0.2272.76, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2015-2238
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| ubuntu_linux | affected | canonical | — | — |
| v8 | affected | — | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.