Vulnerability Name: | CVE-2015-1241 (CCN-102380) | ||||||||||||||||||||||||||||||||
Assigned: | 2015-04-14 | ||||||||||||||||||||||||||||||||
Published: | 2015-04-14 | ||||||||||||||||||||||||||||||||
Updated: | 2017-01-03 | ||||||||||||||||||||||||||||||||
Summary: | Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
4.7 Medium (REDHAT Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-1241 Source: CCN Type: Google Chrome Releases Web site Stable Channel Update Source: CONFIRM Type: Vendor Advisory http://googlechromereleases.blogspot.com/2015/04/stable-channel-update_14.html Source: SUSE Type: UNKNOWN openSUSE-SU-2015:0748 Source: SUSE Type: UNKNOWN openSUSE-SU-2015:1887 Source: REDHAT Type: UNKNOWN RHSA-2015:0816 Source: UBUNTU Type: UNKNOWN USN-2570-1 Source: DEBIAN Type: UNKNOWN DSA-3238 Source: SECTRACK Type: UNKNOWN 1032209 Source: CONFIRM Type: UNKNOWN https://code.google.com/p/chromium/issues/detail?id=418402 Source: CONFIRM Type: UNKNOWN https://codereview.chromium.org/628763003 Source: CONFIRM Type: UNKNOWN https://codereview.chromium.org/660663002 Source: CONFIRM Type: UNKNOWN https://codereview.chromium.org/717573004 Source: CONFIRM Type: UNKNOWN https://codereview.chromium.org/868123002 Source: XF Type: UNKNOWN google-chrome-cve20151241-tapjacking(102380) Source: GENTOO Type: UNKNOWN GLSA-201506-04 Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-1241 | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration RedHat 1: ![]() | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |