Vulnerability Name: | CVE-2015-1251 (CCN-103268) | ||||||||||||||||||||||||||||||||
Assigned: | 2015-05-19 | ||||||||||||||||||||||||||||||||
Published: | 2015-05-19 | ||||||||||||||||||||||||||||||||
Updated: | 2018-10-09 | ||||||||||||||||||||||||||||||||
Summary: | Use-after-free vulnerability in the SpeechRecognitionClient implementation in the Speech subsystem in Google Chrome before 43.0.2357.65 allows remote attackers to execute arbitrary code via a crafted document. CWE-416: Use After Free | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.0 Medium (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||
References: | Source: MISC Type: UNKNOWN http://blog.skylined.nl/20161123001.html Source: MITRE Type: CNA CVE-2015-1251 Source: CCN Type: Google Chrome Releases Web site Stable Channel Update Source: CONFIRM Type: Patch, Vendor Advisory http://googlechromereleases.blogspot.com/2015/05/stable-channel-update_19.html Source: SUSE Type: UNKNOWN openSUSE-SU-2015:0969 Source: SUSE Type: UNKNOWN openSUSE-SU-2015:1877 Source: FULLDISC Type: UNKNOWN 20161125 CVE-2015-1251: Chrome blink Speech­Recognition­Controller use-after-free details Source: DEBIAN Type: UNKNOWN DSA-3267 Source: BUGTRAQ Type: UNKNOWN 20161123 CVE-2015-1251: Chrome blink SpeechÂ-RecognitionÂ-Controller use-after-free details Source: BID Type: UNKNOWN 74723 Source: CCN Type: BID-74723 Google Chrome Prior to 43.0.2357.65 Multiple Security Vulnerabilities Source: SECTRACK Type: UNKNOWN 1032375 Source: MISC Type: UNKNOWN http://zerodayinitiative.com/advisories/ZDI-15-236/ Source: CONFIRM Type: UNKNOWN https://code.google.com/p/chromium/issues/detail?id=481015 Source: XF Type: UNKNOWN google-chrome-cve20151251-code-exec(103268) Source: CCN Type: Packet Storm Security [11-23-2016] Chrome Blink SpeechRecognitionController Use-After-Free Source: GENTOO Type: UNKNOWN GLSA-201506-04 Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-1251 Source: CCN Type: ZDI-15-236 Google Chrome SpeechRecognitionClient Use-After-Free Remote Code Execution Vulnerability | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration RedHat 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |