Vulnerability Name: | CVE-2015-1302 (CCN-107942) | ||||||||||||||||||||||||||||||||
Assigned: | 2015-11-10 | ||||||||||||||||||||||||||||||||
Published: | 2015-11-10 | ||||||||||||||||||||||||||||||||
Updated: | 2018-01-05 | ||||||||||||||||||||||||||||||||
Summary: | The PDF viewer in Google Chrome before 46.0.2490.86 does not properly restrict scripting messages and API exposure, which allows remote attackers to bypass the Same Origin Policy via an unintended embedder or unintended plugin loading, related to pdf.js and out_of_process_instance.cc. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N) 3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-1302 Source: CCN Type: Google Chrome Releases Web site Stable Channel Update Source: CONFIRM Type: Vendor Advisory http://googlechromereleases.blogspot.com/2015/11/stable-channel-update.html Source: SUSE Type: UNKNOWN openSUSE-SU-2015:2068 Source: SUSE Type: UNKNOWN openSUSE-SU-2015:2069 Source: REDHAT Type: UNKNOWN RHSA-2015:1841 Source: DEBIAN Type: UNKNOWN DSA-3415 Source: BID Type: UNKNOWN 77537 Source: CCN Type: BID-77537 Google Chrome CVE-2015-1302 Information Disclosure Vulnerability Source: SECTRACK Type: UNKNOWN 1034132 Source: CONFIRM Type: UNKNOWN https://code.google.com/p/chromium/issues/detail?id=520422 Source: CONFIRM Type: UNKNOWN https://codereview.chromium.org/1316803003 Source: XF Type: UNKNOWN google-chrome-cve20151302-info-disc(107942) Source: GENTOO Type: UNKNOWN GLSA-201603-09 Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-1302 | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: ![]() | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |