Multiple use-after-free vulnerabilities in the DOM implementation in Blink, as used in Google Chrome prior to 41.0.2272.76, allow remote malicious users to cause a denial of service or possibly have unspecified other impact via vectors that trigger movement of a SCRIPT element to different documents, related to (1) the HTMLScriptElement::didMoveToNewDocument function in core/html/HTMLScriptElement.cpp and (2) the SVGScriptElement::didMoveToNewDocument function in core/svg/SVGScriptElement.cpp.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
google chrome |
||
redhat enterprise linux desktop supplementary 6.0 |
||
redhat enterprise linux server supplementary 6.0 |
||
redhat enterprise linux workstation supplementary 6.0 |
||
redhat enterprise linux server supplementary eus 6.6.z |
||
canonical ubuntu linux 14.10 |
||
canonical ubuntu linux 14.04 |