7.5
CVSSv2

CVE-2015-1218

Published: 09/03/2015 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple use-after-free vulnerabilities in the DOM implementation in Blink, as used in Google Chrome prior to 41.0.2272.76, allow remote malicious users to cause a denial of service or possibly have unspecified other impact via vectors that trigger movement of a SCRIPT element to different documents, related to (1) the HTMLScriptElement::didMoveToNewDocument function in core/html/HTMLScriptElement.cpp and (2) the SVGScriptElement::didMoveToNewDocument function in core/svg/SVGScriptElement.cpp.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

redhat enterprise linux desktop supplementary 6.0

redhat enterprise linux server supplementary 6.0

redhat enterprise linux workstation supplementary 6.0

redhat enterprise linux server supplementary eus 6.6.z

canonical ubuntu linux 14.10

canonical ubuntu linux 14.04

Vendor Advisories

Several security issues were fixed in Oxide ...
Multiple use-after-free vulnerabilities in the DOM implementation in Blink, as used in Google Chrome before 410227276, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger movement of a SCRIPT element to different documents, related to (1) the HTMLScriptElement::didMoveToNewDocume ...