5
CVSSv2

CVE-2015-1224

Published: 09/03/2015 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 447
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The VpxVideoDecoder::VpxDecode function in media/filters/vpx_video_decoder.cc in the vpxdecoder implementation in Google Chrome prior to 41.0.2272.76 does not ensure that alpha-plane dimensions are identical to image dimensions, which allows remote malicious users to cause a denial of service (out-of-bounds read) via crafted VPx video data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

Vendor Advisories

Several security issues were fixed in Oxide ...
The VpxVideoDecoder::VpxDecode function in media/filters/vpx_video_decodercc in the vpxdecoder implementation in Google Chrome before 410227276 does not ensure that alpha-plane dimensions are identical to image dimensions, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted VPx video data ...