7.5
CVSSv2

CVE-2015-1227

Published: 09/03/2015 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The DragImage::create function in platform/DragImage.cpp in Blink, as used in Google Chrome prior to 41.0.2272.76, does not initialize memory for image drawing, which allows remote malicious users to have an unspecified impact by triggering a failed image decoding, as demonstrated by an image for which the default orientation cannot be used.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

Vendor Advisories

Several security issues were fixed in Oxide ...
The DragImage::create function in platform/DragImagecpp in Blink, as used in Google Chrome before 410227276, does not initialize memory for image drawing, which allows remote attackers to have an unspecified impact by triggering a failed image decoding, as demonstrated by an image for which the default orientation cannot be used ...