4.3
CVSSv2

CVE-2015-1241

Published: 19/04/2015 Updated: 26/01/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Google Chrome prior to 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote malicious users to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

debian debian linux 8.0

canonical ubuntu linux 14.10

canonical ubuntu linux 15.04

canonical ubuntu linux 14.04

opensuse opensuse 13.1

opensuse opensuse 13.2

suse linux enterprise 12.0

redhat enterprise linux server aus 6.6

redhat enterprise linux desktop 6.0

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

redhat enterprise linux eus 6.6

redhat enterprise linux server eus 6.6

Vendor Advisories

Several security issues were fixed in Oxide ...
Several vulnerabilities were discovered in the chromium web browser CVE-2015-1235 A Same Origin Policy bypass issue was discovered in the HTML parser CVE-2015-1236 Amitay Dobo discovered a Same Origin Policy bypass in the Web Audio API CVE-2015-1237 Khalil Zhani discovered a use-after-free issue in IPC CVE-2015-1238 clo ...
Google Chrome before 420231190 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack ...