5
CVSSv2

CVE-2015-1244

Published: 19/04/2015 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome prior to 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for remote malicious users to obtain sensitive information by sniffing the network for WebSocket traffic.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 14.10

canonical ubuntu linux 14.04

canonical ubuntu linux 15.04

debian debian linux 8.0

google chrome

Vendor Advisories

Several security issues were fixed in Oxide ...
Several vulnerabilities were discovered in the chromium web browser CVE-2015-1235 A Same Origin Policy bypass issue was discovered in the HTML parser CVE-2015-1236 Amitay Dobo discovered a Same Origin Policy bypass in the Web Audio API CVE-2015-1237 Khalil Zhani discovered a use-after-free issue in IPC CVE-2015-1238 clo ...
The URLRequest::GetHSTSRedirect function in url_request/url_requestcc in Google Chrome before 420231190 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for WebSocket traffic ...