5
CVSSv2

CVE-2015-1247

Published: 19/04/2015 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The SearchEngineTabHelper::OnPageHasOSDD function in browser/ui/search_engines/search_engine_tab_helper.cc in Google Chrome prior to 42.0.2311.90 does not prevent use of a file: URL for an OpenSearch descriptor XML document, which might allow remote malicious users to obtain sensitive information from local files via a crafted (1) http or (2) https web site.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

debian debian linux 7.0

Vendor Advisories

Several vulnerabilities were discovered in the chromium web browser CVE-2015-1235 A Same Origin Policy bypass issue was discovered in the HTML parser CVE-2015-1236 Amitay Dobo discovered a Same Origin Policy bypass in the Web Audio API CVE-2015-1237 Khalil Zhani discovered a use-after-free issue in IPC CVE-2015-1238 clo ...
The SearchEngineTabHelper::OnPageHasOSDD function in browser/ui/search_engines/search_engine_tab_helpercc in Google Chrome before 420231190 does not prevent use of a file: URL for an OpenSearch descriptor XML document, which might allow remote attackers to obtain sensitive information from local files via a crafted (1) http or (2) https web sit ...