4.3
CVSSv2

CVE-2015-1248

Published: 19/04/2015 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The FileSystem API in Google Chrome prior to 40.0.2214.91 allows remote malicious users to bypass the SafeBrowsing for Executable Files protection mechanism by creating a .exe file in a temporary filesystem and then referencing this file with a filesystem:http: URL.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 7.0

google chrome

Vendor Advisories

Several vulnerabilities were discovered in the chromium web browser CVE-2015-1235 A Same Origin Policy bypass issue was discovered in the HTML parser CVE-2015-1236 Amitay Dobo discovered a Same Origin Policy bypass in the Web Audio API CVE-2015-1237 Khalil Zhani discovered a use-after-free issue in IPC CVE-2015-1238 clo ...
The FileSystem API in Google Chrome before 400221491 allows remote attackers to bypass the SafeBrowsing for Executable Files protection mechanism by creating a exe file in a temporary filesystem and then referencing this file with a filesystem:http: URL ...