6.8
CVSSv2

CVE-2015-1251

Published: 20/05/2015 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Use-after-free vulnerability in the SpeechRecognitionClient implementation in the Speech subsystem in Google Chrome prior to 43.0.2357.65 allows remote malicious users to execute arbitrary code via a crafted document.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

debian debian linux 8.0

Exploits

A specially crafted web-page can cause the blink rendering engine used by Google Chrome and Chromium to continue to use a speech recognition API object after the memory block that contained the object has been freed An attacker can force the code to read a pointer from the freed memory and use this to call a function, allowing arbitrary code execu ...