4.3
CVSSv2

CVE-2015-1269

Published: 26/06/2015 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The DecodeHSTSPreloadRaw function in net/http/transport_security_state.cc in Google Chrome prior to 43.0.2357.130 does not properly canonicalize DNS hostnames before making comparisons to HSTS or HPKP preload entries, which allows remote malicious users to bypass intended access restrictions via a string that (1) ends in a . (dot) character or (2) is not entirely lowercase.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

Vendor Advisories

Several security issues were fixed in Oxide ...
The DecodeHSTSPreloadRaw function in net/http/transport_security_statecc in Google Chrome before 4302357130 does not properly canonicalize DNS hostnames before making comparisons to HSTS or HPKP preload entries, which allows remote attackers to bypass intended access restrictions via a string that (1) ends in a (dot) character or (2) is not e ...