7.5
CVSSv2

CVE-2015-1277

Published: 23/07/2015 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Use-after-free vulnerability in the accessibility implementation in Google Chrome prior to 44.0.2403.89 allows remote malicious users to cause a denial of service or possibly have unspecified other impact by leveraging lack of certain validity checks for accessibility-tree data structures.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

debian debian linux 8.0

redhat enterprise linux server supplementary eus 6.7z

redhat enterprise linux desktop supplementary 6.0

redhat enterprise linux server supplementary 6.0

redhat enterprise linux workstation supplementary 6.0

opensuse opensuse 13.1

opensuse opensuse 13.2

Vendor Advisories

Several security issues were fixed in Oxide ...
Use-after-free vulnerability in the accessibility implementation in Google Chrome before 440240389 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging lack of certain validity checks for accessibility-tree data structures ...

Exploits

Chrome suffers from a ui::AXTree::Unserialize related use-after-free vulnerability ...