4.3
CVSSv2

CVE-2015-1281

Published: 23/07/2015 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

core/loader/ImageLoader.cpp in Blink, as used in Google Chrome prior to 44.0.2403.89, does not properly determine the V8 context of a microtask, which allows remote malicious users to bypass Content Security Policy (CSP) restrictions by providing an image from an unintended source.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 13.1

opensuse opensuse 13.2

debian debian linux 8.0

google chrome

redhat enterprise linux server supplementary eus 6.7z

redhat enterprise linux desktop supplementary 6.0

redhat enterprise linux server supplementary 6.0

redhat enterprise linux workstation supplementary 6.0

Vendor Advisories

Several security issues were fixed in Oxide ...
core/loader/ImageLoadercpp in Blink, as used in Google Chrome before 440240389, does not properly determine the V8 context of a microtask, which allows remote attackers to bypass Content Security Policy (CSP) restrictions by providing an image from an unintended source ...