7.5
CVSSv2

CVE-2015-1284

Published: 23/07/2015 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The LocalFrame::isURLAllowed function in core/frame/LocalFrame.cpp in Blink, as used in Google Chrome prior to 44.0.2403.89, does not properly check for a page's maximum number of frames, which allows remote malicious users to cause a denial of service (invalid count value and use-after-free) or possibly have unspecified other impact via crafted JavaScript code that makes many createElement calls for IFRAME elements.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

redhat enterprise linux desktop supplementary 6.0

redhat enterprise linux server supplementary 6.0

redhat enterprise linux workstation supplementary 6.0

redhat enterprise linux server supplementary 6.7.z

opensuse opensuse 13.1

opensuse opensuse 13.2

Vendor Advisories

Several security issues were fixed in Oxide ...
The LocalFrame::isURLAllowed function in core/frame/LocalFramecpp in Blink, as used in Google Chrome before 440240389, does not properly check for a page's maximum number of frames, which allows remote attackers to cause a denial of service (invalid count value and use-after-free) or possibly have unspecified other impact via crafted JavaScript ...