5
CVSSv2

CVE-2015-1285

Published: 23/07/2015 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome prior to 44.0.2403.89, does not properly choose a truncation point, which makes it easier for remote malicious users to obtain sensitive information via an unspecified linear-time attack.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux server supplementary eus 6.7z

redhat enterprise linux desktop supplementary 6.0

redhat enterprise linux server supplementary 6.0

redhat enterprise linux workstation supplementary 6.0

debian debian linux 8.0

opensuse opensuse 13.1

opensuse opensuse 13.2

google chrome

Vendor Advisories

Several security issues were fixed in Oxide ...
The XSSAuditor::canonicalize function in core/html/parser/XSSAuditorcpp in the XSS auditor in Blink, as used in Google Chrome before 440240389, does not properly choose a truncation point, which makes it easier for remote attackers to obtain sensitive information via an unspecified linear-time attack ...