Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1263

Опубликовано: 19 мая 2015
Источник: redhat
CVSS2: 6.8

Описание

The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1223271chromium-browser: insecure download of spellcheck dictionary in unspecified component

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.

nvd
около 11 лет назад

The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.

debian
около 11 лет назад

The Spellcheck API implementation in Google Chrome before 43.0.2357.65 ...

github
около 4 лет назад

The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.

fstec
около 11 лет назад

Уязвимость браузера Google Chrome, позволяющая нарушителю подменить данные

6.8 Medium

CVSS2