Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1274

Опубликовано: 21 июл. 2015
Источник: redhat
CVSS2: 6.8

Описание

Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it easier for remote attackers to execute arbitrary code by providing a crafted file and leveraging a user's previous "Always open files of this type" choice, related to download_commands.cc and download_prefs.cc.

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1245577chromium-browser: Settings allowed executable files to run immediately after download in unsepcified

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it easier for remote attackers to execute arbitrary code by providing a crafted file and leveraging a user's previous "Always open files of this type" choice, related to download_commands.cc and download_prefs.cc.

nvd
больше 10 лет назад

Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it easier for remote attackers to execute arbitrary code by providing a crafted file and leveraging a user's previous "Always open files of this type" choice, related to download_commands.cc and download_prefs.cc.

debian
больше 10 лет назад

Google Chrome before 44.0.2403.89 does not ensure that the auto-open l ...

github
больше 3 лет назад

Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it easier for remote attackers to execute arbitrary code by providing a crafted file and leveraging a user's previous "Always open files of this type" choice, related to download_commands.cc and download_prefs.cc.

fstec
больше 10 лет назад

Уязвимость браузера Google Chrome, позволяющая нарушителю выполнить произвольный код

6.8 Medium

CVSS2