Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1275

Опубликовано: 21 июл. 2015
Источник: redhat
CVSS2: 6.8

Описание

Cross-site scripting (XSS) vulnerability in org/chromium/chrome/browser/UrlUtilities.java in Google Chrome before 44.0.2403.89 on Android allows remote attackers to inject arbitrary web script or HTML via a crafted intent: URL, as demonstrated by a trailing alert(document.cookie);// substring, aka "Universal XSS (UXSS)."

Отчет

Not vulnerable. This issue does not affect the version of chromium-browser package as shipped with Red Hat Enterprise Linux 6 since this flaw only affects Android versions of the browser.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6chromium-browserNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1245579chromium-browser: UXSS in Chrome for Android.

6.8 Medium

CVSS2

Связанные уязвимости

nvd
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in org/chromium/chrome/browser/UrlUtilities.java in Google Chrome before 44.0.2403.89 on Android allows remote attackers to inject arbitrary web script or HTML via a crafted intent: URL, as demonstrated by a trailing alert(document.cookie);// substring, aka "Universal XSS (UXSS)."

debian
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in org/chromium/chrome/browse ...

github
больше 3 лет назад

Cross-site scripting (XSS) vulnerability in org/chromium/chrome/browser/UrlUtilities.java in Google Chrome before 44.0.2403.89 on Android allows remote attackers to inject arbitrary web script or HTML via a crafted intent: URL, as demonstrated by a trailing alert(document.cookie);// substring, aka "Universal XSS (UXSS)."

fstec
больше 10 лет назад

Уязвимость браузера Google Chrome, позволяющая нарушителю выполнить произвольный веб или HTML-код

6.8 Medium

CVSS2