Описание
core/rendering/compositing/RenderLayerCompositor.cpp in Blink, as used in Google Chrome before 38.0.2125.102 on Android, does not properly handle a certain IFRAME overflow condition, which allows remote attackers to spoof content via a crafted web site that interferes with the scrollbar.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 38.0.2125.111-0ubuntu1.1103 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [38.0.2125.111-0ubuntu0.14.04.1.1061]] |
| lucid | ignored | end of life |
| precise | ignored | |
| trusty | released | 38.0.2125.111-0ubuntu0.14.04.1.1061 |
| trusty/esm | DNE | trusty was released [38.0.2125.111-0ubuntu0.14.04.1.1061] |
| upstream | released | 38.0.2125.102 |
| utopic | released | 38.0.2125.111-0ubuntu0.14.10.1.1103 |
| vivid | released | 38.0.2125.111-0ubuntu1.1103 |
| wily | released | 38.0.2125.111-0ubuntu1.1103 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected] |
| lucid | DNE | |
| precise | DNE | |
| trusty | not-affected | |
| trusty/esm | DNE | trusty was not-affected |
| upstream | not-affected | |
| utopic | not-affected | |
| vivid | not-affected | |
| wily | not-affected |
Показывать по
EPSS
5 Medium
CVSS2
Связанные уязвимости
core/rendering/compositing/RenderLayerCompositor.cpp in Blink, as used in Google Chrome before 38.0.2125.102 on Android, does not properly handle a certain IFRAME overflow condition, which allows remote attackers to spoof content via a crafted web site that interferes with the scrollbar.
core/rendering/compositing/RenderLayerCompositor.cpp in Blink, as used ...
core/rendering/compositing/RenderLayerCompositor.cpp in Blink, as used in Google Chrome before 38.0.2125.102 on Android, does not properly handle a certain IFRAME overflow condition, which allows remote attackers to spoof content via a crafted web site that interferes with the scrollbar.
EPSS
5 Medium
CVSS2