Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-1266

Опубликовано: 26 июн. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5

Описание

content/browser/webui/content_web_ui_controller_factory.cc in Google Chrome before 43.0.2357.130 does not properly consider the scheme in determining whether a URL is associated with a WebUI SiteInstance, which allows remote attackers to bypass intended access restrictions via a similar URL, as demonstrated by use of http://gpu when there is a WebUI class for handling chrome://gpu requests.

РелизСтатусПримечание
devel

released

43.0.2357.130-0ubuntu1.1188
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [43.0.2357.130-0ubuntu0.14.04.1.1092]]
precise

ignored

trusty

released

43.0.2357.130-0ubuntu0.14.04.1.1092
trusty/esm

DNE

trusty was released [43.0.2357.130-0ubuntu0.14.04.1.1092]
upstream

released

43.0.2357.130
utopic

released

43.0.2357.130-0ubuntu0.14.10.1.1134
vivid

released

43.0.2357.130-0ubuntu0.15.04.1.1174
wily

released

43.0.2357.130-0ubuntu1.1188

Показывать по

РелизСтатусПримечание
devel

released

1.7.9-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1.7.9-0ubuntu0.14.04.1]]
precise

DNE

trusty

released

1.7.9-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [1.7.9-0ubuntu0.14.04.1]
upstream

released

1.7.9
utopic

released

1.7.9-0ubuntu0.14.10.1
vivid

released

1.7.9-0ubuntu0.15.04.1
wily

released

1.7.9-0ubuntu1

Показывать по

EPSS

Процентиль: 75%
0.00911
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
больше 10 лет назад

content/browser/webui/content_web_ui_controller_factory.cc in Google Chrome before 43.0.2357.130 does not properly consider the scheme in determining whether a URL is associated with a WebUI SiteInstance, which allows remote attackers to bypass intended access restrictions via a similar URL, as demonstrated by use of http://gpu when there is a WebUI class for handling chrome://gpu requests.

nvd
больше 10 лет назад

content/browser/webui/content_web_ui_controller_factory.cc in Google Chrome before 43.0.2357.130 does not properly consider the scheme in determining whether a URL is associated with a WebUI SiteInstance, which allows remote attackers to bypass intended access restrictions via a similar URL, as demonstrated by use of http://gpu when there is a WebUI class for handling chrome://gpu requests.

debian
больше 10 лет назад

content/browser/webui/content_web_ui_controller_factory.cc in Google C ...

github
больше 3 лет назад

content/browser/webui/content_web_ui_controller_factory.cc in Google Chrome before 43.0.2357.130 does not properly consider the scheme in determining whether a URL is associated with a WebUI SiteInstance, which allows remote attackers to bypass intended access restrictions via a similar URL, as demonstrated by use of http://gpu when there is a WebUI class for handling chrome://gpu requests.

fstec
больше 10 лет назад

Уязвимость браузера Google Chrome, позволяющая нарушителю обойти ограничения доступа

EPSS

Процентиль: 75%
0.00911
Низкий

5 Medium

CVSS2