Описание
Google Chrome before 41.0.2272.76, when Instant Extended mode is used, does not properly consider the interaction between the "1993 search" features and restore-from-disk RELOAD transitions, which makes it easier for remote attackers to spoof the address bar for a search-results page by leveraging (1) a compromised search engine or (2) an XSS vulnerability in a search engine, a different vulnerability than CVE-2015-1231.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 41.0.2272.76-0ubuntu1.1134 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [41.0.2272.76-0ubuntu0.14.04.1.1076]] |
| lucid | ignored | end of life |
| precise | ignored | |
| trusty | released | 41.0.2272.76-0ubuntu0.14.04.1.1076 |
| trusty/esm | DNE | trusty was released [41.0.2272.76-0ubuntu0.14.04.1.1076] |
| upstream | released | 41.0.2272.76 |
| utopic | released | 41.0.2272.76-0ubuntu0.14.10.1.1118 |
| vivid | released | 41.0.2272.76-0ubuntu1.1134 |
| wily | released | 41.0.2272.76-0ubuntu1.1134 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected] |
| lucid | DNE | |
| precise | DNE | |
| trusty | not-affected | |
| trusty/esm | DNE | trusty was not-affected |
| upstream | not-affected | |
| utopic | not-affected | |
| vivid | not-affected | |
| wily | not-affected |
Показывать по
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Google Chrome before 41.0.2272.76, when Instant Extended mode is used, does not properly consider the interaction between the "1993 search" features and restore-from-disk RELOAD transitions, which makes it easier for remote attackers to spoof the address bar for a search-results page by leveraging (1) a compromised search engine or (2) an XSS vulnerability in a search engine, a different vulnerability than CVE-2015-1231.
Google Chrome before 41.0.2272.76, when Instant Extended mode is used, ...
Google Chrome before 41.0.2272.76, when Instant Extended mode is used, does not properly consider the interaction between the "1993 search" features and restore-from-disk RELOAD transitions, which makes it easier for remote attackers to spoof the address bar for a search-results page by leveraging (1) a compromised search engine or (2) an XSS vulnerability in a search engine, a different vulnerability than CVE-2015-1231.
EPSS
4.3 Medium
CVSS2