[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-1257Date: (C)2015-06-12   (M)2023-12-22


platform/graphics/filters/FEColorMatrix.cpp in the SVG implementation in Blink, as used in Google Chrome before 43.0.2357.65, does not properly handle an insufficient number of values in an feColorMatrix filter, which allows remote attackers to cause a denial of service (container overflow) or possibly have unspecified other impact via a crafted document.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
-1032375
-74723
DSA-3267
GLSA-201506-04
http://googlechromereleases.blogspot.com/2015/05/stable-channel-update_19.html
https://code.google.com/p/chromium/issues/detail?id=468519
https://src.chromium.org/viewvc/blink?view=rev&revision=193571
https://src.chromium.org/viewvc/blink?view=rev&revision=193911
openSUSE-SU-2015:0969
openSUSE-SU-2015:1877

CPE    2
cpe:/o:debian:debian_linux:8.0
cpe:/a:google:chrome
CWE    1
CWE-119
OVAL    12
oval:org.secpod.oval:def:24917
oval:org.secpod.oval:def:24918
oval:org.secpod.oval:def:24935
oval:org.secpod.oval:def:24936
...

© SecPod Technologies