CVE-2015-1210

EUVD-2015-1351
The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, does not properly consider frame access restrictions during the throwing of an exception, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
Affected Products (NVD)
VendorProductVersion
googlechrome
𝑥
< 40.0.2214.111
canonicalubuntu_linux
14.04
canonicalubuntu_linux
14.10
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_eus
6.6
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server_aus
6.6
redhatenterprise_linux_workstation
6.0
opensuseopensuse
13.1
opensuseopensuse
13.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
lucid
ignored
precise
ignored
trusty
Fixed 40.0.2214.111-0ubuntu0.14.04.1.1069
released
utopic
Fixed 40.0.2214.111-0ubuntu0.14.10.1.1111
released
vivid
Fixed 40.0.2214.111-0ubuntu1.1121
released
wily
Fixed 40.0.2214.111-0ubuntu1.1121
released
oxide-qt
lucid
dne
precise
dne
trusty
Fixed 1.4.3-0ubuntu0.14.04.1
released
utopic
Fixed 1.4.3-0ubuntu0.14.10.1
released
vivid
Fixed 1.5.3-0ubuntu2
released
wily
Fixed 1.5.3-0ubuntu2
released
References