CVE-2015-1221

Use-after-free vulnerability in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect ordering of operations in the Web SQL Database thread relative to Blink's main thread, related to the shutdown function in web/WebKit.cpp.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
ChromeCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
VendorProductVersion
googlechrome
𝑥
≤ 40.0.2214.115
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
wily
Fixed 41.0.2272.76-0ubuntu1.1134
released
vivid
Fixed 41.0.2272.76-0ubuntu1.1134
released
utopic
Fixed 41.0.2272.76-0ubuntu0.14.10.1.1118
released
trusty
Fixed 41.0.2272.76-0ubuntu0.14.04.1.1076
released
precise
ignored
lucid
ignored
oxide-qt
wily
Fixed 1.5.5-0ubuntu1
released
vivid
Fixed 1.5.5-0ubuntu1
released
utopic
Fixed 1.5.5-0ubuntu0.14.10.2
released
trusty
Fixed 1.5.5-0ubuntu0.14.04.3
released
precise
dne
lucid
dne