CVE-2015-1254

EUVD-2015-1395
core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritance of the designMode attribute, which allows remote attackers to bypass the Same Origin Policy by leveraging the availability of editing.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
Affected Products (NVD)
VendorProductVersion
debiandebian_linux
8.0
googlechrome
𝑥
≤ 42.0.2311.152
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
precise
ignored
trusty
Fixed 43.0.2357.81-0ubuntu0.14.04.1.1089
released
utopic
Fixed 43.0.2357.81-0ubuntu0.14.10.1.1131
released
vivid
Fixed 43.0.2357.81-0ubuntu0.15.04.1.1170
released
wily
Fixed 43.0.2357.81-0ubuntu1.1179
released
oxide-qt
precise
dne
trusty
Fixed 1.7.8-0ubuntu0.14.04.1
released
utopic
Fixed 1.7.8-0ubuntu0.14.10.1
released
vivid
Fixed 1.7.8-0ubuntu0.15.04.1
released
wily
Fixed 1.7.8-0ubuntu1
released
Common Weakness Enumeration