CVE-2015-1263
20.05.2015, 10:59
The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.Enginsight
Vendor | Product | Version |
---|---|---|
chrome | 𝑥 ≤ 42.0.2311.152 | |
debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
chromium-browser |
| ||||||||||
oxide-qt |
|
Common Weakness Enumeration
References