CVE-2015-1286
23.07.2015, 00:59
Cross-site scripting (XSS) vulnerability in the V8ContextNativeHandler::GetModuleSystem function in extensions/renderer/v8_context_native_handler.cc in Google Chrome before 44.0.2403.89 allows remote attackers to inject arbitrary web script or HTML by leveraging the lack of a certain V8 context restriction, aka a Blink "Universal XSS (UXSS)."
Vendor | Product | Version |
---|---|---|
debian | debian_linux | 8.0 |
opensuse | opensuse | 13.1 |
opensuse | opensuse | 13.2 |
redhat | enterprise_linux_desktop_supplementary | 6.0 |
redhat | enterprise_linux_server_supplementary | 6.0 |
redhat | enterprise_linux_server_supplementary_eus | 6.7z:z |
redhat | enterprise_linux_workstation_supplementary | 6.0 |
chrome | 𝑥 ≤ 43.0.2357.134 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References