Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2015-1300
Description:The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to obtain sensitive information via crafted JavaScript code that leverages a history.back call.
Test IDs: 1.3.6.1.4.1.25623.1.0.703351  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2015-1300
Debian Security Information: DSA-3351 (Google Search)
http://www.debian.org/security/2015/dsa-3351
https://security.gentoo.org/glsa/201603-09
https://github.com/w3c/resource-timing/issues/29
RedHat Security Advisories: RHSA-2015:1712
http://rhn.redhat.com/errata/RHSA-2015-1712.html
http://www.securitytracker.com/id/1033472
SuSE Security Announcement: openSUSE-SU-2015:1586 (Google Search)
http://lists.opensuse.org/opensuse-updates/2015-09/msg00029.html
SuSE Security Announcement: openSUSE-SU-2015:1873 (Google Search)
http://lists.opensuse.org/opensuse-updates/2015-11/msg00013.html




© 1998-2025 E-Soft Inc. All rights reserved.