Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.805996
Category:General
Title:Google Chrome Multiple Vulnerabilities-01 (Oct 2015) - Linux
Summary:Google Chrome is prone to multiple vulnerabilities.
Description:Summary:
Google Chrome is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws exist due to:

- An error in 'ContainerNode::parserInsertBefore' function in
core/dom/ContainerNode.cpp withn Blink.

- A use-after-free error in the CPDFSDK_PageView implementation in
fpdfsdk/src/fsdk_mgr.cpp in PDFium.

- A use-after-free error in content/browser/service_worker/embedded_worker_instance.cc
in the ServiceWorker implementation.

- An error in 'CPDF_Document::GetPage' function in
fpdfapi/fpdf_parser/fpdf_parser_document.cpp in PDFium.

- An error in 'shouldTreatAsUniqueOrigin' function in
platform/weborigin/SecurityOrigin.cpp in Blink.

- An error in the 'Image11::map' function in renderer/d3d/d3d11/Image11.cpp
in libANGLE.

- An error in 'update_dimensions' function in libavcodec/vp8.c in FFmpeg.

- An error in the 'CSSFontFaceSrcValue::fetch' function in
core/css/CSSFontFaceSrcValue.cpp in the Cascading Style Sheets (CSS) implementation.

- Other multiple unspecified errors.

Vulnerability Impact:
Successful exploitation would allow an attacker
to cause a denial of service or possibly have other impact, bypass the security
restrictions and gain access to potentially sensitive information.

Affected Software/OS:
Google Chrome versions prior to 46.0.2490.71
on Linux.

Solution:
Upgrade to Google Chrome version
46.0.2490.71 or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2015-7834
http://www.ubuntu.com/usn/USN-2770-1
http://www.ubuntu.com/usn/USN-2770-2
Common Vulnerability Exposure (CVE) ID: CVE-2015-6763
BugTraq ID: 77071
http://www.securityfocus.com/bid/77071
Debian Security Information: DSA-3376 (Google Search)
http://www.debian.org/security/2015/dsa-3376
https://www.exploit-db.com/exploits/38763/
https://security.gentoo.org/glsa/201603-09
http://packetstormsecurity.com/files/134482/Google-Chrome-Integer-Overflow.html
RedHat Security Advisories: RHSA-2015:1912
http://rhn.redhat.com/errata/RHSA-2015-1912.html
http://www.securitytracker.com/id/1033816
Common Vulnerability Exposure (CVE) ID: CVE-2015-6762
Common Vulnerability Exposure (CVE) ID: CVE-2015-6761
BugTraq ID: 77073
http://www.securityfocus.com/bid/77073
https://lists.debian.org/debian-lts-announce/2018/12/msg00009.html
Common Vulnerability Exposure (CVE) ID: CVE-2015-6760
Common Vulnerability Exposure (CVE) ID: CVE-2015-6759
Common Vulnerability Exposure (CVE) ID: CVE-2015-6758
Common Vulnerability Exposure (CVE) ID: CVE-2015-6757
Common Vulnerability Exposure (CVE) ID: CVE-2015-6756
Common Vulnerability Exposure (CVE) ID: CVE-2015-6755
CopyrightCopyright (C) 2015 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.