![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.806804 |
Category: | General |
Title: | Google Chrome Multiple Vulnerabilities-02 (Dec 2015) - Mac OS X |
Summary: | Google Chrome is prone to multiple vulnerabilities. |
Description: | Summary: Google Chrome is prone to multiple vulnerabilities. Vulnerability Insight: Multiple flaws are due to: - The no proper use of HTML entities in function 'WebPageSerializerImp::openTagToString' in 'WebKit/Source/web/WebPageSerializerImpl.cpp' file in the page serializer. - The difference in execution of multiple threads leading to race condition in the mutation implementation - An improper implementation of handler functions in class 'ObjectBackedNativeHandler' class which is in file 'extensions/renderer/object_backed_native_handler.cc' in the extensions subsystem. Vulnerability Impact: Successful exploitation will allow an attacker to cause denial of service or possibly have other impact, to inject arbitrary web script or HTML, bypass the security restrictions and gain access to potentially sensitive information. Affected Software/OS: Google Chrome versions prior to 47.0.2526.80 on Mac OS X. Solution: Upgrade to Google Chrome version 47.0.2526.80 or later. CVSS Score: 10.0 CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2015-6788 BugTraq ID: 78734 http://www.securityfocus.com/bid/78734 Debian Security Information: DSA-3418 (Google Search) http://www.debian.org/security/2015/dsa-3418 https://security.gentoo.org/glsa/201603-09 RedHat Security Advisories: RHSA-2015:2618 http://rhn.redhat.com/errata/RHSA-2015-2618.html SuSE Security Announcement: openSUSE-SU-2015:2290 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00016.html SuSE Security Announcement: openSUSE-SU-2015:2291 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00017.html Common Vulnerability Exposure (CVE) ID: CVE-2015-6789 http://www.ubuntu.com/usn/USN-2860-1 Common Vulnerability Exposure (CVE) ID: CVE-2015-6790 Common Vulnerability Exposure (CVE) ID: CVE-2015-6791 Common Vulnerability Exposure (CVE) ID: CVE-2015-8548 |
Copyright | Copyright (C) 2015 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |