Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.806804
Category:General
Title:Google Chrome Multiple Vulnerabilities-02 (Dec 2015) - Mac OS X
Summary:Google Chrome is prone to multiple vulnerabilities.
Description:Summary:
Google Chrome is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to:

- The no proper use of HTML entities in function
'WebPageSerializerImp::openTagToString' in
'WebKit/Source/web/WebPageSerializerImpl.cpp' file in the page serializer.

- The difference in execution of multiple threads leading to race condition in
the mutation implementation

- An improper implementation of handler functions in class
'ObjectBackedNativeHandler' class which is in file
'extensions/renderer/object_backed_native_handler.cc' in the extensions
subsystem.

Vulnerability Impact:
Successful exploitation will allow an
attacker to cause denial of service or possibly have other impact, to inject
arbitrary web script or HTML, bypass the security restrictions and gain access
to potentially sensitive information.

Affected Software/OS:
Google Chrome versions prior to 47.0.2526.80
on Mac OS X.

Solution:
Upgrade to Google Chrome version
47.0.2526.80 or later.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2015-6788
BugTraq ID: 78734
http://www.securityfocus.com/bid/78734
Debian Security Information: DSA-3418 (Google Search)
http://www.debian.org/security/2015/dsa-3418
https://security.gentoo.org/glsa/201603-09
RedHat Security Advisories: RHSA-2015:2618
http://rhn.redhat.com/errata/RHSA-2015-2618.html
SuSE Security Announcement: openSUSE-SU-2015:2290 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00016.html
SuSE Security Announcement: openSUSE-SU-2015:2291 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00017.html
Common Vulnerability Exposure (CVE) ID: CVE-2015-6789
http://www.ubuntu.com/usn/USN-2860-1
Common Vulnerability Exposure (CVE) ID: CVE-2015-6790
Common Vulnerability Exposure (CVE) ID: CVE-2015-6791
Common Vulnerability Exposure (CVE) ID: CVE-2015-8548
CopyrightCopyright (C) 2015 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.