CVE-2015-1261
chromium-browser: URL bar spoofing in unspecified component
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use of a URL's fragment identifier during construction of a page-info popup, which allows remote attackers to spoof the URL bar or deliver misleading popup content via crafted text.
android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java en Google Chrome anterior a 43.0.2357.65 en Android no restringe correctamente el uso de el identificador de fragmentos de una URL durante la construcción de una página emergente de información, lo que permite a atacantes remotos falsificar la barra de la URL o entregar contenidos de emergentes engañosos a través de un texto manipulado.
Chromium is an open-source web browser, powered by WebKit. Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Chromium to crash or, potentially, execute arbitrary code with the privileges of the user running Chromium. All Chromium users should upgrade to these updated packages, which contain Chromium version 43.0.2357.65, which corrects these issues. After installing the update, Chromium must be restarted for the changes to take effect.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-01-21 CVE Reserved
- 2015-05-20 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://googlechromereleases.blogspot.com/2015/05/stable-channel-update_19.html | X_refsource_confirm | |
http://www.securityfocus.com/bid/74723 | Vdb Entry | |
http://www.securitytracker.com/id/1032375 | Vdb Entry | |
https://code.google.com/p/chromium/issues/detail?id=466351 | X_refsource_confirm | |
https://codereview.chromium.org/1011383005 | X_refsource_confirm | |
https://codereview.chromium.org/1056743002 | X_refsource_confirm | |
https://codereview.chromium.org/1077483002 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-updates/2015-05/msg00091.html | 2023-11-07 | |
http://lists.opensuse.org/opensuse-updates/2015-11/msg00015.html | 2023-11-07 | |
http://www.debian.org/security/2015/dsa-3267 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2015-1261 | 2015-05-25 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1223269 | 2015-05-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | <= 42.0.2311.107 Search vendor "Google" for product "Chrome" and version " <= 42.0.2311.107" | android |
Affected
|