MEDIUM · 5.0

CVE-2015-1210

The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and be...

Vulnerability Description

The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, does not properly consider frame access restrictions during the throwing of an exception, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
GoogleChrome< 40.0.2214.109
AppleMacos-
LinuxLinux Kernel-
MicrosoftWindows-
CanonicalUbuntu Linux14.04
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Eus6.6
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Server Aus6.6
RedhatEnterprise Linux Workstation6.0
OpensuseOpensuse13.1

References

FAQ

What is CVE-2015-1210?

CVE-2015-1210 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and be...

How severe is CVE-2015-1210?

CVE-2015-1210 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-1210?

Check the references section above for vendor advisories and patch information. Affected products include: Google Chrome, Apple Macos, Linux Linux Kernel, Microsoft Windows, Canonical Ubuntu Linux.