MEDIUM · 5.0

CVE-2015-1254

core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritance of the designMode attribute, which allows remote attackers to bypass the Same Origin Policy by lev...

Vulnerability Description

core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritance of the designMode attribute, which allows remote attackers to bypass the Same Origin Policy by leveraging the availability of editing.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
DebianDebian Linux8.0
GoogleChrome<= 42.0.2311.152

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-1254?

CVE-2015-1254 is a vulnerability with a CVSS score of 5.0 (MEDIUM). core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritance of the designMode attribute, which allows remote attackers to bypass the Same Origin Policy by lev...

How severe is CVE-2015-1254?

CVE-2015-1254 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-1254?

Check the references section above for vendor advisories and patch information. Affected products include: Debian Debian Linux, Google Chrome.