Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2015-1278

EPSS 1.09% · P78
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2015-1278

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
content/browser/web_contents/web_contents_impl.cc in Google Chrome before 44.0.2403.89 does not ensure that a PDF document's modal dialog is closed upon navigation to an interstitial page, which allows remote attackers to spoof URLs via a crafted document, as demonstrated by the alert_dialog.pdf document.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Google Chrome 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Google Chrome是美国谷歌(Google)公司开发的一款Web浏览器。 Google Chrome 44.0.2403.89之前版本的content/browser/web_contents/web_contents_impl.cc文件中存在安全漏洞,该漏洞源于当从PDF导航到空隙页面(interstitial)时,程序没有检查PDF文档的模态对话框(modal dialog)是否关闭。远程攻击者可借助特制的文档利用该漏洞伪造URL。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2015-1278

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2015-1278

登录查看更多情报信息。

Same Patch Batch · n/a · 2015-07-23 · 23 CVEs total

CVE-2015-1280Google Chrome Skia 缓冲区溢出漏洞
CVE-2015-5605Google Chrome V8 拒绝服务漏洞
CVE-2015-1289Google Chrome 拒绝服务漏洞
CVE-2015-1288Google Chrome Spellcheck API 安全漏洞
CVE-2015-1287Google Chrome Blink 安全漏洞
CVE-2015-1286Google Chrome 跨站脚本漏洞
CVE-2015-1285Google Chrome Blink 安全漏洞
CVE-2015-1284Google Chrome Blink 输入验证漏洞
CVE-2015-1283Google Chrome Expat 数字错误漏洞
CVE-2015-1282Google Chrome PDFium 资源管理错误漏洞
CVE-2015-1281Google Chrome Blink 安全漏洞
CVE-2015-4285Cisco ASR9k IOS XR Local Packet Transport Services 资源管理错误漏洞
CVE-2015-1279Google Chrome PDFium 数字错误漏洞
CVE-2015-1277Google Chrome accessibility 释放后重用漏洞
CVE-2015-1275Google Chrome 跨站脚本漏洞
CVE-2015-1274Google Chrome 任意代码执行漏洞
CVE-2015-1273Google Chrome PDFium OpenJPEG 基于堆的缓冲区溢出漏洞
CVE-2015-1272Google Chrome GPU程序释放后重用漏洞
CVE-2015-1271Google Chrome PDFium 缓冲区溢出漏洞
CVE-2015-1270Google Chrome International Components for Unicode 拒绝服务漏洞

Showing top 20 of 23 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2015-1278

No comments yet


Leave a comment