« Volver al listado

CVE-2015-1217

Estado: ModificadaAlta (7.5)—

The V8LazyEventListener::prepareListenerObject function in bindings/core/v8/V8LazyEventListener.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, does not properly compile listeners, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (6)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-1217",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "chrome-cve-admin@google.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-03-09T00:59:09.387",
  "references": [
    {
      "url": "http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2015-0627.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/72901",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-2521-1",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "https://code.google.com/p/chromium/issues/detail?id=456192",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "https://codereview.chromium.org/910683002",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "https://codereview.chromium.org/958543002",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "https://security.gentoo.org/glsa/201503-12",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "https://src.chromium.org/viewvc/blink?revision=189796&view=revision",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2015-0627.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/72901",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-2521-1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://code.google.com/p/chromium/issues/detail?id=456192",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://codereview.chromium.org/910683002",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://codereview.chromium.org/958543002",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.gentoo.org/glsa/201503-12",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://src.chromium.org/viewvc/blink?revision=189796&view=revision",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-17"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The V8LazyEventListener::prepareListenerObject function in bindings/core/v8/V8LazyEventListener.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, does not properly compile listeners, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage \"type confusion.\""
    },
    {
      "lang": "es",
      "value": "La función V8LazyEventListener::prepareListenerObject en bindings/core/v8/V8LazyEventListener.cpp en los enlaces V8 en Blink, utilizado en Google Chrome anterior a 41.0.2272.76, no compila correctamente los oyentes, lo que permite a atacantes remotos causar una denegación de servicio o posiblemente tener otro impacto no especificado a través de vectores que aprovechan una 'confusión de tipos.'"
    }
  ],
  "lastModified": "2026-06-17T00:21:58.527",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E4473BA-37DE-4AF1-A828-99AA9D83AAE7",
              "versionEndIncluding": "40.0.2214.115"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_desktop_supplementary:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8C6E104-EDBC-481E-85B8-D39ED2058D39"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_supplementary:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B74C62D-4A6D-4A4F-ADF6-A508322CD447"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_supplementary_eus:6.6.z:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "04A2B180-08EF-4BE1-B1F2-48782874D6DB"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_workstation_supplementary:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E89B38A-3697-46DD-BB3F-E8D2373588BE"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5A6F2F3-4894-4392-8296-3B8DD2679084"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "49A63F39-30BE-443F-AF10-6245587D3359"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "chrome-cve-admin@google.com"
}