CVE-2015-1254
Summary
| CVE | CVE-2015-1254 |
|---|---|
| State | PUBLISHED |
| Assigner | Chrome |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-05-20 10:59:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritance of the designMode attribute, which allows remote attackers to bypass the Same Origin Policy by leveraging the availability of editing. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Application | Chrome | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Google Chrome Multiple Bugs Let Remote Users Execute Arbitrary Code, Bypass Same-Origin Restrictions, and Spoof URLs - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Debian -- Security Information -- DSA-3267-1 chromium-browser | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| openSUSE-SU-2015:1877-1: moderate: Security update for Chromium | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Chromium: Multiple vulnerabilities (GLSA 201506-04) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Object not found! | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Google Chrome Prior to 43.0.2357.65 Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Issue 444927 - chromium - An open-source project to help move the web forward. - Monorail | af854a3a-2127-422b-91ae-364da2661108 | code.google.com | |
| Chrome Releases: Stable Channel Update | af854a3a-2127-422b-91ae-364da2661108 | googlechromereleases.blogspot.com | |
| [blink] Revision 192658 | af854a3a-2127-422b-91ae-364da2661108 | src.chromium.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.