CVE-2015-1295
Summary
| CVE | CVE-2015-1295 |
|---|---|
| State | PUBLISHED |
| Assigner | Chrome |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-09-03 22:59:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Multiple use-after-free vulnerabilities in the PrintWebViewHelper class in components/printing/renderer/print_web_view_helper.cc in Google Chrome before 45.0.2454.85 allow user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact by triggering nested IPC messages during preparation for printing, as demonstrated by messages associated with PDF documents in conjunction with messages about printer capabilities. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Issue 502562 - chromium - Heap-use-after-free in WebLocalFrameImpl::printBegin - Monorail | af854a3a-2127-422b-91ae-364da2661108 | code.google.com | |
| Debian -- Security Information -- DSA-3351-1 chromium-browser | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| openSUSE-SU-2015:1873-1: moderate: Security update for Chromium | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Chrome Releases: Stable Channel Update | af854a3a-2127-422b-91ae-364da2661108 | googlechromereleases.blogspot.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Google Chrome Multiple Bugs Let Remote Users Execute Arbitrary Code, Bypass Security Restrictions, Obtain Potentially Sensitive Information, and Spoof Content - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Issue 1228693002: Crash on nested IPC handlers in PrintWebViewHelper - Code Review | af854a3a-2127-422b-91ae-364da2661108 | codereview.chromium.org | |
| Chromium: Multiple vulnerabilities (GLSA 201603-09) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| openSUSE-SU-2015:1586-1: moderate: Security update for Chromium | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.