CVE-2015-1300
Summary
| CVE | CVE-2015-1300 |
|---|---|
| State | PUBLISHED |
| Assigner | Chrome |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-09-03 22:59:11 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to obtain sensitive information via crafted JavaScript code that leverages a history.back call. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-3351-1 chromium-browser | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| openSUSE-SU-2015:1873-1: moderate: Security update for Chromium | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Chrome Releases: Stable Channel Update | af854a3a-2127-422b-91ae-364da2661108 | googlechromereleases.blogspot.com | |
| [blink] Revision 199553 | af854a3a-2127-422b-91ae-364da2661108 | src.chromium.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Google Chrome Multiple Bugs Let Remote Users Execute Arbitrary Code, Bypass Security Restrictions, Obtain Potentially Sensitive Information, and Spoof Content - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Issue 511616 - chromium - Security: Performance APIs reveal cross-origin URLs. - Monorail | af854a3a-2127-422b-91ae-364da2661108 | code.google.com | |
| Chromium: Multiple vulnerabilities (GLSA 201603-09) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Cached redirects + History traversal reveal cross-origin URLs · Issue #29 · w3c/resource-timing · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| openSUSE-SU-2015:1586-1: moderate: Security update for Chromium | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.