{"api_version":"1","generated_at":"2026-07-24T18:24:28+00:00","cve":"CVE-2015-1221","urls":{"html":"https://cve.report/CVE-2015-1221","api":"https://cve.report/api/cve/CVE-2015-1221.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-1221","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-1221"},"summary":{"title":"CVE-2015-1221","description":"Use-after-free vulnerability in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect ordering of operations in the Web SQL Database thread relative to Blink's main thread, related to the shutdown function in web/WebKit.cpp.","state":"PUBLISHED","assigner":"Chrome","published_at":"2015-03-09 00:59:14","updated_at":"2026-05-06 22:30:45"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/72901","name":"http://www.securityfocus.com/bid/72901","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Google Chrome Prior to 41.0.2272.76 Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://security.gentoo.org/glsa/201503-12","name":"https://security.gentoo.org/glsa/201503-12","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://code.google.com/p/chromium/issues/detail?id=455368","name":"https://code.google.com/p/chromium/issues/detail?id=455368","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Issue 455368 - \n chromium -\n \n UNKNOWN in blink::SQLStatementBackend::execute - \n An open-source project to help move the web forward. - Google Project Hosting","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://src.chromium.org/viewvc/blink?revision=190035&view=revision","name":"https://src.chromium.org/viewvc/blink?revision=190035&view=revision","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[blink] Revision 190035","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-0627.html","name":"http://rhn.redhat.com/errata/RHSA-2015-0627.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html","name":"http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Chrome Releases: Stable Channel Update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://src.chromium.org/viewvc/blink?revision=190021&view=revision","name":"https://src.chromium.org/viewvc/blink?revision=190021&view=revision","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[blink] Revision 190021","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-2521-1","name":"http://www.ubuntu.com/usn/USN-2521-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"USN-2521-1: Oxide vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-1221","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-1221","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"1221","vulnerable":"1","versionEndIncluding":"40.0.2214.115","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"google","cpe5":"chrome","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T04:33:20.703Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://src.chromium.org/viewvc/blink?revision=190021&view=revision"},{"name":"USN-2521-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-2521-1"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://src.chromium.org/viewvc/blink?revision=190035&view=revision"},{"name":"72901","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/72901"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://code.google.com/p/chromium/issues/detail?id=455368"},{"name":"GLSA-201503-12","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"https://security.gentoo.org/glsa/201503-12"},{"name":"RHSA-2015:0627","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0627.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-03-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"Use-after-free vulnerability in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect ordering of operations in the Web SQL Database thread relative to Blink's main thread, related to the shutdown function in web/WebKit.cpp."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-20T16:57:01.000Z","orgId":"ebfee0ef-53dd-4cf3-9e2a-08a5bd7a7e28","shortName":"Chrome"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://src.chromium.org/viewvc/blink?revision=190021&view=revision"},{"name":"USN-2521-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-2521-1"},{"tags":["x_refsource_CONFIRM"],"url":"https://src.chromium.org/viewvc/blink?revision=190035&view=revision"},{"name":"72901","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/72901"},{"tags":["x_refsource_CONFIRM"],"url":"https://code.google.com/p/chromium/issues/detail?id=455368"},{"name":"GLSA-201503-12","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"https://security.gentoo.org/glsa/201503-12"},{"name":"RHSA-2015:0627","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0627.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@google.com","ID":"CVE-2015-1221","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Use-after-free vulnerability in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect ordering of operations in the Web SQL Database thread relative to Blink's main thread, related to the shutdown function in web/WebKit.cpp."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://src.chromium.org/viewvc/blink?revision=190021&view=revision","refsource":"CONFIRM","url":"https://src.chromium.org/viewvc/blink?revision=190021&view=revision"},{"name":"USN-2521-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-2521-1"},{"name":"https://src.chromium.org/viewvc/blink?revision=190035&view=revision","refsource":"CONFIRM","url":"https://src.chromium.org/viewvc/blink?revision=190035&view=revision"},{"name":"72901","refsource":"BID","url":"http://www.securityfocus.com/bid/72901"},{"name":"https://code.google.com/p/chromium/issues/detail?id=455368","refsource":"CONFIRM","url":"https://code.google.com/p/chromium/issues/detail?id=455368"},{"name":"GLSA-201503-12","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201503-12"},{"name":"RHSA-2015:0627","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2015-0627.html"},{"name":"http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html","refsource":"CONFIRM","url":"http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html"}]}}}},"cveMetadata":{"assignerOrgId":"ebfee0ef-53dd-4cf3-9e2a-08a5bd7a7e28","assignerShortName":"Chrome","cveId":"CVE-2015-1221","datePublished":"2015-03-09T00:00:00.000Z","dateReserved":"2015-01-21T00:00:00.000Z","dateUpdated":"2024-08-06T04:33:20.703Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-03-09 00:59:14","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndIncluding":"40.0.2214.115","matchCriteriaId":"8E4473BA-37DE-4AF1-A828-99AA9D83AAE7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"1221","Ordinal":"1","Title":"CVE-2015-1221","CVE":"CVE-2015-1221","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"1221","Ordinal":"1","NoteData":"Use-after-free vulnerability in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect ordering of operations in the Web SQL Database thread relative to Blink's main thread, related to the shutdown function in web/WebKit.cpp.","Type":"Description","Title":"CVE-2015-1221"},{"CveYear":"2015","CveId":"1221","Ordinal":"2","NoteData":"2015-03-08","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"1221","Ordinal":"3","NoteData":"2016-12-20","Type":"Other","Title":"Modified"}]}}}