{"api_version":"1","generated_at":"2026-07-23T10:23:51+00:00","cve":"CVE-2015-1295","urls":{"html":"https://cve.report/CVE-2015-1295","api":"https://cve.report/api/cve/CVE-2015-1295.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-1295","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-1295"},"summary":{"title":"CVE-2015-1295","description":"Multiple use-after-free vulnerabilities in the PrintWebViewHelper class in components/printing/renderer/print_web_view_helper.cc in Google Chrome before 45.0.2454.85 allow user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact by triggering nested IPC messages during preparation for printing, as demonstrated by messages associated with PDF documents in conjunction with messages about printer capabilities.","state":"PUBLISHED","assigner":"Chrome","published_at":"2015-09-03 22:59:05","updated_at":"2026-05-06 22:30:45"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://code.google.com/p/chromium/issues/detail?id=502562","name":"https://code.google.com/p/chromium/issues/detail?id=502562","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Issue 502562 - \n \n chromium -\n \n Heap-use-after-free in WebLocalFrameImpl::printBegin - \n Monorail","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2015/dsa-3351","name":"http://www.debian.org/security/2015/dsa-3351","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-3351-1 chromium-browser","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-updates/2015-11/msg00013.html","name":"http://lists.opensuse.org/opensuse-updates/2015-11/msg00013.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"openSUSE-SU-2015:1873-1: moderate: Security update for Chromium","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.html","name":"http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Chrome Releases: Stable Channel Update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-1712.html","name":"http://rhn.redhat.com/errata/RHSA-2015-1712.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1033472","name":"http://www.securitytracker.com/id/1033472","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Google Chrome Multiple Bugs Let Remote Users Execute Arbitrary Code, Bypass Security Restrictions, Obtain Potentially Sensitive Information, and Spoof Content - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://codereview.chromium.org/1228693002/","name":"https://codereview.chromium.org/1228693002/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Issue 1228693002: Crash on nested IPC handlers in PrintWebViewHelper -\n    \n    Code Review","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/201603-09","name":"https://security.gentoo.org/glsa/201603-09","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Chromium: Multiple vulnerabilities (GLSA 201603-09) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-updates/2015-09/msg00029.html","name":"http://lists.opensuse.org/opensuse-updates/2015-09/msg00029.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"openSUSE-SU-2015:1586-1: moderate: Security update for Chromium","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-1295","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-1295","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"1295","vulnerable":"1","versionEndIncluding":"44.0.2403","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"google","cpe5":"chrome","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T04:40:18.645Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"openSUSE-SU-2015:1873","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2015-11/msg00013.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.html"},{"name":"RHSA-2015:1712","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2015-1712.html"},{"name":"1033472","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1033472"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://codereview.chromium.org/1228693002/"},{"name":"openSUSE-SU-2015:1586","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2015-09/msg00029.html"},{"name":"DSA-3351","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2015/dsa-3351"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://code.google.com/p/chromium/issues/detail?id=502562"},{"name":"GLSA-201603-09","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"https://security.gentoo.org/glsa/201603-09"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-09-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple use-after-free vulnerabilities in the PrintWebViewHelper class in components/printing/renderer/print_web_view_helper.cc in Google Chrome before 45.0.2454.85 allow user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact by triggering nested IPC messages during preparation for printing, as demonstrated by messages associated with PDF documents in conjunction with messages about printer capabilities."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-20T16:57:01.000Z","orgId":"ebfee0ef-53dd-4cf3-9e2a-08a5bd7a7e28","shortName":"Chrome"},"references":[{"name":"openSUSE-SU-2015:1873","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2015-11/msg00013.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.html"},{"name":"RHSA-2015:1712","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2015-1712.html"},{"name":"1033472","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1033472"},{"tags":["x_refsource_CONFIRM"],"url":"https://codereview.chromium.org/1228693002/"},{"name":"openSUSE-SU-2015:1586","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2015-09/msg00029.html"},{"name":"DSA-3351","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2015/dsa-3351"},{"tags":["x_refsource_CONFIRM"],"url":"https://code.google.com/p/chromium/issues/detail?id=502562"},{"name":"GLSA-201603-09","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"https://security.gentoo.org/glsa/201603-09"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@google.com","ID":"CVE-2015-1295","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple use-after-free vulnerabilities in the PrintWebViewHelper class in components/printing/renderer/print_web_view_helper.cc in Google Chrome before 45.0.2454.85 allow user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact by triggering nested IPC messages during preparation for printing, as demonstrated by messages associated with PDF documents in conjunction with messages about printer capabilities."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"openSUSE-SU-2015:1873","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2015-11/msg00013.html"},{"name":"http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.html","refsource":"CONFIRM","url":"http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.html"},{"name":"RHSA-2015:1712","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2015-1712.html"},{"name":"1033472","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1033472"},{"name":"https://codereview.chromium.org/1228693002/","refsource":"CONFIRM","url":"https://codereview.chromium.org/1228693002/"},{"name":"openSUSE-SU-2015:1586","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2015-09/msg00029.html"},{"name":"DSA-3351","refsource":"DEBIAN","url":"http://www.debian.org/security/2015/dsa-3351"},{"name":"https://code.google.com/p/chromium/issues/detail?id=502562","refsource":"CONFIRM","url":"https://code.google.com/p/chromium/issues/detail?id=502562"},{"name":"GLSA-201603-09","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201603-09"}]}}}},"cveMetadata":{"assignerOrgId":"ebfee0ef-53dd-4cf3-9e2a-08a5bd7a7e28","assignerShortName":"Chrome","cveId":"CVE-2015-1295","datePublished":"2015-09-03T22:00:00.000Z","dateReserved":"2015-01-21T00:00:00.000Z","dateUpdated":"2024-08-06T04:40:18.645Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-09-03 22:59:05","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndIncluding":"44.0.2403","matchCriteriaId":"BBDC4A7D-C94E-42B2-983F-A7660C62A1CD"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"1295","Ordinal":"1","Title":"CVE-2015-1295","CVE":"CVE-2015-1295","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"1295","Ordinal":"1","NoteData":"Multiple use-after-free vulnerabilities in the PrintWebViewHelper class in components/printing/renderer/print_web_view_helper.cc in Google Chrome before 45.0.2454.85 allow user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact by triggering nested IPC messages during preparation for printing, as demonstrated by messages associated with PDF documents in conjunction with messages about printer capabilities.","Type":"Description","Title":"CVE-2015-1295"},{"CveYear":"2015","CveId":"1295","Ordinal":"2","NoteData":"2015-09-03","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"1295","Ordinal":"3","NoteData":"2016-12-20","Type":"Other","Title":"Modified"}]}}}