CVE Vulnerabilities

CVE-2015-1281

Published: Jul 23, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

core/loader/ImageLoader.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly determine the V8 context of a microtask, which allows remote attackers to bypass Content Security Policy (CSP) restrictions by providing an image from an unintended source.

Affected Software

NameVendorStart VersionEnd Version
OpensuseOpensuse13.1 (including)13.1 (including)
OpensuseOpensuse13.2 (including)13.2 (including)
Red Hat Enterprise Linux 6 SupplementaryRedHatchromium-browser-0:44.0.2403.89-1.el6*
Chromium-browserUbuntudevel*
Chromium-browserUbuntuprecise*
Chromium-browserUbuntutrusty*
Chromium-browserUbuntuupstream*
Chromium-browserUbuntuutopic*
Chromium-browserUbuntuvivid*
Chromium-browserUbuntuwily*
Oxide-qtUbuntudevel*
Oxide-qtUbuntutrusty*
Oxide-qtUbuntuupstream*
Oxide-qtUbuntuutopic*
Oxide-qtUbuntuvivid*
Oxide-qtUbuntuwily*

References