CVE-2015-1282 describes multiple use-after-free vulnerabilities within the PDFium library's JavaScript engine, specifically in the Document::delay and Document::DoFieldDelay functions. These flaws, present in Google Chrome prior to version 44.0.2403.89 and affecting products like Debian, Google, OpenSUSE, and Red Hat, can be triggered by a specially crafted PDF document. The vulnerability has a CVSS score of 6.8, indicating a medium severity. An unauthenticated remote attacker could exploit this with medium attack complexity (AV:N/AC:M/Au:N), potentially leading to a denial of service, information disclosure, or arbitrary code execution (C:P/I:P/A:P). While not listed in CISA's KEV catalog, and with no known Metasploit or ExploitDB modules, the vulnerability has garnered some community attention with two mentions and two media articles, suggesting awareness within the security community. Its EPSS score is low, indicating a low probability of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 43.0.2357.134CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
13.1CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* | ||
13.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop_supplementary:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server_supplementary:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.