CVE-2015-1284 describes a denial-of-service vulnerability in the Blink rendering engine, specifically within the LocalFrame::isURLAllowed function. This flaw, affecting Google Chrome versions prior to 44.0.2403.89, as well as OpenSUSE and Red Hat products, stems from improper checking of a page's maximum frame count. An attacker could exploit this by crafting JavaScript to create numerous IFRAME elements, leading to an invalid count value, use-after-free, and a denial of service. The vulnerability carries a CVSS score of 7.5, indicating high severity. It is remotely exploitable with low attack complexity, potentially leading to partial confidentiality, integrity, and availability impacts. While the EPSS score is low, suggesting a low likelihood of exploitation, its FAUCET Risk Score is 54/100. Currently, there is no evidence of active exploitation, and no exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Despite this, the CVE has garnered some community attention with two mentions and two media articles, indicating it was noted by security researchers and news outlets at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 43.0.2357.134CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
13.1CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* | ||
13.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop_supplementary:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server_supplementary:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.