CVE-2015-1295 describes multiple use-after-free vulnerabilities within the PrintWebViewHelper class of Google Chrome, specifically affecting versions prior to 45.0.2454.85. These flaws could be triggered by user-assisted remote attackers through nested IPC messages during print preparation, such as those involving PDF documents and printer capabilities. With a CVSS score of 7.5, this vulnerability is considered highly severe, allowing for potential denial of service and possibly other unspecified impacts due to its network-based attack vector and low attack complexity. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating its notable impact at the time of discovery.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 44.0.2403CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.