CVE-2015-6758 describes a denial-of-service vulnerability in the CPDF_Document::GetPage function within PDFium, affecting Google Chrome versions prior to 46.0.2490.71. This flaw stems from improper casting of a dictionary object when processing crafted PDF documents. With a CVSS score of 6.8, this medium-complexity vulnerability allows remote attackers to trigger a denial of service and potentially achieve other unspecified impacts, including partial confidentiality and integrity compromise. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 45.0.2454.101CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.