CVE Database
/

CVE-2015-1228

Back to search

CVE-2015-1228

Published: Mar 9, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

The RenderCounter::updateCounter function in core/rendering/RenderCounter.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not force a relayout operation and consequently does not initialize memory for a data structure, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted Cascading Style Sheets (CSS) token sequence.

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-2521-1
vendor-advisory
x_refsource_UBUNTU
72901
vdb-entry
x_refsource_BID
GLSA-201503-12
vendor-advisory
x_refsource_GENTOO
RHSA-2015:0627
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now