CVE-2015-1224
The VpxVideoDecoder::VpxDecode function in media/filters/vpx_video_decoder.cc in the vpxdecoder implementation in Google Chrome before 41.0.2272.76 does not ensure that alpha-plane dimensions are identical to image dimensions, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted VPx video data.
- Google Chrome
- ≤ 40.0.2214.115
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 1.8% (77th percentile)
- Weakness
- CWE-17
- NVD status
- Modified
- Published
- 2015-03-09
CVE-2015-1224 at NVD
1 known exploit for CVE-2015-1224
Proof-of-concept code and exploit modules indexed by Sploitus