Sploitus

CVE-2015-1284

No indexed exploits for CVE-2015-1284 yet

The LocalFrame::isURLAllowed function in core/frame/LocalFrame.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly check for a page's maximum number of frames, which allows remote attackers to cause a denial of service (invalid count value and use-after-free) or possibly have unspecified other impact via crafted JavaScript code that makes many createElement calls for IFRAME elements.

Google Chrome
≤ 43.0.2357.134
CVSS 2.0
7.5 HIGH
EPSS
2.2% (80th percentile)
Weakness
CWE-20
NVD status
Modified
Published
2015-07-23
CVE-2015-1284 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2015-1284 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2015-1284 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.