CVE-2015-1283

CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 3.23 % (91th)
3.23% Progress
Affected Products 13
Advisories 17

Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.

Weaknesses
CWE-190
Integer Overflow or Wraparound
Related CVEs
CVE Status
PUBLISHED
CNA
Chrome
Published Date
2015-07-23 00:59:12
(9 years ago)
Updated Date
2023-11-07 02:24:38
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Google Chrome 43.0.2357.134 and prior versions cpe:2.3:a:google:chrome <= 43.0.2357.134

Configuration #2

    CPE23 From Up To
  Libexpat Project Libexpat 2.1.0 and prior versions cpe:2.3:a:libexpat_project:libexpat <= 2.1.0

Configuration #3

    CPE23 From Up To
  Python from 2.7.0 version and prior 2.7.12 version cpe:2.3:a:python:python >= 2.7.0 < 2.7.12
  Python from 3.3.0 version and prior 3.3.7 version cpe:2.3:a:python:python >= 3.3.0 < 3.3.7
  Python from 3.4.0 version and prior 3.4.5 version cpe:2.3:a:python:python >= 3.4.0 < 3.4.5
  Python from 3.5.0 version and prior 3.5.2 version cpe:2.3:a:python:python >= 3.5.0 < 3.5.2

Configuration #4

    CPE23 From Up To
  Debian Linux 7.0 cpe:2.3:o:debian:debian_linux:7.0
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0
  Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0

Configuration #5

    CPE23 From Up To
  Canonical Ubuntu Linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-
  Canonical Ubuntu Linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm
  Canonical Ubuntu Linux 15.04 cpe:2.3:o:canonical:ubuntu_linux:15.04

Configuration #6

    CPE23 From Up To
  Suse Linux Enterprise Debuginfo 11 SP4 cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp4
  Suse Studio Onsite 1.3 cpe:2.3:a:suse:studio_onsite:1.3
  Opensuse Leap 42.1 cpe:2.3:o:opensuse:leap:42.1
  Opensuse 13.1 cpe:2.3:o:opensuse:opensuse:13.1
  Opensuse 13.2 cpe:2.3:o:opensuse:opensuse:13.2
  Suse Linux Enterprise Desktop 12 cpe:2.3:o:suse:linux_enterprise_desktop:12:-
  Suse Linux Enterprise Desktop 12 SP1 cpe:2.3:o:suse:linux_enterprise_desktop:12:sp1
  Suse Linux Enterprise Server 11 SP4 cpe:2.3:o:suse:linux_enterprise_server:11:sp4
  Suse Linux Enterprise Server 12 cpe:2.3:o:suse:linux_enterprise_server:12:-
  Suse Linux Enterprise Server 12 SP1 cpe:2.3:o:suse:linux_enterprise_server:12:sp1
  Suse Linux Enterprise Software Development Kit 11 SP4 cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp4
  Suse Linux Enterprise Software Development Kit 12 cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:-
  Suse Linux Enterprise Software Development Kit 12 SP1 cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:sp1

Configuration #7

    CPE23 From Up To
  Oracle Solaris 10 cpe:2.3:o:oracle:solaris:10
  Oracle Solaris 11.3 cpe:2.3:o:oracle:solaris:11.3
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...