UBUNTU-CVE-2015-1274

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 23 Jul 2015, 00:59
Last modified:08 Sept 2025, 16:43

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Jul 2015, 00:59
Published
Vulnerability first disclosed
08 Sept 2025, 16:43
Last Modified
Vulnerability information updated

Description

Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it easier for remote attackers to execute arbitrary code by providing a crafted file and leveraging a user's previous "Always open files of this type" choice, related to download_commands.cc and download_prefs.cc.

Affected Systems

  • ubuntuchromium-browser

    < 44.0.2403.89-0ubuntu0.14.04.1.1095

References (3)