CVE-2015-8664
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 5.2%
from disclosure to weapon0 days
Published on NVDDec 24
1st PoCDec 18
exploitation probability
5.2%top 8% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Integer overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Google Chrome before 47.0.2526.106 allows remote attackers to cause a denial of service or possibly have unspecified other impact via an RGBA pixel array with crafted dimensions, a different vulnerability than CVE-2015-6792.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/39039⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://googlechromereleases.blogspot.com/2015/12/stable-channel-update_15.htmlhttps://code.google.com/p/chromium/issues/detail?id=565023https://code.google.com/p/chromium/issues/detail?id=569486https://codereview.chromium.org/1498903003http://www.securityfocus.com/bid/79686http://www.securitytracker.com/id/1034491http://www.ubuntu.com/usn/USN-2860-1