V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2015-1241
DEB
Medium

Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gestu…

CVSS
6.4
Medium
EPSS
0.02
p80
Published
2015-01-01
Updated
2015-01-01
Description

Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack.

Tags · CWE
CWE-1021
CWE-352
CAPEC-62
CAPEC-103
CAPEC-111
CAPEC-181
CAPEC-222
CAPEC-462
CAPEC-467
CAPEC-504
CAPEC-506
CAPEC-587
CAPEC-654
Affected products
Chrome < 42.0.2311.90
CVSS vector
AV:N/AC:L/Au:N/C:P/I:P/A:N
Timeline
2015-01-01
Published
2015-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.022 · p80
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-504 · CWE-1021
└ via CAPEC-654 · CWE-1021
└ via CAPEC-654 · CWE-1021
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
chromium-browserTracked
chromium-browserTracked
chromium-browserTracked
chromium-browserTracked
chromium-browserTracked
chromium-browserTracked
chromium-browserTracked
chromium-browserTracked
oxide-qtTracked
oxide-qtTracked
oxide-qtTracked
oxide-qtTracked
chrome*Tracked
debian_linux*Tracked
enterprise_linux_desktop*Tracked
enterprise_linux_eus*Tracked
enterprise_linux_server*Tracked
enterprise_linux_server_aus*Tracked
enterprise_linux_server_eus*Tracked
enterprise_linux_workstation*Tracked
Showing first 20 of 23
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities