Vulnerability · NVD
CVE-2015-1244
CVE-2015-1244, Severity pending severity (CVSS —): 2 tracked apps concerned, all fixed or indeterminable on their current version.
- Severity (CVSS)
- -
- Exploitation
- 1.4 %
- Tracked apps
- 2
- Still exposed
- 0
EPSS, predicted over 30 days
The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for WebSocket traffic.
EPSS
1.44%
above median
percentile 71.2%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
-
Affected ≤42.0.2311.60 Fixed in > 42.0.2311.60 Latest tracked - undetermined
-
Vulnerable CPE configurations (2)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
|
chrome All platforms (wildcard)
|
All platforms (wildcard) | ≤42.0.2311.60 | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | |
|
chrome All platforms (wildcard)
|
All platforms (wildcard) | ≤42.0.2311.60 | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |