CVE-2014-1731
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
core/html/HTMLSelectElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly check renderer state upon a focus event, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion" for SELECT elements.
core/html/HTMLSelectElement.cpp en la implementación DOM en Blink, utilizado en Google Chrome anterior a 34.0.1847.131 en Windows y OS X y anterior a 34.0.1847.132 en Linux, no comprueba debidamente el estado renderer en un evento focus, lo que permite a atacantes remotos causar una denegación de servicio o posiblemente tener otro impacto no especificado a través de vectores que aprovechan "confusión de tipo" para elementos SELECT.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-01-29 CVE Reserved
- 2014-04-26 CVE Published
- 2023-12-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
CAPEC
References (15)
URL | Tag | Source |
---|---|---|
http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.html | X_refsource_confirm | |
http://secunia.com/advisories/58301 | Third Party Advisory | |
http://secunia.com/advisories/60372 | Third Party Advisory | |
http://support.apple.com/kb/HT6254 | X_refsource_confirm | |
http://www.securityfocus.com/bid/67572 | Vdb Entry | |
https://code.google.com/p/chromium/issues/detail?id=349903 | X_refsource_confirm | |
https://src.chromium.org/viewvc/blink?revision=171216&view=revision | X_refsource_confirm | |
https://support.apple.com/kb/HT6537 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | < 34.0.1847.131 Search vendor "Google" for product "Chrome" and version " < 34.0.1847.131" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | - | - |
Safe
|
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | < 34.0.1847.131 Search vendor "Google" for product "Chrome" and version " < 34.0.1847.131" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | < 34.0.1847.132 Search vendor "Google" for product "Chrome" and version " < 34.0.1847.132" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|