CVE-2014-3160
 
Severity Score
6.8
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file.
La función ResourceFetcher::canRequest en core/fetch/ResourceFetcher.cpp en Blink, utilizado en Google Chrome anterior a 36.0.1985.125, no restringe debidamente las solicitudes de subrecursos asociados con ficheros SVG, lo que permite a atacantes remotos evadir Same Origin Policy a través de un fichero manipulado.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-05-03 CVE Reserved
- 2014-07-20 CVE Published
- 2023-11-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://googlechromereleases.blogspot.com/2014/07/stable-channel-update.html | X_refsource_confirm | |
http://secunia.com/advisories/60061 | Third Party Advisory | |
http://secunia.com/advisories/60372 | Third Party Advisory | |
http://www.securityfocus.com/bid/68677 | Vdb Entry | |
https://code.google.com/p/chromium/issues/detail?id=380885 | X_refsource_confirm | |
https://src.chromium.org/viewvc/blink?revision=176084&view=revision | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://security.gentoo.org/glsa/glsa-201408-16.xml | 2023-11-07 | |
http://www.debian.org/security/2014/dsa-3039 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 7.0 Search vendor "Debian" for product "Debian Linux" and version "7.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.1 Search vendor "Google" for product "Chrome" and version "36.0.1985.1" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.2 Search vendor "Google" for product "Chrome" and version "36.0.1985.2" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.3 Search vendor "Google" for product "Chrome" and version "36.0.1985.3" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.4 Search vendor "Google" for product "Chrome" and version "36.0.1985.4" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.5 Search vendor "Google" for product "Chrome" and version "36.0.1985.5" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.6 Search vendor "Google" for product "Chrome" and version "36.0.1985.6" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.8 Search vendor "Google" for product "Chrome" and version "36.0.1985.8" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.12 Search vendor "Google" for product "Chrome" and version "36.0.1985.12" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.13 Search vendor "Google" for product "Chrome" and version "36.0.1985.13" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.14 Search vendor "Google" for product "Chrome" and version "36.0.1985.14" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.15 Search vendor "Google" for product "Chrome" and version "36.0.1985.15" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.16 Search vendor "Google" for product "Chrome" and version "36.0.1985.16" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.17 Search vendor "Google" for product "Chrome" and version "36.0.1985.17" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.18 Search vendor "Google" for product "Chrome" and version "36.0.1985.18" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.19 Search vendor "Google" for product "Chrome" and version "36.0.1985.19" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.20 Search vendor "Google" for product "Chrome" and version "36.0.1985.20" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.21 Search vendor "Google" for product "Chrome" and version "36.0.1985.21" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.22 Search vendor "Google" for product "Chrome" and version "36.0.1985.22" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.23 Search vendor "Google" for product "Chrome" and version "36.0.1985.23" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.24 Search vendor "Google" for product "Chrome" and version "36.0.1985.24" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.25 Search vendor "Google" for product "Chrome" and version "36.0.1985.25" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.26 Search vendor "Google" for product "Chrome" and version "36.0.1985.26" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.27 Search vendor "Google" for product "Chrome" and version "36.0.1985.27" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.28 Search vendor "Google" for product "Chrome" and version "36.0.1985.28" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.29 Search vendor "Google" for product "Chrome" and version "36.0.1985.29" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.30 Search vendor "Google" for product "Chrome" and version "36.0.1985.30" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.31 Search vendor "Google" for product "Chrome" and version "36.0.1985.31" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.32 Search vendor "Google" for product "Chrome" and version "36.0.1985.32" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.33 Search vendor "Google" for product "Chrome" and version "36.0.1985.33" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.34 Search vendor "Google" for product "Chrome" and version "36.0.1985.34" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.35 Search vendor "Google" for product "Chrome" and version "36.0.1985.35" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.36 Search vendor "Google" for product "Chrome" and version "36.0.1985.36" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.37 Search vendor "Google" for product "Chrome" and version "36.0.1985.37" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.38 Search vendor "Google" for product "Chrome" and version "36.0.1985.38" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.39 Search vendor "Google" for product "Chrome" and version "36.0.1985.39" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.40 Search vendor "Google" for product "Chrome" and version "36.0.1985.40" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.41 Search vendor "Google" for product "Chrome" and version "36.0.1985.41" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.42 Search vendor "Google" for product "Chrome" and version "36.0.1985.42" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.43 Search vendor "Google" for product "Chrome" and version "36.0.1985.43" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.44 Search vendor "Google" for product "Chrome" and version "36.0.1985.44" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.45 Search vendor "Google" for product "Chrome" and version "36.0.1985.45" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.46 Search vendor "Google" for product "Chrome" and version "36.0.1985.46" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.47 Search vendor "Google" for product "Chrome" and version "36.0.1985.47" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.48 Search vendor "Google" for product "Chrome" and version "36.0.1985.48" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.49 Search vendor "Google" for product "Chrome" and version "36.0.1985.49" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.50 Search vendor "Google" for product "Chrome" and version "36.0.1985.50" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.51 Search vendor "Google" for product "Chrome" and version "36.0.1985.51" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.52 Search vendor "Google" for product "Chrome" and version "36.0.1985.52" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.53 Search vendor "Google" for product "Chrome" and version "36.0.1985.53" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.54 Search vendor "Google" for product "Chrome" and version "36.0.1985.54" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.55 Search vendor "Google" for product "Chrome" and version "36.0.1985.55" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.56 Search vendor "Google" for product "Chrome" and version "36.0.1985.56" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.57 Search vendor "Google" for product "Chrome" and version "36.0.1985.57" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.58 Search vendor "Google" for product "Chrome" and version "36.0.1985.58" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.59 Search vendor "Google" for product "Chrome" and version "36.0.1985.59" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.60 Search vendor "Google" for product "Chrome" and version "36.0.1985.60" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.61 Search vendor "Google" for product "Chrome" and version "36.0.1985.61" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.62 Search vendor "Google" for product "Chrome" and version "36.0.1985.62" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.63 Search vendor "Google" for product "Chrome" and version "36.0.1985.63" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.64 Search vendor "Google" for product "Chrome" and version "36.0.1985.64" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.65 Search vendor "Google" for product "Chrome" and version "36.0.1985.65" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.66 Search vendor "Google" for product "Chrome" and version "36.0.1985.66" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.67 Search vendor "Google" for product "Chrome" and version "36.0.1985.67" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.68 Search vendor "Google" for product "Chrome" and version "36.0.1985.68" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.69 Search vendor "Google" for product "Chrome" and version "36.0.1985.69" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.70 Search vendor "Google" for product "Chrome" and version "36.0.1985.70" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.72 Search vendor "Google" for product "Chrome" and version "36.0.1985.72" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.73 Search vendor "Google" for product "Chrome" and version "36.0.1985.73" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.74 Search vendor "Google" for product "Chrome" and version "36.0.1985.74" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.75 Search vendor "Google" for product "Chrome" and version "36.0.1985.75" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.76 Search vendor "Google" for product "Chrome" and version "36.0.1985.76" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.77 Search vendor "Google" for product "Chrome" and version "36.0.1985.77" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.78 Search vendor "Google" for product "Chrome" and version "36.0.1985.78" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.79 Search vendor "Google" for product "Chrome" and version "36.0.1985.79" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.81 Search vendor "Google" for product "Chrome" and version "36.0.1985.81" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.82 Search vendor "Google" for product "Chrome" and version "36.0.1985.82" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.83 Search vendor "Google" for product "Chrome" and version "36.0.1985.83" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.84 Search vendor "Google" for product "Chrome" and version "36.0.1985.84" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.85 Search vendor "Google" for product "Chrome" and version "36.0.1985.85" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.86 Search vendor "Google" for product "Chrome" and version "36.0.1985.86" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.87 Search vendor "Google" for product "Chrome" and version "36.0.1985.87" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.88 Search vendor "Google" for product "Chrome" and version "36.0.1985.88" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.89 Search vendor "Google" for product "Chrome" and version "36.0.1985.89" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.90 Search vendor "Google" for product "Chrome" and version "36.0.1985.90" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.91 Search vendor "Google" for product "Chrome" and version "36.0.1985.91" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.92 Search vendor "Google" for product "Chrome" and version "36.0.1985.92" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.93 Search vendor "Google" for product "Chrome" and version "36.0.1985.93" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.94 Search vendor "Google" for product "Chrome" and version "36.0.1985.94" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.95 Search vendor "Google" for product "Chrome" and version "36.0.1985.95" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.96 Search vendor "Google" for product "Chrome" and version "36.0.1985.96" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.97 Search vendor "Google" for product "Chrome" and version "36.0.1985.97" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.98 Search vendor "Google" for product "Chrome" and version "36.0.1985.98" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.99 Search vendor "Google" for product "Chrome" and version "36.0.1985.99" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.100 Search vendor "Google" for product "Chrome" and version "36.0.1985.100" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.101 Search vendor "Google" for product "Chrome" and version "36.0.1985.101" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.102 Search vendor "Google" for product "Chrome" and version "36.0.1985.102" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.103 Search vendor "Google" for product "Chrome" and version "36.0.1985.103" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.104 Search vendor "Google" for product "Chrome" and version "36.0.1985.104" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.105 Search vendor "Google" for product "Chrome" and version "36.0.1985.105" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.106 Search vendor "Google" for product "Chrome" and version "36.0.1985.106" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.122 Search vendor "Google" for product "Chrome" and version "36.0.1985.122" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.123 Search vendor "Google" for product "Chrome" and version "36.0.1985.123" | - |
Affected
| ||||||
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 36.0.1985.124 Search vendor "Google" for product "Chrome" and version "36.0.1985.124" | - |
Affected
|