// For flags

CVE-2014-3172

 

Severity Score

6.4
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Debugger extension API in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 37.0.2062.94 does not validate a tab's URL before an attach operation, which allows remote attackers to bypass intended access limitations via an extension that uses a restricted URL, as demonstrated by a chrome:// URL.

La Api de extensión Debugger en browser/extensions/api/debugger/debugger_api.cc en Google Chrome anterior a 37.0.2062.94 no valida la URL de una pestaña antes de una operación de adjuntar, lo que permite a atacantes remotos evadir las limitaciones de acceso a través de una extensión que utiliza una URL restringida, como fue demostrado por una URL chrome://.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-05-03 CVE Reserved
  • 2014-08-27 CVE Published
  • 2024-07-09 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
<= 37.0.2062.93
Search vendor "Google" for product "Chrome" and version " <= 37.0.2062.93"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.0
Search vendor "Google" for product "Chrome" and version "37.0.2062.0"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.1
Search vendor "Google" for product "Chrome" and version "37.0.2062.1"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.2
Search vendor "Google" for product "Chrome" and version "37.0.2062.2"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.3
Search vendor "Google" for product "Chrome" and version "37.0.2062.3"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.4
Search vendor "Google" for product "Chrome" and version "37.0.2062.4"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.5
Search vendor "Google" for product "Chrome" and version "37.0.2062.5"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.6
Search vendor "Google" for product "Chrome" and version "37.0.2062.6"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.7
Search vendor "Google" for product "Chrome" and version "37.0.2062.7"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.8
Search vendor "Google" for product "Chrome" and version "37.0.2062.8"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.9
Search vendor "Google" for product "Chrome" and version "37.0.2062.9"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.10
Search vendor "Google" for product "Chrome" and version "37.0.2062.10"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.11
Search vendor "Google" for product "Chrome" and version "37.0.2062.11"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.12
Search vendor "Google" for product "Chrome" and version "37.0.2062.12"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.13
Search vendor "Google" for product "Chrome" and version "37.0.2062.13"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.14
Search vendor "Google" for product "Chrome" and version "37.0.2062.14"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.15
Search vendor "Google" for product "Chrome" and version "37.0.2062.15"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.16
Search vendor "Google" for product "Chrome" and version "37.0.2062.16"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.17
Search vendor "Google" for product "Chrome" and version "37.0.2062.17"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.18
Search vendor "Google" for product "Chrome" and version "37.0.2062.18"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.19
Search vendor "Google" for product "Chrome" and version "37.0.2062.19"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.20
Search vendor "Google" for product "Chrome" and version "37.0.2062.20"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.21
Search vendor "Google" for product "Chrome" and version "37.0.2062.21"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.22
Search vendor "Google" for product "Chrome" and version "37.0.2062.22"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.23
Search vendor "Google" for product "Chrome" and version "37.0.2062.23"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.24
Search vendor "Google" for product "Chrome" and version "37.0.2062.24"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.25
Search vendor "Google" for product "Chrome" and version "37.0.2062.25"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.26
Search vendor "Google" for product "Chrome" and version "37.0.2062.26"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.27
Search vendor "Google" for product "Chrome" and version "37.0.2062.27"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.28
Search vendor "Google" for product "Chrome" and version "37.0.2062.28"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.29
Search vendor "Google" for product "Chrome" and version "37.0.2062.29"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.30
Search vendor "Google" for product "Chrome" and version "37.0.2062.30"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.31
Search vendor "Google" for product "Chrome" and version "37.0.2062.31"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.32
Search vendor "Google" for product "Chrome" and version "37.0.2062.32"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.33
Search vendor "Google" for product "Chrome" and version "37.0.2062.33"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.34
Search vendor "Google" for product "Chrome" and version "37.0.2062.34"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.35
Search vendor "Google" for product "Chrome" and version "37.0.2062.35"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.36
Search vendor "Google" for product "Chrome" and version "37.0.2062.36"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.37
Search vendor "Google" for product "Chrome" and version "37.0.2062.37"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.39
Search vendor "Google" for product "Chrome" and version "37.0.2062.39"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.43
Search vendor "Google" for product "Chrome" and version "37.0.2062.43"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.44
Search vendor "Google" for product "Chrome" and version "37.0.2062.44"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.45
Search vendor "Google" for product "Chrome" and version "37.0.2062.45"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.46
Search vendor "Google" for product "Chrome" and version "37.0.2062.46"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.47
Search vendor "Google" for product "Chrome" and version "37.0.2062.47"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.48
Search vendor "Google" for product "Chrome" and version "37.0.2062.48"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.49
Search vendor "Google" for product "Chrome" and version "37.0.2062.49"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.50
Search vendor "Google" for product "Chrome" and version "37.0.2062.50"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.51
Search vendor "Google" for product "Chrome" and version "37.0.2062.51"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.52
Search vendor "Google" for product "Chrome" and version "37.0.2062.52"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.53
Search vendor "Google" for product "Chrome" and version "37.0.2062.53"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.54
Search vendor "Google" for product "Chrome" and version "37.0.2062.54"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.55
Search vendor "Google" for product "Chrome" and version "37.0.2062.55"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.56
Search vendor "Google" for product "Chrome" and version "37.0.2062.56"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.57
Search vendor "Google" for product "Chrome" and version "37.0.2062.57"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.58
Search vendor "Google" for product "Chrome" and version "37.0.2062.58"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.59
Search vendor "Google" for product "Chrome" and version "37.0.2062.59"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.60
Search vendor "Google" for product "Chrome" and version "37.0.2062.60"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.61
Search vendor "Google" for product "Chrome" and version "37.0.2062.61"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.62
Search vendor "Google" for product "Chrome" and version "37.0.2062.62"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.63
Search vendor "Google" for product "Chrome" and version "37.0.2062.63"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.64
Search vendor "Google" for product "Chrome" and version "37.0.2062.64"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.65
Search vendor "Google" for product "Chrome" and version "37.0.2062.65"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.66
Search vendor "Google" for product "Chrome" and version "37.0.2062.66"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.67
Search vendor "Google" for product "Chrome" and version "37.0.2062.67"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.68
Search vendor "Google" for product "Chrome" and version "37.0.2062.68"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.69
Search vendor "Google" for product "Chrome" and version "37.0.2062.69"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.70
Search vendor "Google" for product "Chrome" and version "37.0.2062.70"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.71
Search vendor "Google" for product "Chrome" and version "37.0.2062.71"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.72
Search vendor "Google" for product "Chrome" and version "37.0.2062.72"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.73
Search vendor "Google" for product "Chrome" and version "37.0.2062.73"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.74
Search vendor "Google" for product "Chrome" and version "37.0.2062.74"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.75
Search vendor "Google" for product "Chrome" and version "37.0.2062.75"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.76
Search vendor "Google" for product "Chrome" and version "37.0.2062.76"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.77
Search vendor "Google" for product "Chrome" and version "37.0.2062.77"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.78
Search vendor "Google" for product "Chrome" and version "37.0.2062.78"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.80
Search vendor "Google" for product "Chrome" and version "37.0.2062.80"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.81
Search vendor "Google" for product "Chrome" and version "37.0.2062.81"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.89
Search vendor "Google" for product "Chrome" and version "37.0.2062.89"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.90
Search vendor "Google" for product "Chrome" and version "37.0.2062.90"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.91
Search vendor "Google" for product "Chrome" and version "37.0.2062.91"
-
Affected
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
37.0.2062.92
Search vendor "Google" for product "Chrome" and version "37.0.2062.92"
-
Affected