CVE-2014-7934
chromium-browser: use-after-free in DOM
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Use-after-free vulnerability in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to unexpected absence of document data structures.
Vulnerabilidad de uso después de liberación en la implementación DOM en Blink, utilizado en Google Chrome anterior a 40.0.2214.91, permite a atacantes remotos causar una denegación de servicio o posiblemente tener otro impacto no especificado a través de vectores relacionados con la ausencia no esperada de las estructuras de datos de documentos.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-10-06 CVE Reserved
- 2015-01-22 CVE Published
- 2024-07-18 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-416: Use After Free
CAPEC
References (15)
URL | Tag | Source |
---|---|---|
http://googlechromereleases.blogspot.com/2015/01/stable-update.html | X_refsource_confirm | |
http://secunia.com/advisories/62383 | Third Party Advisory | |
http://secunia.com/advisories/62575 | Third Party Advisory | |
http://secunia.com/advisories/62665 | Third Party Advisory | |
http://www.securityfocus.com/bid/72288 | Vdb Entry | |
http://www.securitytracker.com/id/1031623 | Vdb Entry | |
https://code.google.com/p/chromium/issues/detail?id=427249 | X_refsource_confirm | |
https://src.chromium.org/viewvc/blink?revision=185504&view=revision | X_refsource_confirm | |
https://src.chromium.org/viewvc/blink?revision=185598&view=revision | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2015-0093.html | 2023-11-07 | |
http://security.gentoo.org/glsa/glsa-201502-13.xml | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-2476-1 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2014-7934 | 2015-01-27 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1185214 | 2015-01-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | <= 40.0.2214.85 Search vendor "Google" for product "Chrome" and version " <= 40.0.2214.85" | - |
Affected
|