ID

VAR-201404-0327


CVE

CVE-2014-1735


TITLE

plural OS Run on Google Chrome Used in Google V8 Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2014-002275

DESCRIPTION

Multiple unspecified vulnerabilities in Google V8 before 3.24.35.33, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, allow attackers to cause a denial of service or possibly have other impact via unknown vectors. Google Chrome is prone to multiple security vulnerabilities. Attackers can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts may result in a denial-of-service condition. Versions prior to Chrome 34.0.1847.131 and 34.0.1847.132 are vulnerable. Google Chrome is a web browser developed by Google (Google). ============================================================================ Ubuntu Security Notice USN-2298-1 July 23, 2014 oxide-qt vulnerabilities ============================================================================ A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Oxide. Software Description: - oxide-qt: Web browser engine library for Qt Details: A type confusion bug was discovered in V8. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash, or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2014-1730) A type confusion bug was discovered in Blink. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash, or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2014-1731) Multiple security issues including memory safety bugs were discovered in Chromium. (CVE-2014-1735, CVE-2014-3162) Multiple use-after-free issues were discovered in the WebSockets implementation. (CVE-2014-1740) Multiple integer overflows were discovered in CharacterData implementation. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via renderer crash or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2014-1741) Multiple use-after-free issues were discovered in Blink. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via renderer crash or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2014-1742, CVE-2014-1743) An integer overflow bug was discovered in Chromium. (CVE-2014-1744) An out-of-bounds read was discovered in Chromium. If a user were tricked in to opening a specially crafter website, an attacker could potentially exploit this to cause a denial of service via application crash. (CVE-2014-1746) It was discovered that Blink allowed scrollbar painting to extend in to the parent frame in some circumstances. An attacker could potentially exploit this to conduct clickjacking attacks via UI redress. (CVE-2014-1748) An integer underflow was discovered in Blink. If a user were tricked in to opening a specially crafter website, an attacker could potentially exploit this to cause a denial of service via renderer crash or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2014-3152) A use-after-free was discovered in Chromium. If a use were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2014-3154) A security issue was discovered in the SPDY implementation. (CVE-2014-3155) A heap overflow was discovered in Chromium. If a use were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2014-3157) It was discovered that Blink did not enforce security rules for subresource loading in SVG images. If a user opened a site that embedded a specially crafted image, an attacker could exploit this to log page views. (CVE-2014-3160) It was discovered that the SpeechInput feature in Blink could be activated without consent or any visible indication. If a user were tricked in to opening a specially crafted website, an attacker could exploit this to eavesdrop on the user. (CVE-2014-3803) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: liboxideqtcore0 1.0.4-0ubuntu0.14.04.1 oxideqt-codecs 1.0.4-0ubuntu0.14.04.1 oxideqt-codecs-extra 1.0.4-0ubuntu0.14.04.1 In general, a standard system update will make all the necessary changes. References: http://www.ubuntu.com/usn/usn-2298-1 CVE-2014-1730, CVE-2014-1731, CVE-2014-1735, CVE-2014-1740, CVE-2014-1741, CVE-2014-1742, CVE-2014-1743, CVE-2014-1744, CVE-2014-1746, CVE-2014-1748, CVE-2014-3152, CVE-2014-3154, CVE-2014-3155, CVE-2014-3157, CVE-2014-3160, CVE-2014-3162, CVE-2014-3803, https://launchpad.net/bugs/1337301 Package Information: https://launchpad.net/ubuntu/+source/oxide-qt/1.0.4-0ubuntu0.14.04.1 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2920-1 security@debian.org http://www.debian.org/security/ Michael Gilbert May 03, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : chromium-browser CVE ID : CVE-2014-1730 CVE-2014-1731 CVE-2014-1732 CVE-2014-1733 CVE-2014-1734 CVE-2014-1735 CVE-2014-1736 Several vulnerabilities have been discovered in the chromium web browser. CVE-2014-1731 John Butler discovered a type confusion issue in the WebKit/Blink document object model implementation. CVE-2014-1733 Jed Davis discovered a way to bypass the seccomp-bpf sandbox. CVE-2014-1735 The Google Chrome development team discovered and fixed multiple issues in version 3.24.35.33 of the v8 javascript library. CVE-2014-1736 SkyLined discovered an integer overlflow issue in the v8 javascript library. For the stable distribution (wheezy), these problems have been fixed in version 34.0.1847.132-1~deb7u1. For the testing distribution (jessie), these problems will be fixed soon. For the unstable distribution (sid), these problems have been fixed in version 34.0.1847.132-1. We recommend that you upgrade your chromium-browser packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQQcBAEBCgAGBQJTZWJ6AAoJELjWss0C1vRzK+sgALIEDCn9Ud3owKNxdM6sglkB /yx9toTplWx2reGXn4qyfNPtxQMbS9AyIhcLEKMbIIrXaEY9CjB+JhfP6IC0RPCJ NLPd21uDo63LhiCkgtbNgftPcDK6NwaPy67Uui64zI/MkB6me4C3ECZB2nxmjNAO 0OJQMDQv217ei1w8QCIofouUbJU4Vq56mxpX7tEVUPJkgA6FE4aUNcrxKcKhdnxU WtUW49d1Q+6RcJjthugyWppzb9N+0ClxNpRADzMa5jgaiQxEBuRJewipiJhTQg5l XTB2o6V8G/+NWEqTJPe7t+QKwERE9yUp4pyiwMolttJffKm7ipgbDdIHTan/LYfu A5CQFT7cre7l4r90YtgAo/da/kwDs6whTAoiFb6hxhLLgarpsO5WjMFrCeGHZek1 weOMO6VbhLDaHJHKQOnIy2shhG850OX4twLznOnqZ2x3XcurhqjZEg8XaiFRQiPU p8d2Qy25XraAQ8fG71LKN7M5h6q8yWkofZFrVysNOSu7zeadZUfmO7OXE9vO4Gqu bA8P/1ihaH0+KcUJsd7yP0Lv+avtww++/4Ak1msUn95OiOynjuJ1e5VtEQFFyRDj fRWcJcG1ssKCIKB8lSuqVXcEyYDS5LpfRTcWJq/6Jutz+N5axWYlDBMZwq75CULR EkW6oUrZtq9dACLTBNtRqPF7ClBV6x42lgZ3nfKTly84/nS3tpsfQv8oKDRsckzm GsJPl/DKm/D73kJyZEqYChxiKE3i4WYmsjltcCXQi0PJzEqGnvFaWsAPISD3EEYz nIwpjBMXAYFyVwp16UcNj7uVjlf9ZQetY5dVEF//I3jjTUMWFadHQ0IYZaHpYRle ZC0fKv6xqGN5krE6ommWvAgkLlQdlupU+FT8abaXWyrnWTHTGi2bOFe0wlXzdUPh gp7zgaOehCI7CsMUxK8VeRXF19K4x1KfGUA+VVUsvXF5G5D6Ucowybi6ObTPqFDA LHDrIIL44cnPU4BqZ/KRfN/f0hfu1hHHD7TmonHbt7JeWIFqEWDvtDI4hx4kjaYc nHt1ZyK2YyGRZwJ8drhJi1+iYSRApx36nvIOZn6fa8rZDCqE1VObPOr6lyexuhge tnTDQta21hkXnyTEs/lYRbWK4K0KK4AXyWCtbiAJOe65/9eSd5Yq48dbfPBLUJSe XKFKhkTo0FNDLB2MsgVikTptvpiFG8dwoOrWqCBz9z23eAhFmVGM/vciNBLNyy2B QtSLd4+VSd/za51sldpN6ZFG4CTm6Z5NWGEnNxptHw5iE6cQHior+snS65HzbsQ5 ykJ5HqSGIsGLSkdeKC44XOfBUU9jU14llMOdf5OKx9vfmX/Hl3T0Z+jWwHpKpWk= =/B/T -----END PGP SIGNATURE----- . - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201408-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Chromium: Multiple vulnerabilities Date: August 30, 2014 Bugs: #504328, #504890, #507212, #508788, #510288, #510904, #512944, #517304, #519788, #521276 ID: 201408-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been found in Chromium, the worst of which can allow remote attackers to execute arbitrary code. Background ========== Chromium is an open-source web browser project. Please review the CVE identifiers referenced below for details. Workaround ========== There is no known workaround at this time. Resolution ========== All chromium users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v ">=www-client/chromium-37.0.2062.94" References ========== [ 1 ] CVE-2014-1741 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1741 [ 2 ] CVE-2014-0538 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0538 [ 3 ] CVE-2014-1700 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1700 [ 4 ] CVE-2014-1701 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1701 [ 5 ] CVE-2014-1702 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1702 [ 6 ] CVE-2014-1703 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1703 [ 7 ] CVE-2014-1704 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1704 [ 8 ] CVE-2014-1705 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1705 [ 9 ] CVE-2014-1713 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1713 [ 10 ] CVE-2014-1714 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1714 [ 11 ] CVE-2014-1715 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1715 [ 12 ] CVE-2014-1716 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1716 [ 13 ] CVE-2014-1717 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1717 [ 14 ] CVE-2014-1718 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1718 [ 15 ] CVE-2014-1719 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1719 [ 16 ] CVE-2014-1720 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1720 [ 17 ] CVE-2014-1721 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1721 [ 18 ] CVE-2014-1722 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1722 [ 19 ] CVE-2014-1723 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1723 [ 20 ] CVE-2014-1724 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1724 [ 21 ] CVE-2014-1725 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1725 [ 22 ] CVE-2014-1726 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1726 [ 23 ] CVE-2014-1727 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1727 [ 24 ] CVE-2014-1728 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1728 [ 25 ] CVE-2014-1729 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1729 [ 26 ] CVE-2014-1730 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1730 [ 27 ] CVE-2014-1731 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1731 [ 28 ] CVE-2014-1732 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1732 [ 29 ] CVE-2014-1733 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1733 [ 30 ] CVE-2014-1734 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1734 [ 31 ] CVE-2014-1735 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1735 [ 32 ] CVE-2014-1740 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1740 [ 33 ] CVE-2014-1742 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1742 [ 34 ] CVE-2014-1743 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1743 [ 35 ] CVE-2014-1744 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1744 [ 36 ] CVE-2014-1745 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1745 [ 37 ] CVE-2014-1746 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1746 [ 38 ] CVE-2014-1747 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1747 [ 39 ] CVE-2014-1748 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1748 [ 40 ] CVE-2014-1749 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1749 [ 41 ] CVE-2014-3154 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3154 [ 42 ] CVE-2014-3155 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3155 [ 43 ] CVE-2014-3156 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3156 [ 44 ] CVE-2014-3157 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3157 [ 45 ] CVE-2014-3160 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3160 [ 46 ] CVE-2014-3162 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3162 [ 47 ] CVE-2014-3165 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3165 [ 48 ] CVE-2014-3166 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3166 [ 49 ] CVE-2014-3167 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3167 [ 50 ] CVE-2014-3168 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3168 [ 51 ] CVE-2014-3169 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3169 [ 52 ] CVE-2014-3170 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3170 [ 53 ] CVE-2014-3171 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3171 [ 54 ] CVE-2014-3172 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3172 [ 55 ] CVE-2014-3173 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3173 [ 56 ] CVE-2014-3174 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3174 [ 57 ] CVE-2014-3175 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3175 [ 58 ] CVE-2014-3176 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3176 [ 59 ] CVE-2014-3177 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3177 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-201408-16.xml Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2014 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5

Trust: 2.34

sources: NVD: CVE-2014-1735 // JVNDB: JVNDB-2014-002275 // BID: 67082 // VULHUB: VHN-69674 // VULMON: CVE-2014-1735 // PACKETSTORM: 127584 // PACKETSTORM: 126491 // PACKETSTORM: 128057

AFFECTED PRODUCTS

vendor:googlemodel:chromescope:ltversion:34.0.1847.132

Trust: 1.0

vendor:googlemodel:chromescope:ltversion:34.0.1847.131

Trust: 1.0

vendor:googlemodel:chromescope:ltversion:34.0.1847.131 (windows and mac os x)

Trust: 0.8

vendor:googlemodel:chromescope:ltversion:34.0.1847.132 (linux)

Trust: 0.8

vendor:googlemodel:chromescope:eqversion:34.0.1847.61

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:34.0.1847.59

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:34.0.1847.67

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:34.0.1847.65

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:34.0.1847.6

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:34.0.1847.62

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:34.0.1847.60

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:34.0.1847.63

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:34.0.1847.64

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:34.0.1847.66

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:17.0.96379

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:17.0.96365

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:16.0.91275

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:15.0.874102

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:3.0.195.38

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:3.0.195.33

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:3.0.195.32

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:3.0.195.24

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:3.0.195.21

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:2.0.172.43

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:2.0.172.37

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:2.0.172.33

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:2.0.172.31

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:2.0.172.30

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:3.0.195.37

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:3.0.195.36

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:3.0.195.27

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:3.0.195.25

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:3.0.195.2

Trust: 0.3

vendor:googlemodel:chrome betascope:eqversion:3.0.193.2

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:3.0.190.2

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:3.0.182.2

Trust: 0.3

vendor:googlemodel:chrome betascope:eqversion:3.0

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:2.0.172.8

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:2.0.172.38

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:2.0.172.28

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:2.0.172.27

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:2.0.172.2

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:2.0.172

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:2.0.170.0

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:2.0.169.1

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:2.0.169.0

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:2.0.159.0

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:2.0.158.0

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:2.0.157.2

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:2.0.157.0

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:2.0.156.1

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:19.0.1084.52

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:19

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:18.0.1025.168

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:18.0.1025.162

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:18.0.1025.151

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:18.0.1025.142

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:17.0.963.83

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:17.0.963.78

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:17.0.963.60

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:17.0.963.56

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:17.0.963.46

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:16.0.912.77

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:16.0.912.75

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:16.0.912.63

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:16

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:15.0.874.121

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:15.0.874.120

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:14.0.835.202

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:14.0.835.186

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:14.0.835.163

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:14

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:13.0.782.215

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:13.0.782.112

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:13.0.782.107

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:13

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:12.0.742.91

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:12.0.742.112

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:12.0.742.100

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:12

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:11.0.696.77

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:11.0.696.71

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:11.0.696.68

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:11.0.696.65

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:11.0.696.57

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:11.0.696.43

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:11.0.672.2

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:11

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:10.0.648.205

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:10.0.648.204

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:10.0.648.133

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:10.0.648.128

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:10.0.648.127

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:10

Trust: 0.3

vendor:gentoomodel:linuxscope: - version: -

Trust: 0.3

vendor:debianmodel:linux sparcscope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux s/390scope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux powerpcscope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux mipsscope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux ia-64scope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux ia-32scope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux armscope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux amd64scope:eqversion:6.0

Trust: 0.3

sources: BID: 67082 // JVNDB: JVNDB-2014-002275 // CNNVD: CNNVD-201404-521 // NVD: CVE-2014-1735

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-1735
value: HIGH

Trust: 1.0

NVD: CVE-2014-1735
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201404-521
value: MEDIUM

Trust: 0.6

VULHUB: VHN-69674
value: HIGH

Trust: 0.1

VULMON: CVE-2014-1735
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2014-1735
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-69674
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-69674 // VULMON: CVE-2014-1735 // JVNDB: JVNDB-2014-002275 // CNNVD: CNNVD-201404-521 // NVD: CVE-2014-1735

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2014-1735

THREAT TYPE

remote

Trust: 0.7

sources: PACKETSTORM: 128057 // CNNVD: CNNVD-201404-521

TYPE

Unknown

Trust: 0.3

sources: BID: 67082

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-002275

PATCH

title:Revision 171077url:https://src.chromium.org/viewvc/blink?revision=171077&view=revision

Trust: 0.8

title:Revision 171127url:https://src.chromium.org/viewvc/blink?revision=171127&view=revision

Trust: 0.8

title:Stable Channel Updateurl:http://googlechromereleases.blogspot.jp/2014/04/stable-channel-update_24.html

Trust: 0.8

title:Revision: r20501url:https://code.google.com/p/v8/source/detail?r=20501

Trust: 0.8

title:Revision: r20622url:https://code.google.com/p/v8/source/detail?r=20622

Trust: 0.8

title:Revision: r20624url:https://code.google.com/p/v8/source/detail?r=20624

Trust: 0.8

title:Google Chromeurl:http://www.google.co.jp/chrome/intl/ja/landing_ff_yt.html?hl=ja&hl=ja

Trust: 0.8

title:ChromeSetup-34.0.1847.131url:http://123.124.177.30/web/xxk/bdxqById.tag?id=49639

Trust: 0.6

title:google-chrome-stable_current_34.0.1847.132_i386url:http://123.124.177.30/web/xxk/bdxqById.tag?id=49641

Trust: 0.6

title:googlechrome-34.0.1847.131url:http://123.124.177.30/web/xxk/bdxqById.tag?id=49640

Trust: 0.6

title:Debian Security Advisories: DSA-2920-1 chromium-browser -- security updateurl:https://vulmon.com/vendoradvisory?qidtp=debian_security_advisories&qid=8a6daa62cdbadeea8f416f98fdf61136

Trust: 0.1

title:Ubuntu Security Notice: oxide-qt vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-2298-1

Trust: 0.1

title:Debian CVElist Bug Report Logs: libv8-3.14: multiple security issuesurl:https://vulmon.com/vendoradvisory?qidtp=debian_cvelist_bugreportlogs&qid=1425f9567f764276b1c8ce7f03af0df1

Trust: 0.1

title: - url:https://github.com/Live-Hack-CVE/CVE-2014-1735

Trust: 0.1

sources: VULMON: CVE-2014-1735 // JVNDB: JVNDB-2014-002275 // CNNVD: CNNVD-201404-521

EXTERNAL IDS

db:NVDid:CVE-2014-1735

Trust: 3.2

db:SECUNIAid:60372

Trust: 1.8

db:SECUNIAid:58301

Trust: 1.8

db:JVNDBid:JVNDB-2014-002275

Trust: 0.8

db:CNNVDid:CNNVD-201404-521

Trust: 0.7

db:BIDid:67082

Trust: 0.3

db:VULHUBid:VHN-69674

Trust: 0.1

db:VULMONid:CVE-2014-1735

Trust: 0.1

db:PACKETSTORMid:127584

Trust: 0.1

db:PACKETSTORMid:126491

Trust: 0.1

db:PACKETSTORMid:128057

Trust: 0.1

sources: VULHUB: VHN-69674 // VULMON: CVE-2014-1735 // BID: 67082 // JVNDB: JVNDB-2014-002275 // PACKETSTORM: 127584 // PACKETSTORM: 126491 // PACKETSTORM: 128057 // CNNVD: CNNVD-201404-521 // NVD: CVE-2014-1735

REFERENCES

url:http://security.gentoo.org/glsa/glsa-201408-16.xml

Trust: 1.9

url:http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.html

Trust: 1.8

url:https://code.google.com/p/chromium/issues/detail?id=359130

Trust: 1.8

url:https://code.google.com/p/chromium/issues/detail?id=359525

Trust: 1.8

url:https://code.google.com/p/chromium/issues/detail?id=360429

Trust: 1.8

url:https://code.google.com/p/v8/source/detail?r=20501

Trust: 1.8

url:https://code.google.com/p/v8/source/detail?r=20622

Trust: 1.8

url:https://code.google.com/p/v8/source/detail?r=20624

Trust: 1.8

url:http://www.debian.org/security/2014/dsa-2920

Trust: 1.8

url:http://secunia.com/advisories/58301

Trust: 1.8

url:http://secunia.com/advisories/60372

Trust: 1.8

url:http://lists.opensuse.org/opensuse-updates/2014-05/msg00049.html

Trust: 1.8

url:http://lists.opensuse.org/opensuse-updates/2014-05/msg00050.html

Trust: 1.8

url:https://src.chromium.org/viewvc/blink?revision=171127&view=revision

Trust: 1.7

url:https://src.chromium.org/viewvc/blink?revision=171077&view=revision

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-1735

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-1735

Trust: 0.8

url:http://www.google.com/chrome

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2014-1730

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2014-1731

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2014-1735

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2014-1733

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2014-1732

Trust: 0.2

url:https://src.chromium.org/viewvc/blink?revision=171077&view=revision

Trust: 0.1

url:https://src.chromium.org/viewvc/blink?revision=171127&view=revision

Trust: 0.1

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:https://github.com/live-hack-cve/cve-2014-1735

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://www.debian.org/security/./dsa-2920

Trust: 0.1

url:https://usn.ubuntu.com/2298-1/

Trust: 0.1

url:http://tools.cisco.com/security/center/viewalert.x?alertid=34002

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1740

Trust: 0.1

url:https://launchpad.net/bugs/1337301

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-3160

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1743

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-3157

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1746

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-3154

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1748

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-3803

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-3155

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-3162

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/oxide-qt/1.0.4-0ubuntu0.14.04.1

Trust: 0.1

url:http://www.ubuntu.com/usn/usn-2298-1

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1742

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-3152

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1741

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1744

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1736

Trust: 0.1

url:http://www.debian.org/security/faq

Trust: 0.1

url:http://www.debian.org/security/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1734

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1720

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1720

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1728

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1700

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-3157

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-3167

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1716

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-0538

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1740

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-3173

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1705

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1702

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-3165

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1717

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-3168

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-3171

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-3175

Trust: 0.1

url:http://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1749

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-3156

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1727

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1726

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1724

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1741

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1729

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1716

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1723

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-3166

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1722

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1714

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1713

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1715

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1715

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1725

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-3169

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1701

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1745

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1722

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1748

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1702

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1730

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1725

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-3177

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1717

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1742

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-3174

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1704

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-0538

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1727

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-3170

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1713

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1743

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1721

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1718

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-3155

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1735

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1728

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1747

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1701

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1719

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1704

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1721

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1746

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1726

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-3172

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-3176

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1732

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1734

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1700

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1723

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1718

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-3160

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1714

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1731

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1719

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1705

Trust: 0.1

url:http://security.gentoo.org/

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-3154

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-3162

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1733

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1703

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1724

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1729

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1744

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-1703

Trust: 0.1

sources: VULHUB: VHN-69674 // VULMON: CVE-2014-1735 // BID: 67082 // JVNDB: JVNDB-2014-002275 // PACKETSTORM: 127584 // PACKETSTORM: 126491 // PACKETSTORM: 128057 // CNNVD: CNNVD-201404-521 // NVD: CVE-2014-1735

CREDITS

Anonymous, John Butler, Khalil Zhani, jln@panix.org, and Google.

Trust: 0.3

sources: BID: 67082

SOURCES

db:VULHUBid:VHN-69674
db:VULMONid:CVE-2014-1735
db:BIDid:67082
db:JVNDBid:JVNDB-2014-002275
db:PACKETSTORMid:127584
db:PACKETSTORMid:126491
db:PACKETSTORMid:128057
db:CNNVDid:CNNVD-201404-521
db:NVDid:CVE-2014-1735

LAST UPDATE DATE

2025-04-13T19:47:35.571000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-69674date:2017-01-07T00:00:00
db:VULMONid:CVE-2014-1735date:2022-11-10T00:00:00
db:BIDid:67082date:2014-09-01T09:25:00
db:JVNDBid:JVNDB-2014-002275date:2014-04-30T00:00:00
db:CNNVDid:CNNVD-201404-521date:2022-11-14T00:00:00
db:NVDid:CVE-2014-1735date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-69674date:2014-04-26T00:00:00
db:VULMONid:CVE-2014-1735date:2014-04-26T00:00:00
db:BIDid:67082date:2014-04-24T00:00:00
db:JVNDBid:JVNDB-2014-002275date:2014-04-30T00:00:00
db:PACKETSTORMid:127584date:2014-07-23T20:48:21
db:PACKETSTORMid:126491date:2014-05-06T00:17:05
db:PACKETSTORMid:128057date:2014-09-02T06:19:45
db:CNNVDid:CNNVD-201404-521date:2014-04-29T00:00:00
db:NVDid:CVE-2014-1735date:2014-04-26T10:55:05.590