CVE-2014-3189
- EPSS 0.83%
- Veröffentlicht 08.10.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium component in Google Chrome before 38.0.2125.101 does not properly validate image-data dimensions, which allows remote attackers to cause a denial of service (out-of-bounds read) or...
CVE-2014-3190
- EPSS 0.76%
- Veröffentlicht 08.10.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the Event::currentTarget function in core/events/Event.cpp in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified ...
CVE-2014-3191
- EPSS 0.76%
- Veröffentlicht 08.10.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers a widget-position update th...
CVE-2014-3192
- EPSS 1.74%
- Veröffentlicht 08.10.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of...
CVE-2014-3193
- EPSS 0.77%
- Veröffentlicht 08.10.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors that ...
CVE-2014-3194
- EPSS 0.56%
- Veröffentlicht 08.10.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
- EPSS 0.49%
- Veröffentlicht 08.10.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Google V8, as used in Google Chrome before 38.0.2125.101, does not properly track JavaScript heap-memory allocations as allocations of uninitialized memory and does not properly concatenate arrays of double-precision floating-point numbers, which all...
CVE-2014-3196
- EPSS 0.23%
- Veröffentlicht 08.10.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
base/memory/shared_memory_win.cc in Google Chrome before 38.0.2125.101 on Windows does not properly implement read-only restrictions on shared memory, which allows attackers to bypass a sandbox protection mechanism via unspecified vectors.
- EPSS 0.31%
- Veröffentlicht 08.10.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote at...
- EPSS 0.83%
- Veröffentlicht 08.10.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote attackers to cause a denia...