Lucene search

K
cveChromeCVE-2014-1746
HistoryMay 21, 2014 - 11:14 a.m.

CVE-2014-1746

2014-05-2111:14:09
CWE-119
Chrome
web.nvd.nist.gov
43
cve-2014-1746
google chrome
inmemoryurlprotocol
remote attackers
denial of service
out-of-bounds read
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0.007

Percentile

79.7%

The InMemoryUrlProtocol::Read function in media/filters/in_memory_url_protocol.cc in Google Chrome before 35.0.1916.114 relies on an insufficiently large integer data type, which allows remote attackers to cause a denial of service (out-of-bounds read) via vectors that trigger use of a large buffer.

Affected configurations

Nvd
Node
googlechromeRange35.0.1916.113
OR
googlechromeMatch35.0.1916.0
OR
googlechromeMatch35.0.1916.1
OR
googlechromeMatch35.0.1916.2
OR
googlechromeMatch35.0.1916.3
OR
googlechromeMatch35.0.1916.4
OR
googlechromeMatch35.0.1916.5
OR
googlechromeMatch35.0.1916.6
OR
googlechromeMatch35.0.1916.7
OR
googlechromeMatch35.0.1916.8
OR
googlechromeMatch35.0.1916.9
OR
googlechromeMatch35.0.1916.10
OR
googlechromeMatch35.0.1916.11
OR
googlechromeMatch35.0.1916.13
OR
googlechromeMatch35.0.1916.14
OR
googlechromeMatch35.0.1916.15
OR
googlechromeMatch35.0.1916.17
OR
googlechromeMatch35.0.1916.18
OR
googlechromeMatch35.0.1916.19
OR
googlechromeMatch35.0.1916.20
OR
googlechromeMatch35.0.1916.21
OR
googlechromeMatch35.0.1916.22
OR
googlechromeMatch35.0.1916.23
OR
googlechromeMatch35.0.1916.27
OR
googlechromeMatch35.0.1916.31
OR
googlechromeMatch35.0.1916.32
OR
googlechromeMatch35.0.1916.33
OR
googlechromeMatch35.0.1916.34
OR
googlechromeMatch35.0.1916.35
OR
googlechromeMatch35.0.1916.36
OR
googlechromeMatch35.0.1916.37
OR
googlechromeMatch35.0.1916.38
OR
googlechromeMatch35.0.1916.39
OR
googlechromeMatch35.0.1916.40
OR
googlechromeMatch35.0.1916.41
OR
googlechromeMatch35.0.1916.42
OR
googlechromeMatch35.0.1916.43
OR
googlechromeMatch35.0.1916.44
OR
googlechromeMatch35.0.1916.45
OR
googlechromeMatch35.0.1916.46
OR
googlechromeMatch35.0.1916.47
OR
googlechromeMatch35.0.1916.48
OR
googlechromeMatch35.0.1916.49
OR
googlechromeMatch35.0.1916.51
OR
googlechromeMatch35.0.1916.52
OR
googlechromeMatch35.0.1916.54
OR
googlechromeMatch35.0.1916.56
OR
googlechromeMatch35.0.1916.57
OR
googlechromeMatch35.0.1916.59
OR
googlechromeMatch35.0.1916.61
OR
googlechromeMatch35.0.1916.68
OR
googlechromeMatch35.0.1916.69
OR
googlechromeMatch35.0.1916.71
OR
googlechromeMatch35.0.1916.72
OR
googlechromeMatch35.0.1916.74
OR
googlechromeMatch35.0.1916.77
OR
googlechromeMatch35.0.1916.80
OR
googlechromeMatch35.0.1916.82
OR
googlechromeMatch35.0.1916.84
OR
googlechromeMatch35.0.1916.85
OR
googlechromeMatch35.0.1916.86
OR
googlechromeMatch35.0.1916.88
OR
googlechromeMatch35.0.1916.90
OR
googlechromeMatch35.0.1916.92
OR
googlechromeMatch35.0.1916.93
OR
googlechromeMatch35.0.1916.95
OR
googlechromeMatch35.0.1916.96
OR
googlechromeMatch35.0.1916.98
OR
googlechromeMatch35.0.1916.99
OR
googlechromeMatch35.0.1916.101
OR
googlechromeMatch35.0.1916.103
OR
googlechromeMatch35.0.1916.104
OR
googlechromeMatch35.0.1916.105
OR
googlechromeMatch35.0.1916.106
OR
googlechromeMatch35.0.1916.107
OR
googlechromeMatch35.0.1916.108
OR
googlechromeMatch35.0.1916.109
OR
googlechromeMatch35.0.1916.110
OR
googlechromeMatch35.0.1916.111
OR
googlechromeMatch35.0.1916.112
VendorProductVersionCPE
googlechrome*cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
googlechrome35.0.1916.0cpe:2.3:a:google:chrome:35.0.1916.0:*:*:*:*:*:*:*
googlechrome35.0.1916.1cpe:2.3:a:google:chrome:35.0.1916.1:*:*:*:*:*:*:*
googlechrome35.0.1916.2cpe:2.3:a:google:chrome:35.0.1916.2:*:*:*:*:*:*:*
googlechrome35.0.1916.3cpe:2.3:a:google:chrome:35.0.1916.3:*:*:*:*:*:*:*
googlechrome35.0.1916.4cpe:2.3:a:google:chrome:35.0.1916.4:*:*:*:*:*:*:*
googlechrome35.0.1916.5cpe:2.3:a:google:chrome:35.0.1916.5:*:*:*:*:*:*:*
googlechrome35.0.1916.6cpe:2.3:a:google:chrome:35.0.1916.6:*:*:*:*:*:*:*
googlechrome35.0.1916.7cpe:2.3:a:google:chrome:35.0.1916.7:*:*:*:*:*:*:*
googlechrome35.0.1916.8cpe:2.3:a:google:chrome:35.0.1916.8:*:*:*:*:*:*:*
Rows per page:
1-10 of 801

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0.007

Percentile

79.7%