Lucene search

K
cveChromeCVE-2014-7933
HistoryJan 22, 2015 - 10:59 p.m.

CVE-2014-7933

2015-01-2222:59:14
Chrome
web.nvd.nist.gov
55
cve-2014-7933
vulnerability
matroska
libavformat
ffmpeg
google chrome
denial of service
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

9.3

Confidence

High

EPSS

0.009

Percentile

83.0%

Use-after-free vulnerability in the matroska_read_seek function in libavformat/matroskadec.c in FFmpeg before 2.5.1, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Matroska file that triggers improper maintenance of tracks data.

Affected configurations

Nvd
Node
googlechromeRange40.0.2214.85
Node
ffmpegffmpegRange2.5.0
VendorProductVersionCPE
googlechrome*cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
ffmpegffmpeg*cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

9.3

Confidence

High

EPSS

0.009

Percentile

83.0%