Lucene search

K
cve[email protected]CVE-2014-7939
HistoryJan 22, 2015 - 10:59 p.m.

CVE-2014-7939

2015-01-2222:59:20
CWE-264
web.nvd.nist.gov
29
cve-2014-7939
google chrome
same origin policy
javascript
proxy.create
console.log
http responses
x-content-type-options
nosniff
security vulnerability

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

9 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.0%

Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an “X-Content-Type-Options: nosniff” header.

Affected configurations

NVD
Node
googlechromeRange40.0.2214.85
Node
chromiumchromiumMatch40.0.2214.110
Node
redhatenterprise_linux_desktop_supplementaryMatch6.0
OR
redhatenterprise_linux_server_supplementaryMatch6.0
OR
redhatenterprise_linux_server_supplementary_eusMatch6.6.z
OR
redhatenterprise_linux_workstation_supplementaryMatch6.0
Node
opensuseopensuseMatch13.1
OR
opensuseopensuseMatch13.2

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

9 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.0%