CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
AI Score
Confidence
High
EPSS
Percentile
88.6%
Multiple serious vulnerabilities have been found in Google Chrome 34.0.1847.137 and earlier. Malicious can use these vulnerabilities to cause denial of service, spoof UI or possibly other impact.
Below is a complete list of vulnerabilities
CVE-2014-1748 critical
CVE-2014-1747 warning
CVE-2014-3152 critical
CVE-2014-1749 critical
CVE-2014-1744 critical
CVE-2014-1743 critical
CVE-2014-1746 critical
CVE-2014-1745 critical
Update to the latest version. File with name old_chrome can be still detected after update. It caused by update policy which does not remove old versions when installing updates. Try to contact vendor for further delete instructions or ignore such kind of alerts at your own risk.
Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.
Code injection. Exploitation of vulnerabilities with this impact can lead to changes in target code.
Spoof user interface. Exploitation of vulnerabilities with this impact can lead to changes in user interface to beguile user into inaccurate behavior.