Lucene search

K
nessusTenable8162.PASL
HistoryMar 18, 2014 - 12:00 a.m.

Google Chrome < 33.0.1750.154 (Win) Multiple Vulnerabilities

2014-03-1800:00:00
Tenable
www.tenable.com
19

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.064

Percentile

93.7%

The Google Chrome browser detected on the remote Windows system is older than version 33.0.1750.154, and is therefore vulnerable to the following issues:

  • Memory corruption vulnerability in Google V8 via ArrayBuffer property accesses. (CVE-2014-1705)

  • Use-after-free error related to document.location bindings, which may be leveraged to execute arbitrary code by a context-dependent attacker. (CVE-2014-1713)

  • A sandbox bypass via a flaw related to the clipboard message filter. (CVE-2014-1714)

  • A sandbox bypass via path traversal due to insufficient user input sanitation in the ‘CreatePlatformFileUnsafe()’ function within ‘base/platform_file_win.cc’ (CVE-2014-1715)

Binary data 8162.pasl
VendorProductVersionCPE
googlechromecpe:/a:google:chrome

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.064

Percentile

93.7%