CVE-2014-1713
published 2014-03-16CVE-2014-1713: Use-after-free vulnerability in the AttributeSetter function in bindings/templates/attributes.cpp in the bindings in Blink, as used in Google Chrome before…
PriorityP430high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.27%
81.3th percentile
Use-after-free vulnerability in the AttributeSetter function in bindings/templates/attributes.cpp in the bindings in Blink, as used in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving the document.location value.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 33.0.1750.152 | 33.0.1750.152 | |
| chrome | < 33.0.1750.154 | 33.0.1750.154 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
webkitgtk: use-after-free in the AttributeSetter function (WSA-2015-0001)
vendor_redhat·2015-01-26·CVSS 7.5
CVE-2014-1713 [HIGH] CWE-416 webkitgtk: use-after-free in the AttributeSetter function (WSA-2015-0001)
webkitgtk: use-after-free in the AttributeSetter function (WSA-2015-0001)
Use-after-free vulnerability in the AttributeSetter function in bindings/templates/attributes.cpp in the bindings in Blink, as used in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving the document.location value.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will n
GHSA
GHSA-hc29-7pc8-xhxq: Use-after-free vulnerability in the AttributeSetter function in bindings/templates/attributes
ghsa_unreviewed·2022-05-17
CVE-2014-1713 [HIGH] CWE-416 GHSA-hc29-7pc8-xhxq: Use-after-free vulnerability in the AttributeSetter function in bindings/templates/attributes
Use-after-free vulnerability in the AttributeSetter function in bindings/templates/attributes.cpp in the bindings in Blink, as used in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving the document.location value.
No detection rules found.
No public exploits indexed.
http://archives.neohapsis.com/archives/bugtraq/2014-03/0144.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-04/0009.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-04/0135.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-04/0136.htmlhttp://googlechromereleases.blogspot.com/2014/03/stable-channel-update-for-chrome-os_14.htmlhttp://googlechromereleases.blogspot.com/2014/03/stable-channel-update_14.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00008.htmlhttp://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-2883https://code.google.com/p/chromium/issues/detail?id=352374https://src.chromium.org/viewvc/blink?revision=169176&view=revisionhttps://support.apple.com/kb/HT6537http://archives.neohapsis.com/archives/bugtraq/2014-03/0144.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-04/0009.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-04/0135.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-04/0136.htmlhttp://googlechromereleases.blogspot.com/2014/03/stable-channel-update-for-chrome-os_14.htmlhttp://googlechromereleases.blogspot.com/2014/03/stable-channel-update_14.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00008.htmlhttp://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-2883https://code.google.com/p/chromium/issues/detail?id=352374https://src.chromium.org/viewvc/blink?revision=169176&view=revisionhttps://support.apple.com/kb/HT6537
2014-03-16
Published