CVE-2014-1717
published 2014-04-09CVE-2014-1717: Google V8, as used in Google Chrome before 34.0.1847.116, does not properly use numeric casts during handling of typed arrays, which allows remote attackers to…
PriorityP429high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.32%
68.1th percentile
Google V8, as used in Google Chrome before 34.0.1847.116, does not properly use numeric casts during handling of typed arrays, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JavaScript code.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 34.0.1847.115 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome 34.0.1847.115 V8 Handler numeric error (Nessus ID 73431 / ID 166973)
vuldb·2026-05-10·CVSS 7.5
CVE-2014-1717 [HIGH] Google Chrome 34.0.1847.115 V8 Handler numeric error (Nessus ID 73431 / ID 166973)
A vulnerability was found in Google Chrome 34.0.1847.115. It has been declared as critical. This issue affects some unknown processing of the component V8 Handler. The manipulation results in numeric error.
This vulnerability is cataloged as CVE-2014-1717. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
GHSA
GHSA-w38m-qrcj-jg5r: Google V8, as used in Google Chrome before 34
ghsa_unreviewed·2022-05-17
CVE-2014-1717 [HIGH] GHSA-w38m-qrcj-jg5r: Google V8, as used in Google Chrome before 34
Google V8, as used in Google Chrome before 34.0.1847.116, does not properly use numeric casts during handling of typed arrays, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JavaScript code.
OSV
CVE-2014-1717: Google V8, as used in Google Chrome before 34
osv·2014-04-09·CVSS 7.5
CVE-2014-1717 [HIGH] CVE-2014-1717: Google V8, as used in Google Chrome before 34
Google V8, as used in Google Chrome before 34.0.1847.116, does not properly use numeric casts during handling of typed arrays, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JavaScript code.
Red Hat
v8: numeric casting issues
vendor_redhat·2014-03-18·CVSS 7.5
CVE-2014-1717 [HIGH] v8: numeric casting issues
v8: numeric casting issues
Google V8, as used in Google Chrome before 34.0.1847.116, does not properly use numeric casts during handling of typed arrays, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JavaScript code.
Package: ruby193-v8 (CloudForms Management Engine 5) - Not affected
Package: ruby193-v8 (OpenShift Enterprise 1) - Not affected
Package: v8 (Red Hat OpenShift Enterprise 2) - Not affected
Package: ruby193-v8 (Red Hat OpenStack Platform 3) - Not affected
Package: v8 (Red Hat OpenStack Platform 3) - Not affected
Package: ruby193-v8 (Red Hat OpenStack Platform 4) - Not affected
Package: v8 (Red Hat OpenStack Platform 4) - Not affected
Package: v8 (Red Hat Satellite 6) - Not af
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00012.htmlhttp://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-2905https://code.google.com/p/chromium/issues/detail?id=353004https://code.google.com/p/v8/source/detail?r=20020http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00012.htmlhttp://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-2905https://code.google.com/p/chromium/issues/detail?id=353004https://code.google.com/p/v8/source/detail?r=20020
2014-04-09
Published