CVE-2014-1726
published 2014-04-09CVE-2014-1726: The drag implementation in Google Chrome before 34.0.1847.116 allows user-assisted remote attackers to bypass the Same Origin Policy and forge local pathnames…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.42%
70.1th percentile
The drag implementation in Google Chrome before 34.0.1847.116 allows user-assisted remote attackers to bypass the Same Origin Policy and forge local pathnames by leveraging renderer access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 34.0.1847.115 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8wwh-wv27-42xx: The drag implementation in Google Chrome before 34
ghsa_unreviewed·2022-05-17
CVE-2014-1726 [MEDIUM] GHSA-8wwh-wv27-42xx: The drag implementation in Google Chrome before 34
The drag implementation in Google Chrome before 34.0.1847.116 allows user-assisted remote attackers to bypass the Same Origin Policy and forge local pathnames by leveraging renderer access.
OSV
CVE-2014-1726: The drag implementation in Google Chrome before 34
osv·2014-04-09·CVSS 4.3
CVE-2014-1726 [MEDIUM] CVE-2014-1726: The drag implementation in Google Chrome before 34
The drag implementation in Google Chrome before 34.0.1847.116 allows user-assisted remote attackers to bypass the Same Origin Policy and forge local pathnames by leveraging renderer access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00012.htmlhttp://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-2905https://code.google.com/p/chromium/issues/detail?id=346135https://src.chromium.org/viewvc/chrome?revision=259353&view=revisionhttp://googlechromereleases.blogspot.com/2014/04/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00012.htmlhttp://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-2905https://code.google.com/p/chromium/issues/detail?id=346135https://src.chromium.org/viewvc/chrome?revision=259353&view=revision
2014-04-09
Published