CVE-2014-1731
published 2014-04-26CVE-2014-1731: core/html/HTMLSelectElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.25%
87.1th percentile
core/html/HTMLSelectElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly check renderer state upon a focus event, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion" for SELECT elements.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 34.0.1847.131 | 34.0.1847.131 | |
| chrome | < 34.0.1847.132 | 34.0.1847.132 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome 34.0.1847.130/34.0.1847.131 DOM Type Casting type confusion (Nessus ID 73856 / ID 195570)
vuldb·2026-05-12·CVSS 7.5
CVE-2014-1731 [HIGH] Google Chrome 34.0.1847.130/34.0.1847.131 DOM Type Casting type confusion (Nessus ID 73856 / ID 195570)
A vulnerability has been found in Google Chrome 34.0.1847.130/34.0.1847.131 and classified as critical. Affected by this vulnerability is an unknown functionality of the component DOM Handler. The manipulation leads to type confusion (Type Casting).
This vulnerability is traded as CVE-2014-1731. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
VulDB
Apple Safari up to 6.1.3/7.0.3 WebKit type confusion (Nessus ID 73856 / ID 195570)
vuldb·2026-05-12·CVSS 7.5
CVE-2014-1731 [HIGH] Apple Safari up to 6.1.3/7.0.3 WebKit type confusion (Nessus ID 73856 / ID 195570)
A vulnerability, which was classified as critical, was found in Apple Safari up to 6.1.3/7.0.3. This impacts an unknown function of the component WebKit. Executing a manipulation can lead to type confusion.
This vulnerability is registered as CVE-2014-1731. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
GHSA
GHSA-f9pg-xj46-9mvr: core/html/HTMLSelectElement
ghsa_unreviewed·2022-05-17
CVE-2014-1731 [HIGH] CWE-20 GHSA-f9pg-xj46-9mvr: core/html/HTMLSelectElement
core/html/HTMLSelectElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly check renderer state upon a focus event, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion" for SELECT elements.
OSV
oxide-qt vulnerabilities
osv·2014-07-23·CVSS 7.8
CVE-2014-1730 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
A type confusion bug was discovered in V8. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-1730)
A type confusion bug was discovered in Blink. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-1731)
Multiple security issues including memory safety bugs were discovered in
Chromium. If a user were tricked in to opening a specially crafted website,
an attacker could potentiall
OSV
CVE-2014-1731: core/html/HTMLSelectElement
osv·2014-04-26·CVSS 7.5
CVE-2014-1731 [HIGH] CVE-2014-1731: core/html/HTMLSelectElement
core/html/HTMLSelectElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly check renderer state upon a focus event, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion" for SELECT elements.
Red Hat
webkitgtk: improper renderer state check in core/html/HTMLSelectElement.cpp (WSA-2015-0001)
vendor_redhat·2015-01-26·CVSS 7.5
CVE-2014-1731 [HIGH] webkitgtk: improper renderer state check in core/html/HTMLSelectElement.cpp (WSA-2015-0001)
webkitgtk: improper renderer state check in core/html/HTMLSelectElement.cpp (WSA-2015-0001)
core/html/HTMLSelectElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly check renderer state upon a focus event, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion" for SELECT elements.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitg
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2014-07-23·CVSS 7.8
CVE-2014-1730 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
A type confusion bug was discovered in V8. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-1730)
A type confusion bug was discovered in Blink. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-1731)
Multiple security issues including memory safety bugs were discovered in
Chromium. If a user were tricked in to openin
No detection rules found.
No public exploits indexed.
http://archives.neohapsis.com/archives/bugtraq/2014-05/0128.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-06/0174.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-06/0175.htmlhttp://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00049.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00050.htmlhttp://secunia.com/advisories/58301http://secunia.com/advisories/60372http://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://support.apple.com/kb/HT6254http://www.debian.org/security/2014/dsa-2920http://www.securityfocus.com/bid/67572https://code.google.com/p/chromium/issues/detail?id=349903https://src.chromium.org/viewvc/blink?revision=171216&view=revisionhttps://support.apple.com/kb/HT6537http://archives.neohapsis.com/archives/bugtraq/2014-05/0128.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-06/0174.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-06/0175.htmlhttp://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00049.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00050.htmlhttp://secunia.com/advisories/58301http://secunia.com/advisories/60372http://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://support.apple.com/kb/HT6254http://www.debian.org/security/2014/dsa-2920http://www.securityfocus.com/bid/67572https://code.google.com/p/chromium/issues/detail?id=349903https://src.chromium.org/viewvc/blink?revision=171216&view=revisionhttps://support.apple.com/kb/HT6537
2014-04-26
Published