CVE-2014-1736
published 2014-05-06CVE-2014-1736: Integer overflow in api.cc in Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, allows remote…
PriorityP430high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.07%
79.6th percentile
Integer overflow in api.cc in Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large length value.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 34.0.1847.131 | 34.0.1847.131 | |
| chrome | < 34.0.1847.132 | 34.0.1847.132 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qf53-7c4q-f3hr: Integer overflow in api
ghsa_unreviewed·2022-05-17
CVE-2014-1736 [HIGH] CWE-190 GHSA-qf53-7c4q-f3hr: Integer overflow in api
Integer overflow in api.cc in Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large length value.
OSV
CVE-2014-1736: Integer overflow in api
osv·2014-05-06·CVSS 7.5
CVE-2014-1736 [HIGH] CVE-2014-1736: Integer overflow in api
Integer overflow in api.cc in Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large length value.
Red Hat
v8: integer overflow can lead to a remote denial of service
vendor_redhat·2014-04-24·CVSS 7.5
CVE-2014-1736 [HIGH] CWE-190 v8: integer overflow can lead to a remote denial of service
v8: integer overflow can lead to a remote denial of service
Integer overflow in api.cc in Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large length value.
Package: ruby193-v8 (CloudForms Management Engine 5) - Not affected
Package: ruby193-v8 (OpenShift Enterprise 1) - Not affected
Package: v8 (Red Hat OpenShift Enterprise 2) - Not affected
Package: ruby193-v8 (Red Hat OpenStack Platform 3) - Not affected
Package: v8 (Red Hat OpenStack Platform 3) - Not affected
Package: ruby193-v8 (Red Hat OpenStack Platform 4) - Not affected
Package: v8 (Red Hat OpenStack Platform 4) - Not affected
Package: v8 (Red Hat Satellite 6
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-1736 v8: integer overflow can lead to a remote denial of service [epel-6]
bugzilla·2014-05-06·CVSS 7.5
CVE-2014-1736 [HIGH] CVE-2014-1736 v8: integer overflow can lead to a remote denial of service [epel-6]
CVE-2014-1736 v8: integer overflow can lead to a remote denial of service [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for
Bugzilla
CVE-2014-1736 v8: integer overflow can lead to a remote denial of service [fedora-all]
bugzilla·2014-05-06·CVSS 7.5
CVE-2014-1736 [HIGH] CVE-2014-1736 v8: integer overflow can lead to a remote denial of service [fedora-all]
CVE-2014-1736 v8: integer overflow can lead to a remote denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects
Bugzilla
CVE-2014-1736 v8: integer overflow can lead to a remote denial of service
bugzilla·2014-05-06·CVSS 7.5
CVE-2014-1736 [HIGH] CVE-2014-1736 v8: integer overflow can lead to a remote denial of service
CVE-2014-1736 v8: integer overflow can lead to a remote denial of service
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-1736 to
the following vulnerability:
Name: CVE-2014-1736
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1736
Assigned: 20140129
Reference: http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.html
Reference: https://code.google.com/p/chromium/issues/detail?id=359802
Reference: https://code.google.com/p/v8/source/detail?r=20519
Reference: https://code.google.com/p/v8/source/detail?r=20525
Reference: SECUNIA:58301
Reference: http://secunia.com/advisories/58301
Integer overflow in api.cc in Google V8, as used in Google Chrome
before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on
Linux, allows remote a
http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.htmlhttp://secunia.com/advisories/58301http://www.debian.org/security/2014/dsa-2920https://code.google.com/p/chromium/issues/detail?id=359802https://code.google.com/p/v8/source/detail?r=20519https://code.google.com/p/v8/source/detail?r=20525http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.htmlhttp://secunia.com/advisories/58301http://www.debian.org/security/2014/dsa-2920https://code.google.com/p/chromium/issues/detail?id=359802https://code.google.com/p/v8/source/detail?r=20519https://code.google.com/p/v8/source/detail?r=20525
2014-05-06
Published