cbcvebase.
CVE-2014-1745
published 2014-05-21

CVE-2014-1745: Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of…

PriorityP428high7.1CVSS 3.1
AVNACLPRNUIRSUCHINAL
EPSS
1.67%
73.9th percentile
Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger removal of an SVGFontFaceElement object, related to core/svg/SVGFontFaceElement.cpp.

Affected

85 ranges· showing 25
VendorProductVersion rangeFixed in
appleios_16.4_and_ipados
applemacos_ventura
applesafari
debianwebkit2gtk< webkit2gtk 2.42.1-1~deb12u1 (bookworm)webkit2gtk 2.42.1-1~deb12u1 (bookworm)
debianwpewebkit< webkit2gtk 2.42.1-1~deb12u1 (bookworm)webkit2gtk 2.42.1-1~deb12u1 (bookworm)
googlechrome<= 35.0.1916.113
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome
googlechrome

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.