CVE-2014-1745Uncontrolled Resource Consumption in Google Chrome

Severity
7.1HIGHNVD
EPSS
0.8%
top 25.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 21
Latest updateFeb 5

Description

Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger removal of an SVGFontFaceElement object, related to core/svg/SVGFontFaceElement.cpp.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:LExploitability: 2.8 | Impact: 4.2

Affected Packages6 packages

NVDgoogle/chrome35.0.1916.113+79
debiandebian/wpewebkit< webkit2gtk 2.42.1-1~deb12u1 (bookworm)
debiandebian/webkit2gtk< webkit2gtk 2.42.1-1~deb12u1 (bookworm)
Appleapple/safari16.4

🔴Vulnerability Details

2
GHSA
GHSA-pr96-m2pj-3g36: Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 352022-05-14
OSV
CVE-2014-1745: Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 352014-05-21

📋Vendor Advisories

5
Red Hat
webkitgtk: Processing a file may lead to a denial of service or potentially disclose memory contents2024-02-05
Apple
CVE-2014-1745: Safari 16.42023-03-27
Apple
CVE-2014-1745: macOS Ventura 13.32023-03-27
Apple
CVE-2014-1745: iOS 16.4 and iPadOS 16.42023-03-27
Debian
CVE-2014-1745: webkit2gtk - Use-after-free vulnerability in the SVG implementation in Blink, as used in Goog...2014