CVE-2014-3152
published 2014-05-21CVE-2014-3152: Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Google V8 before 3.25.28.16, as used in Google Chrome before…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.95%
78.1th percentile
Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Google V8 before 3.25.28.16, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a negative key value.
Affected
112 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | <= 35.0.1916.113 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3x5j-mj7x-jgpm: Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm
ghsa_unreviewed·2022-05-14
CVE-2014-3152 [HIGH] GHSA-3x5j-mj7x-jgpm: Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm
Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Google V8 before 3.25.28.16, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a negative key value.
OSV
oxide-qt vulnerabilities
osv·2014-07-23·CVSS 7.8
CVE-2014-1730 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
A type confusion bug was discovered in V8. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-1730)
A type confusion bug was discovered in Blink. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-1731)
Multiple security issues including memory safety bugs were discovered in
Chromium. If a user were tricked in to opening a specially crafted website,
an attacker could potentiall
OSV
CVE-2014-3152: Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm
osv·2014-05-21·CVSS 7.5
CVE-2014-3152 [HIGH] CVE-2014-3152: Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm
Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Google V8 before 3.25.28.16, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a negative key value.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2014-07-23·CVSS 7.8
CVE-2014-1730 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
A type confusion bug was discovered in V8. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-1730)
A type confusion bug was discovered in Blink. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-1731)
Multiple security issues including memory safety bugs were discovered in
Chromium. If a user were tricked in to openin
Red Hat
v8: integer underflow fixed in Google Chrome 35.0.1916.114
vendor_redhat·2014-03-31·CVSS 7.5
CVE-2014-3152 [HIGH] CWE-190 v8: integer underflow fixed in Google Chrome 35.0.1916.114
v8: integer underflow fixed in Google Chrome 35.0.1916.114
Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Google V8 before 3.25.28.16, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a negative key value.
Package: ruby193-v8 (CloudForms Management Engine 5) - Not affected
Package: ruby193-v8 (OpenShift Enterprise 1) - Not affected
Package: v8 (Red Hat OpenShift Enterprise 2) - Not affected
Package: ruby193-v8 (Red Hat OpenStack Platform 3) - Not affected
Package: v8 (Red Hat OpenStack Platform 3) - Not affected
Package: ruby193-v8 (Red Hat OpenStack Platform 4) - Not affected
Package: v8 (Red Hat OpenStack Platform
Suricata
ET WEB_SERVER Possible Oracle Reports Forms RCE CVE-2012-3152
suricata·2014-02-07·CVSS 9.1
CVE-2012-3152 [CRITICAL] ET WEB_SERVER Possible Oracle Reports Forms RCE CVE-2012-3152
ET WEB_SERVER Possible Oracle Reports Forms RCE CVE-2012-3152
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Possible Oracle Reports Forms RCE CVE-2012-3152"; flow:established,to_server; http.uri; content:"/reports/rwservlet?"; nocase; content:"JOBTYPE"; nocase; content:"rwurl"; nocase; content:"URLPARAMETER"; nocase; pcre:"/^\s*?=\s*?[\x22\x27]?(?:f(?:ile|tp)|gopher|https?|mailto)\s*?\x3a/Ri"; reference:url,netinfiltration.com; classtype:web-application-attack; sid:2018092; rev:3; metadata:created_at 2014_02_07, cve CVE_2012_3152, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_04_27;)
Bugzilla
CVE-2014-3152 v8: integer underflow fixed in Google Chrome 35.0.1916.114 [epel-6]
bugzilla·2014-05-26·CVSS 7.5
CVE-2014-3152 [HIGH] CVE-2014-3152 v8: integer underflow fixed in Google Chrome 35.0.1916.114 [epel-6]
CVE-2014-3152 v8: integer underflow fixed in Google Chrome 35.0.1916.114 [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for v
Bugzilla
CVE-2014-3152 v8: integer underflow fixed in Google Chrome 35.0.1916.114
bugzilla·2014-05-26·CVSS 7.5
CVE-2014-3152 [HIGH] CVE-2014-3152 v8: integer underflow fixed in Google Chrome 35.0.1916.114
CVE-2014-3152 v8: integer underflow fixed in Google Chrome 35.0.1916.114
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-3152 to
the following vulnerability:
Name: CVE-2014-3152
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3152
Assigned: 20140503
Reference: http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
Reference: https://code.google.com/p/chromium/issues/detail?id=358057
Reference: https://code.google.com/p/v8/source/detail?r=20363
Integer underflow in the LCodeGen::PrepareKeyedOperand function in
arm/lithium-codegen-arm.cc in Google V8 before 3.25.28.16, as used in
Google Chrome before 35.0.1916.114, allows remote attackers to cause a
denial of service or possibly have unspecified other impact via
vectors that trigger
Bugzilla
CVE-2014-3152 v8: integer underflow fixed in Google Chrome 35.0.1916.114 [fedora-all]
bugzilla·2014-05-26·CVSS 7.5
CVE-2014-3152 [HIGH] CVE-2014-3152 v8: integer underflow fixed in Google Chrome 35.0.1916.114 [fedora-all]
CVE-2014-3152 v8: integer underflow fixed in Google Chrome 35.0.1916.114 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects m
http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157338.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157357.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157363.htmlhttp://lists.opensuse.org/opensuse-updates/2014-06/msg00023.htmlhttp://secunia.com/advisories/58920http://secunia.com/advisories/59155http://secunia.com/advisories/60372http://www.debian.org/security/2014/dsa-2939http://www.securitytracker.com/id/1030270https://code.google.com/p/chromium/issues/detail?id=358057https://code.google.com/p/v8/source/detail?r=20363http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157338.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157357.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157363.htmlhttp://lists.opensuse.org/opensuse-updates/2014-06/msg00023.htmlhttp://secunia.com/advisories/58920http://secunia.com/advisories/59155http://secunia.com/advisories/60372http://www.debian.org/security/2014/dsa-2939http://www.securitytracker.com/id/1030270https://code.google.com/p/chromium/issues/detail?id=358057https://code.google.com/p/v8/source/detail?r=20363
2014-05-21
Published