CVE-2014-3170
published 2014-08-27CVE-2014-3170: extensions/common/url_pattern.cc in Google Chrome before 37.0.2062.94 does not prevent use of a '\0' character in a host name, which allows remote attackers to…
PriorityP430medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
1.88%
77.4th percentile
extensions/common/url_pattern.cc in Google Chrome before 37.0.2062.94 does not prevent use of a '\0' character in a host name, which allows remote attackers to spoof the extension permission dialog by relying on truncation after this character.
Affected
82 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 37.0.2062.93 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r235-v62q-qm9r: extensions/common/url_pattern
ghsa_unreviewed·2022-05-17
CVE-2014-3170 [MEDIUM] GHSA-r235-v62q-qm9r: extensions/common/url_pattern
extensions/common/url_pattern.cc in Google Chrome before 37.0.2062.94 does not prevent use of a '\0' character in a host name, which allows remote attackers to spoof the extension permission dialog by relying on truncation after this character.
OSV
CVE-2014-3170: extensions/common/url_pattern
osv·2014-08-27·CVSS 6.4
CVE-2014-3170 [MEDIUM] CVE-2014-3170: extensions/common/url_pattern
extensions/common/url_pattern.cc in Google Chrome before 37.0.2062.94 does not prevent use of a '\0' character in a host name, which allows remote attackers to spoof the extension permission dialog by relying on truncation after this character.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://googlechromereleases.blogspot.com/2014/08/stable-channel-update_26.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00027.htmlhttp://secunia.com/advisories/60268http://secunia.com/advisories/61482http://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-3039http://www.securityfocus.com/bid/69400http://www.securitytracker.com/id/1030767https://crbug.com/390624https://exchange.xforce.ibmcloud.com/vulnerabilities/95470https://src.chromium.org/viewvc/chrome?revision=285492&view=revisionhttp://googlechromereleases.blogspot.com/2014/08/stable-channel-update_26.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00027.htmlhttp://secunia.com/advisories/60268http://secunia.com/advisories/61482http://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-3039http://www.securityfocus.com/bid/69400http://www.securitytracker.com/id/1030767https://crbug.com/390624https://exchange.xforce.ibmcloud.com/vulnerabilities/95470https://src.chromium.org/viewvc/chrome?revision=285492&view=revision
2014-08-27
Published