CVE-2014-3172
published 2014-08-27CVE-2014-3172: The Debugger extension API in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 37.0.2062.94 does not validate a tab's URL before an…
PriorityP434medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
1.93%
78.0th percentile
The Debugger extension API in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 37.0.2062.94 does not validate a tab's URL before an attach operation, which allows remote attackers to bypass intended access limitations via an extension that uses a restricted URL, as demonstrated by a chrome:// URL.
Affected
82 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 37.0.2062.93 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5x9g-x8x2-c437: The Debugger extension API in browser/extensions/api/debugger/debugger_api
ghsa_unreviewed·2022-05-17
CVE-2014-3172 [MEDIUM] GHSA-5x9g-x8x2-c437: The Debugger extension API in browser/extensions/api/debugger/debugger_api
The Debugger extension API in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 37.0.2062.94 does not validate a tab's URL before an attach operation, which allows remote attackers to bypass intended access limitations via an extension that uses a restricted URL, as demonstrated by a chrome:// URL.
OSV
CVE-2014-3172: The Debugger extension API in browser/extensions/api/debugger/debugger_api
osv·2014-08-27·CVSS 6.4
CVE-2014-3172 [MEDIUM] CVE-2014-3172: The Debugger extension API in browser/extensions/api/debugger/debugger_api
The Debugger extension API in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 37.0.2062.94 does not validate a tab's URL before an attach operation, which allows remote attackers to bypass intended access limitations via an extension that uses a restricted URL, as demonstrated by a chrome:// URL.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://googlechromereleases.blogspot.com/2014/08/stable-channel-update_26.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00027.htmlhttp://secunia.com/advisories/60268http://secunia.com/advisories/61482http://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-3039http://www.securityfocus.com/bid/69401http://www.securitytracker.com/id/1030767https://crbug.com/367567https://exchange.xforce.ibmcloud.com/vulnerabilities/95472https://src.chromium.org/viewvc/chrome?revision=280354&view=revisionhttp://googlechromereleases.blogspot.com/2014/08/stable-channel-update_26.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00027.htmlhttp://secunia.com/advisories/60268http://secunia.com/advisories/61482http://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-3039http://www.securityfocus.com/bid/69401http://www.securitytracker.com/id/1030767https://crbug.com/367567https://exchange.xforce.ibmcloud.com/vulnerabilities/95472https://src.chromium.org/viewvc/chrome?revision=280354&view=revision
2014-08-27
Published