CVE-2014-3174
published 2014-08-27CVE-2014-3174: modules/webaudio/BiquadDSPKernel.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 37.0.2062.94, does not properly consider…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.58%
73.2th percentile
modules/webaudio/BiquadDSPKernel.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 37.0.2062.94, does not properly consider concurrent threads during attempts to update biquad filter coefficients, which allows remote attackers to cause a denial of service (read of uninitialized memory) via crafted API calls.
Affected
82 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 37.0.2062.93 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7292-q6p2-wf79: modules/webaudio/BiquadDSPKernel
ghsa_unreviewed·2022-05-17
CVE-2014-3174 [MEDIUM] CWE-119 GHSA-7292-q6p2-wf79: modules/webaudio/BiquadDSPKernel
modules/webaudio/BiquadDSPKernel.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 37.0.2062.94, does not properly consider concurrent threads during attempts to update biquad filter coefficients, which allows remote attackers to cause a denial of service (read of uninitialized memory) via crafted API calls.
OSV
oxide-qt vulnerabilities
osv·2014-09-02·CVSS 7.5
CVE-2014-3168 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
A use-after-free was discovered in the SVG implementation in Blink. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via renderer
crash, or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2014-3168)
A use-after-free was discovered in the DOM implementation in Blink. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via renderer
crash, or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2014-3169)
A use-after-free was discovered in V8. If a user were tricked in to
opening a specially crafted website, an attacker could potenti
OSV
CVE-2014-3174: modules/webaudio/BiquadDSPKernel
osv·2014-08-26·CVSS 5.0
CVE-2014-3174 [MEDIUM] CVE-2014-3174: modules/webaudio/BiquadDSPKernel
modules/webaudio/BiquadDSPKernel.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 37.0.2062.94, does not properly consider concurrent threads during attempts to update biquad filter coefficients, which allows remote attackers to cause a denial of service (read of uninitialized memory) via crafted API calls.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2014-09-02·CVSS 7.5
CVE-2014-3168 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
A use-after-free was discovered in the SVG implementation in Blink. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via renderer
crash, or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2014-3168)
A use-after-free was discovered in the DOM implementation in Blink. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via renderer
crash, or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2014-3169)
A use-after-free was discovered in V8. If a user were tricked in to
ope
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://googlechromereleases.blogspot.com/2014/08/stable-channel-update_26.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00027.htmlhttp://secunia.com/advisories/60268http://secunia.com/advisories/60424http://secunia.com/advisories/61482http://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-3039http://www.securityfocus.com/bid/69407http://www.securitytracker.com/id/1030767https://crbug.com/389219https://exchange.xforce.ibmcloud.com/vulnerabilities/95474https://src.chromium.org/viewvc/blink?revision=177250&view=revisionhttp://googlechromereleases.blogspot.com/2014/08/stable-channel-update_26.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00027.htmlhttp://secunia.com/advisories/60268http://secunia.com/advisories/60424http://secunia.com/advisories/61482http://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-3039http://www.securityfocus.com/bid/69407http://www.securitytracker.com/id/1030767https://crbug.com/389219https://exchange.xforce.ibmcloud.com/vulnerabilities/95474https://src.chromium.org/viewvc/blink?revision=177250&view=revision
2014-08-27
Published