CVE-2014-3177
published 2014-08-27CVE-2014-3177: Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attackers to…
PriorityP347critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.88%
89.2th percentile
Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-3176.
Affected
82 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 37.0.2062.93 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2c22-7f4c-fw6q: Google Chrome before 37
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2014-3177 [CRITICAL] CWE-94 GHSA-2c22-7f4c-fw6q: Google Chrome before 37
Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-3176.
GHSA
GHSA-h5p3-xphh-6569: Google Chrome before 37
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2014-3176 [CRITICAL] CWE-94 GHSA-h5p3-xphh-6569: Google Chrome before 37
Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-3177.
OSV
CVE-2014-3176: Google Chrome before 37
osv·2014-08-27·CVSS 10.0
CVE-2014-3176 [CRITICAL] CVE-2014-3176: Google Chrome before 37
Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-3177.
OSV
CVE-2014-3177: Google Chrome before 37
osv·2014-08-27·CVSS 10.0
CVE-2014-3177 [CRITICAL] CVE-2014-3177: Google Chrome before 37
Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-3176.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://googlechromereleases.blogspot.com/2014/08/stable-channel-update_26.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00027.htmlhttp://secunia.com/advisories/60268http://secunia.com/advisories/61482http://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-3039http://www.securityfocus.com/bid/69404http://www.securitytracker.com/id/1030767https://crbug.com/386988https://exchange.xforce.ibmcloud.com/vulnerabilities/95477http://googlechromereleases.blogspot.com/2014/08/stable-channel-update_26.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00027.htmlhttp://secunia.com/advisories/60268http://secunia.com/advisories/61482http://security.gentoo.org/glsa/glsa-201408-16.xmlhttp://www.debian.org/security/2014/dsa-3039http://www.securityfocus.com/bid/69404http://www.securitytracker.com/id/1030767https://crbug.com/386988https://exchange.xforce.ibmcloud.com/vulnerabilities/95477
2014-08-27
Published