CVE-2014-3188
published 2014-10-08CVE-2014-3188: Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote…
PriorityP350critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.00%
92.5th percentile
Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data, related to improper parsing of an escaped index by ParseJsonObject in json-parser.h.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 38.0.2125.7 | — | |
| chrome_os | <= 38.0.2125.77 | — | |
| redhat | enterprise_linux_desktop_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary_eus | — | — |
| redhat | enterprise_linux_workstation_supplementary | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xrvv-5xmr-3grf: Google Chrome before 38
ghsa_unreviewed·2022-05-17
CVE-2014-3188 [HIGH] CWE-94 GHSA-xrvv-5xmr-3grf: Google Chrome before 38
Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data, related to improper parsing of an escaped index by ParseJsonObject in json-parser.h.
OSV
oxide-qt vulnerabilities
osv·2014-10-14·CVSS 7.5
CVE-2014-3178 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
Multiple use-after-free issues were discovered in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via renderer crash,
or execute arbitrary code with the privileges of the sandboxed render
process. (CVE-2014-3178, CVE-2014-3190, CVE-2014-3191, CVE-2014-3192)
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash or execute arbitrary code with the
privileges of the user invoking the program. (CVE-2014-3179,
CVE-2014-3200)
It was discovered that Chromium did not properly handle the int
OSV
CVE-2014-3188: Google Chrome before 38
osv·2014-10-08·CVSS 10.0
CVE-2014-3188 [CRITICAL] CVE-2014-3188: Google Chrome before 38
Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data, related to improper parsing of an escaped index by ParseJsonObject in json-parser.h.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2014-10-14·CVSS 7.5
CVE-2014-3178 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
Multiple use-after-free issues were discovered in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via renderer crash,
or execute arbitrary code with the privileges of the sandboxed render
process. (CVE-2014-3178, CVE-2014-3190, CVE-2014-3191, CVE-2014-3192)
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash or execute arbitrary code with the
privileges of the user invoking the program. (CVE-2014-3179,
CVE-2014-3200)
It w
Red Hat
v8: IPC and v8 issue fixed in Google Chrome 38.0.2125.101
vendor_redhat·2014-09-22·CVSS 10.0
CVE-2014-3188 [CRITICAL] v8: IPC and v8 issue fixed in Google Chrome 38.0.2125.101
v8: IPC and v8 issue fixed in Google Chrome 38.0.2125.101
Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data, related to improper parsing of an escaped index by ParseJsonObject in json-parser.h.
Package: ruby193-v8 (CloudForms Management Engine 5) - Will not fix
Package: ruby193-v8 (OpenShift Enterprise 1) - Will not fix
Package: v8 (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Will not fix
Package: v8 (Red Hat OpenShift Enterprise 2) - Will not fix
Package: ruby193-v8 (Red Hat OpenStack Platform 4) - Will not fix
Package: v8 (Red Hat OpenStack Platform 4) - Will not fix
Package: v8 (Red Hat Satellite
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2014/10/stable-channel-update-for-chrome-os.htmlhttp://googlechromereleases.blogspot.com/2014/10/stable-channel-update.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1626.htmlhttps://code.google.com/p/v8/source/detail?r=24125https://crbug.com/416449http://googlechromereleases.blogspot.com/2014/10/stable-channel-update-for-chrome-os.htmlhttp://googlechromereleases.blogspot.com/2014/10/stable-channel-update.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1626.htmlhttps://code.google.com/p/v8/source/detail?r=24125https://crbug.com/416449
2014-10-08
Published