CVE-2014-3192
published 2014-10-08CVE-2014-3192: Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink…
PriorityP433high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.68%
74.4th percentile
Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | apple_tv | — | — |
| apple | ios | — | — |
| apple | iphone_os | <= 8.1.2 | — |
| apple | itunes | <= 12.1.3 | — |
| apple | itunes | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari_8.0.3_safari_7.1.3_and_safari | — | — |
| apple | tvos | <= 7.0.1 | — |
| chrome | <= 38.0.2125.7 | — | |
| redhat | enterprise_linux_desktop_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary_eus | — | — |
| redhat | enterprise_linux_workstation_supplementary | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xxfg-fm6v-83pq: Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction
ghsa_unreviewed·2022-05-14
CVE-2014-3192 [HIGH] CWE-416 GHSA-xxfg-fm6v-83pq: Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction
Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
OSV
oxide-qt vulnerabilities
osv·2014-10-14·CVSS 7.5
CVE-2014-3178 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
Multiple use-after-free issues were discovered in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via renderer crash,
or execute arbitrary code with the privileges of the sandboxed render
process. (CVE-2014-3178, CVE-2014-3190, CVE-2014-3191, CVE-2014-3192)
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash or execute arbitrary code with the
privileges of the user invoking the program. (CVE-2014-3179,
CVE-2014-3200)
It was discovered that Chromium did not properly handle the int
OSV
CVE-2014-3192: Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction
osv·2014-10-08·CVSS 7.5
CVE-2014-3192 [HIGH] CVE-2014-3192: Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction
Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2014-10-14·CVSS 7.5
CVE-2014-3178 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
Multiple use-after-free issues were discovered in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via renderer crash,
or execute arbitrary code with the privileges of the sandboxed render
process. (CVE-2014-3178, CVE-2014-3190, CVE-2014-3191, CVE-2014-3192)
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash or execute arbitrary code with the
privileges of the user invoking the program. (CVE-2014-3179,
CVE-2014-3200)
It w
Red Hat
chromium: use-after-free in DOM, fixed in Chrome 38.0.2125.101
vendor_redhat·2014-10-07·CVSS 7.5
CVE-2014-3192 [HIGH] CWE-416 chromium: use-after-free in DOM, fixed in Chrome 38.0.2125.101
chromium: use-after-free in DOM, fixed in Chrome 38.0.2125.101
Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Statement: This issue affects the versions of webkitgtk and webkitgtk3 as shipped with Red Hat Enterprise Linux 6 and 7 respectively.
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classificat
Apple
CVE-2014-3192: Safari 8.0.3, Safari 7.1.3, and Safari 6.2.3
vendor_apple·CVSS 7.5
CVE-2014-3192 [HIGH] CVE-2014-3192: Safari 8.0.3, Safari 7.1.3, and Safari 6.2.3
Apple Security Update: About the security content of Safari 8.0.3, Safari 7.1.3, and Safari 6.2.3
Product: Safari 8.0.3, Safari 7.1.3, and Safari
Version: 6.2.3
CVE: CVE-2014-3192
Component: CVE-ID
Apple
CVE-2014-3192: iOS 8.1.3
vendor_apple·CVSS 7.5
CVE-2014-3192 [HIGH] CVE-2014-3192: iOS 8.1.3
Apple Security Update: About the security content of iOS 8.1.3
Product: iOS
Version: 8.1.3
CVE: CVE-2014-3192
Component: CVE-ID
Apple
CVE-2014-3192: iTunes 12.2
vendor_apple·CVSS 7.5
CVE-2014-3192 [HIGH] CVE-2014-3192: iTunes 12.2
Apple Security Update: About the security content of iTunes 12.2
Product: iTunes
Version: 12.2
CVE: CVE-2014-3192
Component: CVE-ID
Apple
CVE-2014-3192: Apple TV 7.0.3
vendor_apple·CVSS 7.5
CVE-2014-3192 [HIGH] CVE-2014-3192: Apple TV 7.0.3
Apple Security Update: About the security content of Apple TV 7.0.3
Product: Apple TV
Version: 7.0.3
CVE: CVE-2014-3192
Component: CVE-ID
No detection rules found.
http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.htmlhttp://lists.apple.com/archives/security-announce/2015/Jan/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2015/Jan/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Jan/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Jun/msg00006.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1626.htmlhttp://support.apple.com/HT204243http://support.apple.com/HT204245http://support.apple.com/HT204246http://www.securityfocus.com/bid/70273http://www.securitytracker.com/id/1031647https://crbug.com/403276https://src.chromium.org/viewvc/blink?revision=182309&view=revisionhttps://support.apple.com/kb/HT204949http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.htmlhttp://lists.apple.com/archives/security-announce/2015/Jan/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2015/Jan/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Jan/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Jun/msg00006.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1626.htmlhttp://support.apple.com/HT204243http://support.apple.com/HT204245http://support.apple.com/HT204246http://www.securityfocus.com/bid/70273http://www.securitytracker.com/id/1031647https://crbug.com/403276https://src.chromium.org/viewvc/blink?revision=182309&view=revisionhttps://support.apple.com/kb/HT204949
2014-10-08
Published