CVE-2014-3193
published 2014-10-08CVE-2014-3193: The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101 allows remote attackers to cause a…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.69%
74.7th percentile
The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors that leverage "type confusion" for callback processing.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 38.0.2125.7 | — | |
| redhat | enterprise_linux_desktop_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary_eus | — | — |
| redhat | enterprise_linux_workstation_supplementary | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-59mv-f2pf-cr57: The SessionService::GetLastSession function in browser/sessions/session_service
ghsa_unreviewed·2022-05-17
CVE-2014-3193 [HIGH] CWE-416 GHSA-59mv-f2pf-cr57: The SessionService::GetLastSession function in browser/sessions/session_service
The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors that leverage "type confusion" for callback processing.
OSV
CVE-2014-3193: The SessionService::GetLastSession function in browser/sessions/session_service
osv·2014-10-08·CVSS 7.5
CVE-2014-3193 [HIGH] CVE-2014-3193: The SessionService::GetLastSession function in browser/sessions/session_service
The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors that leverage "type confusion" for callback processing.
Red Hat
chromium: multiple security fixes in Chrome 38.0.2125.101
vendor_redhat·2014-10-07·CVSS 7.5
CVE-2014-3193 [HIGH] chromium: multiple security fixes in Chrome 38.0.2125.101
chromium: multiple security fixes in Chrome 38.0.2125.101
The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors that leverage "type confusion" for callback processing.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1626.htmlhttp://www.securityfocus.com/bid/70273https://codereview.chromium.org/500143002/https://crbug.com/399655http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1626.htmlhttp://www.securityfocus.com/bid/70273https://codereview.chromium.org/500143002/https://crbug.com/399655
2014-10-08
Published