CVE-2014-3194
published 2014-10-08CVE-2014-3194: Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service or…
PriorityP430high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.16%
63.8th percentile
Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 38.0.2125.7 | — | |
| redhat | enterprise_linux_desktop_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary_eus | — | — |
| redhat | enterprise_linux_workstation_supplementary | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2014-10-14·CVSS 7.5
CVE-2014-3178 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
Multiple use-after-free issues were discovered in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via renderer crash,
or execute arbitrary code with the privileges of the sandboxed render
process. (CVE-2014-3178, CVE-2014-3190, CVE-2014-3191, CVE-2014-3192)
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash or execute arbitrary code with the
privileges of the user invoking the program. (CVE-2014-3179,
CVE-2014-3200)
It w
Red Hat
chromium: use-after-free issue in Web Workers fixed in Chrome 38.0.2125.101
vendor_redhat·2014-10-07·CVSS 7.5
CVE-2014-3194 [HIGH] CWE-416 chromium: use-after-free issue in Web Workers fixed in Chrome 38.0.2125.101
chromium: use-after-free issue in Web Workers fixed in Chrome 38.0.2125.101
Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Not affected
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Not affected
GHSA
GHSA-9j9x-j42j-v2mv: Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38
ghsa_unreviewed·2022-05-17
CVE-2014-3194 [HIGH] CWE-416 GHSA-9j9x-j42j-v2mv: Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38
Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
OSV
oxide-qt vulnerabilities
osv·2014-10-14·CVSS 7.5
CVE-2014-3178 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
Multiple use-after-free issues were discovered in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via renderer crash,
or execute arbitrary code with the privileges of the sandboxed render
process. (CVE-2014-3178, CVE-2014-3190, CVE-2014-3191, CVE-2014-3192)
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash or execute arbitrary code with the
privileges of the user invoking the program. (CVE-2014-3179,
CVE-2014-3200)
It was discovered that Chromium did not properly handle the int
OSV
CVE-2014-3194: Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38
osv·2014-10-08·CVSS 7.5
CVE-2014-3194 [HIGH] CVE-2014-3194: Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38
Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1626.htmlhttp://www.securityfocus.com/bid/70273https://crbug.com/401115http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1626.htmlhttp://www.securityfocus.com/bid/70273https://crbug.com/401115
2014-10-08
Published