CVE-2014-3197
published 2014-10-08CVE-2014-3197: The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not…
PriorityP419medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
0.96%
58.0th percentile
The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attackers to obtain sensitive information via a crafted web site.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 38.0.2125.7 | — | |
| redhat | enterprise_linux_desktop_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary_eus | — | — |
| redhat | enterprise_linux_workstation_supplementary | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wmjx-mph9-7xgg: The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler
ghsa_unreviewed·2022-05-17
CVE-2014-3197 [MEDIUM] GHSA-wmjx-mph9-7xgg: The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler
The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attackers to obtain sensitive information via a crafted web site.
OSV
oxide-qt vulnerabilities
osv·2014-10-14·CVSS 7.5
CVE-2014-3178 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
Multiple use-after-free issues were discovered in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via renderer crash,
or execute arbitrary code with the privileges of the sandboxed render
process. (CVE-2014-3178, CVE-2014-3190, CVE-2014-3191, CVE-2014-3192)
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash or execute arbitrary code with the
privileges of the user invoking the program. (CVE-2014-3179,
CVE-2014-3200)
It was discovered that Chromium did not properly handle the int
OSV
CVE-2014-3197: The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler
osv·2014-10-08·CVSS 5.0
CVE-2014-3197 [MEDIUM] CVE-2014-3197: The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler
The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attackers to obtain sensitive information via a crafted web site.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2014-10-14·CVSS 7.5
CVE-2014-3178 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
Multiple use-after-free issues were discovered in Blink. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via renderer crash,
or execute arbitrary code with the privileges of the sandboxed render
process. (CVE-2014-3178, CVE-2014-3190, CVE-2014-3191, CVE-2014-3192)
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash or execute arbitrary code with the
privileges of the user invoking the program. (CVE-2014-3179,
CVE-2014-3200)
It w
Red Hat
chromium: information leak in XSS Auditor fixed in Chrome 38.0.2125.101
vendor_redhat·2014-10-07·CVSS 5.0
CVE-2014-3197 [MEDIUM] CWE-200 chromium: information leak in XSS Auditor fixed in Chrome 38.0.2125.101
chromium: information leak in XSS Auditor fixed in Chrome 38.0.2125.101
The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attackers to obtain sensitive information via a crafted web site.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Not affected
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1626.htmlhttp://www.securityfocus.com/bid/70273https://crbug.com/396544https://src.chromium.org/viewvc/blink?revision=179240&view=revisionhttp://googlechromereleases.blogspot.com/2014/10/stable-channel-update.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1626.htmlhttp://www.securityfocus.com/bid/70273https://crbug.com/396544https://src.chromium.org/viewvc/blink?revision=179240&view=revision
2014-10-08
Published