CVE-2014-3197Sensitive Information Exposure in Google Chrome

Severity
5.0MEDIUMNVD
EPSS
0.3%
top 45.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 8
Latest updateMay 17

Description

The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attackers to obtain sensitive information via a crafted web site.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

Also affects: Enterprise Linux 6.0, 6.6.z

🔴Vulnerability Details

3
GHSA
GHSA-wmjx-mph9-7xgg: The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler2022-05-17
OSV
CVE-2014-3197: The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler2014-10-08
CVEList
CVE-2014-3197: The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler2014-10-08

📋Vendor Advisories

2
Ubuntu
Oxide vulnerabilities2014-10-14
Red Hat
chromium: information leak in XSS Auditor fixed in Chrome 38.0.2125.1012014-10-07

💬Community

1
Bugzilla
CVE-2014-3197 chromium: information leak in XSS Auditor fixed in Chrome 38.0.2125.1012014-10-10
CVE-2014-3197 — Sensitive Information Exposure | cvebase