CVE-2014-3198
published 2014-10-08CVE-2014-3198: The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an…
PriorityP420medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.26%
66.6th percentile
The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 38.0.2125.7 | — | |
| redhat | enterprise_linux_desktop_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary_eus | — | — |
| redhat | enterprise_linux_workstation_supplementary | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rwv6-475g-6grg: The Instance::HandleInputEvent function in pdf/instance
ghsa_unreviewed·2022-05-17
CVE-2014-3198 [MEDIUM] CWE-119 GHSA-rwv6-475g-6grg: The Instance::HandleInputEvent function in pdf/instance
The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
OSV
CVE-2014-3198: The Instance::HandleInputEvent function in pdf/instance
osv·2014-10-08·CVSS 5.0
CVE-2014-3198 [MEDIUM] CVE-2014-3198: The Instance::HandleInputEvent function in pdf/instance
The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
Red Hat
kernel: mptcp: use the workqueue to destroy unaccepted sockets
vendor_redhat·2025-05-02·CVSS 7.8
CVE-2023-53072 [HIGH] CWE-416 kernel: mptcp: use the workqueue to destroy unaccepted sockets
kernel: mptcp: use the workqueue to destroy unaccepted sockets
In the Linux kernel, the following vulnerability has been resolved:
mptcp: use the workqueue to destroy unaccepted sockets
Christoph reported a UaF at token lookup time after having
refactored the passive socket initialization part:
BUG: KASAN: use-after-free in __token_bucket_busy+0x253/0x260
Read of size 4 at addr ffff88810698d5b0 by task syz-executor653/3198
CPU: 1 PID: 3198 Comm: syz-executor653 Not tainted 6.2.0-rc59af4eaa31c1f6c00c8f1e448ed99a45c66340dd5 #6
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014
Call Trace:
dump_stack_lvl+0x6e/0x91
print_report+0x16a/0x46f
kasan_report+0xad/0x130
__token_bucket_busy+0x253/0x260
mptcp_token_new_connect+0x13d/0x4
Red Hat
chromium: OOB reads in PDFium fixed in Chrome 38.0.2125.101
vendor_redhat·2014-10-07·CVSS 5.0
CVE-2014-3198 [MEDIUM] CWE-125 chromium: OOB reads in PDFium fixed in Chrome 38.0.2125.101
chromium: OOB reads in PDFium fixed in Chrome 38.0.2125.101
The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-53072 kernel: mptcp: use the workqueue to destroy unaccepted sockets
bugzilla·2025-05-02·CVSS 7.8
CVE-2023-53072 [HIGH] CVE-2023-53072 kernel: mptcp: use the workqueue to destroy unaccepted sockets
CVE-2023-53072 kernel: mptcp: use the workqueue to destroy unaccepted sockets
In the Linux kernel, the following vulnerability has been resolved:
mptcp: use the workqueue to destroy unaccepted sockets
Christoph reported a UaF at token lookup time after having
refactored the passive socket initialization part:
BUG: KASAN: use-after-free in __token_bucket_busy+0x253/0x260
Read of size 4 at addr ffff88810698d5b0 by task syz-executor653/3198
CPU: 1 PID: 3198 Comm: syz-executor653 Not tainted 6.2.0-rc59af4eaa31c1f6c00c8f1e448ed99a45c66340dd5 #6
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014
Call Trace:
dump_stack_lvl+0x6e/0x91
print_report+0x16a/0x46f
kasan_report+0xad/0x130
__token_bucket_busy+0x253/0x260
mptcp_token_ne
Bugzilla
CVE-2014-3189 CVE-2014-3198 chromium: OOB reads in PDFium fixed in Chrome 38.0.2125.101
bugzilla·2014-10-10·CVSS 7.5
CVE-2014-3189 [HIGH] CVE-2014-3189 CVE-2014-3198 chromium: OOB reads in PDFium fixed in Chrome 38.0.2125.101
CVE-2014-3189 CVE-2014-3198 chromium: OOB reads in PDFium fixed in Chrome 38.0.2125.101
Chrome version 38.0.2125.101 fixes two flaws in the embedded PDF viewer PDFium:
CVE-2014-3189
The chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium component in Google Chrome before 38.0.2125.101 does not properly validate image-data dimensions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via unknown vectors.
https://crbug.com/398384
https://codereview.chromium.org/519873002/
CVE-2014-3198
The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows re
http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1626.htmlhttp://www.securityfocus.com/bid/70273https://codereview.chromium.org/560133004https://crbug.com/415307http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1626.htmlhttp://www.securityfocus.com/bid/70273https://codereview.chromium.org/560133004https://crbug.com/415307
2014-10-08
Published