CVE-2014-7899
published 2014-11-19CVE-2014-7899: Google Chrome before 38.0.2125.101 allows remote attackers to spoof the address bar by placing a blob: substring at the beginning of the URL, followed by the…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.25%
66.5th percentile
Google Chrome before 38.0.2125.101 allows remote attackers to spoof the address bar by placing a blob: substring at the beginning of the URL, followed by the original URI scheme and a long username string.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 38.0.2125.7 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j433-h6rv-q7xm: Google Chrome before 38
ghsa_unreviewed·2022-05-17
CVE-2014-7899 [MEDIUM] CWE-20 GHSA-j433-h6rv-q7xm: Google Chrome before 38
Google Chrome before 38.0.2125.101 allows remote attackers to spoof the address bar by placing a blob: substring at the beginning of the URL, followed by the original URI scheme and a long username string.
OSV
CVE-2014-7899: Google Chrome before 38
osv·2014-11-19·CVSS 5.0
CVE-2014-7899 [MEDIUM] CVE-2014-7899: Google Chrome before 38
Google Chrome before 38.0.2125.101 allows remote attackers to spoof the address bar by placing a blob: substring at the beginning of the URL, followed by the original URI scheme and a long username string.
Red Hat
chromium-browser: Address bar spoofing
vendor_redhat·2014-11-18·CVSS 5.0
CVE-2014-7899 [MEDIUM] CWE-451 chromium-browser: Address bar spoofing
chromium-browser: Address bar spoofing
Google Chrome before 38.0.2125.101 allows remote attackers to spoof the address bar by placing a blob: substring at the beginning of the URL, followed by the original URI scheme and a long username string.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1894.htmlhttp://secunia.com/advisories/60194http://www.securityfocus.com/bid/71160http://www.securitytracker.com/id/1031241https://code.google.com/p/chromium/issues/detail?id=389734https://exchange.xforce.ibmcloud.com/vulnerabilities/98787https://src.chromium.org/viewvc/chrome?revision=279232&view=revisionhttp://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1894.htmlhttp://secunia.com/advisories/60194http://www.securityfocus.com/bid/71160http://www.securitytracker.com/id/1031241https://code.google.com/p/chromium/issues/detail?id=389734https://exchange.xforce.ibmcloud.com/vulnerabilities/98787https://src.chromium.org/viewvc/chrome?revision=279232&view=revision
2014-11-19
Published