CVE-2014-7904
published 2014-11-19CVE-2014-7904: Buffer overflow in Skia, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.63%
73.9th percentile
Buffer overflow in Skia, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 39.0.2171.45 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2014-11-19·CVSS 7.5
CVE-2014-7904 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
A buffer overflow was discovered in Skia. If a user were tricked in to
opening a specially crafted website, an attacked could potentially exploit
this to cause a denial of service via renderer crash or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-7904)
Multiple use-after-frees were discovered in Blink. If a user were tricked
in to opening a specially crafted website, an attacked could potentially
exploit these to cause a denial of service via renderer crash or execute
arbitrary code with the privileges of the sandboxed render process.
(CVE-2014-7907)
An integer overflow was discovered in media. If a user were tricked in to
opening a specially crafted website, an a
Red Hat
chromium-browser: Buffer overflow in Skia
vendor_redhat·2014-11-18·CVSS 7.5
CVE-2014-7904 [HIGH] chromium-browser: Buffer overflow in Skia
chromium-browser: Buffer overflow in Skia
Buffer overflow in Skia, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Statement: This issue did not affect the versions of librsvg2 as shipped with Red Hat Enterprise Linux 5 and 6. This issue affects the version of librsvg2 as shipped with Red Hat Enterprise Linux 7.
Package: librsvg2 (Red Hat Enterprise Linux 5) - Not affected
Package: librsvg2 (Red Hat Enterprise Linux 6) - Not affected
Package: librsvg2 (Red Hat Enterprise Linux 7) - Will not fix
GHSA
GHSA-w9r7-3rj5-pq9r: Buffer overflow in Skia, as used in Google Chrome before 39
ghsa_unreviewed·2022-05-17
CVE-2014-7904 [HIGH] CWE-119 GHSA-w9r7-3rj5-pq9r: Buffer overflow in Skia, as used in Google Chrome before 39
Buffer overflow in Skia, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
OSV
CVE-2014-7904: Buffer overflow in Skia, as used in Google Chrome before 39
osv·2014-11-19·CVSS 7.5
CVE-2014-7904 [HIGH] CVE-2014-7904: Buffer overflow in Skia, as used in Google Chrome before 39
Buffer overflow in Skia, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
OSV
oxide-qt vulnerabilities
osv·2014-11-19·CVSS 7.5
CVE-2014-7904 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
A buffer overflow was discovered in Skia. If a user were tricked in to
opening a specially crafted website, an attacked could potentially exploit
this to cause a denial of service via renderer crash or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-7904)
Multiple use-after-frees were discovered in Blink. If a user were tricked
in to opening a specially crafted website, an attacked could potentially
exploit these to cause a denial of service via renderer crash or execute
arbitrary code with the privileges of the sandboxed render process.
(CVE-2014-7907)
An integer overflow was discovered in media. If a user were tricked in to
opening a specially crafted website, an attacked could potentially exploit
this to cause a denial of
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1894.htmlhttp://secunia.com/advisories/60194http://secunia.com/advisories/62608http://www.securityfocus.com/bid/71166http://www.securitytracker.com/id/1031241https://code.google.com/p/chromium/issues/detail?id=418161https://exchange.xforce.ibmcloud.com/vulnerabilities/98792http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1894.htmlhttp://secunia.com/advisories/60194http://secunia.com/advisories/62608http://www.securityfocus.com/bid/71166http://www.securitytracker.com/id/1031241https://code.google.com/p/chromium/issues/detail?id=418161https://exchange.xforce.ibmcloud.com/vulnerabilities/98792
2014-11-19
Published