CVE-2014-7908
published 2014-11-19CVE-2014-7908: Multiple integer overflows in the CheckMov function in media/base/container_names.cc in Google Chrome before 39.0.2171.65 allow remote attackers to cause a…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.61%
73.5th percentile
Multiple integer overflows in the CheckMov function in media/base/container_names.cc in Google Chrome before 39.0.2171.65 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a large atom in (1) MPEG-4 or (2) QuickTime .mov data.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 39.0.2171.45 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2014-11-19·CVSS 7.5
CVE-2014-7904 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
A buffer overflow was discovered in Skia. If a user were tricked in to
opening a specially crafted website, an attacked could potentially exploit
this to cause a denial of service via renderer crash or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-7904)
Multiple use-after-frees were discovered in Blink. If a user were tricked
in to opening a specially crafted website, an attacked could potentially
exploit these to cause a denial of service via renderer crash or execute
arbitrary code with the privileges of the sandboxed render process.
(CVE-2014-7907)
An integer overflow was discovered in media. If a user were tricked in to
opening a specially crafted website, an a
Red Hat
chromium-browser: Integer overflow in media
vendor_redhat·2014-11-18·CVSS 7.5
CVE-2014-7908 [HIGH] CWE-190 chromium-browser: Integer overflow in media
chromium-browser: Integer overflow in media
Multiple integer overflows in the CheckMov function in media/base/container_names.cc in Google Chrome before 39.0.2171.65 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a large atom in (1) MPEG-4 or (2) QuickTime .mov data.
Statement: This issue affects the versions of webkitgtk and webkitgtk3 as shipped with Red Hat Enterprise Linux 6 and 7 respectively.
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not
GHSA
GHSA-9cq7-783p-x34h: Multiple integer overflows in the CheckMov function in media/base/container_names
ghsa_unreviewed·2022-05-17
CVE-2014-7908 [HIGH] GHSA-9cq7-783p-x34h: Multiple integer overflows in the CheckMov function in media/base/container_names
Multiple integer overflows in the CheckMov function in media/base/container_names.cc in Google Chrome before 39.0.2171.65 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a large atom in (1) MPEG-4 or (2) QuickTime .mov data.
OSV
oxide-qt vulnerabilities
osv·2014-11-19·CVSS 7.5
CVE-2014-7904 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
A buffer overflow was discovered in Skia. If a user were tricked in to
opening a specially crafted website, an attacked could potentially exploit
this to cause a denial of service via renderer crash or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-7904)
Multiple use-after-frees were discovered in Blink. If a user were tricked
in to opening a specially crafted website, an attacked could potentially
exploit these to cause a denial of service via renderer crash or execute
arbitrary code with the privileges of the sandboxed render process.
(CVE-2014-7907)
An integer overflow was discovered in media. If a user were tricked in to
opening a specially crafted website, an attacked could potentially exploit
this to cause a denial of
OSV
CVE-2014-7908: Multiple integer overflows in the CheckMov function in media/base/container_names
osv·2014-11-19·CVSS 7.5
CVE-2014-7908 [HIGH] CVE-2014-7908: Multiple integer overflows in the CheckMov function in media/base/container_names
Multiple integer overflows in the CheckMov function in media/base/container_names.cc in Google Chrome before 39.0.2171.65 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a large atom in (1) MPEG-4 or (2) QuickTime .mov data.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1894.htmlhttp://secunia.com/advisories/60194http://secunia.com/advisories/62608http://www.securityfocus.com/bid/71168http://www.securitytracker.com/id/1031241https://chromium.googlesource.com/chromium/src/+/b2006ac87cec58363090e7d5e10d5d9e3bbda9f9https://code.google.com/p/chromium/issues/detail?id=425980https://exchange.xforce.ibmcloud.com/vulnerabilities/98796http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1894.htmlhttp://secunia.com/advisories/60194http://secunia.com/advisories/62608http://www.securityfocus.com/bid/71168http://www.securitytracker.com/id/1031241https://chromium.googlesource.com/chromium/src/+/b2006ac87cec58363090e7d5e10d5d9e3bbda9f9https://code.google.com/p/chromium/issues/detail?id=425980https://exchange.xforce.ibmcloud.com/vulnerabilities/98796
2014-11-19
Published