CVE-2014-7909Google Chrome vulnerability

CWE-1897 documents6 sources
Severity
5.0MEDIUMNVD
OSV7.5
EPSS
1.4%
top 19.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 19
Latest updateMay 17

Description

effects/SkDashPathEffect.cpp in Skia, as used in Google Chrome before 39.0.2171.65, computes a hash key using uninitialized integer values, which might allow remote attackers to cause a denial of service by rendering crafted data.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDgoogle/chrome39.0.2171.45

🔴Vulnerability Details

3
GHSA
GHSA-cqvp-fwwj-jf77: effects/SkDashPathEffect2022-05-17
OSV
CVE-2014-7909: effects/SkDashPathEffect2014-11-19
OSV
oxide-qt vulnerabilities2014-11-19

📋Vendor Advisories

2
Ubuntu
Oxide vulnerabilities2014-11-19
Red Hat
chromium-browser: Uninitialized memory read in Skia2014-11-18

💬Community

1
Bugzilla
CVE-2014-7909 chromium-browser: Uninitialized memory read in Skia2014-11-19