CVE-2014-7909
published 2014-11-19CVE-2014-7909: effects/SkDashPathEffect.cpp in Skia, as used in Google Chrome before 39.0.2171.65, computes a hash key using uninitialized integer values, which might allow…
PriorityP420medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.62%
73.7th percentile
effects/SkDashPathEffect.cpp in Skia, as used in Google Chrome before 39.0.2171.65, computes a hash key using uninitialized integer values, which might allow remote attackers to cause a denial of service by rendering crafted data.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 39.0.2171.45 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2014-11-19·CVSS 7.5
CVE-2014-7904 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
A buffer overflow was discovered in Skia. If a user were tricked in to
opening a specially crafted website, an attacked could potentially exploit
this to cause a denial of service via renderer crash or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-7904)
Multiple use-after-frees were discovered in Blink. If a user were tricked
in to opening a specially crafted website, an attacked could potentially
exploit these to cause a denial of service via renderer crash or execute
arbitrary code with the privileges of the sandboxed render process.
(CVE-2014-7907)
An integer overflow was discovered in media. If a user were tricked in to
opening a specially crafted website, an a
Red Hat
chromium-browser: Uninitialized memory read in Skia
vendor_redhat·2014-11-18·CVSS 5.0
CVE-2014-7909 [MEDIUM] chromium-browser: Uninitialized memory read in Skia
chromium-browser: Uninitialized memory read in Skia
effects/SkDashPathEffect.cpp in Skia, as used in Google Chrome before 39.0.2171.65, computes a hash key using uninitialized integer values, which might allow remote attackers to cause a denial of service by rendering crafted data.
Statement: This issue did not affect the versions of librsvg2 as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: librsvg2 (Red Hat Enterprise Linux 5) - Not affected
Package: librsvg2 (Red Hat Enterprise Linux 6) - Not affected
Package: librsvg2 (Red Hat Enterprise Linux 7) - Not affected
GHSA
GHSA-cqvp-fwwj-jf77: effects/SkDashPathEffect
ghsa_unreviewed·2022-05-17
CVE-2014-7909 [MEDIUM] GHSA-cqvp-fwwj-jf77: effects/SkDashPathEffect
effects/SkDashPathEffect.cpp in Skia, as used in Google Chrome before 39.0.2171.65, computes a hash key using uninitialized integer values, which might allow remote attackers to cause a denial of service by rendering crafted data.
OSV
CVE-2014-7909: effects/SkDashPathEffect
osv·2014-11-19·CVSS 5.0
CVE-2014-7909 [MEDIUM] CVE-2014-7909: effects/SkDashPathEffect
effects/SkDashPathEffect.cpp in Skia, as used in Google Chrome before 39.0.2171.65, computes a hash key using uninitialized integer values, which might allow remote attackers to cause a denial of service by rendering crafted data.
OSV
oxide-qt vulnerabilities
osv·2014-11-19·CVSS 7.5
CVE-2014-7904 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
A buffer overflow was discovered in Skia. If a user were tricked in to
opening a specially crafted website, an attacked could potentially exploit
this to cause a denial of service via renderer crash or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-7904)
Multiple use-after-frees were discovered in Blink. If a user were tricked
in to opening a specially crafted website, an attacked could potentially
exploit these to cause a denial of service via renderer crash or execute
arbitrary code with the privileges of the sandboxed render process.
(CVE-2014-7907)
An integer overflow was discovered in media. If a user were tricked in to
opening a specially crafted website, an attacked could potentially exploit
this to cause a denial of
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1894.htmlhttp://secunia.com/advisories/60194http://secunia.com/advisories/62608http://www.securityfocus.com/bid/71167http://www.securitytracker.com/id/1031241https://code.google.com/p/chromium/issues/detail?id=391001https://exchange.xforce.ibmcloud.com/vulnerabilities/98797https://skia.googlesource.com/skia/+/1c577cd3ee331944b9061ee0eec147b211ee563chttp://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1894.htmlhttp://secunia.com/advisories/60194http://secunia.com/advisories/62608http://www.securityfocus.com/bid/71167http://www.securitytracker.com/id/1031241https://code.google.com/p/chromium/issues/detail?id=391001https://exchange.xforce.ibmcloud.com/vulnerabilities/98797https://skia.googlesource.com/skia/+/1c577cd3ee331944b9061ee0eec147b211ee563c
2014-11-19
Published