CVE-2014-7928Out-of-bounds Write in Google Chrome

CWE-197 documents6 sources
Severity
7.5HIGHNVD
EPSS
3.2%
top 13.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 22
Latest updateMay 17

Description

hydrogen.cc in Google V8, as used Google Chrome before 40.0.2214.91, does not properly handle arrays with holes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code that triggers an array copy.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDgoogle/chrome40.0.2214.85

🔴Vulnerability Details

3
GHSA
GHSA-v6wq-m5xf-2r3c: hydrogen2022-05-17
OSV
oxide-qt vulnerabilities2015-01-26
OSV
CVE-2014-7928: hydrogen2015-01-22

📋Vendor Advisories

2
Ubuntu
Oxide vulnerabilities2015-01-26
Red Hat
chromium-browser: memory corruption in V82015-01-21

💬Community

1
Bugzilla
CVE-2014-7928 chromium-browser: memory corruption in V82015-01-23