CVE-2014-7941Improper Restriction of Operations within the Bounds of a Memory Buffer in Google Chrome

Severity
5.0MEDIUMNVD
EPSS
2.3%
top 15.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 22
Latest updateMay 14

Description

The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 uses an incorrect data type for a certain length value, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted X11 data.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages5 packages

Also affects: Enterprise Linux 6.0, 6.6.z

🔴Vulnerability Details

3
GHSA
GHSA-6877-256j-g6q4: The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner2022-05-14
CVEList
CVE-2014-7941: The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner2015-01-22
OSV
CVE-2014-7941: The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner2015-01-22

📋Vendor Advisories

1
Red Hat
chromium-browser: out-of-bounds read in UI2015-01-21

💬Community

1
Bugzilla
CVE-2014-7941 chromium-browser: out-of-bounds read in UI2015-01-23
CVE-2014-7941 — Google Chrome vulnerability | cvebase