CVE-2015-1346
published 2015-01-22CVE-2015-1346: Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause a denial of service…
PriorityP430high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.17%
63.8th percentile
Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| chromium | chromium | <= 40.0.2214.94 | — |
| chrome | <= 40.0.2214.85 | — | |
| v8 | <= 3.30.33.14 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-67rm-gwjp-2g22: Multiple unspecified vulnerabilities in Google V8 before 3
ghsa_unreviewed·2022-05-17
CVE-2015-1346 [HIGH] GHSA-67rm-gwjp-2g22: Multiple unspecified vulnerabilities in Google V8 before 3
Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
OSV
oxide-qt vulnerabilities
osv·2015-01-26·CVSS 7.5
CVE-2014-7923 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
Several memory corruption bugs were discovered in ICU. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via renderer crash
or execute arbitrary code with the privileges of the sandboxed render
process. (CVE-2014-7923, CVE-2014-7926)
A use-after-free was discovered in the IndexedDB implementation. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via application
crash or execute arbitrary code with the privileges of the user invoking
the program. (CVE-2014-7924)
A use-after free was discovered in the WebAudio implementation in Blink.
If a user were tricked in to opening a specially crafte
OSV
CVE-2015-1346: Multiple unspecified vulnerabilities in Google V8 before 3
osv·2015-01-22·CVSS 7.5
CVE-2015-1346 [HIGH] CVE-2015-1346: Multiple unspecified vulnerabilities in Google V8 before 3
Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2015-01-26·CVSS 7.5
CVE-2014-7923 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
Several memory corruption bugs were discovered in ICU. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via renderer crash
or execute arbitrary code with the privileges of the sandboxed render
process. (CVE-2014-7923, CVE-2014-7926)
A use-after-free was discovered in the IndexedDB implementation. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via application
crash or execute arbitrary code with the privileges of the user invoking
the program. (CVE-2014-7924)
A use-after free was discovered in the WebAudio implementation in Bli
Red Hat
webkitgtk: improper Unicode encoding interpretation (WSA-2015-0001)
vendor_redhat·2015-01-26·CVSS 5.0
CVE-2014-1346 [MEDIUM] webkitgtk: improper Unicode encoding interpretation (WSA-2015-0001)
webkitgtk: improper Unicode encoding interpretation (WSA-2015-0001)
WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, does not properly interpret Unicode encoding, which allows remote attackers to spoof a postMessage origin, and bypass intended restrictions on sending a message to a connected frame or window, via crafted characters in a URL.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Will not fix
Red Hat
chromium-browser: unspecified vulnerability in Google V8
vendor_redhat·2015-01-21·CVSS 7.5
CVE-2015-1346 [HIGH] chromium-browser: unspecified vulnerability in Google V8
chromium-browser: unspecified vulnerability in Google V8
Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-1346 webkitgtk: improper Unicode encoding interpretation (WSA-2015-0001)
bugzilla·2015-01-27·CVSS 5.0
CVE-2014-1346 [MEDIUM] CVE-2014-1346 webkitgtk: improper Unicode encoding interpretation (WSA-2015-0001)
CVE-2014-1346 webkitgtk: improper Unicode encoding interpretation (WSA-2015-0001)
Following vulnerability was discovered on the 2.4 stable series of WebKitGTK+:
CVE-2014-1346
WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, does not properly interpret Unicode encoding, which allows remote attackers to spoof a postMessage origin, and bypass intended restrictions on sending a message to a connected frame or window, via crafted characters in a URL.
External References:
http://webkitgtk.org/security/WSA-2015-0001.html
Discussion:
Statement:
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https:/
Bugzilla
CVE-2015-1346 chromium-browser: unspecified vulnerability in Google V8
bugzilla·2015-01-23·CVSS 7.5
CVE-2015-1346 [HIGH] CVE-2015-1346 chromium-browser: unspecified vulnerability in Google V8
CVE-2015-1346 chromium-browser: unspecified vulnerability in Google V8
Common Vulnerabilities and Exposures assigned an identifier CVE-2015-1346 to the following vulnerability:
Name: CVE-2015-1346
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1346
Assigned: 20150122
Reference: http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15,
as used in Google Chrome before 40.0.2214.91, allow attackers to cause
a denial of service or possibly have other impact via unknown vectors.
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
http://googlechromereleases.blogspot.com/2015/01/stable-update.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0093.htmlhttp://secunia.com/advisories/62383http://secunia.com/advisories/62575http://security.gentoo.org/glsa/glsa-201502-13.xmlhttp://www.securitytracker.com/id/1031623http://www.ubuntu.com/usn/USN-2476-1https://exchange.xforce.ibmcloud.com/vulnerabilities/100361http://googlechromereleases.blogspot.com/2015/01/stable-update.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0093.htmlhttp://secunia.com/advisories/62383http://secunia.com/advisories/62575http://security.gentoo.org/glsa/glsa-201502-13.xmlhttp://www.securitytracker.com/id/1031623http://www.ubuntu.com/usn/USN-2476-1https://exchange.xforce.ibmcloud.com/vulnerabilities/100361
2015-01-22
Published