Action not permitted
Modal body text goes here.
Modal Title
Modal Body
CVE-2014-3160 (GCVE-0-2014-3160)
Vulnerability from cvelistv5 – Published: 2014-07-20 10:00 – Updated: 2024-08-06 10:35- n/a
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/68677 | vdb-entryx_refsource_BID |
| https://src.chromium.org/viewvc/blink?revision=17… | x_refsource_CONFIRM |
| http://security.gentoo.org/glsa/glsa-201408-16.xml | vendor-advisoryx_refsource_GENTOO |
| http://secunia.com/advisories/60372 | third-party-advisoryx_refsource_SECUNIA |
| http://googlechromereleases.blogspot.com/2014/07/… | x_refsource_CONFIRM |
| http://secunia.com/advisories/60061 | third-party-advisoryx_refsource_SECUNIA |
| http://www.debian.org/security/2014/dsa-3039 | vendor-advisoryx_refsource_DEBIAN |
| https://code.google.com/p/chromium/issues/detail?… | x_refsource_CONFIRM |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T10:35:56.778Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "68677",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/68677"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://src.chromium.org/viewvc/blink?revision=176084\u0026view=revision"
},
{
"name": "GLSA-201408-16",
"tags": [
"vendor-advisory",
"x_refsource_GENTOO",
"x_transferred"
],
"url": "http://security.gentoo.org/glsa/glsa-201408-16.xml"
},
{
"name": "60372",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/60372"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://googlechromereleases.blogspot.com/2014/07/stable-channel-update.html"
},
{
"name": "60061",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/60061"
},
{
"name": "DSA-3039",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN",
"x_transferred"
],
"url": "http://www.debian.org/security/2014/dsa-3039"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://code.google.com/p/chromium/issues/detail?id=380885"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2014-07-16T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-01-04T20:57:01.000Z",
"orgId": "ebfee0ef-53dd-4cf3-9e2a-08a5bd7a7e28",
"shortName": "Chrome"
},
"references": [
{
"name": "68677",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/68677"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://src.chromium.org/viewvc/blink?revision=176084\u0026view=revision"
},
{
"name": "GLSA-201408-16",
"tags": [
"vendor-advisory",
"x_refsource_GENTOO"
],
"url": "http://security.gentoo.org/glsa/glsa-201408-16.xml"
},
{
"name": "60372",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/60372"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://googlechromereleases.blogspot.com/2014/07/stable-channel-update.html"
},
{
"name": "60061",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/60061"
},
{
"name": "DSA-3039",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN"
],
"url": "http://www.debian.org/security/2014/dsa-3039"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://code.google.com/p/chromium/issues/detail?id=380885"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "security@google.com",
"ID": "CVE-2014-3160",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "68677",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/68677"
},
{
"name": "https://src.chromium.org/viewvc/blink?revision=176084\u0026view=revision",
"refsource": "CONFIRM",
"url": "https://src.chromium.org/viewvc/blink?revision=176084\u0026view=revision"
},
{
"name": "GLSA-201408-16",
"refsource": "GENTOO",
"url": "http://security.gentoo.org/glsa/glsa-201408-16.xml"
},
{
"name": "60372",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/60372"
},
{
"name": "http://googlechromereleases.blogspot.com/2014/07/stable-channel-update.html",
"refsource": "CONFIRM",
"url": "http://googlechromereleases.blogspot.com/2014/07/stable-channel-update.html"
},
{
"name": "60061",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/60061"
},
{
"name": "DSA-3039",
"refsource": "DEBIAN",
"url": "http://www.debian.org/security/2014/dsa-3039"
},
{
"name": "https://code.google.com/p/chromium/issues/detail?id=380885",
"refsource": "CONFIRM",
"url": "https://code.google.com/p/chromium/issues/detail?id=380885"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ebfee0ef-53dd-4cf3-9e2a-08a5bd7a7e28",
"assignerShortName": "Chrome",
"cveId": "CVE-2014-3160",
"datePublished": "2014-07-20T10:00:00.000Z",
"dateReserved": "2014-05-03T00:00:00.000Z",
"dateUpdated": "2024-08-06T10:35:56.778Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1",
"vulnerability-lookup:meta": {
"epss": {
"cve": "CVE-2014-3160",
"date": "2026-10-03",
"epss": "0.01343",
"percentile": "0.70406"
}
}
}
BDU:2015-00243 (CVE-2014-3160)
Vulnerability from fstec – Published: 2016-07-06 – Updated: 2017-10-06 – View on bdu.fstec.ru Fixed- CWE-264 - Разрешения, привилегии и средства управления доступом
{
"CVSS 2.0": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS 3.0": null,
"CVSS 4.0": null,
"remediation_\u0418\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440": null,
"remediation_\u041d\u0430\u0438\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u0438\u0435": null,
"\u0412\u0435\u043d\u0434\u043e\u0440 \u041f\u041e": "Google Inc",
"\u0412\u0435\u0440\u0441\u0438\u044f \u041f\u041e": "\u043e\u0442 31.0 \u0434\u043e 36.0.1985.125 (Google Chrome)",
"\u0412\u043e\u0437\u043c\u043e\u0436\u043d\u044b\u0435 \u043c\u0435\u0440\u044b \u043f\u043e \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044e": "\u0414\u043b\u044f \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u044e\u044e \u0432\u0435\u0440\u0441\u0438\u044e \u043f\u0440\u043e\u0434\u0443\u043a\u0442\u0430, \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0443\u044e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u0435. \u041d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u0443\u044e \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043c\u043e\u0436\u043d\u043e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u043e \u0430\u0434\u0440\u0435\u0441\u0443:\nhttp://www.google.com/chrome/",
"\u0414\u0430\u0442\u0430 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f": "20.07.2014",
"\u0414\u0430\u0442\u0430 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0435\u0433\u043e \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f": "06.10.2017",
"\u0414\u0430\u0442\u0430 \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u0438": "06.07.2016",
"\u0418\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440": "BDU:2015-00243",
"\u0418\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440\u044b \u0434\u0440\u0443\u0433\u0438\u0445 \u0441\u0438\u0441\u0442\u0435\u043c \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "CVE-2014-3160",
"\u0418\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e\u0431 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0438": "\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430",
"\u041a\u043b\u0430\u0441\u0441 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043a\u043e\u0434\u0430",
"\u041d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 \u041f\u041e": "Google Chrome",
"\u041d\u0430\u0438\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u0438\u0435 \u041e\u0421 \u0438 \u0442\u0438\u043f \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b": "\u0421\u043e\u043e\u0431\u0449\u0435\u0441\u0442\u0432\u043e \u0441\u0432\u043e\u0431\u043e\u0434\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u043e\u0433\u043e \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f Linux . 64-bit, \u0421\u043e\u043e\u0431\u0449\u0435\u0441\u0442\u0432\u043e \u0441\u0432\u043e\u0431\u043e\u0434\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u043e\u0433\u043e \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f Linux . 32-bit, Apple Inc. MacOS 10 32-bit, \u0421\u043e\u043e\u0431\u0449\u0435\u0441\u0442\u0432\u043e \u0441\u0432\u043e\u0431\u043e\u0434\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u043e\u0433\u043e \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f Linux . PowerPC, Microsoft Corp Windows - 64-bit, Microsoft Corp Windows - 32-bit, Apple Inc. MacOS 10 64-bit, Apple Inc. MacOS 10 PowerPC",
"\u041d\u0430\u0438\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0430 Google Chrome, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0443\u0434\u0430\u043b\u0435\u043d\u043d\u043e\u043c\u0443 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0443 \u043d\u0430\u0440\u0443\u0448\u0438\u0442\u044c \u043a\u043e\u043d\u0444\u0438\u0434\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u044c, \u0446\u0435\u043b\u043e\u0441\u0442\u043d\u043e\u0441\u0442\u044c \u0438 \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u043e\u0441\u0442\u044c \u0437\u0430\u0449\u0438\u0449\u0430\u0435\u043c\u043e\u0439 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438",
"\u041d\u0430\u043b\u0438\u0447\u0438\u0435 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430": "\u0414\u0430\u043d\u043d\u044b\u0435 \u0443\u0442\u043e\u0447\u043d\u044f\u044e\u0442\u0441\u044f",
"\u041e\u043f\u0438\u0441\u0430\u043d\u0438\u0435 \u043e\u0448\u0438\u0431\u043a\u0438 CWE": "\u0420\u0430\u0437\u0440\u0435\u0448\u0435\u043d\u0438\u044f, \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0438 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430 \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u043e\u043c (CWE-264)",
"\u041e\u043f\u0438\u0441\u0430\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u0435\u0442 \u0432 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 ResourceFetcher::canRequest \u0432 core/fetch/ResourceFetcher.cpp \u0432 Blink \u0434\u043b\u044f Google Chrome \u0438\u0437-\u0437\u0430 \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0433\u043e \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u044f \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432 \u0440\u0435\u0441\u0443\u0440\u0441\u043e\u0432, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u044b\u0445 \u0441 SVG-\u0444\u0430\u0439\u043b\u0430\u043c\u0438. \u042d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u044f \u0434\u0430\u043d\u043d\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0430\u043c, \u0434\u0435\u0439\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u043c \u0443\u0434\u0430\u043b\u0435\u043d\u043d\u043e, \u043e\u0431\u043e\u0439\u0442\u0438 \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u044f \u0434\u043e\u043c\u0435\u043d\u0430, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u0441\u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u0444\u0430\u0439\u043b\u044b",
"\u041f\u043e\u0441\u043b\u0435\u0434\u0441\u0442\u0432\u0438\u044f \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": null,
"\u041f\u0440\u043e\u0447\u0430\u044f \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f": null,
"\u0421\u0432\u044f\u0437\u044c \u0441 \u0438\u043d\u0446\u0438\u0434\u0435\u043d\u0442\u0430\u043c\u0438 \u0418\u0411": "\u0414\u0430\u043d\u043d\u044b\u0435 \u0443\u0442\u043e\u0447\u043d\u044f\u044e\u0442\u0441\u044f",
"\u0421\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u0430",
"\u0421\u043f\u043e\u0441\u043e\u0431 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f": "\u0414\u0430\u043d\u043d\u044b\u0435 \u0443\u0442\u043e\u0447\u043d\u044f\u044e\u0442\u0441\u044f",
"\u0421\u043f\u043e\u0441\u043e\u0431 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438": "\u0414\u0430\u043d\u043d\u044b\u0435 \u0443\u0442\u043e\u0447\u043d\u044f\u044e\u0442\u0441\u044f",
"\u0421\u0441\u044b\u043b\u043a\u0438 \u043d\u0430 \u0438\u0441\u0442\u043e\u0447\u043d\u0438\u043a\u0438": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3160",
"\u0421\u0442\u0430\u0442\u0443\u0441 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "\u041f\u043e\u0434\u0442\u0432\u0435\u0440\u0436\u0434\u0435\u043d\u0430 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u0435\u043c",
"\u0422\u0438\u043f \u041f\u041e": "\u041f\u0440\u0438\u043a\u043b\u0430\u0434\u043d\u043e\u0435 \u041f\u041e \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c",
"\u0422\u0438\u043f \u043e\u0448\u0438\u0431\u043a\u0438 CWE": "CWE-264",
"\u0423\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "\u0412\u044b\u0441\u043e\u043a\u0438\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 (\u0431\u0430\u0437\u043e\u0432\u0430\u044f \u043e\u0446\u0435\u043d\u043a\u0430 CVSS 2.0 \u0441\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 7,5)"
}
CERTFR-2014-AVI-327
Vulnerability from certfr_avis - Published: 2014-07-17 - Updated: 2014-07-17
De multiples vulnérabilités ont été corrigées dans Google Chrome. Elles permettent à un attaquant de provoquer un déni de service à distance et un contournement de la politique de sécurité.
Solution
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Chrome versions antérieures à 36.0.1985.125
| Vendor | Product | Description |
|---|
| Title | Publication Time | Tags | |||
|---|---|---|---|---|---|
|
|||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [],
"affected_systems_content": "\u003cP\u003eChrome versions ant\u00e9rieures \u00e0 36.0.1985.125\u003c/P\u003e",
"content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
"cves": [
{
"name": "CVE-2014-3160",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-3160"
},
{
"name": "CVE-2014-3162",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-3162"
}
],
"initial_release_date": "2014-07-17T00:00:00",
"last_revision_date": "2014-07-17T00:00:00",
"links": [],
"reference": "CERTFR-2014-AVI-327",
"revisions": [
{
"description": "version initiale.",
"revision_date": "2014-07-17T00:00:00.000000"
}
],
"risks": [
{
"description": "D\u00e9ni de service \u00e0 distance"
},
{
"description": "Contournement de la politique de s\u00e9curit\u00e9"
}
],
"summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 corrig\u00e9es dans \u003cspan\nclass=\"textit\"\u003eGoogle Chrome\u003c/span\u003e. Elles permettent \u00e0 un attaquant de\nprovoquer un d\u00e9ni de service \u00e0 distance et un contournement de la\npolitique de s\u00e9curit\u00e9.\n",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans Google Chrome",
"vendor_advisories": [
{
"published_at": null,
"title": "Bulletin de s\u00e9curit\u00e9 Google du 17 juillet 2014",
"url": "http://googlechromereleases.blogspot.fr/2014/07/stable-channel-update.html"
}
]
}
FKIE_CVE-2014-3160
Vulnerability from fkie_nvd - Published: 2014-07-20 11:12 - Updated: 2026-06-17 00:07| Vendor | Product | Version | |
|---|---|---|---|
| debian | debian_linux | 7.0 | |
| debian | debian_linux | 8.0 | |
| chrome | 36.0.1985.1 | ||
| chrome | 36.0.1985.2 | ||
| chrome | 36.0.1985.3 | ||
| chrome | 36.0.1985.4 | ||
| chrome | 36.0.1985.5 | ||
| chrome | 36.0.1985.6 | ||
| chrome | 36.0.1985.8 | ||
| chrome | 36.0.1985.12 | ||
| chrome | 36.0.1985.13 | ||
| chrome | 36.0.1985.14 | ||
| chrome | 36.0.1985.15 | ||
| chrome | 36.0.1985.16 | ||
| chrome | 36.0.1985.17 | ||
| chrome | 36.0.1985.18 | ||
| chrome | 36.0.1985.19 | ||
| chrome | 36.0.1985.20 | ||
| chrome | 36.0.1985.21 | ||
| chrome | 36.0.1985.22 | ||
| chrome | 36.0.1985.23 | ||
| chrome | 36.0.1985.24 | ||
| chrome | 36.0.1985.25 | ||
| chrome | 36.0.1985.26 | ||
| chrome | 36.0.1985.27 | ||
| chrome | 36.0.1985.28 | ||
| chrome | 36.0.1985.29 | ||
| chrome | 36.0.1985.30 | ||
| chrome | 36.0.1985.31 | ||
| chrome | 36.0.1985.32 | ||
| chrome | 36.0.1985.33 | ||
| chrome | 36.0.1985.34 | ||
| chrome | 36.0.1985.35 | ||
| chrome | 36.0.1985.36 | ||
| chrome | 36.0.1985.37 | ||
| chrome | 36.0.1985.38 | ||
| chrome | 36.0.1985.39 | ||
| chrome | 36.0.1985.40 | ||
| chrome | 36.0.1985.41 | ||
| chrome | 36.0.1985.42 | ||
| chrome | 36.0.1985.43 | ||
| chrome | 36.0.1985.44 | ||
| chrome | 36.0.1985.45 | ||
| chrome | 36.0.1985.46 | ||
| chrome | 36.0.1985.47 | ||
| chrome | 36.0.1985.48 | ||
| chrome | 36.0.1985.49 | ||
| chrome | 36.0.1985.50 | ||
| chrome | 36.0.1985.51 | ||
| chrome | 36.0.1985.52 | ||
| chrome | 36.0.1985.53 | ||
| chrome | 36.0.1985.54 | ||
| chrome | 36.0.1985.55 | ||
| chrome | 36.0.1985.56 | ||
| chrome | 36.0.1985.57 | ||
| chrome | 36.0.1985.58 | ||
| chrome | 36.0.1985.59 | ||
| chrome | 36.0.1985.60 | ||
| chrome | 36.0.1985.61 | ||
| chrome | 36.0.1985.62 | ||
| chrome | 36.0.1985.63 | ||
| chrome | 36.0.1985.64 | ||
| chrome | 36.0.1985.65 | ||
| chrome | 36.0.1985.66 | ||
| chrome | 36.0.1985.67 | ||
| chrome | 36.0.1985.68 | ||
| chrome | 36.0.1985.69 | ||
| chrome | 36.0.1985.70 | ||
| chrome | 36.0.1985.72 | ||
| chrome | 36.0.1985.73 | ||
| chrome | 36.0.1985.74 | ||
| chrome | 36.0.1985.75 | ||
| chrome | 36.0.1985.76 | ||
| chrome | 36.0.1985.77 | ||
| chrome | 36.0.1985.78 | ||
| chrome | 36.0.1985.79 | ||
| chrome | 36.0.1985.81 | ||
| chrome | 36.0.1985.82 | ||
| chrome | 36.0.1985.83 | ||
| chrome | 36.0.1985.84 | ||
| chrome | 36.0.1985.85 | ||
| chrome | 36.0.1985.86 | ||
| chrome | 36.0.1985.87 | ||
| chrome | 36.0.1985.88 | ||
| chrome | 36.0.1985.89 | ||
| chrome | 36.0.1985.90 | ||
| chrome | 36.0.1985.91 | ||
| chrome | 36.0.1985.92 | ||
| chrome | 36.0.1985.93 | ||
| chrome | 36.0.1985.94 | ||
| chrome | 36.0.1985.95 | ||
| chrome | 36.0.1985.96 | ||
| chrome | 36.0.1985.97 | ||
| chrome | 36.0.1985.98 | ||
| chrome | 36.0.1985.99 | ||
| chrome | 36.0.1985.100 | ||
| chrome | 36.0.1985.101 | ||
| chrome | 36.0.1985.102 | ||
| chrome | 36.0.1985.103 | ||
| chrome | 36.0.1985.104 | ||
| chrome | 36.0.1985.105 | ||
| chrome | 36.0.1985.106 | ||
| chrome | 36.0.1985.122 | ||
| chrome | 36.0.1985.123 | ||
| chrome | 36.0.1985.124 |
{
"affected": [
{
"affectedData": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"source": "chrome-cve-admin@google.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*",
"matchCriteriaId": "16F59A04-14CF-49E2-9973-645477EA09DA",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"matchCriteriaId": "C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.1:*:*:*:*:*:*:*",
"matchCriteriaId": "034EBC36-A9CF-4606-A08F-7159AB86AFCE",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.2:*:*:*:*:*:*:*",
"matchCriteriaId": "BB5738B3-6465-4AF4-A7FA-103FED812F56",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.3:*:*:*:*:*:*:*",
"matchCriteriaId": "188511A2-3516-4993-982D-923ECA1A4C25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.4:*:*:*:*:*:*:*",
"matchCriteriaId": "8CED7E89-3559-439D-8840-B68C01C8D5E0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.5:*:*:*:*:*:*:*",
"matchCriteriaId": "CDC37763-EB39-49BF-9DE8-1E1FE3278A0E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.6:*:*:*:*:*:*:*",
"matchCriteriaId": "E5FB6B01-3610-447D-8F80-BCF45AA8774A",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.8:*:*:*:*:*:*:*",
"matchCriteriaId": "C0BC651A-0811-46DB-B3E2-06574DFCEA77",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.12:*:*:*:*:*:*:*",
"matchCriteriaId": "663584A3-7E9A-4A85-A6FD-139A4901CE0A",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.13:*:*:*:*:*:*:*",
"matchCriteriaId": "C77F9F75-A405-48B0-B4B1-CBEA993EC127",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.14:*:*:*:*:*:*:*",
"matchCriteriaId": "D8E0C87F-44BB-44E0-8D3B-90E77FA97923",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.15:*:*:*:*:*:*:*",
"matchCriteriaId": "CF831B62-3FA4-4AAB-93C5-94C90E09C0D5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.16:*:*:*:*:*:*:*",
"matchCriteriaId": "23CE59C5-6330-4022-9071-D2B1F2C9743B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.17:*:*:*:*:*:*:*",
"matchCriteriaId": "0E349413-FC94-4C7C-831B-AD19E660AAEF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.18:*:*:*:*:*:*:*",
"matchCriteriaId": "DFE28FF7-EACE-474F-8AB1-897C9515D8CC",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.19:*:*:*:*:*:*:*",
"matchCriteriaId": "7411454F-7C8A-4ADB-8F1E-F24F38CC475B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.20:*:*:*:*:*:*:*",
"matchCriteriaId": "C5E38BA8-A312-4374-BA95-095A6C581177",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.21:*:*:*:*:*:*:*",
"matchCriteriaId": "2BCB94DC-B29A-4DE2-8DD7-8027144E9160",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.22:*:*:*:*:*:*:*",
"matchCriteriaId": "289B4894-C04B-42B9-AF34-6F6C3283B92F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.23:*:*:*:*:*:*:*",
"matchCriteriaId": "BAFFBA9E-7B85-498B-ABFC-C1E9FA3E7957",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.24:*:*:*:*:*:*:*",
"matchCriteriaId": "4775EFA0-72D0-40C3-9C57-82719F1E787F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.25:*:*:*:*:*:*:*",
"matchCriteriaId": "F1543632-8553-4B11-8C52-040D9B789D72",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.26:*:*:*:*:*:*:*",
"matchCriteriaId": "BB77631C-E246-4297-A3DF-8C65C7764447",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.27:*:*:*:*:*:*:*",
"matchCriteriaId": "3E4FD7BE-8EF5-4695-9FDE-56E0AEB537A3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.28:*:*:*:*:*:*:*",
"matchCriteriaId": "9D496614-D271-4BDB-9970-113DAD4BD831",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.29:*:*:*:*:*:*:*",
"matchCriteriaId": "8636C621-F6A9-4AE7-BB02-0318BF1DD8B4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.30:*:*:*:*:*:*:*",
"matchCriteriaId": "FBCA4077-F5C9-43D2-9199-944C89633552",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.31:*:*:*:*:*:*:*",
"matchCriteriaId": "DE15A42D-F019-4F64-8A0F-C0EAEFCF35E2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.32:*:*:*:*:*:*:*",
"matchCriteriaId": "3277E700-A60B-48A4-96D5-AE9A154EC3B1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.33:*:*:*:*:*:*:*",
"matchCriteriaId": "2C34880E-02B2-4FA2-A3CE-CD6B57870703",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.34:*:*:*:*:*:*:*",
"matchCriteriaId": "122EBB89-8BB8-42EE-BD7E-BA8A6D78FCA8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.35:*:*:*:*:*:*:*",
"matchCriteriaId": "09CCBBF4-002D-4020-BF73-02FC4783014B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.36:*:*:*:*:*:*:*",
"matchCriteriaId": "9341B2CC-90C5-403D-A6BD-C5D6CB668DF0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.37:*:*:*:*:*:*:*",
"matchCriteriaId": "BE485EA9-4E47-46E5-9E36-F023FA4552B4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.38:*:*:*:*:*:*:*",
"matchCriteriaId": "9C23AD90-B066-40AB-9015-CB27319F5DC8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.39:*:*:*:*:*:*:*",
"matchCriteriaId": "23BA1D89-E3F1-45A9-BDBE-116217FA564E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.40:*:*:*:*:*:*:*",
"matchCriteriaId": "01BD5F1D-1BA1-4993-8A25-393D22229C43",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.41:*:*:*:*:*:*:*",
"matchCriteriaId": "C18A686D-1176-45E1-8BB6-FBFD7EB8125D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.42:*:*:*:*:*:*:*",
"matchCriteriaId": "E77A0160-6D9B-4F31-A3E9-326D47861BD7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.43:*:*:*:*:*:*:*",
"matchCriteriaId": "5D6BB6E3-50DD-49AF-BAD5-8D6B882EC8FF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.44:*:*:*:*:*:*:*",
"matchCriteriaId": "34110090-4076-4F54-B725-6E7FDF8B9AE2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.45:*:*:*:*:*:*:*",
"matchCriteriaId": "641A7CED-5A5B-4234-B457-7D25D9803798",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.46:*:*:*:*:*:*:*",
"matchCriteriaId": "FB8D94F8-532B-442D-AF36-43ADAA29C3EF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.47:*:*:*:*:*:*:*",
"matchCriteriaId": "8A4CB7E6-F4C8-438B-8A0A-72725C4FAAA4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.48:*:*:*:*:*:*:*",
"matchCriteriaId": "336A4169-DE67-4F47-B48B-6FED2FF836BC",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.49:*:*:*:*:*:*:*",
"matchCriteriaId": "D85A3544-3B3A-4C09-A5AD-19C76D50B543",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.50:*:*:*:*:*:*:*",
"matchCriteriaId": "4275E418-3339-4DB8-B1D3-843E233475CB",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.51:*:*:*:*:*:*:*",
"matchCriteriaId": "A9BFCF28-7B2E-4542-B10F-48E107944167",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.52:*:*:*:*:*:*:*",
"matchCriteriaId": "C67843B6-5F11-43F2-AFA8-0525C52D4ACE",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.53:*:*:*:*:*:*:*",
"matchCriteriaId": "707F90CE-9315-4307-8FFD-86E2466731A6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.54:*:*:*:*:*:*:*",
"matchCriteriaId": "41D30577-22E1-48A4-A9F6-FA9AB1E3EEFD",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.55:*:*:*:*:*:*:*",
"matchCriteriaId": "DBBA976C-1225-4BD3-B5AF-C56367B2675A",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.56:*:*:*:*:*:*:*",
"matchCriteriaId": "53D869C6-B72F-4CAB-A61E-2A339AA37BDF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.57:*:*:*:*:*:*:*",
"matchCriteriaId": "4A6FCCCE-2134-4FCC-8B69-1538D232CF8E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.58:*:*:*:*:*:*:*",
"matchCriteriaId": "8E63561C-7674-4261-89B6-9DAC97166BAE",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.59:*:*:*:*:*:*:*",
"matchCriteriaId": "81797436-C14E-4D73-BCE8-D174F3AFD47F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.60:*:*:*:*:*:*:*",
"matchCriteriaId": "8AB3BBF3-6667-4C1E-8A44-53BA9ADE390D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.61:*:*:*:*:*:*:*",
"matchCriteriaId": "C9A52C40-FECD-4DFE-A6FF-5834201F2086",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.62:*:*:*:*:*:*:*",
"matchCriteriaId": "AD6DEE24-CD3C-416D-9FA1-0A3284C7155E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.63:*:*:*:*:*:*:*",
"matchCriteriaId": "EA359EE0-5047-4A22-B352-88FE56EC4A6D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.64:*:*:*:*:*:*:*",
"matchCriteriaId": "4ACB01CD-69F8-4133-B0C8-88C667AF77E5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.65:*:*:*:*:*:*:*",
"matchCriteriaId": "CEE6A128-59E6-4728-B5C6-4BF1813D4C40",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.66:*:*:*:*:*:*:*",
"matchCriteriaId": "5E8D8C88-B0DC-40B6-9388-E175041D8E96",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.67:*:*:*:*:*:*:*",
"matchCriteriaId": "3C96219D-2840-4C31-8C29-8763CF8EA1D0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.68:*:*:*:*:*:*:*",
"matchCriteriaId": "3286D039-6014-453E-8DE6-EF4EC041B3FB",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.69:*:*:*:*:*:*:*",
"matchCriteriaId": "EB694F99-6E1E-46C5-BAB3-6319ADF4191D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.70:*:*:*:*:*:*:*",
"matchCriteriaId": "6B850799-6FA4-427A-B496-373AA97BE924",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.72:*:*:*:*:*:*:*",
"matchCriteriaId": "8344CC6B-620A-4AAD-A3D7-D15254D91442",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.73:*:*:*:*:*:*:*",
"matchCriteriaId": "39E26455-A7E4-4F7E-8C93-A98E531D3421",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.74:*:*:*:*:*:*:*",
"matchCriteriaId": "BDB57BC3-53B7-41D6-8B2F-0621222D9CDF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.75:*:*:*:*:*:*:*",
"matchCriteriaId": "34067661-1C76-43AA-A448-B3598FE76420",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.76:*:*:*:*:*:*:*",
"matchCriteriaId": "4E4ED68C-3156-4286-AF42-964A6BF5CCF5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.77:*:*:*:*:*:*:*",
"matchCriteriaId": "4C487E25-F043-4C84-ADEF-CBBF97A6C294",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.78:*:*:*:*:*:*:*",
"matchCriteriaId": "F78FF9B8-C78F-4A1E-AFB3-46330E2A0EC9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.79:*:*:*:*:*:*:*",
"matchCriteriaId": "0CFBDA89-FB41-496C-A259-E3D0B034674B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.81:*:*:*:*:*:*:*",
"matchCriteriaId": "A6BF5998-676C-4E94-9020-26BD6D5D1780",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.82:*:*:*:*:*:*:*",
"matchCriteriaId": "45E63B35-47C3-46B2-93F5-7564CF6D208F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.83:*:*:*:*:*:*:*",
"matchCriteriaId": "9DD19170-FDD4-41CE-BD56-779A622DF181",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.84:*:*:*:*:*:*:*",
"matchCriteriaId": "E06AD6A4-721C-427F-9B48-77F711DD93C5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.85:*:*:*:*:*:*:*",
"matchCriteriaId": "E8A4C658-D47B-4BC3-890B-CAE400487F9A",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.86:*:*:*:*:*:*:*",
"matchCriteriaId": "16A6D8DE-1428-4B16-B331-02804A36CE38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.87:*:*:*:*:*:*:*",
"matchCriteriaId": "0110A1CE-FDDB-442D-8570-631C540E7893",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.88:*:*:*:*:*:*:*",
"matchCriteriaId": "8913F802-16B1-413F-B506-CDD01EF45254",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.89:*:*:*:*:*:*:*",
"matchCriteriaId": "00FC13E3-B987-4E96-8DE6-1F86C56D3421",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.90:*:*:*:*:*:*:*",
"matchCriteriaId": "8723AA17-560B-4F5F-A2C3-22521C1A6DA5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.91:*:*:*:*:*:*:*",
"matchCriteriaId": "F18EDAA2-D781-4380-9B58-DB56950E5030",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.92:*:*:*:*:*:*:*",
"matchCriteriaId": "CEF5627B-2ACD-4980-8706-EA6A44CACD4E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.93:*:*:*:*:*:*:*",
"matchCriteriaId": "161617EB-3319-4863-8455-3196A10768C6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.94:*:*:*:*:*:*:*",
"matchCriteriaId": "17D4849F-0D38-4883-90C0-92828EA45D37",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.95:*:*:*:*:*:*:*",
"matchCriteriaId": "FA069046-D948-474A-BCAE-447B9149CA32",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.96:*:*:*:*:*:*:*",
"matchCriteriaId": "CFA70EA7-79B2-4762-BF48-464E566D68F8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.97:*:*:*:*:*:*:*",
"matchCriteriaId": "0C41B757-007A-4EE6-B348-D1DD53EE0C3F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.98:*:*:*:*:*:*:*",
"matchCriteriaId": "8B21277A-265E-41B5-BA87-5EC59A37CB19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.99:*:*:*:*:*:*:*",
"matchCriteriaId": "92BB0B75-5563-456D-BC06-5C493F42EFA8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.100:*:*:*:*:*:*:*",
"matchCriteriaId": "F0267B12-C831-49FF-B09D-0F51D7480DF6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.101:*:*:*:*:*:*:*",
"matchCriteriaId": "00978DD0-CEF3-4544-BF55-154F1BFEE7A4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.102:*:*:*:*:*:*:*",
"matchCriteriaId": "35D70A8A-3962-4723-A313-8114F3A3D7CE",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.103:*:*:*:*:*:*:*",
"matchCriteriaId": "8AE52C3A-9E56-4835-AC3B-02356F812805",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.104:*:*:*:*:*:*:*",
"matchCriteriaId": "D43A19BA-BC19-4A01-B7F8-568753ACBD67",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.105:*:*:*:*:*:*:*",
"matchCriteriaId": "4330A8C3-A9C7-4D20-B1E1-B050FE660BE1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.106:*:*:*:*:*:*:*",
"matchCriteriaId": "323B3255-DB94-41B2-AFED-12AA8A8B2EBE",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.122:*:*:*:*:*:*:*",
"matchCriteriaId": "21AF0201-C7F6-4884-939F-81466F0F9FED",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.123:*:*:*:*:*:*:*",
"matchCriteriaId": "266D9AD9-7256-4627-89A1-0DA3389A19CA",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:google:chrome:36.0.1985.124:*:*:*:*:*:*:*",
"matchCriteriaId": "02C1BF3E-264A-4809-87BE-6A00F041DBCE",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file."
},
{
"lang": "es",
"value": "La funci\u00f3n ResourceFetcher::canRequest en core/fetch/ResourceFetcher.cpp en Blink, utilizado en Google Chrome anterior a 36.0.1985.125, no restringe debidamente las solicitudes de subrecursos asociados con ficheros SVG, lo que permite a atacantes remotos evadir Same Origin Policy a trav\u00e9s de un fichero manipulado."
}
],
"id": "CVE-2014-3160",
"lastModified": "2026-06-17T00:07:42.000",
"metrics": {
"cvssMetricV2": [
{
"acInsufInfo": false,
"baseSeverity": "MEDIUM",
"cvssData": {
"accessComplexity": "MEDIUM",
"accessVector": "NETWORK",
"authentication": "NONE",
"availabilityImpact": "PARTIAL",
"baseScore": 6.8,
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"version": "2.0"
},
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"obtainAllPrivilege": false,
"obtainOtherPrivilege": false,
"obtainUserPrivilege": false,
"source": "nvd@nist.gov",
"type": "Primary",
"userInteractionRequired": false
}
]
},
"published": "2014-07-20T11:12:50.243",
"references": [
{
"source": "chrome-cve-admin@google.com",
"url": "http://googlechromereleases.blogspot.com/2014/07/stable-channel-update.html"
},
{
"source": "chrome-cve-admin@google.com",
"url": "http://secunia.com/advisories/60061"
},
{
"source": "chrome-cve-admin@google.com",
"url": "http://secunia.com/advisories/60372"
},
{
"source": "chrome-cve-admin@google.com",
"url": "http://security.gentoo.org/glsa/glsa-201408-16.xml"
},
{
"source": "chrome-cve-admin@google.com",
"url": "http://www.debian.org/security/2014/dsa-3039"
},
{
"source": "chrome-cve-admin@google.com",
"url": "http://www.securityfocus.com/bid/68677"
},
{
"source": "chrome-cve-admin@google.com",
"url": "https://code.google.com/p/chromium/issues/detail?id=380885"
},
{
"source": "chrome-cve-admin@google.com",
"url": "https://src.chromium.org/viewvc/blink?revision=176084\u0026view=revision"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "http://googlechromereleases.blogspot.com/2014/07/stable-channel-update.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "http://secunia.com/advisories/60061"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "http://secunia.com/advisories/60372"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "http://security.gentoo.org/glsa/glsa-201408-16.xml"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "http://www.debian.org/security/2014/dsa-3039"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "http://www.securityfocus.com/bid/68677"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "https://code.google.com/p/chromium/issues/detail?id=380885"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "https://src.chromium.org/viewvc/blink?revision=176084\u0026view=revision"
}
],
"sourceIdentifier": "chrome-cve-admin@google.com",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-264"
}
],
"source": "nvd@nist.gov",
"type": "Primary"
}
]
}
GHSA-RXRQ-C9JP-32RM
Vulnerability from github – Published: 2022-05-17 03:06 – Updated: 2022-05-17 03:06The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file.
{
"affected": [],
"aliases": [
"CVE-2014-3160"
],
"database_specific": {
"cwe_ids": [],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2014-07-20T11:12:00Z",
"severity": "MODERATE"
},
"details": "The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file.",
"id": "GHSA-rxrq-c9jp-32rm",
"modified": "2022-05-17T03:06:08Z",
"published": "2022-05-17T03:06:08Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2014-3160"
},
{
"type": "WEB",
"url": "https://code.google.com/p/chromium/issues/detail?id=380885"
},
{
"type": "WEB",
"url": "https://src.chromium.org/viewvc/blink?revision=176084\u0026view=revision"
},
{
"type": "WEB",
"url": "http://googlechromereleases.blogspot.com/2014/07/stable-channel-update.html"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/60061"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/60372"
},
{
"type": "WEB",
"url": "http://security.gentoo.org/glsa/glsa-201408-16.xml"
},
{
"type": "WEB",
"url": "http://www.debian.org/security/2014/dsa-3039"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/68677"
}
],
"schema_version": "1.4.0",
"severity": []
}
GSD-2014-3160
Vulnerability from gsd - Updated: 2023-12-13 01:22{
"GSD": {
"alias": "CVE-2014-3160",
"description": "The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file.",
"id": "GSD-2014-3160",
"references": [
"https://www.suse.com/security/cve/CVE-2014-3160.html",
"https://www.debian.org/security/2014/dsa-3039",
"https://ubuntu.com/security/CVE-2014-3160"
]
},
"gsd": {
"metadata": {
"exploitCode": "unknown",
"remediation": "unknown",
"reportConfidence": "confirmed",
"type": "vulnerability"
},
"osvSchema": {
"aliases": [
"CVE-2014-3160"
],
"details": "The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file.",
"id": "GSD-2014-3160",
"modified": "2023-12-13T01:22:53.913527Z",
"schema_version": "1.4.0"
}
},
"namespaces": {
"cve.org": {
"CVE_data_meta": {
"ASSIGNER": "security@google.com",
"ID": "CVE-2014-3160",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "68677",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/68677"
},
{
"name": "https://src.chromium.org/viewvc/blink?revision=176084\u0026view=revision",
"refsource": "CONFIRM",
"url": "https://src.chromium.org/viewvc/blink?revision=176084\u0026view=revision"
},
{
"name": "GLSA-201408-16",
"refsource": "GENTOO",
"url": "http://security.gentoo.org/glsa/glsa-201408-16.xml"
},
{
"name": "60372",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/60372"
},
{
"name": "http://googlechromereleases.blogspot.com/2014/07/stable-channel-update.html",
"refsource": "CONFIRM",
"url": "http://googlechromereleases.blogspot.com/2014/07/stable-channel-update.html"
},
{
"name": "60061",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/60061"
},
{
"name": "DSA-3039",
"refsource": "DEBIAN",
"url": "http://www.debian.org/security/2014/dsa-3039"
},
{
"name": "https://code.google.com/p/chromium/issues/detail?id=380885",
"refsource": "CONFIRM",
"url": "https://code.google.com/p/chromium/issues/detail?id=380885"
}
]
}
},
"nvd.nist.gov": {
"configurations": {
"CVE_data_version": "4.0",
"nodes": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.95:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.94:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.87:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.97:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.96:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.89:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.88:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.81:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.8:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.72:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.70:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.63:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.62:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.56:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.55:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.54:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.48:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.47:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.40:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.4:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.32:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.31:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.25:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.24:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.18:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.17:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.104:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.103:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.124:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.99:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.98:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.91:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.90:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.83:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.82:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.74:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.73:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.65:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.64:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.58:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.57:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.5:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.49:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.42:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.41:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.35:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.34:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.33:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.27:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.26:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.2:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.19:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.106:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.105:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.122:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.123:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.86:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.79:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.78:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.77:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.69:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.68:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.61:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.60:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.53:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.52:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.46:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.45:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.39:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.38:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.30:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.3:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.23:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.22:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.16:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.15:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.102:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.101:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.93:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.92:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.85:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.84:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.76:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.75:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.67:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.66:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.6:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.59:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.51:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.50:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.44:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.43:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.37:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.36:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.29:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.28:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.21:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.20:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.14:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.13:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.12:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.100:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:google:chrome:36.0.1985.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
}
]
},
"cve": {
"CVE_data_meta": {
"ASSIGNER": "security@google.com",
"ID": "CVE-2014-3160"
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "en",
"value": "The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "http://googlechromereleases.blogspot.com/2014/07/stable-channel-update.html",
"refsource": "CONFIRM",
"tags": [
"Vendor Advisory"
],
"url": "http://googlechromereleases.blogspot.com/2014/07/stable-channel-update.html"
},
{
"name": "https://code.google.com/p/chromium/issues/detail?id=380885",
"refsource": "CONFIRM",
"tags": [],
"url": "https://code.google.com/p/chromium/issues/detail?id=380885"
},
{
"name": "https://src.chromium.org/viewvc/blink?revision=176084\u0026view=revision",
"refsource": "CONFIRM",
"tags": [
"Patch"
],
"url": "https://src.chromium.org/viewvc/blink?revision=176084\u0026view=revision"
},
{
"name": "DSA-3039",
"refsource": "DEBIAN",
"tags": [],
"url": "http://www.debian.org/security/2014/dsa-3039"
},
{
"name": "68677",
"refsource": "BID",
"tags": [],
"url": "http://www.securityfocus.com/bid/68677"
},
{
"name": "GLSA-201408-16",
"refsource": "GENTOO",
"tags": [],
"url": "http://security.gentoo.org/glsa/glsa-201408-16.xml"
},
{
"name": "60372",
"refsource": "SECUNIA",
"tags": [],
"url": "http://secunia.com/advisories/60372"
},
{
"name": "60061",
"refsource": "SECUNIA",
"tags": [],
"url": "http://secunia.com/advisories/60061"
}
]
}
},
"impact": {
"baseMetricV2": {
"cvssV2": {
"accessComplexity": "MEDIUM",
"accessVector": "NETWORK",
"authentication": "NONE",
"availabilityImpact": "PARTIAL",
"baseScore": 6.8,
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"version": "2.0"
},
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"obtainAllPrivilege": false,
"obtainOtherPrivilege": false,
"obtainUserPrivilege": false,
"severity": "MEDIUM",
"userInteractionRequired": false
}
},
"lastModifiedDate": "2017-01-07T02:59Z",
"publishedDate": "2014-07-20T11:12Z"
}
}
}
OPENSUSE-SU-2024:10171-1
Vulnerability from csaf_opensuse - Published: 2024-06-15 00:00 - Updated: 2026-09-20 19:53OPENSUSE-SU-2024:12948-1
Vulnerability from csaf_opensuse - Published: 2024-06-15 00:00 - Updated: 2026-09-20 20:50UBUNTU-CVE-2014-3160 (CVE-2014-3160)
Vulnerability from osv_ubuntu – Published: 2014-07-20 00:00 – Updated: 2025-09-08 16:43 – Source websiteThe ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file.
| URL | Type | |
|---|---|---|
{
"affected": [
{
"ecosystem_specific": {
"availability": "No subscription required",
"binaries": [
{
"binary_name": "chromium-browser",
"binary_version": "36.0.1985.125-0ubuntu1.14.04.0~pkg1029"
},
{
"binary_name": "chromium-browser-l10n",
"binary_version": "36.0.1985.125-0ubuntu1.14.04.0~pkg1029"
},
{
"binary_name": "chromium-chromedriver",
"binary_version": "36.0.1985.125-0ubuntu1.14.04.0~pkg1029"
},
{
"binary_name": "chromium-codecs-ffmpeg",
"binary_version": "36.0.1985.125-0ubuntu1.14.04.0~pkg1029"
},
{
"binary_name": "chromium-codecs-ffmpeg-extra",
"binary_version": "36.0.1985.125-0ubuntu1.14.04.0~pkg1029"
}
]
},
"package": {
"ecosystem": "Ubuntu:14.04:LTS",
"name": "chromium-browser",
"purl": "pkg:deb/ubuntu/chromium-browser@36.0.1985.125-0ubuntu1.14.04.0~pkg1029?arch=source\u0026distro=trusty"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "36.0.1985.125-0ubuntu1.14.04.0~pkg1029"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"29.0.1547.65-0ubuntu2",
"31.0.1650.63-0ubuntu1~20131204.1",
"32.0.1700.107-0ubuntu1~20140204.977.1",
"33.0.1750.152-0ubuntu1~pkg995.1",
"34.0.1847.116-0ubuntu2"
]
},
{
"ecosystem_specific": {
"availability": "No subscription required",
"binaries": [
{
"binary_name": "liboxideqt-qmlplugin",
"binary_version": "1.0.4-0ubuntu0.14.04.1"
},
{
"binary_name": "liboxideqtcore0",
"binary_version": "1.0.4-0ubuntu0.14.04.1"
},
{
"binary_name": "oxideqmlscene",
"binary_version": "1.0.4-0ubuntu0.14.04.1"
},
{
"binary_name": "oxideqt-codecs",
"binary_version": "1.0.4-0ubuntu0.14.04.1"
},
{
"binary_name": "oxideqt-codecs-extra",
"binary_version": "1.0.4-0ubuntu0.14.04.1"
}
]
},
"package": {
"ecosystem": "Ubuntu:14.04:LTS",
"name": "oxide-qt",
"purl": "pkg:deb/ubuntu/oxide-qt@1.0.4-0ubuntu0.14.04.1?arch=source\u0026distro=trusty"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.0.4-0ubuntu0.14.04.1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.0.0~bzr437-0ubuntu1",
"1.0.0~bzr452-0ubuntu1",
"1.0.0~bzr475-0ubuntu1",
"1.0.0~bzr490-0ubuntu1",
"1.0.0~bzr501-0ubuntu1",
"1.0.0~bzr501-0ubuntu2"
]
}
],
"aliases": [],
"details": "The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file.",
"id": "UBUNTU-CVE-2014-3160",
"modified": "2025-09-08T16:43:09Z",
"published": "2014-07-20T00:00:00Z",
"references": [
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2014-3160"
},
{
"type": "ADVISORY",
"url": "https://ubuntu.com/security/notices/USN-2298-1"
},
{
"type": "REPORT",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-3160"
}
],
"related": [
"USN-2298-1"
],
"schema_version": "1.7.0",
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
],
"upstream": [
"CVE-2014-3160"
]
}
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.