Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-3188

Опубликовано: 08 окт. 2014
Источник: nvd
CVSS2: 10
EPSS Низкий

Описание

Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data, related to improper parsing of an escaped index by ParseJsonObject in json-parser.h.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:google:chrome_os:*:*:*:*:*:*:*:*
Версия до 38.0.2125.77 (включая)
Конфигурация 2
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Версия до 38.0.2125.7 (включая)
Конфигурация 3

Одно из

cpe:2.3:o:redhat:enterprise_linux_desktop_supplementary:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_supplementary:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_supplementary_eus:6.6.z:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation_supplementary:6.0:*:*:*:*:*:*:*

EPSS

Процентиль: 87%
0.03581
Низкий

10 Critical

CVSS2

Дефекты

CWE-94

Связанные уязвимости

ubuntu
больше 11 лет назад

Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data, related to improper parsing of an escaped index by ParseJsonObject in json-parser.h.

redhat
больше 11 лет назад

Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data, related to improper parsing of an escaped index by ParseJsonObject in json-parser.h.

debian
больше 11 лет назад

Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 ...

github
больше 3 лет назад

Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data, related to improper parsing of an escaped index by ParseJsonObject in json-parser.h.

EPSS

Процентиль: 87%
0.03581
Низкий

10 Critical

CVSS2

Дефекты

CWE-94