Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3198

Опубликовано: 07 окт. 2014
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

Дополнительная информация

Статус:

Critical
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1151368chromium: OOB reads in PDFium fixed in Chrome 38.0.2125.101

EPSS

Процентиль: 74%
0.00832
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

nvd
больше 11 лет назад

The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

debian
больше 11 лет назад

The Instance::HandleInputEvent function in pdf/instance.cc in the PDFi ...

github
больше 3 лет назад

The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

EPSS

Процентиль: 74%
0.00832
Низкий

6.8 Medium

CVSS2