Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-7939

Опубликовано: 21 янв. 2015
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an "X-Content-Type-Options: nosniff" header.

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1185219chromium-browser: same-origin-bypass in V8

EPSS

Процентиль: 71%
0.00694
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an "X-Content-Type-Options: nosniff" header.

nvd
около 11 лет назад

Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an "X-Content-Type-Options: nosniff" header.

debian
около 11 лет назад

Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 ...

github
больше 3 лет назад

Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an "X-Content-Type-Options: nosniff" header.

EPSS

Процентиль: 71%
0.00694
Низкий

6.8 Medium

CVSS2