7.5
CVSSv2

CVE-2014-3171

Published: 27/08/2014 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Use-after-free vulnerability in the V8 bindings in Blink, as used in Google Chrome prior to 37.0.2062.94, allows remote malicious users to cause a denial of service or possibly have unspecified other impact by leveraging improper use of HashMap add operations instead of HashMap set operations, related to bindings/core/v8/DOMWrapperMap.h and bindings/core/v8/SerializedScriptValue.cpp.

Affected Products

Vendor Product Versions
GoogleChrome37.0.2062.0, 37.0.2062.1, 37.0.2062.2, 37.0.2062.3, 37.0.2062.4, 37.0.2062.5, 37.0.2062.6, 37.0.2062.7, 37.0.2062.8, 37.0.2062.9, 37.0.2062.10, 37.0.2062.11, 37.0.2062.12, 37.0.2062.13, 37.0.2062.14, 37.0.2062.15, 37.0.2062.16, 37.0.2062.17, 37.0.2062.18, 37.0.2062.19, 37.0.2062.20, 37.0.2062.21, 37.0.2062.22, 37.0.2062.23, 37.0.2062.24, 37.0.2062.25, 37.0.2062.26, 37.0.2062.27, 37.0.2062.28, 37.0.2062.29, 37.0.2062.30, 37.0.2062.31, 37.0.2062.32, 37.0.2062.33, 37.0.2062.34, 37.0.2062.35, 37.0.2062.36, 37.0.2062.37, 37.0.2062.39, 37.0.2062.43, 37.0.2062.44, 37.0.2062.45, 37.0.2062.46, 37.0.2062.47, 37.0.2062.48, 37.0.2062.49, 37.0.2062.50, 37.0.2062.51, 37.0.2062.52, 37.0.2062.53, 37.0.2062.54, 37.0.2062.55, 37.0.2062.56, 37.0.2062.57, 37.0.2062.58, 37.0.2062.59, 37.0.2062.60, 37.0.2062.61, 37.0.2062.62, 37.0.2062.63, 37.0.2062.64, 37.0.2062.65, 37.0.2062.66, 37.0.2062.67, 37.0.2062.68, 37.0.2062.69, 37.0.2062.70, 37.0.2062.71, 37.0.2062.72, 37.0.2062.73, 37.0.2062.74, 37.0.2062.75, 37.0.2062.76, 37.0.2062.77, 37.0.2062.78, 37.0.2062.80, 37.0.2062.81, 37.0.2062.89, 37.0.2062.90, 37.0.2062.91, 37.0.2062.92, 37.0.2062.93

Vendor Advisories

Several security issues were fixed in Oxide ...