5
CVSSv2

CVE-2014-3197

Published: 08/10/2014 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome prior to 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote malicious users to obtain sensitive information via a crafted web site.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

redhat enterprise linux desktop supplementary 6.0

redhat enterprise linux server supplementary 6.0

redhat enterprise linux workstation supplementary 6.0

redhat enterprise linux server supplementary eus 6.6.z

Vendor Advisories

Several security issues were fixed in Oxide ...
The NavigationScheduler::schedulePageBlock function in core/loader/NavigationSchedulercpp in Blink, as used in Google Chrome before 3802125101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attackers to obtain sensitive information via a crafted web site ...