5
CVSSv2

CVE-2014-3198

Published: 08/10/2014 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome prior to 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote malicious users to cause a denial of service (out-of-bounds read) via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

redhat enterprise linux desktop supplementary 6.0

redhat enterprise linux server supplementary 6.0

redhat enterprise linux workstation supplementary 6.0

redhat enterprise linux server supplementary eus 6.6.z

Vendor Advisories

The Instance::HandleInputEvent function in pdf/instancecc in the PDFium component in Google Chrome before 3802125101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors ...