4.3
CVSSv2

CVE-2014-7939

Published: 22/01/2015 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Google Chrome prior to 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote malicious users to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an "X-Content-Type-Options: nosniff" header.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

chromium chromium 40.0.2214.110

redhat enterprise linux desktop supplementary 6.0

redhat enterprise linux server supplementary 6.0

redhat enterprise linux workstation supplementary 6.0

redhat enterprise linux server supplementary eus 6.6.z

opensuse opensuse 13.1

opensuse opensuse 13.2

Vendor Advisories

Synopsis Important: chromium-browser security update Type/Severity Security Advisory: Important Topic Updated chromium-browser packages that fix multiple security issues are nowavailable for Red Hat Enterprise Linux 6 SupplementaryRed Hat Product Security has rated this update as having Important securityi ...
Google Chrome before 400221491, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxycreate and consolelog calls, related to HTTP responses that lack an "X-Content-Type-Options: nosniff" header ...

Github Repositories

✔️ More than 100 security checks for your Node.js API

Strong Nodejs 💪 Exhaustive checklist to assist in a security review of a Nodejs web service code Focused on Express and Hapi environments The next documents have been using as main references: The SANS SWAT (Securing Web Applications Technologies) checklist The CWE (Common Weakness Enumeration) dictionary Related: ☠️ Awesome Nodejs for penetration tes