5
CVSSv2

CVE-2014-7941

Published: 22/01/2015 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome prior to 40.0.2214.91 uses an incorrect data type for a certain length value, which allows remote malicious users to cause a denial of service (out-of-bounds read) via crafted X11 data.

Vulnerable Product Search on Vulmon Subscribe to Product

chromium chromium 40.0.2214.110

redhat enterprise linux desktop supplementary 6.0

redhat enterprise linux server supplementary 6.0

redhat enterprise linux workstation supplementary 6.0

redhat enterprise linux server supplementary eus 6.6.z

google chrome

opensuse opensuse 13.1

opensuse opensuse 13.2

Vendor Advisories

Synopsis Important: chromium-browser security update Type/Severity Security Advisory: Important Topic Updated chromium-browser packages that fix multiple security issues are nowavailable for Red Hat Enterprise Linux 6 SupplementaryRed Hat Product Security has rated this update as having Important securityi ...
The SelectionOwner::ProcessTarget function in ui/base/x/selection_ownercc in the UI implementation in Google Chrome before 400221491 uses an incorrect data type for a certain length value, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted X11 data ...