« Volver al listado

CVE-2014-3190

Estado: ModificadaAlta (7.5)—

Use-after-free vulnerability in the Event::currentTarget function in core/events/Event.cpp in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code that accesses the path property of an Event object.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-3190",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "chrome-cve-admin@google.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-10-08T10:55:06.347",
  "references": [
    {
      "url": "http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2014-1626.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/70273",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "https://crbug.com/400476",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "https://src.chromium.org/viewvc/blink?revision=181234&view=revision",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2014-1626.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/70273",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://crbug.com/400476",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://src.chromium.org/viewvc/blink?revision=181234&view=revision",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Use-after-free vulnerability in the Event::currentTarget function in core/events/Event.cpp in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code that accesses the path property of an Event object."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de uso después de liberación en la función Event::currentTarget en core/events/Event.cpp en Blink, utilizado en Google Chrome anterior a 38.0.2125.101, permite a atacantes remotos causar una denegación de servicio (caída de la aplicación) o posiblemente tener otro impacto no especificado a través de código JavaScript manipulado que accede a la propiedad de ruta de un objeto Event."
    }
  ],
  "lastModified": "2026-06-17T00:07:45.967",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "49217EEC-AE40-4FBD-A5D4-B4A323CD5645",
              "versionEndIncluding": "38.0.2125.7"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_desktop_supplementary:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8C6E104-EDBC-481E-85B8-D39ED2058D39"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_supplementary:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B74C62D-4A6D-4A4F-ADF6-A508322CD447"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_supplementary_eus:6.6.z:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "04A2B180-08EF-4BE1-B1F2-48782874D6DB"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_workstation_supplementary:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E89B38A-3697-46DD-BB3F-E8D2373588BE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "<a href=\"http://cwe.mitre.org/data/definitions/416.html\">CWE-416: Use After Free</a>",
  "sourceIdentifier": "chrome-cve-admin@google.com"
}