PT-2014-8330 · Google+3 · Google Chrome+3

Published

2014-10-19

·

Updated

2024-06-15

·

CVE-2014-7899

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 38.0.2125.101
Description The issue allows remote attackers to spoof the address bar. This can be achieved by placing a blob: substring at the beginning of the URL, followed by the original URI scheme and a long username string.
Recommendations For versions prior to 38.0.2125.101, update to version 38.0.2125.101 or later to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2280
ALT-PU-2014-2430
CVE-2014-7899
OPENSUSE-SU-2014_1626-1
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2014:1894
RHSA-2014_1894

Affected Products

Alt Linux
Google Chrome
Red Hat
Suse