CVE-2014-3190

EUVD-2014-3208
Use-after-free vulnerability in the Event::currentTarget function in core/events/Event.cpp in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code that accesses the path property of an Event object.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
Affected Products (NVD)
VendorProductVersion
googlechrome
𝑥
≤ 38.0.2125.7
redhatenterprise_linux_desktop_supplementary
6.0
redhatenterprise_linux_server_supplementary
6.0
redhatenterprise_linux_server_supplementary_eus
6.6.z:z
redhatenterprise_linux_workstation_supplementary
6.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
lucid
ignored
precise
ignored
trusty
Fixed 38.0.2125.111-0ubuntu0.14.04.1.1061
released
utopic
Fixed 38.0.2125.111-0ubuntu0.14.10.1.1103
released
vivid
Fixed 38.0.2125.111-0ubuntu1.1103
released
wily
Fixed 38.0.2125.111-0ubuntu1.1103
released
oxide-qt
lucid
dne
precise
dne
trusty
Fixed 1.2.5-0ubuntu0.14.04.1
released
utopic
Fixed 1.2.5-0ubuntu1
released
vivid
Fixed 1.2.5-0ubuntu1
released
wily
Fixed 1.2.5-0ubuntu1
released