CVE-2014-3197

EUVD-2014-3215
The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attackers to obtain sensitive information via a crafted web site.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
Affected Products (NVD)
VendorProductVersion
googlechrome
𝑥
≤ 38.0.2125.7
redhatenterprise_linux_desktop_supplementary
6.0
redhatenterprise_linux_server_supplementary
6.0
redhatenterprise_linux_server_supplementary_eus
6.6.z:z
redhatenterprise_linux_workstation_supplementary
6.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
lucid
ignored
precise
not-affected
trusty
dne
oxide-qt
lucid
dne
precise
dne
trusty
Fixed 1.2.5-0ubuntu0.14.04.1
released
Common Weakness Enumeration