| Vulnerability Name: | CVE-2014-7939 (CCN-100310) | ||||||||||||||||||||||||||||
| Assigned: | 2014-10-06 | ||||||||||||||||||||||||||||
| Published: | 2015-01-21 | ||||||||||||||||||||||||||||
| Updated: | 2018-10-30 | ||||||||||||||||||||||||||||
| Summary: | Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an "X-Content-Type-Options: nosniff" header. | ||||||||||||||||||||||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
5.0 Medium (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||
| Vulnerability Type: | CWE-264 | ||||||||||||||||||||||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2014-7939 Source: CCN Type: Google Chrome Releases Web site Stable Channel Update Source: CONFIRM Type: Vendor Advisory http://googlechromereleases.blogspot.com/2015/01/stable-update.html Source: SUSE Type: UNKNOWN openSUSE-SU-2015:0441 Source: CCN Type: RHSA-2015-0093 Important: chromium-browser security update Source: REDHAT Type: UNKNOWN RHSA-2015:0093 Source: SECUNIA Type: UNKNOWN 62383 Source: SECUNIA Type: UNKNOWN 62665 Source: GENTOO Type: UNKNOWN GLSA-201502-13 Source: BID Type: UNKNOWN 72288 Source: CCN Type: BID-72288 Google Chrome 40.0.2214.91 Multiple Security Vulnerabilities Source: SECTRACK Type: UNKNOWN 1031623 Source: CONFIRM Type: Vendor Advisory https://code.google.com/p/chromium/issues/detail?id=399951 Source: XF Type: UNKNOWN google-chrome-cve20147939-sec-bypass(100310) Source: CCN Type: WhiteSource Vulnerability Database CVE-2014-7939 | ||||||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||||||