CVE-2014-7939

Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an "X-Content-Type-Options: nosniff" header.
Configurations

Configuration 1 (hide)

cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:chromium:chromium:40.0.2214.110:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_desktop_supplementary:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_supplementary:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_supplementary_eus:6.6.z:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation_supplementary:6.0:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*

History

21 Nov 2024, 02:18

Type Values Removed Values Added
References () http://googlechromereleases.blogspot.com/2015/01/stable-update.html - () http://googlechromereleases.blogspot.com/2015/01/stable-update.html -
References () http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.html - () http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.html -
References () http://rhn.redhat.com/errata/RHSA-2015-0093.html - () http://rhn.redhat.com/errata/RHSA-2015-0093.html -
References () http://secunia.com/advisories/62383 - () http://secunia.com/advisories/62383 -
References () http://secunia.com/advisories/62665 - () http://secunia.com/advisories/62665 -
References () http://security.gentoo.org/glsa/glsa-201502-13.xml - () http://security.gentoo.org/glsa/glsa-201502-13.xml -
References () http://www.securityfocus.com/bid/72288 - () http://www.securityfocus.com/bid/72288 -
References () http://www.securitytracker.com/id/1031623 - () http://www.securitytracker.com/id/1031623 -
References () https://code.google.com/p/chromium/issues/detail?id=399951 - () https://code.google.com/p/chromium/issues/detail?id=399951 -

07 Nov 2023, 02:22

Type Values Removed Values Added
References (SECUNIA) http://secunia.com/advisories/62383 - () http://secunia.com/advisories/62383 -
References (GENTOO) http://security.gentoo.org/glsa/glsa-201502-13.xml - () http://security.gentoo.org/glsa/glsa-201502-13.xml -
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.html - () http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.html -
References (SECTRACK) http://www.securitytracker.com/id/1031623 - () http://www.securitytracker.com/id/1031623 -
References (CONFIRM) http://googlechromereleases.blogspot.com/2015/01/stable-update.html - Vendor Advisory () http://googlechromereleases.blogspot.com/2015/01/stable-update.html -
References (CONFIRM) https://code.google.com/p/chromium/issues/detail?id=399951 - Vendor Advisory () https://code.google.com/p/chromium/issues/detail?id=399951 -
References (SECUNIA) http://secunia.com/advisories/62665 - () http://secunia.com/advisories/62665 -
References (BID) http://www.securityfocus.com/bid/72288 - () http://www.securityfocus.com/bid/72288 -
References (REDHAT) http://rhn.redhat.com/errata/RHSA-2015-0093.html - () http://rhn.redhat.com/errata/RHSA-2015-0093.html -

Information

Published : 2015-01-22 22:59

Updated : 2024-11-21 02:18


NVD link : CVE-2014-7939

Mitre link : CVE-2014-7939

CVE.ORG link : CVE-2014-7939


JSON object : View

Products Affected

opensuse

  • opensuse

redhat

  • enterprise_linux_server_supplementary_eus
  • enterprise_linux_server_supplementary
  • enterprise_linux_workstation_supplementary
  • enterprise_linux_desktop_supplementary

google

  • chrome

chromium

  • chromium
CWE
CWE-264

Permissions, Privileges, and Access Controls