MEDIUM · 5.0

CVE-2014-3195

Google V8, as used in Google Chrome before 38.0.2125.101, does not properly track JavaScript heap-memory allocations as allocations of uninitialized memory and does not properly concatenate arrays of ...

Vulnerability Description

Google V8, as used in Google Chrome before 38.0.2125.101, does not properly track JavaScript heap-memory allocations as allocations of uninitialized memory and does not properly concatenate arrays of double-precision floating-point numbers, which allows remote attackers to obtain sensitive information via crafted JavaScript code, related to the PagedSpace::AllocateRaw and NewSpace::AllocateRaw functions in heap/spaces-inl.h, the LargeObjectSpace::AllocateRaw function in heap/spaces.cc, and the Runtime_ArrayConcat function in runtime.cc.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
GoogleChrome<= 38.0.2125.7
RedhatEnterprise Linux Desktop Supplementary6.0
RedhatEnterprise Linux Server Supplementary6.0
RedhatEnterprise Linux Server Supplementary Eus6.6.z
RedhatEnterprise Linux Workstation Supplementary6.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-3195?

CVE-2014-3195 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Google V8, as used in Google Chrome before 38.0.2125.101, does not properly track JavaScript heap-memory allocations as allocations of uninitialized memory and does not properly concatenate arrays of ...

How severe is CVE-2014-3195?

CVE-2014-3195 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-3195?

Check the references section above for vendor advisories and patch information. Affected products include: Google Chrome, Redhat Enterprise Linux Desktop Supplementary, Redhat Enterprise Linux Server Supplementary, Redhat Enterprise Linux Server Supplementary Eus, Redhat Enterprise Linux Workstation Supplementary.