CVE-2014-7939

Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an "X-Content-Type-Options: nosniff" header.
Configurations

Configuration 1 (hide)

cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:chromium:chromium:40.0.2214.110:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_desktop_supplementary:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_supplementary:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_supplementary_eus:6.6.z:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation_supplementary:6.0:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*

History

07 Nov 2023, 02:22

Type Values Removed Values Added
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.html - () http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.html -
References (GENTOO) http://security.gentoo.org/glsa/glsa-201502-13.xml - () http://security.gentoo.org/glsa/glsa-201502-13.xml -
References (SECTRACK) http://www.securitytracker.com/id/1031623 - () http://www.securitytracker.com/id/1031623 -
References (REDHAT) http://rhn.redhat.com/errata/RHSA-2015-0093.html - () http://rhn.redhat.com/errata/RHSA-2015-0093.html -
References (SECUNIA) http://secunia.com/advisories/62665 - () http://secunia.com/advisories/62665 -
References (BID) http://www.securityfocus.com/bid/72288 - () http://www.securityfocus.com/bid/72288 -
References (CONFIRM) https://code.google.com/p/chromium/issues/detail?id=399951 - Vendor Advisory () https://code.google.com/p/chromium/issues/detail?id=399951 -
References (CONFIRM) http://googlechromereleases.blogspot.com/2015/01/stable-update.html - Vendor Advisory () http://googlechromereleases.blogspot.com/2015/01/stable-update.html -
References (SECUNIA) http://secunia.com/advisories/62383 - () http://secunia.com/advisories/62383 -

Information

Published : 2015-01-22 22:59

Updated : 2023-12-10 11:31


NVD link : CVE-2014-7939

Mitre link : CVE-2014-7939

CVE.ORG link : CVE-2014-7939


JSON object : View

Products Affected

redhat

  • enterprise_linux_server_supplementary_eus
  • enterprise_linux_server_supplementary
  • enterprise_linux_workstation_supplementary
  • enterprise_linux_desktop_supplementary

chromium

  • chromium

opensuse

  • opensuse

google

  • chrome
CWE
CWE-264

Permissions, Privileges, and Access Controls