CVE-2014-3160 (CNNVD-201407-504)
MEDIUM
中文标题:
Google Chrome Blink 权限许可和访问控制漏洞
英文标题:
The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Goog...
CVSS分数:
6.8
发布时间:
2014-07-20 10:00:00
漏洞类型:
授权问题
状态:
PUBLISHED
数据质量分数:
0.30
数据版本:
v3
漏洞描述
中文描述:
Google Chrome是美国谷歌(Google)公司开发的一款Web浏览器。Blink是美国谷歌(Google)公司和挪威欧朋(Opera Software)公司共同开发的一套浏览器排版引擎(渲染引擎)。 Google Chrome 36.0.1985.124及之前版本使用的Blink的core/fetch/ResourceFetcher.cpp文件中的‘ResourceFetcher::canRequest’函数存在安全漏洞,该漏洞源于程序没有正确限制与SVG文件关联的子资源请求。远程攻击者可借助特制的文件利用该漏洞绕过同源策略。
英文描述:
The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file.
CWE类型:
CWE-264
标签:
(暂无数据)
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| debian | debian_linux | 7.0 | - | - |
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
|
| debian | debian_linux | 8.0 | - | - |
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
|
| chrome | 36.0.1985.1 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.1:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.2 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.2:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.3 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.3:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.4 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.4:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.5 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.5:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.6 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.6:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.8 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.8:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.12 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.12:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.13 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.13:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.14 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.14:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.15 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.15:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.16 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.16:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.17 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.17:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.18 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.18:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.19 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.19:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.20 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.20:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.21 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.21:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.22 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.22:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.23 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.23:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.24 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.24:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.25 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.25:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.26 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.26:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.27 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.27:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.28 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.28:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.29 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.29:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.30 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.30:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.31 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.31:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.32 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.32:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.33 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.33:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.34 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.34:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.35 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.35:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.36 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.36:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.37 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.37:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.38 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.38:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.39 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.39:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.40 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.40:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.41 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.41:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.42 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.42:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.43 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.43:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.44 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.44:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.45 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.45:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.46 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.46:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.47 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.47:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.48 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.48:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.49 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.49:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.50 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.50:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.51 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.51:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.52 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.52:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.53 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.53:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.54 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.54:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.55 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.55:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.56 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.56:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.57 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.57:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.58 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.58:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.59 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.59:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.60 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.60:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.61 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.61:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.62 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.62:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.63 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.63:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.64 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.64:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.65 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.65:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.66 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.66:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.67 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.67:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.68 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.68:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.69 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.69:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.70 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.70:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.72 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.72:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.73 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.73:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.74 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.74:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.75 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.75:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.76 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.76:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.77 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.77:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.78 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.78:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.79 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.79:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.81 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.81:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.82 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.82:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.83 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.83:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.84 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.84:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.85 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.85:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.86 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.86:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.87 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.87:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.88 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.88:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.89 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.89:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.90 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.90:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.91 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.91:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.92 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.92:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.93 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.93:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.94 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.94:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.95 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.95:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.96 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.96:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.97 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.97:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.98 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.98:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.99 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.99:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.100 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.100:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.101 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.101:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.102 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.102:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.103 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.103:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.104 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.104:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.105 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.105:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.106 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.106:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.122 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.122:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.123 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.123:*:*:*:*:*:*:*
|
|
| chrome | 36.0.1985.124 | - | - |
cpe:2.3:a:google:chrome:36.0.1985.124:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
CVSS评分详情
6.8
MEDIUM
CVSS向量:
AV:N/AC:M/Au:N/C:P/I:P/A:P
CVSS版本:
2.0
机密性
PARTIAL
完整性
PARTIAL
可用性
PARTIAL
时间信息
发布时间:
2014-07-20 10:00:00
修改时间:
2024-08-06 10:35:56
创建时间:
2025-11-11 15:33:46
更新时间:
2025-11-11 15:51:30
利用信息
暂无可利用代码信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2014-3160 |
2025-11-11 15:18:45 | 2025-11-11 07:33:46 |
| NVD | nvd_CVE-2014-3160 |
2025-11-11 14:54:33 | 2025-11-11 07:42:32 |
| CNNVD | cnnvd_CNNVD-201407-504 |
2025-11-11 15:09:28 | 2025-11-11 07:51:30 |
版本与语言
当前版本:
v3
主要语言:
EN
支持语言:
EN
ZH
安全公告
暂无安全公告信息
变更历史
v3
CNNVD
2025-11-11 15:51:30
vulnerability_type: 未提取 → 授权问题; cnnvd_id: 未提取 → CNNVD-201407-504; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-201407-504
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2
NVD
2025-11-11 15:42:32
cvss_score: 未提取 → 6.8; cvss_vector: NOT_EXTRACTED → AV:N/AC:M/Au:N/C:P/I:P/A:P; cvss_version: NOT_EXTRACTED → 2.0; affected_products_count: 0 → 105; data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 6.8
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:M/Au:N/C:P/I:P/A:P
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 105
- data_sources: ['cve'] -> ['cve', 'nvd']