CVE-2014-3188
Last modified
CVE-2014-3188 is a vulnerability of currently unknown severity. Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data, related to improper parsing of an escaped index by ParseJsonObject in json-parser.h.. EPSS estimates a 5.95% chance of exploitation in the next 30 days.
Description
Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data, related to improper parsing of an escaped index by ParseJsonObject in json-parser.h.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Chrome Os | <= 38.0.2125.77 | |
| Chrome | <= 38.0.2125.7 | |
| Redhat | Enterprise Linux Desktop Supplementary | 6.0 |
| Redhat | Enterprise Linux Server Supplementary | 6.0 |
| Redhat | Enterprise Linux Server Supplementary Eus | 6.6.z |
| Redhat | Enterprise Linux Workstation Supplementary | 6.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-3188?
How severe is CVE-2014-3188?
How do I fix CVE-2014-3188?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-3182Array index error in the logi_dj_raw_event function in drive…
- CVE-2014-3183Heap-based buffer overflow in the logi_dj_ll_raw_request fun…
- CVE-2014-3184The report_fixup functions in the HID subsystem in the Linux…
- CVE-2014-3185Multiple buffer overflows in the command_port_read_callback …
- CVE-2014-3186Buffer overflow in the picolcd_raw_event function in devices…
- CVE-2014-3187Google Chrome before 37.0.2062.60 and 38.x before 38.0.2125.…
- CVE-2014-3189The chrome_pdf::CopyImage function in pdf/draw_utils.cc in t…
- CVE-2014-3190Use-after-free vulnerability in the Event::currentTarget fun…
- CVE-2014-3191Use-after-free vulnerability in Blink, as used in Google Chr…
- CVE-2014-3192Use-after-free vulnerability in the ProcessingInstruction::s…
- CVE-2014-3193The SessionService::GetLastSession function in browser/sessi…
- CVE-2014-3194Use-after-free vulnerability in the Web Workers implementati…
Are you affected by CVE-2014-3188?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
