Vulnerabilities > CVE-2014-1732 - Use After Free vulnerability in Google Chrome

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

Use-after-free vulnerability in browser/ui/views/speech_recognition_bubble_views.cc in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via an INPUT element that triggers the presence of a Speech Recognition Bubble window for an incorrect duration.

Vulnerable Configurations

Part Description Count
Application
Google
3548
OS
Apple
1
OS
Microsoft
1
OS
Linux
1

Common Weakness Enumeration (CWE)

Nessus

  • NASL familySuSE Local Security Checks
    NASL idOPENSUSE-2014-371.NASL
    description - Update to Chromium 34.0.1847.132 - Security update : - CVE-2014-1730: Type confusion in V8 - CVE-2014-1731: Type confusion in DOM - CVE-2014-1732: Use-after-free in Speech Recognition - CVE-2014-1733: Compiler bug in Seccomp-BPF - CVE-2014-1734: Various fixes from internal audits, fuzzing and other initiatives - CVE-2014-1735: Multiple vulnerabilities in V8 fixed in version 3.24.35.33 - Update to Chromium 34.0.1847.131 - Bugfixes
    last seen2020-06-05
    modified2014-06-13
    plugin id75361
    published2014-06-13
    reporterThis script is Copyright (C) 2014-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/75361
    titleopenSUSE Security Update : chromium (openSUSE-SU-2014:0669-1)
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-2920.NASL
    descriptionSeveral vulnerabilities have been discovered in the chromium web browser. - CVE-2014-1730 A type confusion issue was discovered in the v8 JavaScript library. - CVE-2014-1731 John Butler discovered a type confusion issue in the WebKit/Blink document object model implementation. - CVE-2014-1732 Khalil Zhani discovered a use-after-free issue in the speech recognition feature. - CVE-2014-1733 Jed Davis discovered a way to bypass the seccomp-bpf sandbox. - CVE-2014-1734 The Google Chrome development team discovered and fixed multiple issues with potential security impact. - CVE-2014-1735 The Google Chrome development team discovered and fixed multiple issues in version 3.24.35.33 of the v8 JavaScript library. - CVE-2014-1736 SkyLined discovered an integer overlflow issue in the v8 JavaScript library.
    last seen2020-03-17
    modified2014-05-05
    plugin id73856
    published2014-05-05
    reporterThis script is Copyright (C) 2014-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/73856
    titleDebian DSA-2920-1 : chromium-browser - security update
  • NASL familyWindows
    NASL idGOOGLE_CHROME_34_0_1847_131.NASL
    descriptionThe version of Google Chrome installed on the remote host is a version prior to 34.0.1847.131. It is, therefore, affected by the following vulnerabilities : - A buffer overflow error exists related to the included version of Flash Player. (CVE-2014-0515) - Type confusion errors exist related to the V8 JavaScript engine and DOM handling. (CVE-2014-1730, CVE-2014-1731) - A use-after-free error exists related to speech recognition processing. (CVE-2014-1732) - An error exists related to compiling in
    last seen2020-06-01
    modified2020-06-02
    plugin id73710
    published2014-04-25
    reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/73710
    titleGoogle Chrome < 34.0.1847.131 Multiple Vulnerabilities
  • NASL familySuSE Local Security Checks
    NASL idOPENSUSE-2014-370.NASL
    description - Update to Chromium 34.0.1847.132 - Security update : - CVE-2014-1730: Type confusion in V8 - CVE-2014-1731: Type confusion in DOM - CVE-2014-1732: Use-after-free in Speech Recognition - CVE-2014-1733: Compiler bug in Seccomp-BPF - CVE-2014-1734: Various fixes from internal audits, fuzzing and other initiatives - CVE-2014-1735: Multiple vulnerabilities in V8 fixed in version 3.24.35.33 - Update to Chromium 34.0.1847.131 - Bugfixes
    last seen2020-06-05
    modified2014-06-13
    plugin id75360
    published2014-06-13
    reporterThis script is Copyright (C) 2014-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/75360
    titleopenSUSE Security Update : chromium (openSUSE-SU-2014:0668-1)
  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-201408-16.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-201408-16 (Chromium: Multiple vulnerabilities) Multiple vulnerabilities have been discovered in Chromium. Please review the CVE identifiers referenced below for details. Impact : A remote attacker could conduct a number of attacks which include: cross site scripting attacks, bypassing of sandbox protection, potential execution of arbitrary code with the privileges of the process, or cause a Denial of Service condition. Workaround : There is no known workaround at this time.
    last seen2020-06-01
    modified2020-06-02
    plugin id77460
    published2014-08-30
    reporterThis script is Copyright (C) 2014-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/77460
    titleGLSA-201408-16 : Chromium: Multiple vulnerabilities
  • NASL familyMacOS X Local Security Checks
    NASL idMACOSX_GOOGLE_CHROME_34_0_1847_131.NASL
    descriptionThe version of Google Chrome installed on the remote Mac OS X host is a version prior to 34.0.1847.131. It is, therefore, affected by the following vulnerabilities : - A buffer overflow error exists related to the included version of Flash Player. (CVE-2014-0515) - Type confusion errors exist related to the V8 JavaScript engine and DOM handling. (CVE-2014-1730, CVE-2014-1731) - A use-after-free error exists related to speech recognition processing. (CVE-2014-1732) - An error exists related to compiling in
    last seen2020-06-01
    modified2020-06-02
    plugin id73711
    published2014-04-25
    reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/73711
    titleGoogle Chrome < 34.0.1847.131 Multiple Vulnerabilities (Mac OS X)
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_7CF25A0CD03111E3947B00262D5ED8EE.NASL
    descriptionGoogle Chrome Releases reports (belatedly) : 9 security fixes in this release, including : - [354967] High CVE-2014-1730: Type confusion in V8. Credit to Anonymous. - [349903] High CVE-2014-1731: Type confusion in DOM. Credit to John Butler. - [359802] High CVE-2014-1736: Integer overflow in V8. Credit to SkyLined working with HP
    last seen2020-06-01
    modified2020-06-02
    plugin id73793
    published2014-05-01
    reporterThis script is Copyright (C) 2014 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/73793
    titleFreeBSD : chromium -- multiple vulnerabilities (7cf25a0c-d031-11e3-947b-00262d5ed8ee)