LiveActive security incident?Get immediate response
CVE archive

January 2014

Browse CVE records published in January 2014, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 895 matching CVEs · Page 9 of 18.

Unknown · CVSS Not scored

CVE-2014-7930: Use-after-free vulnerability in core/events/TreeScopeEventContext.cpp in the DOM implementation in Blink, a...

Use-after-free vulnerability in core/events/TreeScopeEventContext.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers improper maintenance of TreeScope data.

Published Jan 22, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-7927: The SimplifiedLowering::DoLoadBuffer function in compiler/simplified-lowering.cc in Google V8, as used in G...

The SimplifiedLowering::DoLoadBuffer function in compiler/simplified-lowering.cc in Google V8, as used in Google Chrome before 40.0.2214.91, does not properly choose an integer data type, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code.

Published Jan 22, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-7957: Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allo...

Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the toggled parameter in a toggle action in the pods-components page to wp-admin/admin.php, (2) delete a pod in a delete action in the pods page to wp-admin/admin.php, (3) reset pod settings and data via the pods_reset parameter in the pod-settings page to wp-admin/admin.php, (4) deactivate and reset pod data via the pods_reset_deactivate parameter in the pod-settings page to wp-admin/admin.php, (5) delete the admin role via the id parameter in a delete action in the pods-component-roles-and-capabilities page to wp-admin/admin.php, or (6) enable "roles and capabilities" in a toggle action in the pods-components page to wp-admin/admin.php.

Published Jan 15, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-7946: The RenderTable::simplifiedNormalFlowLayout function in core/rendering/RenderTable.cpp in Blink, as used in...

The RenderTable::simplifiedNormalFlowLayout function in core/rendering/RenderTable.cpp in Blink, as used in Google Chrome before 40.0.2214.91, skips captions during table layout in certain situations, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors related to the Fonts implementation.

Published Jan 22, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-7933: Use-after-free vulnerability in the matroska_read_seek function in libavformat/matroskadec.c in FFmpeg befo...

Use-after-free vulnerability in the matroska_read_seek function in libavformat/matroskadec.c in FFmpeg before 2.5.1, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Matroska file that triggers improper maintenance of tracks data.

Published Jan 22, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-7948: The AppCacheUpdateJob::URLFetcher::OnResponseStarted function in content/browser/appcache/appcache_update_j...

The AppCacheUpdateJob::URLFetcher::OnResponseStarted function in content/browser/appcache/appcache_update_job.cc in Google Chrome before 40.0.2214.91 proceeds with AppCache caching for SSL sessions even if there is an X.509 certificate error, which allows man-in-the-middle attackers to spoof HTML5 application content via a crafted certificate.

Published Jan 22, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-7926: The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944...

The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a zero-length quantifier.

Published Jan 22, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-7925: Use-after-free vulnerability in the WebAudio implementation in Blink, as used in Google Chrome before 40.0....

Use-after-free vulnerability in the WebAudio implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an audio-rendering thread in which AudioNode data is improperly maintained.

Published Jan 22, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-7923: The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944...

The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a look-behind expression.

Published Jan 22, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-7936: Use-after-free vulnerability in the ZoomBubbleView::Close function in browser/ui/views/location_bar/zoom_bu...

Use-after-free vulnerability in the ZoomBubbleView::Close function in browser/ui/views/location_bar/zoom_bubble_view.cc in the Views implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document that triggers improper maintenance of a zoom bubble.

Published Jan 22, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-7924: Use-after-free vulnerability in the IndexedDB implementation in Google Chrome before 40.0.2214.91 allows re...

Use-after-free vulnerability in the IndexedDB implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering duplicate BLOB references, related to content/browser/indexed_db/indexed_db_callbacks.cc and content/browser/indexed_db/indexed_db_dispatcher_host.cc.

Published Jan 22, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-7932: Use-after-free vulnerability in the Element::detach function in core/dom/Element.cpp in the DOM implementat...

Use-after-free vulnerability in the Element::detach function in core/dom/Element.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving pending updates of detached elements.

Published Jan 22, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-7929: Use-after-free vulnerability in the HTMLScriptElement::didMoveToNewDocument function in core/html/HTMLScrip...

Use-after-free vulnerability in the HTMLScriptElement::didMoveToNewDocument function in core/html/HTMLScriptElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving movement of a SCRIPT element across documents.

Published Jan 22, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-7940: The collator implementation in i18n/ucol.cpp in International Components for Unicode (ICU) 52 through SVN r...

The collator implementation in i18n/ucol.cpp in International Components for Unicode (ICU) 52 through SVN revision 293126, as used in Google Chrome before 40.0.2214.91, does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted character sequence.

Published Jan 22, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-7222: Buffer overflow in TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial...

Buffer overflow in TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (application crash) by connecting to a channel with a different client instance, and placing crafted data in the Chat/Server tab with two \\ (backslash) characters, a digit, a \ (backslash) character, and "z" in a series of nested img BBCODE tags.

Published Jan 8, 2018 · Updated Aug 6, 2024