Input validation error in Google Chrome - CVE-2014-1748

 

Input validation error in Google Chrome - CVE-2014-1748

Published: May 21, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41649
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-1748
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The ScrollView::paint function in platform/scroll/ScrollView.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to spoof the UI by extending scrollbar painting into the parent frame.


Affected software

Google Chrome

How to mitigate CVE-2014-1748

Install update from vendor's website.


External References

Related Security Bulletins