CVE Vulnerabilities

CVE-2014-1748

Published: May 21, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The ScrollView::paint function in platform/scroll/ScrollView.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to spoof the UI by extending scrollbar painting into the parent frame.

Affected Software

NameVendorStart VersionEnd Version
ChromeGoogle*35.0.1916.113 (including)
ChromeGoogle35.0.1916.0 (including)35.0.1916.0 (including)
ChromeGoogle35.0.1916.1 (including)35.0.1916.1 (including)
ChromeGoogle35.0.1916.2 (including)35.0.1916.2 (including)
ChromeGoogle35.0.1916.3 (including)35.0.1916.3 (including)
ChromeGoogle35.0.1916.4 (including)35.0.1916.4 (including)
ChromeGoogle35.0.1916.5 (including)35.0.1916.5 (including)
ChromeGoogle35.0.1916.6 (including)35.0.1916.6 (including)
ChromeGoogle35.0.1916.7 (including)35.0.1916.7 (including)
ChromeGoogle35.0.1916.8 (including)35.0.1916.8 (including)
ChromeGoogle35.0.1916.9 (including)35.0.1916.9 (including)
ChromeGoogle35.0.1916.10 (including)35.0.1916.10 (including)
ChromeGoogle35.0.1916.11 (including)35.0.1916.11 (including)
ChromeGoogle35.0.1916.13 (including)35.0.1916.13 (including)
ChromeGoogle35.0.1916.14 (including)35.0.1916.14 (including)
ChromeGoogle35.0.1916.15 (including)35.0.1916.15 (including)
ChromeGoogle35.0.1916.17 (including)35.0.1916.17 (including)
ChromeGoogle35.0.1916.18 (including)35.0.1916.18 (including)
ChromeGoogle35.0.1916.19 (including)35.0.1916.19 (including)
ChromeGoogle35.0.1916.20 (including)35.0.1916.20 (including)
ChromeGoogle35.0.1916.21 (including)35.0.1916.21 (including)
ChromeGoogle35.0.1916.22 (including)35.0.1916.22 (including)
ChromeGoogle35.0.1916.23 (including)35.0.1916.23 (including)
ChromeGoogle35.0.1916.27 (including)35.0.1916.27 (including)
ChromeGoogle35.0.1916.31 (including)35.0.1916.31 (including)
ChromeGoogle35.0.1916.32 (including)35.0.1916.32 (including)
ChromeGoogle35.0.1916.33 (including)35.0.1916.33 (including)
ChromeGoogle35.0.1916.34 (including)35.0.1916.34 (including)
ChromeGoogle35.0.1916.35 (including)35.0.1916.35 (including)
ChromeGoogle35.0.1916.36 (including)35.0.1916.36 (including)
ChromeGoogle35.0.1916.37 (including)35.0.1916.37 (including)
ChromeGoogle35.0.1916.38 (including)35.0.1916.38 (including)
ChromeGoogle35.0.1916.39 (including)35.0.1916.39 (including)
ChromeGoogle35.0.1916.40 (including)35.0.1916.40 (including)
ChromeGoogle35.0.1916.41 (including)35.0.1916.41 (including)
ChromeGoogle35.0.1916.42 (including)35.0.1916.42 (including)
ChromeGoogle35.0.1916.43 (including)35.0.1916.43 (including)
ChromeGoogle35.0.1916.44 (including)35.0.1916.44 (including)
ChromeGoogle35.0.1916.45 (including)35.0.1916.45 (including)
ChromeGoogle35.0.1916.46 (including)35.0.1916.46 (including)
ChromeGoogle35.0.1916.47 (including)35.0.1916.47 (including)
ChromeGoogle35.0.1916.48 (including)35.0.1916.48 (including)
ChromeGoogle35.0.1916.49 (including)35.0.1916.49 (including)
ChromeGoogle35.0.1916.51 (including)35.0.1916.51 (including)
ChromeGoogle35.0.1916.52 (including)35.0.1916.52 (including)
ChromeGoogle35.0.1916.54 (including)35.0.1916.54 (including)
ChromeGoogle35.0.1916.56 (including)35.0.1916.56 (including)
ChromeGoogle35.0.1916.57 (including)35.0.1916.57 (including)
ChromeGoogle35.0.1916.59 (including)35.0.1916.59 (including)
ChromeGoogle35.0.1916.61 (including)35.0.1916.61 (including)
ChromeGoogle35.0.1916.68 (including)35.0.1916.68 (including)
ChromeGoogle35.0.1916.69 (including)35.0.1916.69 (including)
ChromeGoogle35.0.1916.71 (including)35.0.1916.71 (including)
ChromeGoogle35.0.1916.72 (including)35.0.1916.72 (including)
ChromeGoogle35.0.1916.74 (including)35.0.1916.74 (including)
ChromeGoogle35.0.1916.77 (including)35.0.1916.77 (including)
ChromeGoogle35.0.1916.80 (including)35.0.1916.80 (including)
ChromeGoogle35.0.1916.82 (including)35.0.1916.82 (including)
ChromeGoogle35.0.1916.84 (including)35.0.1916.84 (including)
ChromeGoogle35.0.1916.85 (including)35.0.1916.85 (including)
ChromeGoogle35.0.1916.86 (including)35.0.1916.86 (including)
ChromeGoogle35.0.1916.88 (including)35.0.1916.88 (including)
ChromeGoogle35.0.1916.90 (including)35.0.1916.90 (including)
ChromeGoogle35.0.1916.92 (including)35.0.1916.92 (including)
ChromeGoogle35.0.1916.93 (including)35.0.1916.93 (including)
ChromeGoogle35.0.1916.95 (including)35.0.1916.95 (including)
ChromeGoogle35.0.1916.96 (including)35.0.1916.96 (including)
ChromeGoogle35.0.1916.98 (including)35.0.1916.98 (including)
ChromeGoogle35.0.1916.99 (including)35.0.1916.99 (including)
ChromeGoogle35.0.1916.101 (including)35.0.1916.101 (including)
ChromeGoogle35.0.1916.103 (including)35.0.1916.103 (including)
ChromeGoogle35.0.1916.104 (including)35.0.1916.104 (including)
ChromeGoogle35.0.1916.105 (including)35.0.1916.105 (including)
ChromeGoogle35.0.1916.106 (including)35.0.1916.106 (including)
ChromeGoogle35.0.1916.107 (including)35.0.1916.107 (including)
ChromeGoogle35.0.1916.108 (including)35.0.1916.108 (including)
ChromeGoogle35.0.1916.109 (including)35.0.1916.109 (including)
ChromeGoogle35.0.1916.110 (including)35.0.1916.110 (including)
ChromeGoogle35.0.1916.111 (including)35.0.1916.111 (including)
ChromeGoogle35.0.1916.112 (including)35.0.1916.112 (including)
Chromium-browserUbuntudevel*
Chromium-browserUbuntulucid*
Chromium-browserUbuntuprecise*
Chromium-browserUbuntusaucy*
Chromium-browserUbuntutrusty*
Chromium-browserUbuntuupstream*
Oxide-qtUbuntudevel*
Oxide-qtUbuntutrusty*
Oxide-qtUbuntuupstream*

References