CVE Vulnerabilities

CVE-2014-7939

Published: Jan 22, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an X-Content-Type-Options: nosniff header.

Affected Software

NameVendorStart VersionEnd Version
ChromeGoogle*40.0.2214.85 (including)
Supplementary for Red Hat Enterprise Linux 6RedHatchromium-browser-0:40.0.2214.91-1.el6_6*
Chromium-browserUbuntudevel*
Chromium-browserUbuntulucid*
Chromium-browserUbuntuprecise*
Chromium-browserUbuntutrusty*
Chromium-browserUbuntuupstream*
Chromium-browserUbuntuutopic*
Chromium-browserUbuntuvivid*
Chromium-browserUbuntuwily*

References