CVE-2014-1710
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
16/03/2014
Last modified:
12/04/2025
Description
The AsyncPixelTransfersCompletedQuery::End function in gpu/command_buffer/service/query_manager.cc in Google Chrome, as used in Google Chrome OS before 33.0.1750.152, does not check whether a certain position is within the bounds of a shared-memory segment, which allows remote attackers to cause a denial of service (GPU command-buffer memory corruption) or possibly have unspecified other impact via unknown vectors.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:google:chrome_os:*:*:*:*:*:*:*:* | 33.0.1750.149 (including) | |
| cpe:2.3:o:google:chrome_os:33.0.1750.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:chrome_os:33.0.1750.5:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:chrome_os:33.0.1750.16:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:chrome_os:33.0.1750.29:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:chrome_os:33.0.1750.51:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:chrome_os:33.0.1750.58:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:chrome_os:33.0.1750.70:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:chrome_os:33.0.1750.93:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:chrome_os:33.0.1750.112:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:chrome_os:33.0.1750.124:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://googlechromereleases.blogspot.com/2014/03/stable-channel-update-for-chrome-os_14.html
- https://code.google.com/p/chromium/issues/detail?id=351852
- https://src.chromium.org/viewvc/chrome?revision=256723&view=revision
- https://src.chromium.org/viewvc/chrome?revision=256918&view=revision
- http://googlechromereleases.blogspot.com/2014/03/stable-channel-update-for-chrome-os_14.html
- https://code.google.com/p/chromium/issues/detail?id=351852
- https://src.chromium.org/viewvc/chrome?revision=256723&view=revision
- https://src.chromium.org/viewvc/chrome?revision=256918&view=revision



