CVE-2014-3201
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
10/10/2014
Last modified:
12/04/2025
Description
core/rendering/compositing/RenderLayerCompositor.cpp in Blink, as used in Google Chrome before 38.0.2125.102 on Android, does not properly handle a certain IFRAME overflow condition, which allows remote attackers to spoof content via a crafted web site that interferes with the scrollbar.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:google:chrome:*:*:*:*:*:android:*:* | 38.0.2125.101 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://googlechromereleases.blogspot.com/2014/10/chrome-for-android-update.html
- https://crbug.com/406593
- https://src.chromium.org/viewvc/blink?revision=182021&view=revision
- http://googlechromereleases.blogspot.com/2014/10/chrome-for-android-update.html
- https://crbug.com/406593
- https://src.chromium.org/viewvc/blink?revision=182021&view=revision