ALT-PU-2014-2430-1
Closed vulnerabilities
Modified: 2025-04-12
CVE-2014-0574
Double free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors.
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://helpx.adobe.com/security/products/flash-player/apsb14-24.html
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.html
- https://code.google.com/p/chromium/issues/detail?id=423703
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://helpx.adobe.com/security/products/flash-player/apsb14-24.html
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.html
- https://code.google.com/p/chromium/issues/detail?id=423703
Modified: 2025-04-12
CVE-2014-7899
Google Chrome before 38.0.2125.101 allows remote attackers to spoof the address bar by placing a blob: substring at the beginning of the URL, followed by the original URI scheme and a long username string.
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://rhn.redhat.com/errata/RHSA-2014-1894.html
- http://secunia.com/advisories/60194
- http://www.securityfocus.com/bid/71160
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=389734
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98787
- https://src.chromium.org/viewvc/chrome?revision=279232&view=revision
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://rhn.redhat.com/errata/RHSA-2014-1894.html
- http://secunia.com/advisories/60194
- http://www.securityfocus.com/bid/71160
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=389734
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98787
- https://src.chromium.org/viewvc/chrome?revision=279232&view=revision
Modified: 2025-04-12
CVE-2014-7900
Use-after-free vulnerability in the CPDF_Parser::IsLinearizedFile function in fpdfapi/fpdf_parser/fpdf_parser_parser.cpp in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://www.securityfocus.com/bid/71163
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=406868
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98788
- https://pdfium.googlesource.com/pdfium/+/1b04ea3b0fbae3be3ae6b3824c5e0dadc0e73d44
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://www.securityfocus.com/bid/71163
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=406868
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98788
- https://pdfium.googlesource.com/pdfium/+/1b04ea3b0fbae3be3ae6b3824c5e0dadc0e73d44
Modified: 2025-04-12
CVE-2014-7901
Integer overflow in the opj_t2_read_packet_data function in fxcodec/fx_libopenjpeg/libopenjpeg20/t2.c in OpenJPEG in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long segment in a JPEG image.
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://www.securityfocus.com/bid/71158
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=413375
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98789
- https://pdfium.googlesource.com/pdfium/+/e93d5341d87c54713a9632c8823288fa901a3b78
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://www.securityfocus.com/bid/71158
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=413375
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98789
- https://pdfium.googlesource.com/pdfium/+/e93d5341d87c54713a9632c8823288fa901a3b78
Modified: 2025-04-12
CVE-2014-7902
Use-after-free vulnerability in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://www.securityfocus.com/bid/71165
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=414504
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98790
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://www.securityfocus.com/bid/71165
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=414504
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98790
Modified: 2025-04-12
CVE-2014-7903
Buffer overflow in OpenJPEG before r2911 in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted JPEG image.
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://www.securityfocus.com/bid/71164
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=414525
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98791
- https://pdfium.googlesource.com/pdfium/+/4dc95e74e1acc75f4eab08bc771874cd2a9c3a9b
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://www.securityfocus.com/bid/71164
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=414525
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98791
- https://pdfium.googlesource.com/pdfium/+/4dc95e74e1acc75f4eab08bc771874cd2a9c3a9b
Modified: 2025-04-12
CVE-2014-7904
Buffer overflow in Skia, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://rhn.redhat.com/errata/RHSA-2014-1894.html
- http://secunia.com/advisories/60194
- http://secunia.com/advisories/62608
- http://www.securityfocus.com/bid/71166
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=418161
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98792
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://rhn.redhat.com/errata/RHSA-2014-1894.html
- http://secunia.com/advisories/60194
- http://secunia.com/advisories/62608
- http://www.securityfocus.com/bid/71166
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=418161
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98792
Modified: 2025-04-12
CVE-2014-7905
Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL lacks CATEGORY_BROWSABLE, which allows remote attackers to bypass intended access restrictions via a crafted web site.
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://www.securityfocus.com/bid/71162
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=421817
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98793
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://www.securityfocus.com/bid/71162
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=421817
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98793
Modified: 2025-04-12
CVE-2014-7906
Use-after-free vulnerability in the Pepper plugins in Google Chrome before 39.0.2171.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted Flash content that triggers an attempted PepperMediaDeviceManager access outside of the object's lifetime.
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://rhn.redhat.com/errata/RHSA-2014-1894.html
- http://secunia.com/advisories/60194
- http://www.securityfocus.com/bid/71159
- http://www.securitytracker.com/id/1031241
- https://chromium.googlesource.com/chromium/src/+/3a2cf7d1376ae33054b878232fb38b8fbed29e31
- https://code.google.com/p/chromium/issues/detail?id=423030
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98794
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://rhn.redhat.com/errata/RHSA-2014-1894.html
- http://secunia.com/advisories/60194
- http://www.securityfocus.com/bid/71159
- http://www.securitytracker.com/id/1031241
- https://chromium.googlesource.com/chromium/src/+/3a2cf7d1376ae33054b878232fb38b8fbed29e31
- https://code.google.com/p/chromium/issues/detail?id=423030
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98794
Modified: 2025-04-12
CVE-2014-7907
Multiple use-after-free vulnerabilities in modules/screen_orientation/ScreenOrientationController.cpp in Blink, as used in Google Chrome before 39.0.2171.65, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger improper handling of a detached frame, related to the (1) lock and (2) unlock methods.
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://rhn.redhat.com/errata/RHSA-2014-1894.html
- http://secunia.com/advisories/60194
- http://secunia.com/advisories/62608
- http://www.securityfocus.com/bid/71170
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=424453
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98795
- https://src.chromium.org/viewvc/blink?revision=184185&view=revision
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://rhn.redhat.com/errata/RHSA-2014-1894.html
- http://secunia.com/advisories/60194
- http://secunia.com/advisories/62608
- http://www.securityfocus.com/bid/71170
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=424453
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98795
- https://src.chromium.org/viewvc/blink?revision=184185&view=revision
Modified: 2025-04-12
CVE-2014-7908
Multiple integer overflows in the CheckMov function in media/base/container_names.cc in Google Chrome before 39.0.2171.65 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a large atom in (1) MPEG-4 or (2) QuickTime .mov data.
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://rhn.redhat.com/errata/RHSA-2014-1894.html
- http://secunia.com/advisories/60194
- http://secunia.com/advisories/62608
- http://www.securityfocus.com/bid/71168
- http://www.securitytracker.com/id/1031241
- https://chromium.googlesource.com/chromium/src/+/b2006ac87cec58363090e7d5e10d5d9e3bbda9f9
- https://code.google.com/p/chromium/issues/detail?id=425980
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98796
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://rhn.redhat.com/errata/RHSA-2014-1894.html
- http://secunia.com/advisories/60194
- http://secunia.com/advisories/62608
- http://www.securityfocus.com/bid/71168
- http://www.securitytracker.com/id/1031241
- https://chromium.googlesource.com/chromium/src/+/b2006ac87cec58363090e7d5e10d5d9e3bbda9f9
- https://code.google.com/p/chromium/issues/detail?id=425980
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98796
Modified: 2025-04-12
CVE-2014-7909
effects/SkDashPathEffect.cpp in Skia, as used in Google Chrome before 39.0.2171.65, computes a hash key using uninitialized integer values, which might allow remote attackers to cause a denial of service by rendering crafted data.
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://rhn.redhat.com/errata/RHSA-2014-1894.html
- http://secunia.com/advisories/60194
- http://secunia.com/advisories/62608
- http://www.securityfocus.com/bid/71167
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=391001
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98797
- https://skia.googlesource.com/skia/+/1c577cd3ee331944b9061ee0eec147b211ee563c
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://rhn.redhat.com/errata/RHSA-2014-1894.html
- http://secunia.com/advisories/60194
- http://secunia.com/advisories/62608
- http://www.securityfocus.com/bid/71167
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=391001
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98797
- https://skia.googlesource.com/skia/+/1c577cd3ee331944b9061ee0eec147b211ee563c
Modified: 2025-04-12
CVE-2014-7910
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://rhn.redhat.com/errata/RHSA-2014-1894.html
- http://secunia.com/advisories/60194
- http://secunia.com/advisories/62608
- http://www.securityfocus.com/bid/71161
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=337071
- https://code.google.com/p/chromium/issues/detail?id=340387
- https://code.google.com/p/chromium/issues/detail?id=389451
- https://code.google.com/p/chromium/issues/detail?id=391001
- https://code.google.com/p/chromium/issues/detail?id=397396
- https://code.google.com/p/chromium/issues/detail?id=408426
- https://code.google.com/p/chromium/issues/detail?id=409454
- https://code.google.com/p/chromium/issues/detail?id=409508
- https://code.google.com/p/chromium/issues/detail?id=411159
- https://code.google.com/p/chromium/issues/detail?id=411162
- https://code.google.com/p/chromium/issues/detail?id=411165
- https://code.google.com/p/chromium/issues/detail?id=413743
- https://code.google.com/p/chromium/issues/detail?id=413744
- https://code.google.com/p/chromium/issues/detail?id=414134
- https://code.google.com/p/chromium/issues/detail?id=415407
- https://code.google.com/p/chromium/issues/detail?id=417210
- https://code.google.com/p/chromium/issues/detail?id=417329
- https://code.google.com/p/chromium/issues/detail?id=421090
- https://code.google.com/p/chromium/issues/detail?id=421321
- https://code.google.com/p/chromium/issues/detail?id=421504
- https://code.google.com/p/chromium/issues/detail?id=421720
- https://code.google.com/p/chromium/issues/detail?id=421981
- https://code.google.com/p/chromium/issues/detail?id=422482
- https://code.google.com/p/chromium/issues/detail?id=423030
- https://code.google.com/p/chromium/issues/detail?id=423891
- https://code.google.com/p/chromium/issues/detail?id=424215
- https://code.google.com/p/chromium/issues/detail?id=424999
- https://code.google.com/p/chromium/issues/detail?id=425151
- https://code.google.com/p/chromium/issues/detail?id=425152
- https://code.google.com/p/chromium/issues/detail?id=433500
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98798
- https://www.exploit-db.com/exploits/34879/
- http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
- http://rhn.redhat.com/errata/RHSA-2014-1894.html
- http://secunia.com/advisories/60194
- http://secunia.com/advisories/62608
- http://www.securityfocus.com/bid/71161
- http://www.securitytracker.com/id/1031241
- https://code.google.com/p/chromium/issues/detail?id=337071
- https://code.google.com/p/chromium/issues/detail?id=340387
- https://code.google.com/p/chromium/issues/detail?id=389451
- https://code.google.com/p/chromium/issues/detail?id=391001
- https://code.google.com/p/chromium/issues/detail?id=397396
- https://code.google.com/p/chromium/issues/detail?id=408426
- https://code.google.com/p/chromium/issues/detail?id=409454
- https://code.google.com/p/chromium/issues/detail?id=409508
- https://code.google.com/p/chromium/issues/detail?id=411159
- https://code.google.com/p/chromium/issues/detail?id=411162
- https://code.google.com/p/chromium/issues/detail?id=411165
- https://code.google.com/p/chromium/issues/detail?id=413743
- https://code.google.com/p/chromium/issues/detail?id=413744
- https://code.google.com/p/chromium/issues/detail?id=414134
- https://code.google.com/p/chromium/issues/detail?id=415407
- https://code.google.com/p/chromium/issues/detail?id=417210
- https://code.google.com/p/chromium/issues/detail?id=417329
- https://code.google.com/p/chromium/issues/detail?id=421090
- https://code.google.com/p/chromium/issues/detail?id=421321
- https://code.google.com/p/chromium/issues/detail?id=421504
- https://code.google.com/p/chromium/issues/detail?id=421720
- https://code.google.com/p/chromium/issues/detail?id=421981
- https://code.google.com/p/chromium/issues/detail?id=422482
- https://code.google.com/p/chromium/issues/detail?id=423030
- https://code.google.com/p/chromium/issues/detail?id=423891
- https://code.google.com/p/chromium/issues/detail?id=424215
- https://code.google.com/p/chromium/issues/detail?id=424999
- https://code.google.com/p/chromium/issues/detail?id=425151
- https://code.google.com/p/chromium/issues/detail?id=425152
- https://code.google.com/p/chromium/issues/detail?id=433500
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98798
- https://www.exploit-db.com/exploits/34879/