CVE-2014-3157

CVSS V2 High 7.5 CVSS V3 None
Description
Heap-based buffer overflow in the FFmpegVideoDecoder::GetVideoBuffer function in media/filters/ffmpeg_video_decoder.cc in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging VideoFrame data structures that are too small for proper interaction with an underlying FFmpeg library.
Overview
  • CVE ID
  • CVE-2014-3157
  • Assigner
  • cve-coordination@google.com
  • Vulnerability Status
  • Modified
  • Published Version
  • 2014-06-11T10:57:18
  • Last Modified Date
  • 2017-12-29T02:29:21
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* 1 OR 35.0.1916.152
cpe:2.3:a:google:chrome:35.0.1916.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.9:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.10:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.11:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.13:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.14:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.15:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.17:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.18:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.19:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.20:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.21:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.22:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.23:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.27:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.31:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.32:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.33:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.34:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.35:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.36:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.37:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.38:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.39:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.40:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.41:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.42:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.43:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.44:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.45:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.46:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.47:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.48:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.49:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.51:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.52:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.54:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.56:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.57:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.59:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.61:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.68:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.69:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.71:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.72:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.74:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.77:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.80:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.82:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.84:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.85:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.86:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.88:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.90:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.92:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.93:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.95:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.96:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.98:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.99:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.101:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.103:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.104:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.105:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.106:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.107:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.108:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.109:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.110:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.111:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.112:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.113:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.114:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.115:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.116:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.117:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.118:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.119:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.120:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.121:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.122:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.123:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.124:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.125:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.126:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.127:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.128:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.137:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.138:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.140:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.141:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.142:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.149:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.150:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:google:chrome:35.0.1916.151:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:L/Au:N/C:P/I:P/A:P
  • Access Vector
  • NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 7.5
  • Severity
  • HIGH
  • Exploitability Score
  • 10
  • Impact Score
  • 6.4
History
Created Old Value New Value Data Type Notes
2022-05-10 18:54:03 Added to TrackCVE
2022-12-01 23:30:47 security@google.com cve-coordination@google.com CVE Assigner updated
2022-12-01 23:30:47 2014-06-11T10:57Z 2014-06-11T10:57:18 CVE Published Date updated
2022-12-01 23:30:47 2017-12-29T02:29:21 CVE Modified Date updated
2022-12-01 23:30:47 Modified Vulnerability Status updated