Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-3160
Description:The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file.
Test IDs: 1.3.6.1.4.1.25623.1.0.703039  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-3160
BugTraq ID: 68677
http://www.securityfocus.com/bid/68677
Debian Security Information: DSA-3039 (Google Search)
http://www.debian.org/security/2014/dsa-3039
http://security.gentoo.org/glsa/glsa-201408-16.xml
http://secunia.com/advisories/60061
http://secunia.com/advisories/60372




© 1998-2025 E-Soft Inc. All rights reserved.