CVE-2014-3197: XSS
The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attackers to obtain sensitive information via a crafted web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3197?
The severity of CVE-2014-3197 is classified as high due to the potential for sensitive information disclosure.
How do I fix CVE-2014-3197?
To fix CVE-2014-3197, users should upgrade to Google Chrome version 38.0.2125.101 or later.
Which versions of Google Chrome are affected by CVE-2014-3197?
CVE-2014-3197 affects Google Chrome versions prior to 38.0.2125.101.
Can CVE-2014-3197 be exploited remotely?
Yes, CVE-2014-3197 can be exploited remotely, allowing attackers to obtain sensitive information.
What systems are impacted by CVE-2014-3197?
CVE-2014-3197 impacts specific versions of Google Chrome and various Red Hat Enterprise Linux products.