CVE-2014-3174
Summary
| CVE | CVE-2014-3174 |
|---|---|
| State | PUBLISHED |
| Assigner | Chrome |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-08-27 01:55:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | modules/webaudio/BiquadDSPKernel.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 37.0.2062.94, does not properly consider concurrent threads during attempts to update biquad filter coefficients, which allows remote attackers to cause a denial of service (read of uninitialized memory) via crafted API calls. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Chrome | 37.0.2062.0 | All | All | All | |
| Application | Chrome | 37.0.2062.1 | All | All | All | |
| Application | Chrome | 37.0.2062.10 | All | All | All | |
| Application | Chrome | 37.0.2062.11 | All | All | All | |
| Application | Chrome | 37.0.2062.12 | All | All | All | |
| Application | Chrome | 37.0.2062.13 | All | All | All | |
| Application | Chrome | 37.0.2062.14 | All | All | All | |
| Application | Chrome | 37.0.2062.15 | All | All | All | |
| Application | Chrome | 37.0.2062.16 | All | All | All | |
| Application | Chrome | 37.0.2062.17 | All | All | All | |
| Application | Chrome | 37.0.2062.18 | All | All | All | |
| Application | Chrome | 37.0.2062.19 | All | All | All | |
| Application | Chrome | 37.0.2062.2 | All | All | All | |
| Application | Chrome | 37.0.2062.20 | All | All | All | |
| Application | Chrome | 37.0.2062.21 | All | All | All | |
| Application | Chrome | 37.0.2062.22 | All | All | All | |
| Application | Chrome | 37.0.2062.23 | All | All | All | |
| Application | Chrome | 37.0.2062.24 | All | All | All | |
| Application | Chrome | 37.0.2062.25 | All | All | All | |
| Application | Chrome | 37.0.2062.26 | All | All | All | |
| Application | Chrome | 37.0.2062.27 | All | All | All | |
| Application | Chrome | 37.0.2062.28 | All | All | All | |
| Application | Chrome | 37.0.2062.29 | All | All | All | |
| Application | Chrome | 37.0.2062.3 | All | All | All | |
| Application | Chrome | 37.0.2062.30 | All | All | All | |
| Application | Chrome | 37.0.2062.31 | All | All | All | |
| Application | Chrome | 37.0.2062.32 | All | All | All | |
| Application | Chrome | 37.0.2062.33 | All | All | All | |
| Application | Chrome | 37.0.2062.34 | All | All | All | |
| Application | Chrome | 37.0.2062.35 | All | All | All | |
| Application | Chrome | 37.0.2062.36 | All | All | All | |
| Application | Chrome | 37.0.2062.37 | All | All | All | |
| Application | Chrome | 37.0.2062.39 | All | All | All | |
| Application | Chrome | 37.0.2062.4 | All | All | All | |
| Application | Chrome | 37.0.2062.43 | All | All | All | |
| Application | Chrome | 37.0.2062.44 | All | All | All | |
| Application | Chrome | 37.0.2062.45 | All | All | All | |
| Application | Chrome | 37.0.2062.46 | All | All | All | |
| Application | Chrome | 37.0.2062.47 | All | All | All | |
| Application | Chrome | 37.0.2062.48 | All | All | All | |
| Application | Chrome | 37.0.2062.49 | All | All | All | |
| Application | Chrome | 37.0.2062.5 | All | All | All | |
| Application | Chrome | 37.0.2062.50 | All | All | All | |
| Application | Chrome | 37.0.2062.51 | All | All | All | |
| Application | Chrome | 37.0.2062.52 | All | All | All | |
| Application | Chrome | 37.0.2062.53 | All | All | All | |
| Application | Chrome | 37.0.2062.54 | All | All | All | |
| Application | Chrome | 37.0.2062.55 | All | All | All | |
| Application | Chrome | 37.0.2062.56 | All | All | All | |
| Application | Chrome | 37.0.2062.57 | All | All | All | |
| Application | Chrome | 37.0.2062.58 | All | All | All | |
| Application | Chrome | 37.0.2062.59 | All | All | All | |
| Application | Chrome | 37.0.2062.6 | All | All | All | |
| Application | Chrome | 37.0.2062.60 | All | All | All | |
| Application | Chrome | 37.0.2062.61 | All | All | All | |
| Application | Chrome | 37.0.2062.62 | All | All | All | |
| Application | Chrome | 37.0.2062.63 | All | All | All | |
| Application | Chrome | 37.0.2062.64 | All | All | All | |
| Application | Chrome | 37.0.2062.65 | All | All | All | |
| Application | Chrome | 37.0.2062.66 | All | All | All | |
| Application | Chrome | 37.0.2062.67 | All | All | All | |
| Application | Chrome | 37.0.2062.68 | All | All | All | |
| Application | Chrome | 37.0.2062.69 | All | All | All | |
| Application | Chrome | 37.0.2062.7 | All | All | All | |
| Application | Chrome | 37.0.2062.70 | All | All | All | |
| Application | Chrome | 37.0.2062.71 | All | All | All | |
| Application | Chrome | 37.0.2062.72 | All | All | All | |
| Application | Chrome | 37.0.2062.73 | All | All | All | |
| Application | Chrome | 37.0.2062.74 | All | All | All | |
| Application | Chrome | 37.0.2062.75 | All | All | All | |
| Application | Chrome | 37.0.2062.76 | All | All | All | |
| Application | Chrome | 37.0.2062.77 | All | All | All | |
| Application | Chrome | 37.0.2062.78 | All | All | All | |
| Application | Chrome | 37.0.2062.8 | All | All | All | |
| Application | Chrome | 37.0.2062.80 | All | All | All | |
| Application | Chrome | 37.0.2062.81 | All | All | All | |
| Application | Chrome | 37.0.2062.89 | All | All | All | |
| Application | Chrome | 37.0.2062.9 | All | All | All | |
| Application | Chrome | 37.0.2062.90 | All | All | All | |
| Application | Chrome | 37.0.2062.91 | All | All | All | |
| Application | Chrome | 37.0.2062.92 | All | All | All | |
| Application | Chrome | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Advisory SA61482 - SUSE update for chromium - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [blink] Revision 177250 | af854a3a-2127-422b-91ae-364da2661108 | src.chromium.org | |
| Gentoo Linux Documentation -- Chromium: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Google Chrome Multiple Bugs Let Remote Users Execute Arbitrary Code and Obtain Information - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| [security-announce] openSUSE-SU-2014:1151-1: important: chromium to 37.0 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Debian -- Security Information -- DSA-3039-1 chromium-browser | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Chrome Releases: Stable Channel Update | af854a3a-2127-422b-91ae-364da2661108 | googlechromereleases.blogspot.com | |
| Security Advisory SA60424 - Ubuntu update for oxide-qt - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Google Chrome CVE-2014-3174 Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Issue 389219 - chromium - Use-of-uninitialized-value in WebCore::BiquadDSPKernel::updateCoefficientsIfNecessary - An open-source project to help move the web forward. - Google Project Hosting | af854a3a-2127-422b-91ae-364da2661108 | crbug.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.