{"api_version":"1","generated_at":"2026-07-23T09:05:48+00:00","cve":"CVE-2014-3166","urls":{"html":"https://cve.report/CVE-2014-3166","api":"https://cve.report/api/cve/CVE-2014-3166.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-3166","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-3166"},"summary":{"title":"CVE-2014-3166","description":"The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY connections, which allows remote attackers to obtain sensitive information by leveraging the use of multiple domain names.","state":"PUBLISHED","assigner":"Chrome","published_at":"2014-08-13 04:57:12","updated_at":"2026-05-06 22:30:45"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/59904","name":"http://secunia.com/advisories/59904","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ietf.org/mail-archive/web/tls/current/msg13345.html","name":"http://www.ietf.org/mail-archive/web/tls/current/msg13345.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Re: [TLS] Inter-protocol attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/60798","name":"http://secunia.com/advisories/60798","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About Secunia Research | Flexera","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://src.chromium.org/viewvc/chrome?revision=286598&view=revision","name":"https://src.chromium.org/viewvc/chrome?revision=286598&view=revision","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[chrome] Revision 286598","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/59693","name":"http://secunia.com/advisories/59693","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://security.gentoo.org/glsa/glsa-201408-16.xml","name":"http://security.gentoo.org/glsa/glsa-201408-16.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo Linux Documentation\n--\n  Chromium: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2014/dsa-3039","name":"http://www.debian.org/security/2014/dsa-3039","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-3039-1 chromium-browser","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/69202","name":"http://www.securityfocus.com/bid/69202","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Google Chrome CVE-2014-3166 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://googlechromereleases.blogspot.com/2014/08/chrome-for-android-update.html","name":"http://googlechromereleases.blogspot.com/2014/08/chrome-for-android-update.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Chrome Releases: Chrome for Android Update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://googlechromereleases.blogspot.com/2014/08/chrome-for-ios-update.html","name":"http://googlechromereleases.blogspot.com/2014/08/chrome-for-ios-update.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Chrome Releases: Chrome for iOS Update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/60685","name":"http://secunia.com/advisories/60685","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA60685 - Google Chrome for iOS SPDY Information Disclosure Vulnerability - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://code.google.com/p/chromium/issues/detail?id=398925","name":"https://code.google.com/p/chromium/issues/detail?id=398925","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Issue 398925 - \n chromium -\n \n Security: SPDY connection sharing logic errors allows for MITM - \n An open-source project to help move the web forward. - Google Project Hosting","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://googlechromereleases.blogspot.com/2014/08/stable-channel-update.html","name":"http://googlechromereleases.blogspot.com/2014/08/stable-channel-update.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Chrome Releases: Stable Channel Update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://src.chromium.org/viewvc/chrome?revision=288435&view=revision","name":"https://src.chromium.org/viewvc/chrome?revision=288435&view=revision","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[chrome] Revision 288435","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1030732","name":"http://www.securitytracker.com/id/1030732","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Google Chrome Multiple Bugs Let Remote Users Execute Arbitrary Code and Obtain Information - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-3166","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3166","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"3166","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"3166","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"google","cpe5":"chrome","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"3166","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"3166","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T10:35:56.615Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://src.chromium.org/viewvc/chrome?revision=286598&view=revision"},{"name":"59693","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/59693"},{"name":"[tls] 20140810 Re: Inter-protocol attacks","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.ietf.org/mail-archive/web/tls/current/msg13345.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://googlechromereleases.blogspot.com/2014/08/chrome-for-android-update.html"},{"name":"59904","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/59904"},{"name":"60685","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/60685"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://src.chromium.org/viewvc/chrome?revision=288435&view=revision"},{"name":"GLSA-201408-16","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://security.gentoo.org/glsa/glsa-201408-16.xml"},{"name":"60798","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/60798"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://code.google.com/p/chromium/issues/detail?id=398925"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://googlechromereleases.blogspot.com/2014/08/stable-channel-update.html"},{"name":"69202","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/69202"},{"name":"DSA-3039","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2014/dsa-3039"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://googlechromereleases.blogspot.com/2014/08/chrome-for-ios-update.html"},{"name":"1030732","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1030732"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-08-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY connections, which allows remote attackers to obtain sensitive information by leveraging the use of multiple domain names."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-01-04T20:57:01.000Z","orgId":"ebfee0ef-53dd-4cf3-9e2a-08a5bd7a7e28","shortName":"Chrome"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://src.chromium.org/viewvc/chrome?revision=286598&view=revision"},{"name":"59693","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/59693"},{"name":"[tls] 20140810 Re: Inter-protocol attacks","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.ietf.org/mail-archive/web/tls/current/msg13345.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://googlechromereleases.blogspot.com/2014/08/chrome-for-android-update.html"},{"name":"59904","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/59904"},{"name":"60685","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/60685"},{"tags":["x_refsource_CONFIRM"],"url":"https://src.chromium.org/viewvc/chrome?revision=288435&view=revision"},{"name":"GLSA-201408-16","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://security.gentoo.org/glsa/glsa-201408-16.xml"},{"name":"60798","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/60798"},{"tags":["x_refsource_CONFIRM"],"url":"https://code.google.com/p/chromium/issues/detail?id=398925"},{"tags":["x_refsource_CONFIRM"],"url":"http://googlechromereleases.blogspot.com/2014/08/stable-channel-update.html"},{"name":"69202","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/69202"},{"name":"DSA-3039","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2014/dsa-3039"},{"tags":["x_refsource_CONFIRM"],"url":"http://googlechromereleases.blogspot.com/2014/08/chrome-for-ios-update.html"},{"name":"1030732","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1030732"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@google.com","ID":"CVE-2014-3166","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY connections, which allows remote attackers to obtain sensitive information by leveraging the use of multiple domain names."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://src.chromium.org/viewvc/chrome?revision=286598&view=revision","refsource":"CONFIRM","url":"https://src.chromium.org/viewvc/chrome?revision=286598&view=revision"},{"name":"59693","refsource":"SECUNIA","url":"http://secunia.com/advisories/59693"},{"name":"[tls] 20140810 Re: Inter-protocol attacks","refsource":"MLIST","url":"http://www.ietf.org/mail-archive/web/tls/current/msg13345.html"},{"name":"http://googlechromereleases.blogspot.com/2014/08/chrome-for-android-update.html","refsource":"CONFIRM","url":"http://googlechromereleases.blogspot.com/2014/08/chrome-for-android-update.html"},{"name":"59904","refsource":"SECUNIA","url":"http://secunia.com/advisories/59904"},{"name":"60685","refsource":"SECUNIA","url":"http://secunia.com/advisories/60685"},{"name":"https://src.chromium.org/viewvc/chrome?revision=288435&view=revision","refsource":"CONFIRM","url":"https://src.chromium.org/viewvc/chrome?revision=288435&view=revision"},{"name":"GLSA-201408-16","refsource":"GENTOO","url":"http://security.gentoo.org/glsa/glsa-201408-16.xml"},{"name":"60798","refsource":"SECUNIA","url":"http://secunia.com/advisories/60798"},{"name":"https://code.google.com/p/chromium/issues/detail?id=398925","refsource":"CONFIRM","url":"https://code.google.com/p/chromium/issues/detail?id=398925"},{"name":"http://googlechromereleases.blogspot.com/2014/08/stable-channel-update.html","refsource":"CONFIRM","url":"http://googlechromereleases.blogspot.com/2014/08/stable-channel-update.html"},{"name":"69202","refsource":"BID","url":"http://www.securityfocus.com/bid/69202"},{"name":"DSA-3039","refsource":"DEBIAN","url":"http://www.debian.org/security/2014/dsa-3039"},{"name":"http://googlechromereleases.blogspot.com/2014/08/chrome-for-ios-update.html","refsource":"CONFIRM","url":"http://googlechromereleases.blogspot.com/2014/08/chrome-for-ios-update.html"},{"name":"1030732","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1030732"}]}}}},"cveMetadata":{"assignerOrgId":"ebfee0ef-53dd-4cf3-9e2a-08a5bd7a7e28","assignerShortName":"Chrome","cveId":"CVE-2014-3166","datePublished":"2014-08-13T01:00:00.000Z","dateReserved":"2014-05-03T00:00:00.000Z","dateUpdated":"2024-08-06T10:35:56.615Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-08-13 04:57:12","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndExcluding":"36.0.1985.143","matchCriteriaId":"BB447639-EAF0-473D-8099-C84C90FBE371"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*","matchCriteriaId":"4781BF1E-8A4E-4AFF-9540-23D523EE30DD"},{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndExcluding":"36.0.1985.135","matchCriteriaId":"004C2ADD-1573-4FEB-872C-49BB3576BA79"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:google:android:-:*:*:*:*:*:*:*","matchCriteriaId":"F8B9FEC8-73B6-43B8-B24E-1F7C20D91D26"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*","matchCriteriaId":"16F59A04-14CF-49E2-9973-645477EA09DA"},{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","matchCriteriaId":"C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndExcluding":"36.0.1985.57","matchCriteriaId":"A01A46B8-3882-4CA9-9866-2CA0359337F9"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*","matchCriteriaId":"B5415705-33E5-46D5-8E4D-9EBADC8C5705"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"3166","Ordinal":"1","Title":"CVE-2014-3166","CVE":"CVE-2014-3166","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"3166","Ordinal":"1","NoteData":"The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY connections, which allows remote attackers to obtain sensitive information by leveraging the use of multiple domain names.","Type":"Description","Title":"CVE-2014-3166"},{"CveYear":"2014","CveId":"3166","Ordinal":"2","NoteData":"2014-08-12","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"3166","Ordinal":"3","NoteData":"2017-01-04","Type":"Other","Title":"Modified"}]}}}