Use-after-free vulnerability in the AttributeSetter function in bindings/templates/attributes.cpp in the bindings in Blink, as used in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving the document.location value.
2014-03-16T14:06:45.617
2025-04-12T10:46:40.837
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | chrome | < 33.0.1750.152 | Yes | |
Operating System | apple | mac_os_x | - | No |
Operating System | linux | linux_kernel | - | No |
Application | chrome | < 33.0.1750.154 | Yes | |
Operating System | microsoft | windows | - | No |