Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-3166


The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY connections, which allows remote attackers to obtain sensitive information by leveraging the use of multiple domain names.


Published

2014-08-13T04:57:12.613

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application google chrome < 36.0.1985.143 Yes
Operating System apple mac_os_x - No
Operating System linux linux_kernel - No
Operating System microsoft windows - No
Application google chrome < 36.0.1985.135 Yes
Operating System google android - No
Operating System debian debian_linux 7.0 Yes
Operating System debian debian_linux 8.0 Yes
Application google chrome < 36.0.1985.57 Yes
Operating System apple iphone_os - No

References