CVE-2014-1748
The ScrollView::paint function in platform/scroll/ScrollView.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to spoof the UI by extending scrollbar painting into the parent frame.
Ver en NVDSeveridad
N/A
EPSS
Probabilidad de explotación (próx. 30 días): 0.0064 (0.6%)
Percentil: 70.5%
EPSS: 2026-05-06
Afecta
google:chromeDescripción técnica
The ScrollView::paint function in platform/scroll/ScrollView.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to spoof the UI by extending scrollbar painting into the parent frame.
Publicada: 21/5/2014, 11:14:09
Última modificación: 6/5/2026, 22:30:45
Referencias
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- http://lists.apple.com/archives/security-announce/2014/Dec/msg00000.html
- http://lists.opensuse.org/opensuse-updates/2014-06/msg00023.html
- http://lists.opensuse.org/opensuse-updates/2016-03/msg00132.html
- http://secunia.com/advisories/58920
- http://secunia.com/advisories/59155
- http://secunia.com/advisories/60372
- http://security.gentoo.org/glsa/glsa-201408-16.xml