CVE-2014-3152 describes an integer underflow vulnerability in the LCodeGen::PrepareKeyedOperand function of Google V8, affecting Google Chrome and Fedora Project products. This flaw allows remote attackers to trigger a negative key value, potentially leading to a denial of service or other unspecified impacts. With a CVSS score of 7.5, it is considered highly severe due to its network-based attack vector and low attack complexity, enabling partial confidentiality, integrity, and availability compromise. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
20CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:* | ||
21CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:* | ||
22CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:* | ||
<= 3.25.28CPE matchmatch criteria | cpe:2.3:a:google:v8:*:*:*:*:*:*:*:* | ||
3.25.0CPE matchmatch criteria | cpe:2.3:a:google:v8:3.25.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.