{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-21T08:05:27.352","vulnerabilities":[{"cve":{"id":"CVE-2014-7939","sourceIdentifier":"chrome-cve-admin@google.com","published":"2015-01-22T22:59:20.117","lastModified":"2026-06-17T00:15:59.297","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an \"X-Content-Type-Options: nosniff\" header."},{"lang":"es","value":"Google Chrome anterior aq 40.0.2214.91, cuando el proxy Harmony en Google V8 está habilitado, permite a atacantes remotos evadir Same Origin Policy a través de código JavaScript manipulado con llamadas Proxy.create y console.log, relacionado con respuestas HTTP a que les falta una cabecera'X-Content-Type-Options: nosniff'."}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-264"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*","versionEndIncluding":"40.0.2214.85","matchCriteriaId":"B248CC65-0394-4432-9520-52E99C17EA4A"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:chromium:chromium:40.0.2214.110:*:*:*:*:*:*:*","matchCriteriaId":"3498003A-1D2A-4C87-901F-C76C02DAE271"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_desktop_supplementary:6.0:*:*:*:*:*:*:*","matchCriteriaId":"B8C6E104-EDBC-481E-85B8-D39ED2058D39"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_server_supplementary:6.0:*:*:*:*:*:*:*","matchCriteriaId":"4B74C62D-4A6D-4A4F-ADF6-A508322CD447"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_server_supplementary_eus:6.6.z:*:*:*:*:*:*:*","matchCriteriaId":"04A2B180-08EF-4BE1-B1F2-48782874D6DB"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_workstation_supplementary:6.0:*:*:*:*:*:*:*","matchCriteriaId":"6E89B38A-3697-46DD-BB3F-E8D2373588BE"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*","matchCriteriaId":"A10BC294-9196-425F-9FB0-B1625465B47F"},{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*","matchCriteriaId":"03117DF1-3BEC-4B8D-AD63-DBBDB2126081"}]}]}],"references":[{"url":"http://googlechromereleases.blogspot.com/2015/01/stable-update.html","source":"chrome-cve-admin@google.com"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.html","source":"chrome-cve-admin@google.com"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-0093.html","source":"chrome-cve-admin@google.com"},{"url":"http://secunia.com/advisories/62383","source":"chrome-cve-admin@google.com"},{"url":"http://secunia.com/advisories/62665","source":"chrome-cve-admin@google.com"},{"url":"http://security.gentoo.org/glsa/glsa-201502-13.xml","source":"chrome-cve-admin@google.com"},{"url":"http://www.securityfocus.com/bid/72288","source":"chrome-cve-admin@google.com"},{"url":"http://www.securitytracker.com/id/1031623","source":"chrome-cve-admin@google.com"},{"url":"https://code.google.com/p/chromium/issues/detail?id=399951","source":"chrome-cve-admin@google.com"},{"url":"http://googlechromereleases.blogspot.com/2015/01/stable-update.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-0093.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://secunia.com/advisories/62383","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://secunia.com/advisories/62665","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://security.gentoo.org/glsa/glsa-201502-13.xml","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/72288","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securitytracker.com/id/1031623","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://code.google.com/p/chromium/issues/detail?id=399951","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}