CVE-2014-3175

Description

Multiple unspecified vulnerabilities in Google Chrome before 37.0.2062.94 allow attackers to cause a denial of service or possibly have other impact via unknown vectors, related to the load_truetype_glyph function in truetype/ttgload.c in FreeType and other functions in other components.

10.0
CVSS
Severity: Critical
CVSS 2.0 •
EPSS 2.03% Top 20%
Vendor Advisory gentoo.org Vendor Advisory opensuse.org Vendor Advisory debian.org
Affected: n/a n/a
Published at:
Updated at:

References

Link Tags
https://code.google.com/p/chromium/issues/detail?id=389216
https://code.google.com/p/chromium/issues/detail?id=389280
https://code.google.com/p/chromium/issues/detail?id=382242
https://code.google.com/p/chromium/issues/detail?id=393938
https://code.google.com/p/chromium/issues/detail?id=357452
https://code.google.com/p/chromium/issues/detail?id=382243
http://www.securityfocus.com/bid/69402 vdb entry
https://code.google.com/p/chromium/issues/detail?id=379656
https://code.google.com/p/chromium/issues/detail?id=382240
https://code.google.com/p/chromium/issues/detail?id=387371
https://code.google.com/p/chromium/issues/detail?id=389570
https://code.google.com/p/chromium/issues/detail?id=382639
https://code.google.com/p/chromium/issues/detail?id=396255
https://code.google.com/p/chromium/issues/detail?id=364062
http://googlechromereleases.blogspot.com/2014/08/stable-channel-update_26.html
https://code.google.com/p/chromium/issues/detail?id=382656
https://code.google.com/p/chromium/issues/detail?id=384662
https://code.google.com/p/chromium/issues/detail?id=381244
https://code.google.com/p/chromium/issues/detail?id=390176
http://secunia.com/advisories/60424 third party advisory
https://code.google.com/p/chromium/issues/detail?id=372410
https://code.google.com/p/chromium/issues/detail?id=368978
https://code.google.com/p/chromium/issues/detail?id=372413
http://security.gentoo.org/glsa/glsa-201408-16.xml vendor advisory
https://code.google.com/p/chromium/issues/detail?id=390304
https://code.google.com/p/chromium/issues/detail?id=389285
https://code.google.com/p/chromium/issues/detail?id=382601
https://code.google.com/p/chromium/issues/detail?id=366687
https://code.google.com/p/chromium/issues/detail?id=383703
https://code.google.com/p/chromium/issues/detail?id=350782
https://code.google.com/p/chromium/issues/detail?id=381031
https://code.google.com/p/chromium/issues/detail?id=382606
https://code.google.com/p/chromium/issues/detail?id=367991
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00027.html vendor advisory
https://code.google.com/p/chromium/issues/detail?id=381521
https://code.google.com/p/chromium/issues/detail?id=389316
https://crbug.com/406143
https://code.google.com/p/chromium/issues/detail?id=149871
https://code.google.com/p/chromium/issues/detail?id=388771
http://secunia.com/advisories/60268 third party advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/95475 vdb entry
https://code.google.com/p/chromium/issues/detail?id=382820
http://www.securitytracker.com/id/1030767 vdb entry
https://code.google.com/p/chromium/issues/detail?id=387315
https://code.google.com/p/chromium/issues/detail?id=387016
http://www.debian.org/security/2014/dsa-3039 vendor advisory
https://code.google.com/p/chromium/issues/detail?id=394026
https://code.google.com/p/chromium/issues/detail?id=382241
https://code.google.com/p/chromium/issues/detail?id=395972
https://code.google.com/p/chromium/issues/detail?id=337572
https://code.google.com/p/chromium/issues/detail?id=397258

Frequently Asked Questions

What is the severity of CVE-2014-3175?
CVE-2014-3175 has been scored as a critical severity vulnerability.
How to fix CVE-2014-3175?
To fix CVE-2014-3175, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2014-3175 being actively exploited in the wild?
It is possible that CVE-2014-3175 is being exploited or will be exploited in a near future based on public information. According to its EPSS score, there is a ~2% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.