CVE-2014-1741

high
Published 2014-05-14 ยท Modified 2026-05-06
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
7.5

Description

Multiple integer overflows in the replace-data functionality in the CharacterData interface implementation in core/dom/CharacterData.cpp in Blink, as used in Google Chrome before 34.0.1847.137, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to ranges.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
gcp googlechrome{"endIncluding":"34.0.1847.136"}
gcp googlechrome34.0.1847.0
gcp googlechrome34.0.1847.1
gcp googlechrome34.0.1847.2
gcp googlechrome34.0.1847.3
gcp googlechrome34.0.1847.4
gcp googlechrome34.0.1847.5
gcp googlechrome34.0.1847.6
gcp googlechrome34.0.1847.7
gcp googlechrome34.0.1847.8
gcp googlechrome34.0.1847.9
gcp googlechrome34.0.1847.10
gcp googlechrome34.0.1847.12
gcp googlechrome34.0.1847.14
gcp googlechrome34.0.1847.15
gcp googlechrome34.0.1847.23
gcp googlechrome34.0.1847.24
gcp googlechrome34.0.1847.25
gcp googlechrome34.0.1847.36
gcp googlechrome34.0.1847.37
gcp googlechrome34.0.1847.38
gcp googlechrome34.0.1847.39
gcp googlechrome34.0.1847.41
gcp googlechrome34.0.1847.42
gcp googlechrome34.0.1847.43
gcp googlechrome34.0.1847.44
gcp googlechrome34.0.1847.45
gcp googlechrome34.0.1847.46
gcp googlechrome34.0.1847.47
gcp googlechrome34.0.1847.48
gcp googlechrome34.0.1847.49
gcp googlechrome34.0.1847.50
gcp googlechrome34.0.1847.51
gcp googlechrome34.0.1847.52
gcp googlechrome34.0.1847.53
gcp googlechrome34.0.1847.54
gcp googlechrome34.0.1847.55
gcp googlechrome34.0.1847.56
gcp googlechrome34.0.1847.57
gcp googlechrome34.0.1847.58
gcp googlechrome34.0.1847.59
gcp googlechrome34.0.1847.60
gcp googlechrome34.0.1847.61
gcp googlechrome34.0.1847.62
gcp googlechrome34.0.1847.63
gcp googlechrome34.0.1847.64
gcp googlechrome34.0.1847.65
gcp googlechrome34.0.1847.66
gcp googlechrome34.0.1847.67
gcp googlechrome34.0.1847.68
gcp googlechrome34.0.1847.69
gcp googlechrome34.0.1847.71
gcp googlechrome34.0.1847.72
gcp googlechrome34.0.1847.73
gcp googlechrome34.0.1847.74
gcp googlechrome34.0.1847.75
gcp googlechrome34.0.1847.76
gcp googlechrome34.0.1847.77
gcp googlechrome34.0.1847.78
gcp googlechrome34.0.1847.79
gcp googlechrome34.0.1847.80
gcp googlechrome34.0.1847.81
gcp googlechrome34.0.1847.82
gcp googlechrome34.0.1847.83
gcp googlechrome34.0.1847.85
gcp googlechrome34.0.1847.86
gcp googlechrome34.0.1847.87
gcp googlechrome34.0.1847.91
gcp googlechrome34.0.1847.92
gcp googlechrome34.0.1847.94
gcp googlechrome34.0.1847.97
gcp googlechrome34.0.1847.98
gcp googlechrome34.0.1847.99
gcp googlechrome34.0.1847.100
gcp googlechrome34.0.1847.101
gcp googlechrome34.0.1847.102
gcp googlechrome34.0.1847.103
gcp googlechrome34.0.1847.104
gcp googlechrome34.0.1847.109
gcp googlechrome34.0.1847.111
gcp googlechrome34.0.1847.112
gcp googlechrome34.0.1847.113
gcp googlechrome34.0.1847.114
gcp googlechrome34.0.1847.115
gcp googlechrome34.0.1847.116
gcp googlechrome34.0.1847.118
gcp googlechrome34.0.1847.120
gcp googlechrome34.0.1847.130
gcp googlechrome34.0.1847.131
gcp googlechrome34.0.1847.132
gcp googlechrome34.0.1847.133
gcp googlechrome34.0.1847.134
gcp googlechrome34.0.1847.135

References

CWEs

CWE-189

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.