Google Security Advisories · October 2013 — Google Security Advisories
28 advisories 28 CVEs 3 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2013-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 3 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

DSA-2785-1

Open SourceExploitedVulnCheck KEV listed2013-10-26

chromium-browser - several

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:7 chromium-browser
Upstream advisory

MGASA-2013-0306

Open SourceExploitedVulnCheck KEV listedCRITICAL2013-10-17

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:2 chromium-browser-stable
chromium-browser-stable affected Mageia:3 chromium-browser-stable
Upstream advisory

CVE-2013-2912

GoogleExploitedVulnCheck KEV listedCRITICAL2013-10-01

Use-after-free vulnerability in the PepperInProcessRouter::SendToHost function in content/renderer/pepper/pepper_in_process_router.cc in the Pepper Plug-in API (PPAPI) in Google Chrome before 30.0.1599.66 allows remote attackers to cause a denial of se...

CVEs:CVE-2013-2912

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2924

GoogleEPSS <= 49%CRITICAL2013-10-01

Use-after-free vulnerability in International Components for Unicode (ICU), as used in Google Chrome before 30.0.1599.66 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vect...

CVEs:CVE-2013-2924

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-4384

GoogleEPSS <= 49%CRITICAL2013-10-09

Cross-site scripting (XSS) vulnerability in Google Site Search module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.10 for Drupal allows remote attackers to inject arbitrary web script or HTML by causing crafted data to be returned by the Google API.

CVEs:CVE-2013-4384

Affected products

ProductStatusVendorPackageEcosystem
google_site_search_module affected google_site_search_project
Upstream advisory

CVE-2013-2919

GoogleEPSS <= 49%CRITICAL2013-10-01

Google V8, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2013-2919

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2013-2909

GoogleEPSS <= 49%CRITICAL2013-10-01

Use-after-free vulnerability in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to inline-block rendering for bidirectional Unicode ...

CVEs:CVE-2013-2909

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2927

GoogleEPSS <= 49%CRITICAL2013-10-16

Use-after-free vulnerability in the HTMLFormElement::prepareForSubmission function in core/html/HTMLFormElement.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows remote attackers to cause a denial of service or possibly have unspecifi...

CVEs:CVE-2013-2927

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2013-2926

GoogleEPSS <= 49%CRITICAL2013-10-16

Use-after-free vulnerability in the IndentOutdentCommand::tryIndentingAsListItem function in core/editing/IndentOutdentCommand.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows user-assisted remote attackers to cause a denial of servi...

CVEs:CVE-2013-2926

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2917

GoogleEPSS <= 49%HIGH2013-10-01

The ReverbConvolverStage::ReverbConvolverStage function in core/platform/audio/ReverbConvolverStage.cpp in the Web Audio implementation in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service (out-of...

CVEs:CVE-2013-2917

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2920

GoogleEPSS <= 49%HIGH2013-10-01

The DoResolveRelativeHost function in url/url_canon_relative.cc in Google Chrome before 30.0.1599.66 allows remote attackers to cause a denial of service (out-of-bounds read) via a relative URL containing a hostname, as demonstrated by a protocol-relat...

CVEs:CVE-2013-2920

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2910

GoogleEPSS <= 49%CRITICAL2013-10-01

Use-after-free vulnerability in modules/webaudio/AudioScheduledSourceNode.cpp in the Web Audio implementation in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified othe...

CVEs:CVE-2013-2910

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2918

GoogleEPSS <= 49%CRITICAL2013-10-01

Use-after-free vulnerability in the RenderBlock::collapseAnonymousBlockChild function in core/rendering/RenderBlock.cpp in the DOM implementation in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of servi...

CVEs:CVE-2013-2918

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2907

GoogleEPSS <= 49%HIGH2013-10-01

The Window.prototype object implementation in Google Chrome before 30.0.1599.66 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2013-2907

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2925

GoogleEPSS <= 49%CRITICAL2013-10-16

Use-after-free vulnerability in core/xml/XMLHttpRequest.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger multiple confli...

CVEs:CVE-2013-2925

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2923

GoogleEPSS <= 49%HIGH2013-10-01

Multiple unspecified vulnerabilities in Google Chrome before 30.0.1599.66 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2013-2923

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2928

GoogleEPSS <= 49%HIGH2013-10-16

Multiple unspecified vulnerabilities in Google Chrome before 30.0.1599.101 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2013-2928

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2911

GoogleEPSS <= 49%CRITICAL2013-10-01

Use-after-free vulnerability in the XSLStyleSheet::compileStyleSheet function in core/xml/XSLStyleSheetLibxslt.cpp in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified...

CVEs:CVE-2013-2911

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2913

GoogleEPSS <= 49%CRITICAL2013-10-01

Use-after-free vulnerability in the XMLDocumentParser::append function in core/xml/parser/XMLDocumentParser.cpp in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified ot...

CVEs:CVE-2013-2913

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2921

GoogleEPSS <= 49%CRITICAL2013-10-01

Double free vulnerability in the ResourceFetcher::didLoadResource function in core/fetch/ResourceFetcher.cpp in the resource loader in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly...

CVEs:CVE-2013-2921

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2922

GoogleEPSS <= 49%CRITICAL2013-10-01

Use-after-free vulnerability in core/html/HTMLTemplateElement.cpp in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that op...

CVEs:CVE-2013-2922

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2908

GoogleEPSS <= 49%MEDIUM2013-10-01

Google Chrome before 30.0.1599.66 uses incorrect function calls to determine the values of NavigationEntry objects, which allows remote attackers to spoof the address bar via vectors involving a response with a 204 (aka No Content) status code.

CVEs:CVE-2013-2908

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2914

GoogleEPSS <= 49%CRITICAL2013-10-01

Use-after-free vulnerability in the color-chooser dialog in Google Chrome before 30.0.1599.66 on Windows allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to color_chooser_dialog.cc and c...

CVEs:CVE-2013-2914

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2906

GoogleEPSS <= 49%HIGH2013-10-01

Multiple race conditions in the Web Audio implementation in Blink, as used in Google Chrome before 30.0.1599.66, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to threading in core/html...

CVEs:CVE-2013-2906

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2915

GoogleEPSS <= 49%MEDIUM2013-10-01

Google Chrome before 30.0.1599.66 preserves pending NavigationEntry objects in certain invalid circumstances, which allows remote attackers to spoof the address bar via a URL with a malformed scheme, as demonstrated by a nonexistent:12121 URL.

CVEs:CVE-2013-2915

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2916

GoogleEPSS <= 49%MEDIUM2013-10-01

Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to spoof the address bar via vectors involving a response with a 204 (aka No Content) status code, in conjunction with a delay in notifying the user of an attempted spoof.

CVEs:CVE-2013-2916

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-4738

Open SourceEPSS <= 49%CRITICAL2013-10-15

Multiple stack-based buffer overflows in the MSM camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allow attackers to gain privileges via (1) a crafted VIDIOC_...

CVEs:CVE-2013-4738

Affected products

ProductStatusVendorPackageEcosystem
android-msm affected codeaurora
quic_mobile_station_modem_kernel affected qualcomm
Upstream advisory

CVE-2013-4739

Open SourceEPSS <= 49%HIGH2013-10-15

The MSM camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to obtain sensitive information from kernel stack memory via (1) a crafted MSM_MCR_I...

CVEs:CVE-2013-4739

Affected products

ProductStatusVendorPackageEcosystem
android-msm affected codeaurora
quic_mobile_station_modem_kernel affected qualcomm
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.