Google Security Advisories · November 2013 — Google Security Advisories
35 advisories 19 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2013-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

DSA-2799-1

Open SourceWeaponized exploit2013-11-16

chromium-browser - several

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:7 chromium-browser
Upstream advisory

MGASA-2013-0324

Open SourceWeaponized exploitCRITICAL2013-11-13

Updated chromium-browser-stable packages fix multiple vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:2 chromium-browser-stable
chromium-browser-stable affected Mageia:3 chromium-browser-stable
Upstream advisory

CVE-2013-6627

GoogleWeaponized exploitHIGH2013-11-13

net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP Informational (aka 1xx) status codes, which allows remote web servers to cause a denial of service (out-of-bounds read) via a crafted response.

CVEs:CVE-2013-6627

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-6629

GooglePoC exploitHIGH2013-11-14

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of seg...

CVEs:CVE-2013-6629

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
firefox affected mozilla
gpl_ghostscript affected artifex
libjpeg-turbo affected libjpeg-turbo
opensuse affected opensuse
seamonkey affected mozilla
solaris affected oracle
thunderbird affected mozilla
ubuntu_linux affected canonical
Upstream advisory

CVE-2013-4204

GooglePoC exploit2013-11-15

Improper Neutralization of Input During Web Page Generation in Google Web Toolkit

CVEs:CVE-2013-4204

Affected products

ProductStatusVendorPackageEcosystem
com.google.gwt:gwt affected Maven com.google.gwt:gwt
Upstream advisory

CVE-2013-4204

GooglePoC exploitCRITICAL2013-08-04

Multiple cross-site scripting (XSS) vulnerabilities in the JUnit files in the GWTTestCase in Google Web Toolkit (GWT) before 2.5.1 RC1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVEs:CVE-2013-4204

Affected products

ProductStatusVendorPackageEcosystem
web_toolkit affected google
Upstream advisory

CVE-2013-6632

GoogleEPSS <= 49%HIGH2013-11-15

Integer overflow in Google Chrome before 31.0.1650.57 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as demonstrated during a Mobile Pwn2Own competition at PacSec 2013.

CVEs:CVE-2013-6632

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2013-2931

GoogleEPSS <= 49%HIGH2013-11-13

Multiple unspecified vulnerabilities in Google Chrome before 31.0.1650.48 allow attackers to execute arbitrary code or possibly have other impact via unknown vectors.

CVEs:CVE-2013-2931

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-6630

GoogleEPSS <= 49%HIGH2013-11-15

The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Tab...

CVEs:CVE-2013-6630

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-6621

GoogleEPSS <= 49%CRITICAL2013-11-13

Use-after-free vulnerability in Google Chrome before 31.0.1650.48 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the x-webkit-speech attribute in a text INPUT element.

CVEs:CVE-2013-6621

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

MGASA-2013-0321

Open SourceEPSS <= 49%CRITICAL2013-11-09

Updated chromium-browser-stable packages fix multiple vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:2 chromium-browser-stable
chromium-browser-stable affected Mageia:3 chromium-browser-stable
Upstream advisory

CVE-2013-6631

GoogleEPSS <= 49%CRITICAL2013-11-15

Use-after-free vulnerability in the Channel::SendRTCPPacket function in voice_engine/channel.cc in libjingle in WebRTC, as used in Google Chrome before 31.0.1650.48 and other products, allows remote attackers to cause a denial of service (heap memory c...

CVEs:CVE-2013-6631

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-6625

GoogleEPSS <= 49%CRITICAL2013-11-13

Use-after-free vulnerability in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 31.0.1650.48, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper handling of DOM ran...

CVEs:CVE-2013-6625

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-6624

GoogleEPSS <= 49%CRITICAL2013-11-13

Use-after-free vulnerability in Google Chrome before 31.0.1650.48 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving the string values of id attributes.

CVEs:CVE-2013-6624

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-6623

GoogleEPSS <= 49%HIGH2013-11-13

The SVG implementation in Blink, as used in Google Chrome before 31.0.1650.48, allows remote attackers to cause a denial of service (out-of-bounds read) by leveraging the use of tree order, rather than transitive dependency order, for layout.

CVEs:CVE-2013-6623

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-6802

GoogleEPSS <= 49%MEDIUM2013-11-16

Google Chrome before 31.0.1650.57 allows remote attackers to bypass intended sandbox restrictions by leveraging access to a renderer process, as demonstrated during a Mobile Pwn2Own competition at PacSec 2013, a different vulnerability than CVE-2013-6632.

CVEs:CVE-2013-6802

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-6622

GoogleEPSS <= 49%CRITICAL2013-11-13

Use-after-free vulnerability in the HTMLMediaElement::didMoveToNewDocument function in core/html/HTMLMediaElement.cpp in Blink, as used in Google Chrome before 31.0.1650.48, allows remote attackers to cause a denial of service or possibly have unspecif...

CVEs:CVE-2013-6622

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-6626

GoogleEPSS <= 49%MEDIUM2013-11-13

The WebContentsImpl::AttachInterstitialPage function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 31.0.1650.48 does not cancel JavaScript dialogs upon generating an interstitial warning, which allows remote attackers to ...

CVEs:CVE-2013-6626

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-6628

GoogleEPSS <= 49%MEDIUM2013-11-13

net/socket/ssl_client_socket_nss.cc in the TLS implementation in Google Chrome before 31.0.1650.48 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which might allow remote web servers t...

CVEs:CVE-2013-6628

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-6392

Open SourceEPSS <= 49%MEDIUM2013-11-30

The genlock_dev_ioctl function in genlock.c in the Genlock driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly initialize a certain data structure, wh...

CVEs:CVE-2013-6392

Affected products

ProductStatusVendorPackageEcosystem
android-msm affected codeaurora
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.