Google Security Advisories · December 2013 — Google Security Advisories
11 advisories 11 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2013-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2013-6271

Open SourceActive exploitation (sightings)HIGH2013-12-14

Android 4.0 through 4.3 allows attackers to bypass intended access restrictions and remove device locks via a crafted application that invokes the updateUnlockMethodAndFinish method in the com.android.settings.ChooseLockGeneric class with the PASSWORD_...

CVEs:CVE-2013-6271

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MGASA-2013-0383

Open SourceEPSS <= 49%HIGH2013-12-23

Updated chromium-browser-stable fixes multiple vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:3 chromium-browser-stable
Upstream advisory

DSA-2811-1

Open SourceEPSS <= 49%2013-12-07

chromium-browser - several

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:7 chromium-browser
Upstream advisory

CVE-2013-6638

GoogleEPSS <= 49%CRITICAL2013-12-05

Multiple buffer overflows in runtime.cc in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a large typed ar...

CVEs:CVE-2013-6638

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
v8 affected google
Upstream advisory

CVE-2013-6639

GoogleEPSS <= 49%CRITICAL2013-12-05

The DehoistArrayIndex function in hydrogen-dehoist.cc (aka hydrogen.cc) in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified...

CVEs:CVE-2013-6639

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
v8 affected google
Upstream advisory

CVE-2013-6640

GoogleEPSS <= 49%HIGH2013-12-05

The DehoistArrayIndex function in hydrogen-dehoist.cc (aka hydrogen.cc) in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cause a denial of service (out-of-bounds read) via JavaScript code that sets...

CVEs:CVE-2013-6640

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
v8 affected google
Upstream advisory

CVE-2013-6635

GoogleEPSS <= 49%CRITICAL2013-12-05

Use-after-free vulnerability in the editing implementation in Blink, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via JavaScript code that triggers removal ...

CVEs:CVE-2013-6635

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-6634

GoogleEPSS <= 49%MEDIUM2013-12-05

The OneClickSigninHelper::ShowInfoBarIfPossible function in browser/ui/sync/one_click_signin_helper.cc in Google Chrome before 31.0.1650.63 uses an incorrect URL during realm validation, which allows remote attackers to conduct session fixation attacks...

CVEs:CVE-2013-6634

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-6637

GoogleEPSS <= 49%HIGH2013-12-05

Multiple unspecified vulnerabilities in Google Chrome before 31.0.1650.63 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2013-6637

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-6636

GoogleEPSS <= 49%MEDIUM2013-12-05

The FrameLoader::notifyIfInitialDocumentAccessed function in core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 31.0.1650.63, makes an incorrect check for an empty document during presentation of a modal dialog, which allows remote a...

CVEs:CVE-2013-6636

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-6123

Open SourceEPSS <= 49%MEDIUM2013-12-14

Multiple array index errors in drivers/media/video/msm/server/msm_cam_server.c in the MSM camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allow attackers to ...

CVEs:CVE-2013-6123

Affected products

ProductStatusVendorPackageEcosystem
android-msm affected codeaurora
quic_mobile_station_modem_kernel affected qualcomm
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.