Google Security Advisories · January 2014 — Google Security Advisories
15 advisories 15 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2014-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2013-5349

GoogleEPSS <= 49%CRITICAL2014-01-09

Integer underflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a crafted JPEG tag that triggers a heap-based buffer overflow, as demonstrated using a Canon RAW CR2 file with a large JPE...

CVEs:CVE-2013-5349

Affected products

ProductStatusVendorPackageEcosystem
picasa affected google
Upstream advisory

CVE-2013-5357

GoogleEPSS <= 49%CRITICAL2014-01-09

Integer overflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a long TIFF tag that triggers a heap-based buffer overflow, as demonstrated using a Canon RAW CR2 file with a long TIFF Str...

CVEs:CVE-2013-5357

Affected products

ProductStatusVendorPackageEcosystem
picasa affected google
Upstream advisory

CVE-2013-5359

GoogleEPSS <= 49%CRITICAL2014-01-09

Stack-based buffer overflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 might allow remote attackers to execute arbitrary code via a crafted RAW file, as demonstrated using a KDC file with a certain size.

CVEs:CVE-2013-5359

Affected products

ProductStatusVendorPackageEcosystem
picasa affected google
Upstream advisory

CVE-2013-6650

GoogleEPSS <= 49%CRITICAL2014-01-28

The StoreBuffer::ExemptPopularPages function in store-buffer.cc in Google V8 before 3.22.24.16, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other i...

CVEs:CVE-2013-6650

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2013-6644

GoogleEPSS <= 49%HIGH2014-01-15

Multiple unspecified vulnerabilities in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2013-6644

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2013-6646

GoogleEPSS <= 49%CRITICAL2014-01-15

Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact ...

CVEs:CVE-2013-6646

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2013-6649

GoogleEPSS <= 49%CRITICAL2014-01-28

Use-after-free vulnerability in the RenderSVGImage::paint function in core/rendering/svg/RenderSVGImage.cpp in Blink, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service or possibly have unspecified other...

CVEs:CVE-2013-6649

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2013-6641

GoogleEPSS <= 49%CRITICAL2014-01-15

Use-after-free vulnerability in the FormAssociatedElement::formRemovedFromTree function in core/html/FormAssociatedElement.cpp in Blink, as used in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux, allows remot...

CVEs:CVE-2013-6641

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2013-6645

GoogleEPSS <= 49%CRITICAL2014-01-15

Use-after-free vulnerability in the OnWindowRemovingFromRootWindow function in content/browser/web_contents/web_contents_view_aura.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows user-assisted rem...

CVEs:CVE-2013-6645

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2013-5358

GoogleEPSS <= 49%CRITICAL2014-01-09

Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to trigger memory corruption via a crafted TIFF tag, as demonstrated using a KDC file with a DSLR-A100 model and certain sequences of tags.

CVEs:CVE-2013-5358

Affected products

ProductStatusVendorPackageEcosystem
picasa affected google
Upstream advisory

CVE-2014-1681

GoogleEPSS <= 49%HIGH2014-01-28

Multiple unspecified vulnerabilities in Google Chrome before 32.0.1700.102 have unknown impact and attack vectors, related to 12 "security fixes [that were not] either contributed by external researchers or particularly interesting."

CVEs:CVE-2014-1681

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-6643

GoogleEPSS <= 49%HIGH2014-01-15

The OneClickSigninBubbleView::WindowClosing function in browser/ui/views/sync/one_click_signin_bubble_view.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows attackers to trigger a sync with an arbit...

CVEs:CVE-2013-6643

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2012-2899

GoogleEPSS <= 49%CRITICAL2014-01-05

Google Chrome before 21.0.1180.82 on iOS makes certain incorrect calls to WebView methods that trigger use of an applewebdata: URL, which allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors invo...

CVEs:CVE-2012-2899

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-6642

GoogleEPSS <= 49%MEDIUM2014-01-15

Google Chrome through 32.0.1700.23 on Android allows remote attackers to spoof the address bar via unspecified vectors.

CVEs:CVE-2013-6642

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2898

GoogleEPSS <= 49%MEDIUM2014-01-05

Google Chrome before 21.0.1180.82 on iOS on iPad devices allows remote attackers to spoof the Omnibox URL via vectors involving SSL error messages, a related issue to CVE-2012-0674.

CVEs:CVE-2012-2898

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.