Advisories
Open SourceWeaponized exploitHIGH2014-03-03
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, which allows remote attackers to execute arbitrary methods of Java objects or cause a denial of service (r...
CVEs:CVE-2013-4710
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceWeaponized exploitCRITICAL2014-03-03
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary methods of Java objects by using the Java Reflection API within crafted JavaScript code that is loaded in...
CVEs:CVE-2012-6636
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android_api |
affected |
google |
— |
— |
Open SourceWeaponized exploitHIGH2014-03-30
The CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.3 and 4.4 does not properly restrict the set of users who can execute /system/xbin/su with the --daemon option, which allows attackers to gain privileges by leveraging ADB shell...
CVEs:CVE-2013-6770
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| superuser |
affected |
koushik_dutta |
— |
— |
Open SourcePoC exploit2014-03-23
chromium-browser - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser |
affected |
Debian:7 |
chromium-browser |
— |
Open SourcePoC exploitCRITICAL2014-03-06
Updated chromium-browser-stable package fixes security vulnerabilities
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:3 |
chromium-browser-stable |
— |
| chromium-browser-stable |
affected |
Mageia:4 |
chromium-browser-stable |
— |
GooglePoC exploitHIGH2014-03-04
Multiple unspecified vulnerabilities in Google V8 before 3.24.35.10, as used in Google Chrome before 33.0.1750.146, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2013-6668
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| node.js |
affected |
nodejs |
— |
— |
| v8 |
affected |
google |
— |
— |
Open SourcePoC exploitCRITICAL2014-03-19
Updated chromium-browser-stable packages fix security vulnerabilities
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:3 |
chromium-browser-stable |
— |
| chromium-browser-stable |
affected |
Mageia:4 |
chromium-browser-stable |
— |
GooglePoC exploitCRITICAL2014-03-16
Use-after-free vulnerability in the AttributeSetter function in bindings/templates/attributes.cpp in the bindings in Blink, as used in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows, allows remote attackers to ...
CVEs:CVE-2014-1713
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GooglePoC exploitCRITICAL2014-03-04
Use-after-free vulnerability in the SVGImage::setContainerSize function in core/svg/graphics/SVGImage.cpp in the SVG implementation in Blink, as used in Google Chrome before 33.0.1750.146, allows remote attackers to cause a denial of service or possibl...
CVEs:CVE-2013-6663
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GooglePoC exploitCRITICAL2014-03-04
Heap-based buffer overflow in the ResourceProvider::InitializeSoftware function in cc/resources/resource_provider.cc in Google Chrome before 33.0.1750.146 allows remote attackers to cause a denial of service or possibly have unspecified other impact vi...
CVEs:CVE-2013-6665
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GooglePoC exploitHIGH2014-03-04
Multiple unspecified vulnerabilities in Google Chrome before 33.0.1750.146 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2013-6667
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GooglePoC exploitCRITICAL2014-03-04
Use-after-free vulnerability in the FormAssociatedElement::formRemovedFromTree function in core/html/FormAssociatedElement.cpp in Blink, as used in Google Chrome before 33.0.1750.146, allows remote attackers to cause a denial of service or possibly hav...
CVEs:CVE-2013-6664
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GooglePoC exploitCRITICAL2014-03-04
The PepperFlashRendererHost::OnNavigate function in renderer/pepper/pepper_flash_renderer_host.cc in Google Chrome before 33.0.1750.146 does not verify that all headers are Cross-Origin Resource Sharing (CORS) simple headers before proceeding with a PP...
CVEs:CVE-2013-6666
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2014-03-16
Google V8, as used in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
CVEs:CVE-2014-1705
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%HIGH2014-03-16
The boot implementation in Google Chrome OS before 33.0.1750.152 does not properly consider file persistence, which allows remote attackers to execute arbitrary code via unspecified vectors.
CVEs:CVE-2014-1708
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome_os |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2014-03-16
The ScopedClipboardWriter::WritePickledData function in ui/base/clipboard/scoped_clipboard_writer.cc in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows does not verify a certain format value, which allows remote...
CVEs:CVE-2014-1714
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceEPSS <= 49%CRITICAL2014-03-19
The NTT DOCOMO sp mode mail application 5900 through 6300 for Android 4.0.x and 6000 through 6620 for Android 4.1 through 4.4 allows remote attackers to execute arbitrary Java methods via Deco-mail emoticon POP data in an e-mail message.
CVEs:CVE-2014-1979
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| spmode_mail_android |
affected |
nttdocomo |
— |
— |
GoogleEPSS <= 49%HIGH2014-03-16
Directory traversal vulnerability in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows has unspecified impact and attack vectors.
CVEs:CVE-2014-1715
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2014-03-16
Multiple unspecified vulnerabilities in Google V8 before 3.23.17.18, as used in Google Chrome before 33.0.1750.149, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2014-1704
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| v8 |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2014-03-11
Use-after-free vulnerability in the WebSocketDispatcherHost::SendOrDrop function in content/browser/renderer_host/websocket_dispatcher_host.cc in the Web Sockets implementation in Google Chrome before 33.0.1750.149 might allow remote attackers to bypas...
CVEs:CVE-2014-1703
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2014-03-11
Use-after-free vulnerability in modules/speech/SpeechSynthesis.cpp in Blink, as used in Google Chrome before 33.0.1750.149, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper handling o...
CVEs:CVE-2014-1700
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2014-03-11
Use-after-free vulnerability in the DatabaseThread::cleanupDatabaseThread function in modules/webdatabase/DatabaseThread.cpp in the web database implementation in Blink, as used in Google Chrome before 33.0.1750.149, allows remote attackers to cause a ...
CVEs:CVE-2014-1702
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2014-03-16
The GenerateFunction function in bindings/scripts/code_generator_v8.pm in Blink, as used in Google Chrome before 33.0.1750.149, does not implement a certain cross-origin restriction for the EventTarget::dispatchEvent function, which allows remote attac...
CVEs:CVE-2014-1701
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2014-03-16
The AsyncPixelTransfersCompletedQuery::End function in gpu/command_buffer/service/query_manager.cc in Google Chrome, as used in Google Chrome OS before 33.0.1750.152, does not check whether a certain position is within the bounds of a shared-memory seg...
CVEs:CVE-2014-1710
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome_os |
affected |
google |
— |
— |
Open SourceEPSS <= 49%CRITICAL2014-03-03
java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by leveraging access to the searchB...
CVEs:CVE-2014-1939
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| shareit |
affected |
lenovo |
— |
— |
Open SourceEPSS <= 49%HIGH2014-03-19
The NTT DOCOMO sp mode mail application 6300 and earlier for Android 4.0.x and 6700 and earlier for Android 4.1 through 4.4 uses weak permissions for attachments during processing of incoming e-mail messages, which allows attackers to obtain sensitive ...
CVEs:CVE-2014-1977
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| spmode_mail_android |
affected |
nttdocomo |
— |
— |
Open SourceEPSS <= 49%HIGH2014-03-19
The application link interface in the NTT DOCOMO sp mode mail application 6100 through 6300 for Android 4.0.x and 6130 through 6700 for Android 4.1 through 4.4 writes message content to the SD card during e-mail composition, which allows attackers to o...
CVEs:CVE-2014-1978
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| spmode_mail_android |
affected |
nttdocomo |
— |
— |
GoogleEPSS <= 49%CRITICAL2014-03-16
The GPU driver in the kernel in Google Chrome OS before 33.0.1750.152 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.
CVEs:CVE-2014-1711
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome_os |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2014-03-16
Directory traversal vulnerability in CrosDisks in Google Chrome OS before 33.0.1750.152 has unspecified impact and attack vectors.
CVEs:CVE-2014-1707
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome_os |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2014-03-16
crosh in Google Chrome OS before 33.0.1750.152 allows attackers to inject commands via unspecified vectors.
CVEs:CVE-2014-1706
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome_os |
affected |
google |
— |
— |