Google Security Advisories · May 2014 — Google Security Advisories
22 advisories 22 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2014-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

DSA-2939-1

Open SourcePoC exploit2014-05-31

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:7 chromium-browser
Upstream advisory

CVE-2014-1745

GooglePoC exploitCRITICAL2014-05-21

Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger removal of an SVGFon...

CVEs:CVE-2014-1745

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MGASA-2014-0213

Open SourceEPSS <= 49%CRITICAL2014-05-10

Updated chromium-browser-stable packages fix multiple vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:3 chromium-browser-stable
chromium-browser-stable affected Mageia:4 chromium-browser-stable
Upstream advisory

DSA-2920-1

Open SourceEPSS <= 49%2014-05-03

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:7 chromium-browser
Upstream advisory

CVE-2014-1736

GoogleEPSS <= 49%CRITICAL2014-05-06

Integer overflow in api.cc in Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large len...

CVEs:CVE-2014-1736

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2014-1909

Open SourceEPSS <= 49%CRITICAL2014-05-14

DEBIAN-CVE-2014-1909

Affected products

ProductStatusVendorPackageEcosystem
android-platform-system-core affected Debian:11 android-platform-system-core
Upstream advisory

CVE-2014-1909

Open SourceEPSS <= 49%CRITICAL2014-05-14

Integer signedness error in system/core/adb/adb_client.c in Android Debug Bridge (ADB) for Android 4.4 in the Android SDK Platform Tools 18.0.1 allows ADB servers to execute arbitrary code via a negative length value, which bypasses a signed comparison...

CVEs:CVE-2014-1909

Affected products

ProductStatusVendorPackageEcosystem
android_debug_bridge affected google
android_sdk_platform_tools affected google
opensuse affected opensuse
Upstream advisory

CVE-2014-3152

GoogleEPSS <= 49%HIGH2014-05-21

Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Google V8 before 3.25.28.16, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspecifi...

CVEs:CVE-2014-3152

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
v8 affected google
Upstream advisory

CVE-2014-1747

GoogleEPSS <= 49%CRITICAL2014-05-21

Cross-site scripting (XSS) vulnerability in the DocumentLoader::maybeCreateArchive function in core/loader/DocumentLoader.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to inject arbitrary web script or HTML via cr...

CVEs:CVE-2014-1747

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2014-1744

GoogleEPSS <= 49%CRITICAL2014-05-21

Integer overflow in the AudioInputRendererHost::OnCreateStream function in content/browser/renderer_host/media/audio_input_renderer_host.cc in Google Chrome before 35.0.1916.114 allows remote attackers to cause a denial of service or possibly have unsp...

CVEs:CVE-2014-1744

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MGASA-2014-0232

Open SourceEPSS <= 49%CRITICAL2014-05-22

Updated chromium-browser-stable packages fix multiple vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:3 chromium-browser-stable
chromium-browser-stable affected Mageia:4 chromium-browser-stable
Upstream advisory

DSA-2930-1

Open SourceEPSS <= 49%2014-05-17

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:7 chromium-browser
Upstream advisory

CVE-2014-1740

GoogleEPSS <= 49%CRITICAL2014-05-14

Multiple use-after-free vulnerabilities in net/websockets/websocket_job.cc in the WebSockets implementation in Google Chrome before 34.0.1847.137 allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors ...

CVEs:CVE-2014-1740

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2014-1741

GoogleEPSS <= 49%CRITICAL2014-05-14

Multiple integer overflows in the replace-data functionality in the CharacterData interface implementation in core/dom/CharacterData.cpp in Blink, as used in Google Chrome before 34.0.1847.137, allow remote attackers to cause a denial of service or pos...

CVEs:CVE-2014-1741

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2014-1743

GoogleEPSS <= 49%CRITICAL2014-05-21

Use-after-free vulnerability in the StyleElement::removedFromDocument function in core/dom/StyleElement.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service (application crash) or possibly ha...

CVEs:CVE-2014-1743

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2014-1742

GoogleEPSS <= 49%CRITICAL2014-05-14

Use-after-free vulnerability in the FrameSelection::updateAppearance function in core/editing/FrameSelection.cpp in Blink, as used in Google Chrome before 34.0.1847.137, allows remote attackers to cause a denial of service or possibly have unspecified ...

CVEs:CVE-2014-1742

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2014-1748

GoogleEPSS <= 49%MEDIUM2014-05-21

The ScrollView::paint function in platform/scroll/ScrollView.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to spoof the UI by extending scrollbar painting into the parent frame.

CVEs:CVE-2014-1748

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2014-1746

GoogleEPSS <= 49%HIGH2014-05-21

The InMemoryUrlProtocol::Read function in media/filters/in_memory_url_protocol.cc in Google Chrome before 35.0.1916.114 relies on an insufficiently large integer data type, which allows remote attackers to cause a denial of service (out-of-bounds read)...

CVEs:CVE-2014-1746

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2014-3803

GoogleEPSS <= 49%MEDIUM2014-05-21

The SpeechInput feature in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to enable microphone access and obtain speech-recognition text without indication via an INPUT element with a -x-webkit-speech attribute.

CVEs:CVE-2014-3803

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2014-0362

GoogleEPSS <= 49%CRITICAL2014-05-08

Cross-site scripting (XSS) vulnerability on Google Search Appliance (GSA) devices before 7.0.14.G.216 and 7.2 before 7.2.0.G.114, when dynamic navigation is configured, allows remote attackers to inject arbitrary web script or HTML via input included i...

CVEs:CVE-2014-0362

Affected products

ProductStatusVendorPackageEcosystem
search_appliance_software affected google
Upstream advisory

CVE-2014-1749

GoogleEPSS <= 49%HIGH2014-05-21

Multiple unspecified vulnerabilities in Google Chrome before 35.0.1916.114 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2014-1749

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4832

Open SourceEPSS <= 49%CRITICAL2014-05-14

Android OS before 2.2 does not display the correct SSL certificate in certain cases, which might allow remote attackers to spoof trusted web sites via a web page containing references to external sources in which (1) the certificate of the last loaded ...

CVEs:CVE-2010-4832

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.