Advisories
GooglePoC exploitHIGH2014-07-01
Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689) allows remote attackers to execute arbitrary code via a crafted color palette table in a MAC Pict texture, which triggers an out-of-bounds stack write. NOTE: this vulnerability exists...
CVEs:CVE-2013-3664
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| sketchup |
affected |
google |
— |
— |
| sketchup |
affected |
trimble |
— |
— |
GoogleEPSS <= 49%HIGH2014-07-01
Timbre SketchUp (formerly Google SketchUp) before 8 Maintenance 2 allows remote attackers to execute arbitrary code via a crafted color palette table in a MAC Pict texture, which triggers a stack-based buffer overflow.
CVEs:CVE-2013-3662
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| sketchup |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2014-07-01
Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689), allows remote attackers to execute arbitrary code via a crafted RLE4-compressed bitmap (BMP). NOTE: this issue was SPLIT from CVE-2...
CVEs:CVE-2013-7388
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| sketchup |
affected |
google |
— |
— |
| sketchup |
affected |
trimble |
— |
— |
Open SourceEPSS <= 49%CRITICAL2014-07-02
Stack-based buffer overflow in the encode_key function in /system/bin/keystore in the KeyStore service in Android 4.3 allows attackers to execute arbitrary code, and consequently obtain sensitive key information or bypass intended restrictions on crypt...
CVEs:CVE-2014-3100
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2014-07-17
The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the S...
CVEs:CVE-2014-3160
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleEPSS <= 49%HIGH2014-07-17
Multiple unspecified vulnerabilities in Google Chrome before 36.0.1985.125 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2014-3162
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleEPSS <= 49%MEDIUM2014-07-20
The WebContentsDelegateAndroid::OpenURLFromTab function in components/web_contents_delegate_android/web_contents_delegate_android.cc in Google Chrome before 36.0.1985.122 on Android does not properly restrict URL loading, which allows remote attackers ...
CVEs:CVE-2014-3159
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2014-07-20
The WebMediaPlayerAndroid::load function in content/renderer/media/android/webmediaplayer_android.cc in Google Chrome before 36.0.1985.122 on Android does not properly interact with redirects, which allows remote attackers to bypass the Same Origin Pol...
CVEs:CVE-2014-3161
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |