Google Security Advisories · July 2014 — Google Security Advisories
8 advisories 8 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2014-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2013-3664

GooglePoC exploitHIGH2014-07-01

Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689) allows remote attackers to execute arbitrary code via a crafted color palette table in a MAC Pict texture, which triggers an out-of-bounds stack write. NOTE: this vulnerability exists...

CVEs:CVE-2013-3664

Affected products

ProductStatusVendorPackageEcosystem
sketchup affected google
sketchup affected trimble
Upstream advisory

CVE-2013-3662

GoogleEPSS <= 49%HIGH2014-07-01

Timbre SketchUp (formerly Google SketchUp) before 8 Maintenance 2 allows remote attackers to execute arbitrary code via a crafted color palette table in a MAC Pict texture, which triggers a stack-based buffer overflow.

CVEs:CVE-2013-3662

Affected products

ProductStatusVendorPackageEcosystem
sketchup affected google
Upstream advisory

CVE-2013-7388

GoogleEPSS <= 49%HIGH2014-07-01

Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689), allows remote attackers to execute arbitrary code via a crafted RLE4-compressed bitmap (BMP). NOTE: this issue was SPLIT from CVE-2...

CVEs:CVE-2013-7388

Affected products

ProductStatusVendorPackageEcosystem
sketchup affected google
sketchup affected trimble
Upstream advisory

CVE-2014-3100

Open SourceEPSS <= 49%CRITICAL2014-07-02

Stack-based buffer overflow in the encode_key function in /system/bin/keystore in the KeyStore service in Android 4.3 allows attackers to execute arbitrary code, and consequently obtain sensitive key information or bypass intended restrictions on crypt...

CVEs:CVE-2014-3100

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-3160

GoogleEPSS <= 49%CRITICAL2014-07-17

The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the S...

CVEs:CVE-2014-3160

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2014-3162

GoogleEPSS <= 49%HIGH2014-07-17

Multiple unspecified vulnerabilities in Google Chrome before 36.0.1985.125 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2014-3162

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2014-3159

GoogleEPSS <= 49%MEDIUM2014-07-20

The WebContentsDelegateAndroid::OpenURLFromTab function in components/web_contents_delegate_android/web_contents_delegate_android.cc in Google Chrome before 36.0.1985.122 on Android does not properly restrict URL loading, which allows remote attackers ...

CVEs:CVE-2014-3159

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2014-3161

GoogleEPSS <= 49%HIGH2014-07-20

The WebMediaPlayerAndroid::load function in content/renderer/media/android/webmediaplayer_android.cc in Google Chrome before 36.0.1985.122 on Android does not properly interact with redirects, which allows remote attackers to bypass the Same Origin Pol...

CVEs:CVE-2014-3161

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.