Google Security Advisories · September 2014 — Google Security Advisories
12 advisories 12 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2014-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2014-6041

Open SourceWeaponized exploitMEDIUM2014-09-02

The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 character, as demonstrated by an onclick="window.open('\u0000javascript: sequence to the Android Browser appl...

CVEs:CVE-2014-6041

Affected products

ProductStatusVendorPackageEcosystem
android_browser affected google
Upstream advisory

CVE-2014-1568

GooglePoC exploitHIGH2014-09-24

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x...

CVEs:CVE-2014-1568

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
firefox affected mozilla
firefox_esr affected mozilla
network_security_services affected mozilla
seamonkey affected mozilla
thunderbird affected mozilla
Upstream advisory

CVE-2014-6060

Open SourcePoC exploitHIGH2014-09-04

The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which triggers the option to be proces...

CVEs:CVE-2014-6060

Affected products

ProductStatusVendorPackageEcosystem
android affected google
dhcpcd affected dhcpcd_project
Upstream advisory

DSA-3039-1

Open SourceEPSS <= 49%2014-09-28

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:7 chromium-browser
Upstream advisory

CVE-2014-3178

GoogleEPSS <= 49%CRITICAL2014-09-10

Use-after-free vulnerability in core/dom/Node.cpp in Blink, as used in Google Chrome before 37.0.2062.120, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper handling of render-tree inc...

CVEs:CVE-2014-3178

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2014-3179

GoogleEPSS <= 49%HIGH2014-09-10

Multiple unspecified vulnerabilities in Google Chrome before 37.0.2062.120 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2014-3179

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2014-6239

GoogleEPSS <= 49%CRITICAL2014-09-11

SQL injection vulnerability in the Address visualization with Google Maps (st_address_map) extension before 0.3.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVEs:CVE-2014-6239

Affected products

ProductStatusVendorPackageEcosystem
address_visualization_with_google_maps affected address_visualization_with_google_maps_project
Upstream advisory

CVE-2014-6240

GoogleEPSS <= 49%CRITICAL2014-09-11

Cross-site scripting (XSS) vulnerability in the Google Sitemap (weeaar_googlesitemap) extension 0.4.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVEs:CVE-2014-6240

Affected products

ProductStatusVendorPackageEcosystem
google_sitemap affected google_sitemap_project
Upstream advisory

CVE-2014-6024

Open SourceEPSS <= 49%HIGH2014-09-09

The Flurry library before 3.4.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVEs:CVE-2014-6024

Affected products

ProductStatusVendorPackageEcosystem
flurry-analytics-android affected flurry
Upstream advisory

CVE-2014-5889

Open SourceEPSS <= 49%HIGH2014-09-15

The Android Forums (aka com.tapatalk.androidforumscom) application 2.4.4.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifi...

CVEs:CVE-2014-5889

Affected products

ProductStatusVendorPackageEcosystem
forum_for_android affected androidforums
Upstream advisory

CVE-2014-5770

Open SourceEPSS <= 49%HIGH2014-09-09

The Web Browser for Android (aka explore.web.browser) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVEs:CVE-2014-5770

Affected products

ProductStatusVendorPackageEcosystem
web_browser_for_android affected web_browser_for_android_project
Upstream advisory

CVE-2014-5819

GoogleEPSS <= 49%HIGH2014-09-09

The PHONE for Google Voice & GTalk (aka com.moplus.gvphone) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certif...

CVEs:CVE-2014-5819

Affected products

ProductStatusVendorPackageEcosystem
phone_for_google_voice_\&_gtalk affected mopl
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.