Advisories
Open SourceWeaponized exploitMEDIUM2014-09-02
The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 character, as demonstrated by an onclick="window.open('\u0000javascript: sequence to the Android Browser appl...
CVEs:CVE-2014-6041
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android_browser |
affected |
google |
— |
— |
GooglePoC exploitHIGH2014-09-24
Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x...
CVEs:CVE-2014-1568
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| firefox |
affected |
mozilla |
— |
— |
| firefox_esr |
affected |
mozilla |
— |
— |
| network_security_services |
affected |
mozilla |
— |
— |
| seamonkey |
affected |
mozilla |
— |
— |
| thunderbird |
affected |
mozilla |
— |
— |
Open SourcePoC exploitHIGH2014-09-04
The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which triggers the option to be proces...
CVEs:CVE-2014-6060
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| dhcpcd |
affected |
dhcpcd_project |
— |
— |
Open SourceEPSS <= 49%2014-09-28
chromium-browser - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser |
affected |
Debian:7 |
chromium-browser |
— |
GoogleEPSS <= 49%CRITICAL2014-09-10
Use-after-free vulnerability in core/dom/Node.cpp in Blink, as used in Google Chrome before 37.0.2062.120, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper handling of render-tree inc...
CVEs:CVE-2014-3178
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2014-09-10
Multiple unspecified vulnerabilities in Google Chrome before 37.0.2062.120 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2014-3179
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2014-09-11
SQL injection vulnerability in the Address visualization with Google Maps (st_address_map) extension before 0.3.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVEs:CVE-2014-6239
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| address_visualization_with_google_maps |
affected |
address_visualization_with_google_maps_project |
— |
— |
GoogleEPSS <= 49%CRITICAL2014-09-11
Cross-site scripting (XSS) vulnerability in the Google Sitemap (weeaar_googlesitemap) extension 0.4.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVEs:CVE-2014-6240
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_sitemap |
affected |
google_sitemap_project |
— |
— |
Open SourceEPSS <= 49%HIGH2014-09-09
The Flurry library before 3.4.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVEs:CVE-2014-6024
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| flurry-analytics-android |
affected |
flurry |
— |
— |
Open SourceEPSS <= 49%HIGH2014-09-15
The Android Forums (aka com.tapatalk.androidforumscom) application 2.4.4.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifi...
CVEs:CVE-2014-5889
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| forum_for_android |
affected |
androidforums |
— |
— |
Open SourceEPSS <= 49%HIGH2014-09-09
The Web Browser for Android (aka explore.web.browser) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVEs:CVE-2014-5770
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| web_browser_for_android |
affected |
web_browser_for_android_project |
— |
— |
GoogleEPSS <= 49%HIGH2014-09-09
The PHONE for Google Voice & GTalk (aka com.moplus.gvphone) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certif...
CVEs:CVE-2014-5819
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| phone_for_google_voice_\&_gtalk |
affected |
mopl |
— |
— |