Google Security Advisories · October 2014 — Google Security Advisories
33 advisories 28 CVEs 10 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2014-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 10 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2014-4113

GoogleExploitedCISA KEV listedHIGH2014-10-15

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to...

CVEs:CVE-2014-4113

Affected products

ProductStatusVendorPackageEcosystem
windows_7 affected microsoft
windows_8 affected microsoft
windows_8.1 affected microsoft
windows_rt affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2003 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_vista affected microsoft
Upstream advisory

CVE-2014-4113

Project ZeroExploitedCISA KEV listed2014-10-15

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability."

CVEs:CVE-2014-4113

Upstream advisory

CVE-2014-4114

GoogleExploitedCISA KEV listedHIGH2014-10-15

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office ...

CVEs:CVE-2014-4114

Affected products

ProductStatusVendorPackageEcosystem
windows_7 affected microsoft
windows_8 affected microsoft
windows_8.1 affected microsoft
windows_rt affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_vista affected microsoft
Upstream advisory

CVE-2014-4114

Project ZeroExploitedCISA KEV listed2014-10-15

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document, as exploited in the wild with a "Sandworm" attack in June through October 2014, aka "Windows OLE Remote Code Execution Vulnerability."

CVEs:CVE-2014-4114

Upstream advisory

CVE-2014-6352

GoogleExploitedCISA KEV listedHIGH2014-10-22

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object, as exploited...

CVEs:CVE-2014-6352

Affected products

ProductStatusVendorPackageEcosystem
windows_7 affected microsoft
windows_8 affected microsoft
windows_8.1 affected microsoft
windows_rt affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_vista affected microsoft
Upstream advisory

CVE-2014-6352

Project ZeroExploitedCISA KEV listed2014-10-22

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object, as exploited in the wild in October 2014 with a crafted PowerPoint document.

CVEs:CVE-2014-6352

Upstream advisory

CVE-2014-4148

GoogleExploitedCISA KEV listedHIGH2014-10-15

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attacke...

CVEs:CVE-2014-4148

Affected products

ProductStatusVendorPackageEcosystem
windows_7 affected microsoft
windows_8 affected microsoft
windows_8.1 affected microsoft
windows_rt affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2003 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_vista affected microsoft
Upstream advisory

CVE-2014-4148

Project ZeroExploitedCISA KEV listed2014-10-15

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted TrueType font, as exploited in the wild in October 2014, aka "TrueType Font Parsing Remote Code Execution Vulnerability."

CVEs:CVE-2014-4148

Upstream advisory

CVE-2014-4123

GoogleExploitedCISA KEV listedCRITICAL2014-10-15

Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a different vulnerability than CVE-2014-...

CVEs:CVE-2014-4123

Affected products

ProductStatusVendorPackageEcosystem
internet_explorer affected microsoft
Upstream advisory

CVE-2014-4123

Project ZeroExploitedCISA KEV listed2014-10-15

Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124.

CVEs:CVE-2014-4123

Upstream advisory

CVE-2014-7138

GoogleWeaponized exploitCRITICAL2014-10-16

Cross-site scripting (XSS) vulnerability in the Google Calendar Events plugin before 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gce_feed_ids parameter in a gce_ajax action to wp-admin/admin-ajax.php.

CVEs:CVE-2014-7138

Affected products

ProductStatusVendorPackageEcosystem
google_calendar_events affected google_calendar_events_project
Upstream advisory

MGASA-2014-0428

Open SourceEPSS <= 49%CRITICAL2014-10-28

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:3 chromium-browser-stable
chromium-browser-stable affected Mageia:4 chromium-browser-stable
Upstream advisory

CVE-2014-3188

GoogleEPSS <= 49%HIGH2014-10-08

Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data, related to improper parsing of a...

CVEs:CVE-2014-3188

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
Upstream advisory

CVE-2014-3192

GoogleEPSS <= 49%CRITICAL2014-10-08

Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of s...

CVEs:CVE-2014-3192

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2014-3193

GoogleEPSS <= 49%CRITICAL2014-10-08

The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors that le...

CVEs:CVE-2014-3193

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
Upstream advisory

CVE-2014-3191

GoogleEPSS <= 49%CRITICAL2014-10-08

Use-after-free vulnerability in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers a widget-position update that...

CVEs:CVE-2014-3191

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
Upstream advisory

CVE-2014-3200

GoogleEPSS <= 49%HIGH2014-10-08

Multiple unspecified vulnerabilities in Google Chrome before 38.0.2125.101 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2014-3200

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
Upstream advisory

CVE-2014-3190

GoogleEPSS <= 49%CRITICAL2014-10-08

Use-after-free vulnerability in the Event::currentTarget function in core/events/Event.cpp in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified ot...

CVEs:CVE-2014-3190

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
Upstream advisory

MGASA-2014-0410

Open SourceEPSS <= 49%2014-10-09

Updated golang packages fix CVE-2014-7189

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:4 golang
Upstream advisory

CVE-2014-7189

GoogleEPSS <= 49%MEDIUM2014-10-07

crpyto/tls in Go 1.1 before 1.3.2, when SessionTicketsDisabled is enabled, allows man-in-the-middle attackers to spoof clients via unspecified vectors.

CVEs:CVE-2014-7189

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

CVE-2014-3198

GoogleEPSS <= 49%HIGH2014-10-08

The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote attackers to cause a denial ...

CVEs:CVE-2014-3198

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
Upstream advisory

CVE-2014-3199

GoogleEPSS <= 49%HIGH2014-10-08

The wrap function in bindings/core/v8/custom/V8EventCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 38.0.2125.101, has an erroneous fallback outcome for wrapper-selection failures, which allows remote attackers to cause a denial...

CVEs:CVE-2014-3199

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
Upstream advisory

CVE-2014-3189

GoogleEPSS <= 49%HIGH2014-10-08

The chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium component in Google Chrome before 38.0.2125.101 does not properly validate image-data dimensions, which allows remote attackers to cause a denial of service (out-of-bounds read) or p...

CVEs:CVE-2014-3189

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
Upstream advisory

CVE-2014-3195

GoogleEPSS <= 49%HIGH2014-10-08

Google V8, as used in Google Chrome before 38.0.2125.101, does not properly track JavaScript heap-memory allocations as allocations of uninitialized memory and does not properly concatenate arrays of double-precision floating-point numbers, which allow...

CVEs:CVE-2014-3195

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
Upstream advisory

CVE-2014-3194

GoogleEPSS <= 49%CRITICAL2014-10-08

Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2014-3194

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
Upstream advisory

CVE-2014-3196

GoogleEPSS <= 49%HIGH2014-10-08

base/memory/shared_memory_win.cc in Google Chrome before 38.0.2125.101 on Windows does not properly implement read-only restrictions on shared memory, which allows attackers to bypass a sandbox protection mechanism via unspecified vectors.

CVEs:CVE-2014-3196

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2014-3197

GoogleEPSS <= 49%CRITICAL2014-10-08

The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote atta...

CVEs:CVE-2014-3197

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
Upstream advisory

CVE-2014-3187

GoogleEPSS <= 49%MEDIUM2014-10-08

Google Chrome before 37.0.2062.60 and 38.x before 38.0.2125.59 on iOS does not properly restrict processing of (1) facetime:// and (2) facetime-audio:// URLs, which allows remote attackers to obtain video and audio data from a device via a crafted web ...

CVEs:CVE-2014-3187

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
Upstream advisory

CVE-2014-3201

GoogleEPSS <= 49%MEDIUM2014-10-10

core/rendering/compositing/RenderLayerCompositor.cpp in Blink, as used in Google Chrome before 38.0.2125.102 on Android, does not properly handle a certain IFRAME overflow condition, which allows remote attackers to spoof content via a crafted web site...

CVEs:CVE-2014-3201

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2014-7967

GoogleEPSS <= 49%HIGH2014-10-08

Multiple unspecified vulnerabilities in Google V8 before 3.28.71.15, as used in Google Chrome before 38.0.2125.101, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2014-7967

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
v8 affected google
Upstream advisory

CVE-2014-7008

Open SourceEPSS <= 49%HIGH2014-10-16

The Forum FrAndroid beta (aka com.tapatalk.forumfrandroidcom) application 3.4.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted ce...

CVEs:CVE-2014-7008

Affected products

ProductStatusVendorPackageEcosystem
forum_frandroid_beta affected frandroid
Upstream advisory

CVE-2014-7111

Open SourceEPSS <= 49%HIGH2014-10-19

The Android Excellence (aka an.exc.ap) application 1.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVEs:CVE-2014-7111

Affected products

ProductStatusVendorPackageEcosystem
android_excellence affected android_excellence_project
Upstream advisory

MGASA-2014-0413

Open SourceAll remaining2014-10-09

Updated chromium-browser-stable packages fix security vulnerabilites

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:3 chromium-browser-stable
chromium-browser-stable affected Mageia:4 chromium-browser-stable
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.