Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2014-12-15 CVE-2014-8609 Permissions, Privileges, and Access Controls vulnerability in Google Android
The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Android before 5.0.0 does not properly create a PendingIntent, which allows attackers to use the SYSTEM uid for broadcasting an intent with arbitrary component, action, or category information via a third-party authenticator in a crafted application, aka Bug 17356824.
local
low complexity
google CWE-264
7.2
2014-12-15 CVE-2014-8507 SQL Injection vulnerability in Google Android
Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/WapPushManager.java in the WAPPushManager module in Android before 5.0.0 allow remote attackers to execute arbitrary SQL commands, and consequently launch an activity or service, via the (1) wapAppId or (2) contentType field of a PDU for a malformed WAPPush message, aka Bug 17969135.
network
low complexity
google CWE-89
7.5
2014-09-25 CVE-2014-1568 Cryptographic Issues vulnerability in Google Chrome
Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.
network
low complexity
google apple microsoft mozilla CWE-310
7.5
2014-09-10 CVE-2014-0548 Permissions, Privileges, and Access Controls vulnerability in Adobe Air, Adobe AIR SDK and Flash Player
Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow remote attackers to bypass the Same Origin Policy via unspecified vectors.
network
low complexity
adobe google apple microsoft linux CWE-264
7.5
2014-05-14 CVE-2014-1909 Numeric Errors vulnerability in multiple products
Integer signedness error in system/core/adb/adb_client.c in Android Debug Bridge (ADB) for Android 4.4 in the Android SDK Platform Tools 18.0.1 allows ADB servers to execute arbitrary code via a negative length value, which bypasses a signed comparison and triggers a stack-based buffer overflow.
network
low complexity
google opensuse CWE-189
7.5
2014-04-29 CVE-2013-7373 Information Exposure vulnerability in Google Android
Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging use of the PRNG within multiple applications.
network
low complexity
google CWE-200
7.5
2014-03-31 CVE-2013-6770 Permissions, Privileges, and Access Controls vulnerability in multiple products
The CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.3 and 4.4 does not properly restrict the set of users who can execute /system/xbin/su with the --daemon option, which allows attackers to gain privileges by leveraging ADB shell access and a certain Linux UID, and then creating a Trojan horse script.
network
high complexity
koushik-dutta google CWE-264
7.6
2014-03-05 CVE-2013-6668 Multiple unspecified vulnerabilities in Google V8 before 3.24.35.10, as used in Google Chrome before 33.0.1750.146, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
network
low complexity
google nodejs debian
7.5
2014-03-05 CVE-2013-6667 Multiple Security vulnerability in Google Chrome Prior to 33.0.1750.146
Multiple unspecified vulnerabilities in Google Chrome before 33.0.1750.146 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
network
low complexity
google
7.5
2014-03-05 CVE-2013-6665 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Google Chrome
Heap-based buffer overflow in the ResourceProvider::InitializeSoftware function in cc/resources/resource_provider.cc in Google Chrome before 33.0.1750.146 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large texture size that triggers improper memory allocation in the software renderer.
network
low complexity
google CWE-119
7.5