Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-1939

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2014-1939
Last Modified 04 Mar 2014 11:02:59
Published 02 Mar 2014 11:50:46
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2014-1939

Summary

java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by leveraging access to the searchBoxJavaBridge_ interface at certain Android API levels.

Vulnerable Systems

Operating System

  • Google Android 4.0

  • Google Android 4.0.1

  • Google Android 4.0.2

  • Google Android 4.0.3

  • Google Android 4.0.4

  • Google Android 4.1

  • Google Android 4.1.2

  • Google Android 4.2

  • Google Android 4.2.1

  • Google Android 4.2.2

  • Google Android 4.3

  • Google Android 4.3.1


References

MLIST - [oss-security] 20140210 CVE-2014-1939 searchBoxJavaBridge_ in Android Jelly Bean

CONFIRM - http://blog.chromium.org/2013/11/introducing-chromium-powered-android.html


Last Updated: 27 May 2016 11:04:32