CVE-2014-1939
published 2014-03-03CVE-2014-1939: java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl…
PriorityP341high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.07%
61.5th percentile
java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by leveraging access to the searchBoxJavaBridge_ interface at certain Android API levels.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | <= 4.3.1 | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| lenovo | shareit | <= 3.5.88_ww | — |
| linux | linux_kernel | >= 6.13.0 < 6.18.3 | 6.18.3 |
| linux | linux_kernel | >= 6.5.0 < 6.6.120 | 6.6.120 |
| linux | linux_kernel | >= 6.7.0 < 6.12.64 | 6.12.64 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
f2fs: ensure node page reads complete before f2fs_put_super() finishes
osv·2026-01-14·CVSS 5.5
CVE-2025-71107 f2fs: ensure node page reads complete before f2fs_put_super() finishes
f2fs: ensure node page reads complete before f2fs_put_super() finishes
In the Linux kernel, the following vulnerability has been resolved:
f2fs: ensure node page reads complete before f2fs_put_super() finishes
Xfstests generic/335, generic/336 sometimes crash with the following message:
F2FS-fs (dm-0): detect filesystem reference count leak during umount, type: 9, count: 1
------------[ cut here ]------------
kernel BUG at fs/f2fs/super.c:1939!
Oops: invalid opcode: 0000 [#1] SMP NOPTI
CPU: 1 UID: 0 PID: 609351 Comm: umount Tainted: G W 6.17.0-rc5-xfstests-g9dd1835ecda5 #1 PREEMPT(none)
Tainted: [W]=WARN
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:f2fs_put_super+0x3b3/0x3c0
Call Trace:
generic_shutdown_super+0x7e/0x190
kill_bloc
GHSA
GHSA-62jr-f896-9v4h: java/android/webkit/BrowserFrame
ghsa_unreviewed·2022-05-17
CVE-2014-1939 [HIGH] CWE-94 GHSA-62jr-f896-9v4h: java/android/webkit/BrowserFrame
java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by leveraging access to the searchBoxJavaBridge_ interface at certain Android API levels.
Red Hat
kernel: f2fs: ensure node page reads complete before f2fs_put_super() finishes
vendor_redhat·2026-01-14·CVSS 5.5
CVE-2025-71107 [MEDIUM] kernel: f2fs: ensure node page reads complete before f2fs_put_super() finishes
kernel: f2fs: ensure node page reads complete before f2fs_put_super() finishes
In the Linux kernel, the following vulnerability has been resolved:
f2fs: ensure node page reads complete before f2fs_put_super() finishes
Xfstests generic/335, generic/336 sometimes crash with the following message:
F2FS-fs (dm-0): detect filesystem reference count leak during umount, type: 9, count: 1
------------[ cut here ]------------
kernel BUG at fs/f2fs/super.c:1939!
Oops: invalid opcode: 0000 [#1] SMP NOPTI
CPU: 1 UID: 0 PID: 609351 Comm: umount Tainted: G W 6.17.0-rc5-xfstests-g9dd1835ecda5 #1 PREEMPT(none)
Tainted: [W]=WARN
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:f2fs_put_super+0x3b3/0x3c0
Call Trace:
generic_shutdown_super+0x7e/0x190
kill
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://blog.chromium.org/2013/11/introducing-chromium-powered-android.htmlhttp://openwall.com/lists/oss-security/2014/02/11/2https://support.lenovo.com/us/en/product_security/len_6421http://blog.chromium.org/2013/11/introducing-chromium-powered-android.htmlhttp://openwall.com/lists/oss-security/2014/02/11/2https://support.lenovo.com/us/en/product_security/len_6421
2014-03-03
Published