CVE-2014-2125
published 2014-04-02CVE-2014-2125: Cross-site scripting (XSS) vulnerability in the Web Inbox in Cisco Unity Connection 8.6(2a)SU3 and earlier allows remote attackers to inject arbitrary web…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.15%
63.5th percentile
Cross-site scripting (XSS) vulnerability in the Web Inbox in Cisco Unity Connection 8.6(2a)SU3 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCui33028.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unity_connection | <= 8.6 | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat10.0CRITICAL
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mhp5-9hjj-mhrx: Cross-site scripting (XSS) vulnerability in the Web Inbox in Cisco Unity Connection 8
ghsa_unreviewed·2022-05-17
CVE-2014-2125 [MEDIUM] CWE-79 GHSA-mhp5-9hjj-mhrx: Cross-site scripting (XSS) vulnerability in the Web Inbox in Cisco Unity Connection 8
Cross-site scripting (XSS) vulnerability in the Web Inbox in Cisco Unity Connection 8.6(2a)SU3 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCui33028.
Red Hat
chromium-browser: Address bar spoofing
vendor_redhat·2014-11-18·CVSS 5.0
CVE-2014-7899 [MEDIUM] CWE-451 chromium-browser: Address bar spoofing
chromium-browser: Address bar spoofing
Google Chrome before 38.0.2125.101 allows remote attackers to spoof the address bar by placing a blob: substring at the beginning of the URL, followed by the original URI scheme and a long username string.
Red Hat
v8: multiple unspecified issues fixed in Google Chrome 38.0.2125.101
vendor_redhat·2014-10-08·CVSS 7.5
CVE-2014-7967 [HIGH] v8: multiple unspecified issues fixed in Google Chrome 38.0.2125.101
v8: multiple unspecified issues fixed in Google Chrome 38.0.2125.101
Multiple unspecified vulnerabilities in Google V8 before 3.28.71.15, as used in Google Chrome before 38.0.2125.101, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Statement: Red Hat Satellite 6.5 ship v8 however has been rated as a security impact of Moderate, product version Satellite 6.6 onward is not affected. Satellite 6.5 is in Maintenance Support phase of the product life cycle and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Satellite 6 Life Cycle: https://access.redhat.com/support/policy/updates/satellite.
Package: ruby193-v8 (CloudForms Management Engine 5) - Will not fix
Package: ruby193-v8 (OpenS
Red Hat
chromium: multiple unspecified issues fixed in Chrome 38.0.2125.101
vendor_redhat·2014-10-07·CVSS 7.5
CVE-2014-3200 [HIGH] chromium: multiple unspecified issues fixed in Chrome 38.0.2125.101
chromium: multiple unspecified issues fixed in Chrome 38.0.2125.101
Multiple unspecified vulnerabilities in Google Chrome before 38.0.2125.101 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Statement: This issue affects the versions of webkitgtk and webkitgtk3 as shipped with Red Hat Enterprise Linux 6 and 7 respectively.
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Will not fix
Red Hat
chromium: OOB reads in PDFium fixed in Chrome 38.0.2125.101
vendor_redhat·2014-10-07·CVSS 7.5
CVE-2014-3189 [HIGH] CWE-125 chromium: OOB reads in PDFium fixed in Chrome 38.0.2125.101
chromium: OOB reads in PDFium fixed in Chrome 38.0.2125.101
The chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium component in Google Chrome before 38.0.2125.101 does not properly validate image-data dimensions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via unknown vectors.
Red Hat
chromium: information leak in XSS Auditor fixed in Chrome 38.0.2125.101
vendor_redhat·2014-10-07·CVSS 5.0
CVE-2014-3197 [MEDIUM] CWE-200 chromium: information leak in XSS Auditor fixed in Chrome 38.0.2125.101
chromium: information leak in XSS Auditor fixed in Chrome 38.0.2125.101
The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attackers to obtain sensitive information via a crafted web site.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Not affected
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Not affected
Red Hat
chromium: OOB reads in PDFium fixed in Chrome 38.0.2125.101
vendor_redhat·2014-10-07·CVSS 5.0
CVE-2014-3198 [MEDIUM] CWE-125 chromium: OOB reads in PDFium fixed in Chrome 38.0.2125.101
chromium: OOB reads in PDFium fixed in Chrome 38.0.2125.101
The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
Red Hat
chromium: multiple security fixes in Chrome 38.0.2125.101
vendor_redhat·2014-10-07·CVSS 7.5
CVE-2014-3190 [HIGH] chromium: multiple security fixes in Chrome 38.0.2125.101
chromium: multiple security fixes in Chrome 38.0.2125.101
Use-after-free vulnerability in the Event::currentTarget function in core/events/Event.cpp in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code that accesses the path property of an Event object.
Red Hat
chromium: multiple security fixes in Chrome 38.0.2125.101
vendor_redhat·2014-10-07·CVSS 5.0
CVE-2014-3199 [MEDIUM] chromium: multiple security fixes in Chrome 38.0.2125.101
chromium: multiple security fixes in Chrome 38.0.2125.101
The wrap function in bindings/core/v8/custom/V8EventCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 38.0.2125.101, has an erroneous fallback outcome for wrapper-selection failures, which allows remote attackers to cause a denial of service via vectors that trigger stopping a worker process that had been handling an Event object.
Red Hat
chromium: multiple security fixes in Chrome 38.0.2125.101
vendor_redhat·2014-10-07·CVSS 7.5
CVE-2014-3193 [HIGH] chromium: multiple security fixes in Chrome 38.0.2125.101
chromium: multiple security fixes in Chrome 38.0.2125.101
The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors that leverage "type confusion" for callback processing.
Red Hat
chromium: use-after-free in DOM, fixed in Chrome 38.0.2125.101
vendor_redhat·2014-10-07·CVSS 7.5
CVE-2014-3192 [HIGH] CWE-416 chromium: use-after-free in DOM, fixed in Chrome 38.0.2125.101
chromium: use-after-free in DOM, fixed in Chrome 38.0.2125.101
Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Statement: This issue affects the versions of webkitgtk and webkitgtk3 as shipped with Red Hat Enterprise Linux 6 and 7 respectively.
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classificat
Red Hat
chromium: use-after-free issue in Web Workers fixed in Chrome 38.0.2125.101
vendor_redhat·2014-10-07·CVSS 7.5
CVE-2014-3194 [HIGH] CWE-416 chromium: use-after-free issue in Web Workers fixed in Chrome 38.0.2125.101
chromium: use-after-free issue in Web Workers fixed in Chrome 38.0.2125.101
Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Not affected
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Not affected
Red Hat
chromium: multiple security fixes in Chrome 38.0.2125.101
vendor_redhat·2014-10-07·CVSS 7.5
CVE-2014-3191 [HIGH] chromium: multiple security fixes in Chrome 38.0.2125.101
chromium: multiple security fixes in Chrome 38.0.2125.101
Use-after-free vulnerability in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers a widget-position update that improperly interacts with the render tree, related to the FrameView::updateLayoutAndStyleForPainting function in core/frame/FrameView.cpp and the RenderLayerScrollableArea::setScrollOffset function in core/rendering/RenderLayerScrollableArea.cpp.
Red Hat
v8: IPC and v8 issue fixed in Google Chrome 38.0.2125.101
vendor_redhat·2014-09-22·CVSS 10.0
CVE-2014-3188 [CRITICAL] v8: IPC and v8 issue fixed in Google Chrome 38.0.2125.101
v8: IPC and v8 issue fixed in Google Chrome 38.0.2125.101
Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data, related to improper parsing of an escaped index by ParseJsonObject in json-parser.h.
Package: ruby193-v8 (CloudForms Management Engine 5) - Will not fix
Package: ruby193-v8 (OpenShift Enterprise 1) - Will not fix
Package: v8 (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Will not fix
Package: v8 (Red Hat OpenShift Enterprise 2) - Will not fix
Package: ruby193-v8 (Red Hat OpenStack Platform 4) - Will not fix
Package: v8 (Red Hat OpenStack Platform 4) - Will not fix
Package: v8 (Red Hat Satellite
Red Hat
v8: information leak fixed in Google Chrome 38.0.2125.101
vendor_redhat·2014-09-18·CVSS 5.0
CVE-2014-3195 [MEDIUM] v8: information leak fixed in Google Chrome 38.0.2125.101
v8: information leak fixed in Google Chrome 38.0.2125.101
Google V8, as used in Google Chrome before 38.0.2125.101, does not properly track JavaScript heap-memory allocations as allocations of uninitialized memory and does not properly concatenate arrays of double-precision floating-point numbers, which allows remote attackers to obtain sensitive information via crafted JavaScript code, related to the PagedSpace::AllocateRaw and NewSpace::AllocateRaw functions in heap/spaces-inl.h, the LargeObjectSpace::AllocateRaw function in heap/spaces.cc, and the Runtime_ArrayConcat function in runtime.cc.
Package: ruby193-v8 (CloudForms Management Engine 5) - Will not fix
Package: ruby193-v8 (OpenShift Enterprise 1) - Will not fix
Package: v8 (Red Hat Enterprise Linux OpenStack Platform 5 (Icehous
Cisco
Cisco Unity Connection Cross-Site Scripting Vulnerability
vendor_cisco·2014-04-01·CVSS 4.3
CVE-2014-2125 [MEDIUM] CWE-79 Cisco Unity Connection Cross-Site Scripting Vulnerability
Cisco Unity Connection Cross-Site Scripting Vulnerability
A vulnerability in Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack.
The vulnerability is due to insufficient input validation of a parameter. An attacker could exploit this vulnerability by persuading a user to access a malicious link.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit the vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading language or instructions to persuade the user to follow the provided link.
Cisco indicates through the CVSS score that proof-of-concept exploit code exists; however, the code is not known to be publicly availa
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3200 chromium: multiple unspecified issues fixed in Chrome 38.0.2125.101
bugzilla·2014-10-10·CVSS 7.5
CVE-2014-3200 [HIGH] CVE-2014-3200 chromium: multiple unspecified issues fixed in Chrome 38.0.2125.101
CVE-2014-3200 chromium: multiple unspecified issues fixed in Chrome 38.0.2125.101
Multiple unspecified vulnerabilities in Google Chrome before 38.0.2125.101 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
https://code.google.com/p/chromium/issues/detail?id=420899
External References:
http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html
Discussion:
Upstream bug links a long list of other bugs for issue that were (most likely incorrectly) grouped under a single CVE. With most of those other bugs being non-public, it's quite impossible to determine if any of the corrected issues may affect any WebKit version.
---
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Bugzilla
CVE-2014-3197 chromium: information leak in XSS Auditor fixed in Chrome 38.0.2125.101
bugzilla·2014-10-10·CVSS 5.0
CVE-2014-3197 [MEDIUM] CVE-2014-3197 chromium: information leak in XSS Auditor fixed in Chrome 38.0.2125.101
CVE-2014-3197 chromium: information leak in XSS Auditor fixed in Chrome 38.0.2125.101
The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attackers to obtain sensitive information via a crafted web site.
https://crbug.com/396544
https://src.chromium.org/viewvc/blink?revision=179240&view=revision
External References:
http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html
Discussion:
While WebKit contains NavigationScheduler, it does not seem to contain functionality corrected by the fix for this issue. Note that XSS auditor is feature of the Chrome/Chromium browser, hence
Bugzilla
CVE-2014-3190 CVE-2014-3191 CVE-2014-3193 CVE-2014-3199 chromium: multiple security fixes in Chrome 38.0.2125.101
bugzilla·2014-10-10·CVSS 7.5
CVE-2014-3190 [HIGH] CVE-2014-3190 CVE-2014-3191 CVE-2014-3193 CVE-2014-3199 chromium: multiple security fixes in Chrome 38.0.2125.101
CVE-2014-3190 CVE-2014-3191 CVE-2014-3193 CVE-2014-3199 chromium: multiple security fixes in Chrome 38.0.2125.101
Chrome version 38.0.2125.101 fixes multiple security flaws:
CVE-2014-3190
Use-after-free vulnerability in the Event::currentTarget function in core/events/Event.cpp in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code that accesses the path property of an Event object.
https://crbug.com/400476
https://src.chromium.org/viewvc/blink?revision=181234&view=revision
CVE-2014-3191
Use-after-free vulnerability in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have
Bugzilla
CVE-2014-3192 chromium: use-after-free in DOM, fixed in Chrome 38.0.2125.101
bugzilla·2014-10-10·CVSS 7.5
CVE-2014-3192 [HIGH] CVE-2014-3192 chromium: use-after-free in DOM, fixed in Chrome 38.0.2125.101
CVE-2014-3192 chromium: use-after-free in DOM, fixed in Chrome 38.0.2125.101
Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
https://crbug.com/403276
https://src.chromium.org/viewvc/blink?revision=182309&view=revision
External References:
http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html
Discussion:
Patch also seems applicable to WebKit, but it's unclear if it is really affected too. I have not looked at any QtWebKit version.
---
This issue has been addressed in the following products:
Bugzilla
CVE-2014-3194 chromium: use-after-free issue in Web Workers fixed in Chrome 38.0.2125.101
bugzilla·2014-10-10·CVSS 7.5
CVE-2014-3194 [HIGH] CVE-2014-3194 chromium: use-after-free issue in Web Workers fixed in Chrome 38.0.2125.101
CVE-2014-3194 chromium: use-after-free issue in Web Workers fixed in Chrome 38.0.2125.101
Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
https://crbug.com/401115
External References:
http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html
Discussion:
Upstream bug is close, there does not seem to be any details available for this flaw. It's currently unclear if this may affect any WebKit version.
---
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2014:1626 https://rhn.redhat.com/errata/RHSA-2014-1626.html
---
Upstream commit:
ht
Bugzilla
CVE-2014-3189 CVE-2014-3198 chromium: OOB reads in PDFium fixed in Chrome 38.0.2125.101
bugzilla·2014-10-10·CVSS 7.5
CVE-2014-3189 [HIGH] CVE-2014-3189 CVE-2014-3198 chromium: OOB reads in PDFium fixed in Chrome 38.0.2125.101
CVE-2014-3189 CVE-2014-3198 chromium: OOB reads in PDFium fixed in Chrome 38.0.2125.101
Chrome version 38.0.2125.101 fixes two flaws in the embedded PDF viewer PDFium:
CVE-2014-3189
The chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium component in Google Chrome before 38.0.2125.101 does not properly validate image-data dimensions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via unknown vectors.
https://crbug.com/398384
https://codereview.chromium.org/519873002/
CVE-2014-3198
The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows re
Bugzilla
CVE-2014-3188 v8: IPC and v8 issue fixed in Google Chrome 38.0.2125.101
bugzilla·2014-10-09·CVSS 10.0
CVE-2014-3188 [CRITICAL] CVE-2014-3188 v8: IPC and v8 issue fixed in Google Chrome 38.0.2125.101
CVE-2014-3188 v8: IPC and v8 issue fixed in Google Chrome 38.0.2125.101
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-3188 to
the following vulnerability:
Name: CVE-2014-3188
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3188
Assigned: 20140503
Reference: http://googlechromereleases.blogspot.com/2014/10/stable-channel-update-for-chrome-os.html
Reference: http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html
Reference: https://code.google.com/p/v8/source/detail?r=24125
Reference: https://crbug.com/416449
Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101
do not properly handle the interaction of IPC and Google V8, which
allows remote attackers to execute arbitrary code via vectors
involving JSON data, related t
Bugzilla
CVE-2014-3195 v8: information leak fixed in Google Chrome 38.0.2125.101
bugzilla·2014-10-09·CVSS 5.0
CVE-2014-3195 [MEDIUM] CVE-2014-3195 v8: information leak fixed in Google Chrome 38.0.2125.101
CVE-2014-3195 v8: information leak fixed in Google Chrome 38.0.2125.101
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-3195 to
the following vulnerability:
Name: CVE-2014-3195
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3195
Assigned: 20140503
Reference: http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html
Reference: https://code.google.com/p/v8/source/detail?r=23144
Reference: https://code.google.com/p/v8/source/detail?r=23268
Reference: https://crbug.com/403409
Google V8, as used in Google Chrome before 38.0.2125.101, does not
properly track JavaScript heap-memory allocations as allocations of
uninitialized memory and does not properly concatenate arrays of
double-precision floating-point numbers, which allows remote attacke
Bugzilla
CVE-2014-7967 v8: multiple unspecified issues fixed in Google Chrome 38.0.2125.101
bugzilla·2014-10-09·CVSS 7.5
CVE-2014-7967 [HIGH] CVE-2014-7967 v8: multiple unspecified issues fixed in Google Chrome 38.0.2125.101
CVE-2014-7967 v8: multiple unspecified issues fixed in Google Chrome 38.0.2125.101
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-7967 to
the following vulnerability:
Name: CVE-2014-7967
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7967
Assigned: 20141008
Reference: http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html
Multiple unspecified vulnerabilities in Google V8 before 3.28.71.15,
as used in Google Chrome before 38.0.2125.101, allow attackers to
cause a denial of service or possibly have other impact via unknown
vectors.
It is not clear if the Fedora v8 packages are affected or not.
Discussion:
manifest.txt:36260:rhn_satellite:6.5/v8-3.14.5.10-19.el7sat
At this time, we have no additional z-streams planned for sat-6.5.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2125http://tools.cisco.com/security/center/viewAlert.x?alertId=33603http://www.securitytracker.com/id/1029988http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2125http://tools.cisco.com/security/center/viewAlert.x?alertId=33603http://www.securitytracker.com/id/1029988
2014-04-02
Published