CVE-2014-7905
published 2014-11-19CVE-2014-7905: Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL lacks CATEGORY_BROWSABLE, which allows…
PriorityP420medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.06%
61.3th percentile
Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL lacks CATEGORY_BROWSABLE, which allows remote attackers to bypass intended access restrictions via a crafted web site.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 39.0.2171.45 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jwgh-94cg-cfg5: Google Chrome before 39
ghsa_unreviewed·2022-05-17
CVE-2014-7905 [MEDIUM] CWE-284 GHSA-jwgh-94cg-cfg5: Google Chrome before 39
Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL lacks CATEGORY_BROWSABLE, which allows remote attackers to bypass intended access restrictions via a crafted web site.
OSV
CVE-2014-7905: Google Chrome before 39
osv·2014-11-19·CVSS 5.0
CVE-2014-7905 [MEDIUM] CVE-2014-7905: Google Chrome before 39
Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL lacks CATEGORY_BROWSABLE, which allows remote attackers to bypass intended access restrictions via a crafted web site.
Red Hat
chromium-browser: Flaw allowing navigation to intents that do not have the BROWSABLE category
vendor_redhat·2014-11-18·CVSS 5.0
CVE-2014-7905 [MEDIUM] chromium-browser: Flaw allowing navigation to intents that do not have the BROWSABLE category
chromium-browser: Flaw allowing navigation to intents that do not have the BROWSABLE category
Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL lacks CATEGORY_BROWSABLE, which allows remote attackers to bypass intended access restrictions via a crafted web site.
Statement: Not vulnerable. This issue does not affect the version of chromium-browser as shipped with Red Hat Enterprise Linux 6.
Package: chromium-browser (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.htmlhttp://www.securityfocus.com/bid/71162http://www.securitytracker.com/id/1031241https://code.google.com/p/chromium/issues/detail?id=421817https://exchange.xforce.ibmcloud.com/vulnerabilities/98793http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.htmlhttp://www.securityfocus.com/bid/71162http://www.securitytracker.com/id/1031241https://code.google.com/p/chromium/issues/detail?id=421817https://exchange.xforce.ibmcloud.com/vulnerabilities/98793
2014-11-19
Published