← Back

CVE-2014-1939

nvd nist
Published: Mar 3, 2014Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by leveraging access to the searchBoxJavaBridge_ interface at certain Android API levels.

Affected (13)

Products: Google: Android · Lenovo: Shareit
1 product
Android
1 product
Shareit
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Google
Up to 4.3.1
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.0
Version 4.1.2
Version 4.1
Version 4.2.1
Version 4.2.2
Version 4.2
Version 4.3
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.5.88_ww

Timeline

No history available yet.