AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2013-6774

HIGH · CVSS 10 EPSS 1.60%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-03-31 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2013-6774
Severity
HIGH
CVSS
10
EPSS
1.60%
Android

Original NVD Description

Untrusted search path vulnerability in the ChainsDD Superuser package 3.1.3 for Android 4.2.x and earlier, CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.2.x and earlier, and Chainfire SuperSU package before 1.69 for Android 4.2.x and earlier allows attackers to load an arbitrary .jar file and gain privileges via a crafted BOOTCLASSPATH environment variable for a /system/xbin/su process. NOTE: another researcher was unable to reproduce this with ChainsDD Superuser.