Google Security Advisories · November 2005 — Google Security Advisories
8 advisories 8 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2005-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2005-3757

GoogleActive exploitation (sightings)CRITICAL2005-11-22

The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to obtain sensitive information and execute arbitrary code via dangerous Java class methods in select attribute of xsl:value-of tags in...

CVEs:CVE-2005-3757

Affected products

ProductStatusVendorPackageEcosystem
mini_search_appliance affected google
search_appliance affected google
Upstream advisory

CVE-2005-3758

GooglePoC exploitCRITICAL2005-11-22

Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via a proxystylesheet variable that contains ...

CVEs:CVE-2005-3758

Affected products

ProductStatusVendorPackageEcosystem
mini_search_appliance affected google
search_appliance affected google
Upstream advisory

CVE-2005-3755

GoogleEPSS <= 49%HIGH2005-11-22

Directory traversal vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to determine the existence of arbitrary files via a relative path from a style sheet directory, then comparing the resultin...

CVEs:CVE-2005-3755

Affected products

ProductStatusVendorPackageEcosystem
mini_search_appliance affected google
search_appliance affected google
Upstream advisory

CVE-2005-3869

GoogleEPSS <= 49%CRITICAL2005-11-29

Cross-site scripting (XSS) vulnerability in index.php in Google API Search 1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the REQ parameter.

CVEs:CVE-2005-3869

Affected products

ProductStatusVendorPackageEcosystem
api_search affected google
Upstream advisory

CVE-2005-3754

GoogleEPSS <= 49%CRITICAL2005-11-22

Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via the proxystylesheet variable, which will ...

CVEs:CVE-2005-3754

Affected products

ProductStatusVendorPackageEcosystem
mini_search_appliance affected google
search_appliance affected google
Upstream advisory

CVE-2005-3756

GoogleEPSS <= 49%MEDIUM2005-11-22

Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to port scan arbitrary hosts via URLs with modified targets and ports, then comparing the resulting error messages to determine open and closed ports.

CVEs:CVE-2005-3756

Affected products

ProductStatusVendorPackageEcosystem
mini_search_appliance affected google
search_appliance affected google
Upstream advisory

CVE-2005-3678

GoogleEPSS <= 49%HIGH2005-11-18

Google Talk before 1.0.0.76, with email notification enabled, allows remote attackers to cause a denial of service (connection reset) via email with a blank sender.

CVEs:CVE-2005-3678

Affected products

ProductStatusVendorPackageEcosystem
talk affected google
Upstream advisory

CVE-2005-3899

GoogleEPSS <= 49%HIGH2005-11-29

The automatic update feature in Google Talk allows remote attackers to cause a denial of service (CPU and memory consumption) by poisoning a target's DNS cache and causing a large update file to be sent, which consumes large amounts of CPU and memory d...

CVEs:CVE-2005-3899

Affected products

ProductStatusVendorPackageEcosystem
talk affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.