Google Security Advisories · January 2011 — Google Security Advisories
18 advisories 18 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2011-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2011-0485

GoogleEPSS <= 49%HIGH2011-01-14

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle speech data, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "stale pointer."

CVEs:CVE-2011-0485

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
Upstream advisory

CVE-2011-0474

GoogleEPSS <= 49%HIGH2011-01-14

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading Style Sheets (CSS) token sequences in conjunction with cursors, which allows remote attackers to cause a denial of service or possibly have unspecified o...

CVEs:CVE-2011-0474

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
debian_linux affected debian
Upstream advisory

CVE-2011-0477

GoogleEPSS <= 49%HIGH2011-01-14

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle a mismatch in video frame sizes, which allows remote attackers to cause a denial of service (incorrect memory access) or possibly have unspecified other impact via...

CVEs:CVE-2011-0477

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
Upstream advisory

CVE-2011-0478

GoogleEPSS <= 49%HIGH2011-01-14

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle SVG use elements, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale po...

CVEs:CVE-2011-0478

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
Upstream advisory

CVE-2011-0476

GoogleEPSS <= 49%HIGH2011-01-14

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allow remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via a PDF document that triggers an out-of-memory error.

CVEs:CVE-2011-0476

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
Upstream advisory

CVE-2011-0471

GoogleEPSS <= 49%HIGH2011-01-14

The node-iteration implementation in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 does not properly handle pointers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown v...

CVEs:CVE-2011-0471

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
Upstream advisory

CVE-2011-0473

GoogleEPSS <= 49%HIGH2011-01-14

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading Style Sheets (CSS) token sequences in conjunction with CANVAS elements, which allows remote attackers to cause a denial of service or possibly have unspe...

CVEs:CVE-2011-0473

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
Upstream advisory

CVE-2011-0481

GoogleEPSS <= 49%HIGH2011-01-14

Buffer overflow in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to PDF shading.

CVEs:CVE-2011-0481

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
Upstream advisory

CVE-2011-0480

GoogleEPSS <= 49%HIGH2011-01-14

Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corruption and application crash) or po...

CVEs:CVE-2011-0480

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
debian_linux affected debian
ubuntu_linux affected canonical
Upstream advisory

CVE-2011-0472

GoogleEPSS <= 49%HIGH2011-01-14

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle the printing of PDF documents, which allows user-assisted remote attackers to cause a denial of service (application crash) or possibly have unspecified other impa...

CVEs:CVE-2011-0472

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
Upstream advisory

CVE-2011-0475

GoogleEPSS <= 49%HIGH2011-01-14

Use-after-free vulnerability in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a PDF document.

CVEs:CVE-2011-0475

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
Upstream advisory

CVE-2011-0484

GoogleEPSS <= 49%HIGH2011-01-14

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform DOM node removal, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale r...

CVEs:CVE-2011-0484

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
Upstream advisory

CVE-2011-0482

GoogleEPSS <= 49%HIGH2011-01-14

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform a cast of an unspecified variable during handling of anchors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact...

CVEs:CVE-2011-0482

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
debian_linux affected debian
Upstream advisory

CVE-2011-0470

GoogleEPSS <= 49%HIGH2011-01-14

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle extensions notification, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

CVEs:CVE-2011-0470

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
Upstream advisory

CVE-2011-0680

Open SourceEPSS <= 49%MEDIUM2011-01-31

data/WorkingMessage.java in the Mms application in Android before 2.2.2 and 2.3.x before 2.3.2 does not properly manage the draft cache, which allows remote attackers to read SMS messages intended for other recipients in opportunistic circumstances via...

CVEs:CVE-2011-0680

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2011-0483

GoogleEPSS <= 49%HIGH2011-01-14

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform a cast of an unspecified variable during handling of video, which allows remote attackers to cause a denial of service or possibly have unspecified other impact v...

CVEs:CVE-2011-0483

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
Upstream advisory

CVE-2011-0479

GoogleEPSS <= 49%HIGH2011-01-14

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly interact with extensions, which allows remote attackers to cause a denial of service via a crafted extension that triggers an uninitialized pointer.

CVEs:CVE-2011-0479

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
Upstream advisory

CVE-2011-1042

GoogleEPSS <= 49%CRITICAL2011-01-27

Use-after-free vulnerability in flimflamd in flimflam in Google Chrome OS before 0.9.130.14 Beta allows user-assisted remote attackers to cause a denial of service (daemon crash) by providing the name of a hidden WiFi network that does not respond to c...

CVEs:CVE-2011-1042

Affected products

ProductStatusVendorPackageEcosystem
chrome_os affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.