Google Security Advisories · February 2011 — Google Security Advisories
16 advisories 16 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2011-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

DSA-2166-1

Open SourcePoC exploit2011-02-16

chromium-browser - several

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:6.0 chromium-browser
Upstream advisory

CVE-2011-0983

GooglePoC exploitHIGH2011-02-08

Google Chrome before 9.0.597.94 does not properly handle anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

CVEs:CVE-2011-0983

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-0982

GoogleEPSS <= 49%HIGH2011-02-09

Use-after-free vulnerability in Google Chrome before 9.0.597.94 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG font faces.

CVEs:CVE-2011-0982

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-0981

GoogleEPSS <= 49%HIGH2011-02-08

Google Chrome before 9.0.597.94 does not properly perform event handling for animations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

CVEs:CVE-2011-0981

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-0984

GoogleEPSS <= 49%HIGH2011-02-09

Google Chrome before 9.0.597.94 does not properly handle plug-ins, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2011-0984

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2011-0985

GoogleEPSS <= 49%HIGH2011-02-09

Google Chrome before 9.0.597.94 does not properly perform process termination upon memory exhaustion, which has unspecified impact and remote attack vectors.

CVEs:CVE-2011-0985

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2011-0777

GoogleEPSS <= 49%CRITICAL2011-02-04

Use-after-free vulnerability in Google Chrome before 9.0.597.84 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to image loading.

CVEs:CVE-2011-0777

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-0779

GoogleEPSS <= 49%HIGH2011-02-04

Google Chrome before 9.0.597.84 does not properly handle a missing key in an extension, which allows remote attackers to cause a denial of service (application crash) via a crafted extension.

CVEs:CVE-2011-0779

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2011-1059

GoogleEPSS <= 49%CRITICAL2011-02-22

Use-after-free vulnerability in WebCore in WebKit before r77705, as used in Google Chrome before 11.0.672.2 and other products, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly have unspecified other im...

CVEs:CVE-2011-1059

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-0778

GoogleEPSS <= 49%HIGH2011-02-04

Google Chrome before 9.0.597.84 does not properly restrict drag and drop operations, which might allow remote attackers to bypass the Same Origin Policy via unspecified vectors.

CVEs:CVE-2011-0778

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-0784

GoogleEPSS <= 49%CRITICAL2011-02-04

Race condition in Google Chrome before 9.0.597.84 allows remote attackers to execute arbitrary code via vectors related to audio.

CVEs:CVE-2011-0784

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-0783

GoogleEPSS <= 49%HIGH2011-02-04

Unspecified vulnerability in Google Chrome before 9.0.597.84 allows user-assisted remote attackers to cause a denial of service (application crash) via vectors involving a "bad volume setting."

CVEs:CVE-2011-0783

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2011-0782

GoogleEPSS <= 49%HIGH2011-02-04

Google Chrome before 9.0.597.84 on Mac OS X does not properly mitigate an unspecified flaw in the Mac OS X 10.5 SSL libraries, which allows remote attackers to cause a denial of service (application crash) via unknown vectors.

CVEs:CVE-2011-0782

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-0776

GoogleEPSS <= 49%HIGH2011-02-04

The sandbox implementation in Google Chrome before 9.0.597.84 on Mac OS X might allow remote attackers to obtain potentially sensitive information about local files via vectors related to the stat system call.

CVEs:CVE-2011-0776

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-0780

GoogleEPSS <= 49%HIGH2011-02-04

The PDF event handler in Google Chrome before 9.0.597.84 does not properly interact with print operations, which allows user-assisted remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknow...

CVEs:CVE-2011-0780

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-0781

GoogleEPSS <= 49%HIGH2011-02-04

Google Chrome before 9.0.597.84 does not properly handle autofill profile merging, which has unspecified impact and remote attack vectors.

CVEs:CVE-2011-0781

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.