Google Security Advisories · March 2011 — Google Security Advisories
54 advisories 54 CVEs 1 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2011-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2011-0609

GoogleExploitedCISA KEV listedHIGH2011-03-15

Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x...

CVEs:CVE-2011-0609

Affected products

ProductStatusVendorPackageEcosystem
acrobat affected adobe
acrobat_reader affected adobe
air affected adobe
chrome affected google
flash_player affected adobe
linux_enterprise affected suse
opensuse affected opensuse
Upstream advisory

DSA-2192-1

Open SourcePoC exploit2011-03-15

chromium-browser - several

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:6.0 chromium-browser
Upstream advisory

CVE-2011-1202

GooglePoC exploitHIGH2011-03-11

The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XM...

CVEs:CVE-2011-1202

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
libxslt affected xmlsoft
Upstream advisory

CVE-2011-1117

GooglePoC exploitHIGH2011-03-01

Google Chrome before 9.0.597.107 does not properly handle XHTML documents, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale nodes."

CVEs:CVE-2011-1117

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-1204

GooglePoC exploitHIGH2011-03-11

Google Chrome before 10.0.648.127 does not properly handle attributes, which allows remote attackers to cause a denial of service (DOM tree corruption) or possibly have unspecified other impact via a crafted document.

CVEs:CVE-2011-1204

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-1186

GoogleEPSS <= 49%HIGH2011-03-11

Google Chrome before 10.0.648.127 on Linux does not properly handle parallel execution of calls to the print method, which might allow remote attackers to cause a denial of service (application crash) via crafted JavaScript code.

CVEs:CVE-2011-1186

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1111

GoogleEPSS <= 49%HIGH2011-03-01

Google Chrome before 9.0.597.107 does not properly implement forms controls, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-1111

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1296

GoogleEPSS <= 49%HIGH2011-03-25

Google Chrome before 10.0.648.204 does not properly handle SVG text, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

CVEs:CVE-2011-1296

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

DSA-2189-1

Open SourceEPSS <= 49%2011-03-10

chromium-browser - several

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:6.0 chromium-browser
Upstream advisory

CVE-2011-1114

GoogleEPSS <= 49%HIGH2011-03-01

Google Chrome before 9.0.597.107 does not properly handle tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."

CVEs:CVE-2011-1114

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-1115

GoogleEPSS <= 49%HIGH2011-03-01

Google Chrome before 9.0.597.107 does not properly render tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

CVEs:CVE-2011-1115

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-1121

GoogleEPSS <= 49%CRITICAL2011-03-01

Integer overflow in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a TEXTAREA element.

CVEs:CVE-2011-1121

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-1293

GoogleEPSS <= 49%CRITICAL2011-03-25

Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-1293

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-1190

GoogleEPSS <= 49%MEDIUM2011-03-11

The Web Workers implementation in Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."

CVEs:CVE-2011-1190

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2011-1203

GoogleEPSS <= 49%HIGH2011-03-11

Google Chrome before 10.0.648.127 does not properly handle SVG cursors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

CVEs:CVE-2011-1203

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-1188

GoogleEPSS <= 49%CRITICAL2011-03-11

Google Chrome before 10.0.648.127 does not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-1188

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-1295

GoogleEPSS <= 49%CRITICAL2011-03-25

WebKit, as used in Google Chrome before 10.0.648.204 and Apple Safari before 5.0.6, does not properly handle node parentage, which allows remote attackers to cause a denial of service (DOM tree corruption), conduct cross-site scripting (XSS) attacks, o...

CVEs:CVE-2011-1295

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2011-1109

GoogleEPSS <= 49%HIGH2011-03-01

Google Chrome before 9.0.597.107 does not properly process nodes in Cascading Style Sheets (CSS) stylesheets, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale...

CVEs:CVE-2011-1109

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-1193

GoogleEPSS <= 49%HIGH2011-03-11

Google V8, as used in Google Chrome before 10.0.648.127, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

CVEs:CVE-2011-1193

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1465

GoogleEPSS <= 49%HIGH2011-03-20

The SPDY implementation in net/http/http_network_transaction.cc in Google Chrome before 11.0.696.14 drains the bodies from SPDY responses, which might allow remote SPDY servers to cause a denial of service (application exit) by canceling a stream.

CVEs:CVE-2011-1465

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1292

GoogleEPSS <= 49%CRITICAL2011-03-25

Use-after-free vulnerability in the frame-loader implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-1292

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2011-1291

GoogleEPSS <= 49%HIGH2011-03-25

Google Chrome before 10.0.648.204 does not properly handle base strings, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, related to a "buffer error."

CVEs:CVE-2011-1291

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1191

GoogleEPSS <= 49%CRITICAL2011-03-11

Use-after-free vulnerability in Google Chrome before 10.0.648.127 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of DOM URLs.

CVEs:CVE-2011-1191

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1195

GoogleEPSS <= 49%CRITICAL2011-03-11

Use-after-free vulnerability in Google Chrome before 10.0.648.127 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to "document script lifetime handling."

CVEs:CVE-2011-1195

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1196

GoogleEPSS <= 49%CRITICAL2011-03-11

The OGG container implementation in Google Chrome before 10.0.648.127 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.

CVEs:CVE-2011-1196

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1198

GoogleEPSS <= 49%HIGH2011-03-11

The video functionality in Google Chrome before 10.0.648.127 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger use of a malformed "out-of-bounds structure."

CVEs:CVE-2011-1198

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1192

GoogleEPSS <= 49%HIGH2011-03-11

Google Chrome before 10.0.648.127 on Linux does not properly handle Unicode ranges, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2011-1192

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1197

GoogleEPSS <= 49%HIGH2011-03-11

Google Chrome before 10.0.648.127 does not properly perform table painting, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

CVEs:CVE-2011-1197

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1187

GoogleEPSS <= 49%MEDIUM2011-03-11

Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."

CVEs:CVE-2011-1187

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
firefox affected mozilla
seamonkey affected mozilla
thunderbird affected mozilla
Upstream advisory

CVE-2011-1286

GoogleEPSS <= 49%HIGH2011-03-11

Google V8, as used in Google Chrome before 10.0.648.127, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger incorrect access to memory.

CVEs:CVE-2011-1286

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1413

GoogleEPSS <= 49%HIGH2011-03-11

Google Chrome before 10.0.648.127 on Linux does not properly mitigate an unspecified flaw in an X server, which allows remote attackers to cause a denial of service (application crash) via vectors involving long messages.

CVEs:CVE-2011-1413

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1189

GoogleEPSS <= 49%HIGH2011-03-11

Google Chrome before 10.0.648.127 does not properly perform box layout, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."

CVEs:CVE-2011-1189

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1294

GoogleEPSS <= 49%HIGH2011-03-25

Google Chrome before 10.0.648.204 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale poin...

CVEs:CVE-2011-1294

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1199

GoogleEPSS <= 49%HIGH2011-03-11

Google Chrome before 10.0.648.127 does not properly handle DataView objects, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-1199

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1201

GoogleEPSS <= 49%HIGH2011-03-11

The context implementation in WebKit, as used in Google Chrome before 10.0.648.127, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

CVEs:CVE-2011-1201

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1110

GoogleEPSS <= 49%HIGH2011-03-01

Google Chrome before 9.0.597.107 does not properly implement key frame rules, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

CVEs:CVE-2011-1110

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1112

GoogleEPSS <= 49%HIGH2011-03-01

Google Chrome before 9.0.597.107 does not properly perform SVG rendering, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-1112

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1116

GoogleEPSS <= 49%HIGH2011-03-01

Google Chrome before 9.0.597.107 does not properly handle SVG animations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

CVEs:CVE-2011-1116

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1124

GoogleEPSS <= 49%CRITICAL2011-03-01

Use-after-free vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to blocked plug-ins.

CVEs:CVE-2011-1124

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1125

GoogleEPSS <= 49%HIGH2011-03-01

Google Chrome before 9.0.597.107 does not properly perform layout, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

CVEs:CVE-2011-1125

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1285

GoogleEPSS <= 49%CRITICAL2011-03-11

The regular-expression functionality in Google Chrome before 10.0.648.127 does not properly implement reentrancy, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-1285

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1120

GoogleEPSS <= 49%HIGH2011-03-01

The WebGL implementation in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, aka Issue 71717.

CVEs:CVE-2011-1120

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1122

GoogleEPSS <= 49%HIGH2011-03-01

The WebGL implementation in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, aka Issue 71960.

CVEs:CVE-2011-1122

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1113

GoogleEPSS <= 49%HIGH2011-03-01

Google Chrome before 9.0.597.107 on 64-bit Linux platforms does not properly perform pickle deserialization, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2011-1113

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1119

GoogleEPSS <= 49%HIGH2011-03-01

Google Chrome before 9.0.597.107 does not properly determine device orientation, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

CVEs:CVE-2011-1119

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1107

GoogleEPSS <= 49%MEDIUM2011-03-01

Unspecified vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to spoof the URL bar via unknown vectors.

CVEs:CVE-2011-1107

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2011-1194

GoogleEPSS <= 49%MEDIUM2011-03-11

Multiple unspecified vulnerabilities in Google Chrome before 10.0.648.127 allow remote attackers to bypass the pop-up blocker via unknown vectors.

CVEs:CVE-2011-1194

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1185

GoogleEPSS <= 49%HIGH2011-03-11

Google Chrome before 10.0.648.127 does not prevent (1) navigation and (2) close operations on the top location of a sandboxed frame, which has unspecified impact and remote attack vectors.

CVEs:CVE-2011-1185

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1200

GoogleEPSS <= 49%HIGH2011-03-11

Google Chrome before 10.0.648.127 does not properly perform a cast of an unspecified variable during text rendering, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.

CVEs:CVE-2011-1200

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1108

GoogleEPSS <= 49%HIGH2011-03-01

Google Chrome before 9.0.597.107 does not properly implement JavaScript dialogs, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document.

CVEs:CVE-2011-1108

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1118

GoogleEPSS <= 49%HIGH2011-03-01

Google Chrome before 9.0.597.107 does not properly handle TEXTAREA elements, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document.

CVEs:CVE-2011-1118

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1123

GoogleEPSS <= 49%HIGH2011-03-01

Google Chrome before 9.0.597.107 does not properly restrict access to internal extension functions, which has unspecified impact and remote attack vectors.

CVEs:CVE-2011-1123

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1306

GoogleEPSS <= 49%HIGH2011-03-08

Unspecified vulnerability in the Scratchpad application in Google Chrome OS before R10 0.10.156.46 Beta has unknown impact and attack vectors.

CVEs:CVE-2011-1306

Affected products

ProductStatusVendorPackageEcosystem
chrome_os affected google
Upstream advisory

CVE-2011-0458

GoogleEPSS <= 49%MEDIUM2011-03-28

Untrusted search path vulnerability in the Locate on Disk feature in Google Picasa before 3.8 allows local users to gain privileges via a Trojan horse executable file in the current working directory.

CVEs:CVE-2011-0458

Affected products

ProductStatusVendorPackageEcosystem
picasa affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.