Google Security Advisories · May 2011 — Google Security Advisories
13 advisories 13 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2011-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2011-0419

Open SourceWeaponized exploitHIGH2011-05-12

Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac O...

CVEs:CVE-2011-0419

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
freebsd affected freebsd
http_server affected apache
linux_enterprise_server affected suse
mac_os_x affected apple
netbsd affected netbsd
openbsd affected openbsd
portable_runtime affected apache
solaris affected oracle
Upstream advisory

DSA-2245-1

Open SourcePoC exploit2011-05-29

chromium-browser - several vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:6.0 chromium-browser
Upstream advisory

CVE-2011-1807

GoogleEPSS <= 49%HIGH2011-05-25

Google Chrome before 11.0.696.71 does not properly handle blobs, which allows remote attackers to execute arbitrary code via unspecified vectors that trigger an out-of-bounds write.

CVEs:CVE-2011-1807

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1806

GoogleEPSS <= 49%HIGH2011-05-25

Google Chrome before 11.0.696.71 does not properly implement the GPU command buffer, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

CVEs:CVE-2011-1806

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2075

GoogleEPSS <= 49%HIGH2011-05-10

Unspecified vulnerability in Google Chrome 11.0.696.65 on Windows 7 SP1 allows remote attackers to execute arbitrary code via unknown vectors. NOTE: as of 20110510, the only disclosure is a vague advisory that possibly relates to multiple vulnerabilit...

CVEs:CVE-2011-2075

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1804

GoogleEPSS <= 49%HIGH2011-05-25

rendering/RenderBox.cpp in WebCore in WebKit before r86862, as used in Google Chrome before 11.0.696.71, does not properly render floats, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown v...

CVEs:CVE-2011-1804

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1800

GoogleEPSS <= 49%CRITICAL2011-05-13

Multiple integer overflows in the SVG Filters implementation in WebCore in WebKit in Google Chrome before 11.0.696.68 allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-1800

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1799

GoogleEPSS <= 49%HIGH2011-05-13

Google Chrome before 11.0.696.68 does not properly perform casts of variables during interaction with the WebKit engine, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-1799

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2011-1801

GoogleEPSS <= 49%MEDIUM2011-05-25

Unspecified vulnerability in Google Chrome before 11.0.696.71 allows remote attackers to bypass the pop-up blocker via unknown vectors.

CVEs:CVE-2011-1801

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1305

GoogleEPSS <= 49%HIGH2011-05-03

Race condition in Google Chrome before 11.0.696.57 on Linux and Mac OS X allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to linked lists and a database.

CVEs:CVE-2011-1305

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2171

GoogleEPSS <= 49%HIGH2011-05-24

Unspecified vulnerability in the dbugs package in Google Chrome OS before R12 0.12.433.38 Beta has unknown impact and attack vectors.

CVEs:CVE-2011-2171

Affected products

ProductStatusVendorPackageEcosystem
chrome_os affected google
Upstream advisory

CVE-2011-2169

GoogleEPSS <= 49%HIGH2011-05-24

Google Chrome OS before R12 0.12.433.38 Beta allows local users to gain privileges by creating a /var/lib/chromeos-aliases.conf file and placing commands in it.

CVEs:CVE-2011-2169

Affected products

ProductStatusVendorPackageEcosystem
chrome_os affected google
Upstream advisory

CVE-2011-2170

GoogleEPSS <= 49%HIGH2011-05-24

Google Chrome OS before R12 0.12.433.38 Beta, when Guest mode is enabled, does not prevent changes on the about:flags page, which has unspecified impact and local attack vectors.

CVEs:CVE-2011-2170

Affected products

ProductStatusVendorPackageEcosystem
chrome_os affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.