Google Security Advisories · July 2011 — Google Security Advisories
6 advisories 6 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2011-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2011-1797

Open SourceEPSS <= 49%HIGH2011-07-21

WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in AP...

CVEs:CVE-2011-1797

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chromium_project
safari affected apple
webkit affected apple
Upstream advisory

CVE-2011-2747

GoogleEPSS <= 49%HIGH2011-07-21

Google Picasa before 3.6 Build 105.67 does not properly handle invalid properties in JPEG images, which allows remote attackers to execute arbitrary code via a crafted image file.

CVEs:CVE-2011-2747

Affected products

ProductStatusVendorPackageEcosystem
picasa affected google
Upstream advisory

CVE-2011-1001

Open SourceEPSS <= 49%CRITICAL2011-07-08

dexdump in Android SDK before 2.3 does not properly perform structural verification, which allows user-assisted remote attackers to cause a denial of service (dexdump crash) and possibly execute arbitrary code via a malformed APK or dex file that calls...

CVEs:CVE-2011-1001

Affected products

ProductStatusVendorPackageEcosystem
android_sdk affected google
Upstream advisory

CVE-2011-2344

Open SourceEPSS <= 49%HIGH2011-07-08

Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which allows remote attackers to gain privileges and access private pictures and web albums by sniffing the tok...

CVEs:CVE-2011-2344

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2011-2761

GoogleEPSS <= 49%HIGH2011-07-18

Google Chrome 14.0.794.0 does not properly handle a reload of a page generated in response to a POST, which allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted web site, related to GetWidget methods.

CVEs:CVE-2011-2761

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-1339

GoogleEPSS <= 49%CRITICAL2011-07-15

Cross-site scripting (XSS) vulnerability in Google Search Appliance before 5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVEs:CVE-2011-1339

Affected products

ProductStatusVendorPackageEcosystem
search_appliance affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.