Advisories
Open SourceEPSS <= 49%HIGH2011-07-21
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in AP...
CVEs:CVE-2011-1797
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
chromium_project |
— |
— |
| safari |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
GoogleEPSS <= 49%HIGH2011-07-21
Google Picasa before 3.6 Build 105.67 does not properly handle invalid properties in JPEG images, which allows remote attackers to execute arbitrary code via a crafted image file.
CVEs:CVE-2011-2747
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| picasa |
affected |
google |
— |
— |
Open SourceEPSS <= 49%CRITICAL2011-07-08
dexdump in Android SDK before 2.3 does not properly perform structural verification, which allows user-assisted remote attackers to cause a denial of service (dexdump crash) and possibly execute arbitrary code via a malformed APK or dex file that calls...
CVEs:CVE-2011-1001
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android_sdk |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2011-07-08
Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which allows remote attackers to gain privileges and access private pictures and web albums by sniffing the tok...
CVEs:CVE-2011-2344
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2011-07-18
Google Chrome 14.0.794.0 does not properly handle a reload of a page generated in response to a POST, which allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted web site, related to GetWidget methods.
CVEs:CVE-2011-2761
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2011-07-15
Cross-site scripting (XSS) vulnerability in Google Search Appliance before 5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVEs:CVE-2011-1339
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| search_appliance |
affected |
google |
— |
— |