Google Security Advisories · August 2011 — Google Security Advisories
44 advisories 44 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2011-08. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2011-2821

GooglePoC exploitCRITICAL2011-08-22

Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.

CVEs:CVE-2011-2821

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_eus affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2011-2823

GooglePoC exploitCRITICAL2011-08-23

Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a line box.

CVEs:CVE-2011-2823

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-2359

GooglePoC exploitHIGH2011-08-03

Google Chrome before 13.0.782.107 does not properly track line boxes during rendering, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

CVEs:CVE-2011-2359

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-2788

GooglePoC exploitCRITICAL2011-08-03

Buffer overflow in the inspector serialization functionality in Google Chrome before 13.0.782.107 allows user-assisted remote attackers to have an unspecified impact via unknown vectors.

CVEs:CVE-2011-2788

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-2819

GooglePoC exploitMEDIUM2011-08-03

Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy via vectors related to handling of the base URI.

CVEs:CVE-2011-2819

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2008-7298

Open SourcePoC exploitMEDIUM2011-08-09

The Android browser in Android cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to la...

CVEs:CVE-2008-7298

Affected products

ProductStatusVendorPackageEcosystem
android affected google
android_browser affected android
Upstream advisory

CVE-2011-2357

Open SourceEPSS <= 49%CRITICAL2011-08-12

Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4 and 3.1 allows local applications to bypass the sandbox and execute arbitrary Javascript in arbitrary domains by (1) causing the MAX_TAB number of tabs ...

CVEs:CVE-2011-2357

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2011-2825

GoogleEPSS <= 49%HIGH2011-08-23

Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving custom fonts.

CVEs:CVE-2011-2825

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-2806

GoogleEPSS <= 49%HIGH2011-08-23

Google Chrome before 13.0.782.215 on Windows does not properly handle vertex data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

CVEs:CVE-2011-2806

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2827

GoogleEPSS <= 49%CRITICAL2011-08-23

Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to text searching.

CVEs:CVE-2011-2827

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-2790

GoogleEPSS <= 49%CRITICAL2011-08-03

Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving floating styles.

CVEs:CVE-2011-2790

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-2797

GoogleEPSS <= 49%CRITICAL2011-08-03

Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to resource caching.

CVEs:CVE-2011-2797

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-2799

GoogleEPSS <= 49%CRITICAL2011-08-03

Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to HTML range handling.

CVEs:CVE-2011-2799

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-2792

GoogleEPSS <= 49%CRITICAL2011-08-03

Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to float removal.

CVEs:CVE-2011-2792

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-2800

GoogleEPSS <= 49%HIGH2011-08-03

Google Chrome before 13.0.782.107 allows remote attackers to obtain potentially sensitive information about client-side redirect targets via a crafted web site.

CVEs:CVE-2011-2800

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2011-2804

GoogleEPSS <= 49%HIGH2011-08-03

Google Chrome before 13.0.782.107 does not properly handle nested functions in PDF documents, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted document.

CVEs:CVE-2011-2804

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2805

GoogleEPSS <= 49%CRITICAL2011-08-03

Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy and conduct script injection attacks via unspecified vectors.

CVEs:CVE-2011-2805

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2011-2818

GoogleEPSS <= 49%CRITICAL2011-08-03

Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to display box rendering.

CVEs:CVE-2011-2818

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-2839

GoogleEPSS <= 49%HIGH2011-08-23

The PDF implementation in Google Chrome before 13.0.782.215 on Linux does not properly use the memset library function, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-2839

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2782

GoogleEPSS <= 49%CRITICAL2011-08-03

The drag-and-drop implementation in Google Chrome before 13.0.782.107 on Linux does not properly enforce permissions for files, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.

CVEs:CVE-2011-2782

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2793

GoogleEPSS <= 49%CRITICAL2011-08-03

Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to media selectors.

CVEs:CVE-2011-2793

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2803

GoogleEPSS <= 49%HIGH2011-08-03

Google Chrome before 13.0.782.107 does not properly handle Skia paths, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2011-2803

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2789

GoogleEPSS <= 49%CRITICAL2011-08-03

Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to instantiation of the Pepper plug-in.

CVEs:CVE-2011-2789

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2791

GoogleEPSS <= 49%CRITICAL2011-08-03

The International Components for Unicode (ICU) functionality in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.

CVEs:CVE-2011-2791

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2794

GoogleEPSS <= 49%HIGH2011-08-03

Google Chrome before 13.0.782.107 does not properly perform text iteration, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2011-2794

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2796

GoogleEPSS <= 49%CRITICAL2011-08-03

Use-after-free vulnerability in Skia, as used in Google Chrome before 13.0.782.107, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-2796

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2801

GoogleEPSS <= 49%CRITICAL2011-08-03

Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the frame loader.

CVEs:CVE-2011-2801

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2795

GoogleEPSS <= 49%MEDIUM2011-08-03

Google Chrome before 13.0.782.107 does not prevent calls to functions in other frames, which allows remote attackers to bypass intended access restrictions via a crafted web site, related to a "cross-frame function leak."

CVEs:CVE-2011-2795

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2787

GoogleEPSS <= 49%HIGH2011-08-03

Google Chrome before 13.0.782.107 does not properly address re-entrancy issues associated with the GPU lock, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

CVEs:CVE-2011-2787

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2826

GoogleEPSS <= 49%HIGH2011-08-23

Google Chrome before 13.0.782.215 allows remote attackers to bypass the Same Origin Policy via vectors related to empty origins.

CVEs:CVE-2011-2826

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2360

GoogleEPSS <= 49%MEDIUM2011-08-03

Google Chrome before 13.0.782.107 does not ensure that the user is prompted before download of a dangerous file, which makes it easier for remote attackers to bypass intended content restrictions via a crafted web site.

CVEs:CVE-2011-2360

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2824

GoogleEPSS <= 49%CRITICAL2011-08-23

Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving counter nodes.

CVEs:CVE-2011-2824

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2828

GoogleEPSS <= 49%CRITICAL2011-08-23

Google V8, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.

CVEs:CVE-2011-2828

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2783

GoogleEPSS <= 49%MEDIUM2011-08-03

Google Chrome before 13.0.782.107 does not ensure that developer-mode NPAPI extension installations are confirmed by a browser dialog, which makes it easier for remote attackers to modify the product's functionality via a Trojan horse extension.

CVEs:CVE-2011-2783

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2358

GoogleEPSS <= 49%MEDIUM2011-08-03

Google Chrome before 13.0.782.107 does not ensure that extension installations are confirmed by a browser dialog, which makes it easier for remote attackers to modify the product's functionality via a Trojan horse extension.

CVEs:CVE-2011-2358

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2802

GoogleEPSS <= 49%HIGH2011-08-03

Google V8, as used in Google Chrome before 13.0.782.107, does not properly perform const lookups, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted web site.

CVEs:CVE-2011-2802

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2785

GoogleEPSS <= 49%MEDIUM2011-08-03

The extensions implementation in Google Chrome before 13.0.782.107 does not properly validate the URL for the home page, which allows remote attackers to have an unspecified impact via a crafted extension.

CVEs:CVE-2011-2785

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2008-7294

GoogleEPSS <= 49%MEDIUM2011-08-09

Google Chrome before 4.0.211.0 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to la...

CVEs:CVE-2008-7294

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2829

GoogleEPSS <= 49%CRITICAL2011-08-23

Integer overflow in Google Chrome before 13.0.782.215 on 32-bit platforms allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving uniform arrays.

CVEs:CVE-2011-2829

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2798

GoogleEPSS <= 49%MEDIUM2011-08-03

Google Chrome before 13.0.782.107 does not properly restrict access to internal schemes, which allows remote attackers to have an unspecified impact via a crafted web site.

CVEs:CVE-2011-2798

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2822

GoogleEPSS <= 49%HIGH2011-08-23

Google Chrome before 13.0.782.215 on Windows does not properly parse URLs located on the command line, which has unspecified impact and attack vectors.

CVEs:CVE-2011-2822

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2786

GoogleEPSS <= 49%MEDIUM2011-08-03

Google Chrome before 13.0.782.107 does not ensure that the speech-input bubble is shown on the product's screen, which might make it easier for remote attackers to make audio recordings via a crafted web page containing an INPUT element.

CVEs:CVE-2011-2786

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2361

GoogleEPSS <= 49%MEDIUM2011-08-03

The Basic Authentication dialog implementation in Google Chrome before 13.0.782.107 does not properly handle strings, which might make it easier for remote attackers to capture credentials via a crafted web site.

CVEs:CVE-2011-2361

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2784

GoogleEPSS <= 49%HIGH2011-08-03

Google Chrome before 13.0.782.107 allows remote attackers to obtain sensitive information via a request for the GL program log, which reveals a local path in an unspecified log entry.

CVEs:CVE-2011-2784

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.