Google Security Advisories · November 2011 — Google Security Advisories
20 advisories 10 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2011-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2011-3895

GoogleEPSS <= 49%CRITICAL2011-11-11

Heap-based buffer overflow in the Vorbis decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.

CVEs:CVE-2011-3895

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2011-3892

GoogleEPSS <= 49%CRITICAL2011-11-11

Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.

CVEs:CVE-2011-3892

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2011-3893

GoogleEPSS <= 49%HIGH2011-11-11

Google Chrome before 15.0.874.120 does not properly implement the MKV and Vorbis media handlers, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2011-3893

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3897

GoogleEPSS <= 49%CRITICAL2011-11-10

Use-after-free vulnerability in Google Chrome before 15.0.874.120 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing.

CVEs:CVE-2011-3897

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3898

GoogleEPSS <= 49%HIGH2011-11-11

Google Chrome before 15.0.874.120, when Java Runtime Environment (JRE) 7 is used, does not request user confirmation before applet execution begins, which allows remote attackers to have an unspecified impact via a crafted applet.

CVEs:CVE-2011-3898

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-4457

GoogleEPSS <= 49%LOW2011-11-17

OWASP HTML Sanitizer allows redirecting to an arbitrary URL when JavaScript is disabled

CVEs:CVE-2011-4457

Affected products

ProductStatusVendorPackageEcosystem
com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer affected Maven com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer
Upstream advisory

CVE-2011-4457

GoogleEPSS <= 49%HIGH2011-11-17

OWASP HTML Sanitizer (aka owasp-java-html-sanitizer) before 88, when JavaScript is disabled, allows user-assisted remote attackers to obtain potentially sensitive information via a crafted FORM element within a NOSCRIPT element.

CVEs:CVE-2011-4457

Affected products

ProductStatusVendorPackageEcosystem
owasp-java-html-sanitizer affected owasp-java-html-sanitizer_project
Upstream advisory

CVE-2011-3900

GoogleEPSS <= 49%CRITICAL2011-11-17

Google V8, as used in Google Chrome before 15.0.874.121, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write operation.

CVEs:CVE-2011-3900

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3896

GoogleEPSS <= 49%CRITICAL2011-11-11

Buffer overflow in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to shader variable mapping.

CVEs:CVE-2011-3896

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3894

GoogleEPSS <= 49%CRITICAL2011-11-11

Google Chrome before 15.0.874.120 does not properly perform VP8 decoding, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted stream.

CVEs:CVE-2011-3894

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-4548

GoogleEPSS <= 49%HIGH2011-11-24

Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.44 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

CVEs:CVE-2011-4548

Affected products

ProductStatusVendorPackageEcosystem
ac700_chromebook affected acer
chrome_os affected google
cr-48_chromebook affected google
series_5_chromebook affected samsung
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.