Google Security Advisories · January 2012 — Google Security Advisories
11 advisories 11 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2012-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2011-3874

Open SourceActive exploitation (sightings)HIGH2012-01-27

Stack-based buffer overflow in libsysutils in Android 2.2.x through 2.2.2 and 2.3.x through 2.3.6 allows user-assisted remote attackers to execute arbitrary code via an application that calls the FrameworkListener::dispatchCommand method with the wrong...

CVEs:CVE-2011-3874

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2011-3919

GooglePoC exploitCRITICAL2012-01-06

Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-3919

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_server_eus affected redhat
enterprise_linux_workstation affected redhat
iphone_os affected apple
linux_enterprise_server affected suse
mac_os_x affected apple
Upstream advisory

CVE-2011-3926

GoogleEPSS <= 49%CRITICAL2012-01-24

Heap-based buffer overflow in the tree builder in Google Chrome before 16.0.912.77 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-3926

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3922

GoogleEPSS <= 49%CRITICAL2012-01-07

Stack-based buffer overflow in Google Chrome before 16.0.912.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to glyph handling.

CVEs:CVE-2011-3922

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3924

GoogleEPSS <= 49%CRITICAL2012-01-24

Use-after-free vulnerability in Google Chrome before 16.0.912.77 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to DOM selections.

CVEs:CVE-2011-3924

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3928

GoogleEPSS <= 49%CRITICAL2012-01-23

Use-after-free vulnerability in Google Chrome before 16.0.912.77 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to DOM handling.

CVEs:CVE-2011-3928

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2011-3921

GoogleEPSS <= 49%CRITICAL2012-01-07

Use-after-free vulnerability in Google Chrome before 16.0.912.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving animation frames.

CVEs:CVE-2011-3921

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3925

GoogleEPSS <= 49%CRITICAL2012-01-24

Use-after-free vulnerability in the Safe Browsing feature in Google Chrome before 16.0.912.75 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via vectors related to a navigation en...

CVEs:CVE-2011-3925

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3927

GoogleEPSS <= 49%HIGH2012-01-24

Skia, as used in Google Chrome before 16.0.912.77, does not perform all required initialization of values, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-3927

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-0695

GoogleEPSS <= 49%HIGH2012-01-12

Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.27 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

CVEs:CVE-2012-0695

Affected products

ProductStatusVendorPackageEcosystem
ac700_chromebook affected acer
chrome_os affected google
cr-48_chromebook affected google
series_5_chromebook affected samsung
Upstream advisory

CVE-2011-4276

Open SourceEPSS <= 49%MEDIUM2012-01-25

The Bluetooth service (com/android/phone/BluetoothHeadsetService.java) in Android 2.3 before 2.3.6 allows remote attackers within Bluetooth range to obtain contact data via an AT phonebook transfer.

CVEs:CVE-2011-4276

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.