Advisories
Open SourcePoC exploitHIGH2012-03-05
The Matrix3D component in Adobe Flash Player before 10.3.183.16 and 11.x before 11.1.102.63 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.7 on Android 2.x and 3.x; and before 11.1.115.7 on Android 4.x allows attackers to execute arbitrary c...
CVEs:CVE-2012-0768
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| flash_player |
affected |
adobe |
— |
— |
| flash_player_for_android |
affected |
adobe |
— |
— |
Open SourcePoC exploitHIGH2012-03-05
Adobe Flash Player before 10.3.183.16 and 11.x before 11.1.102.63 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.7 on Android 2.x and 3.x; and before 11.1.115.7 on Android 4.x does not properly handle integers, which allows attackers to obta...
CVEs:CVE-2012-0769
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| flash_player |
affected |
adobe |
— |
— |
| flash_player_for_android |
affected |
adobe |
— |
— |
GooglePoC exploitCRITICAL2012-03-22
Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execu...
CVEs:CVE-2011-3045
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux |
affected |
redhat |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server_aus |
affected |
redhat |
— |
— |
| enterprise_linux_server_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| gluster_storage |
affected |
redhat |
— |
— |
| libpng |
affected |
libpng |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| storage |
affected |
redhat |
— |
— |
| storage_for_public_cloud |
affected |
redhat |
— |
— |
GooglePoC exploitCRITICAL2012-03-05
Use-after-free vulnerability in the element wrapper in Google V8, as used in Google Chrome before 17.0.963.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
CVEs:CVE-2011-3031
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GooglePoC exploitCRITICAL2012-03-05
Buffer overflow in Skia, as used in Google Chrome before 17.0.963.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
CVEs:CVE-2011-3033
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GooglePoC exploitCRITICAL2012-03-04
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to multi-column handling.
CVEs:CVE-2011-3038
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| safari |
affected |
apple |
— |
— |
GooglePoC exploitCRITICAL2012-03-04
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of SVG values.
CVEs:CVE-2011-3032
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| safari |
affected |
apple |
— |
— |
GooglePoC exploitHIGH2012-03-04
Google Chrome before 17.0.963.65 does not properly perform casts of unspecified variables during the splitting of anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
CVEs:CVE-2011-3037
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| safari |
affected |
apple |
— |
— |
GooglePoC exploitCRITICAL2012-03-04
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of table sections.
CVEs:CVE-2011-3042
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| safari |
affected |
apple |
— |
— |
GooglePoC exploitCRITICAL2012-03-04
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving an SVG document.
CVEs:CVE-2011-3034
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| safari |
affected |
apple |
— |
— |
GooglePoC exploitCRITICAL2012-03-04
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG use elements.
CVEs:CVE-2011-3035
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| safari |
affected |
apple |
— |
— |
GooglePoC exploitHIGH2012-03-04
Google Chrome before 17.0.963.65 does not properly perform a cast of an unspecified variable during handling of line boxes, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
CVEs:CVE-2011-3036
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| safari |
affected |
apple |
— |
— |
GooglePoC exploitCRITICAL2012-03-04
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to quote handling.
CVEs:CVE-2011-3039
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| safari |
affected |
apple |
— |
— |
GooglePoC exploitHIGH2012-03-04
Google Chrome before 17.0.963.65 does not properly handle text, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.
CVEs:CVE-2011-3040
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| safari |
affected |
apple |
— |
— |
GooglePoC exploitCRITICAL2012-03-04
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of class attributes.
CVEs:CVE-2011-3041
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| safari |
affected |
apple |
— |
— |
GooglePoC exploitCRITICAL2012-03-04
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a flexbox (aka flexible box) in conjunction with the floating of eleme...
CVEs:CVE-2011-3043
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| safari |
affected |
apple |
— |
— |
GooglePoC exploitCRITICAL2012-03-04
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG animation elements.
CVEs:CVE-2011-3044
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| safari |
affected |
apple |
— |
— |
GoogleEPSS <= 49%HIGH2012-03-22
Use-after-free vulnerability in Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the DEP and ASLR protection mechanisms, and execute arbitrary code, via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition a...
CVEs:CVE-2012-1845
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2012-03-08
The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigation, which allows remote attackers to execute arbitrary code by leveraging a "Universal XSS (UXSS)" issue.
CVEs:CVE-2011-3046
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| safari |
affected |
apple |
— |
— |
GoogleEPSS <= 49%HIGH2012-03-22
Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a sandboxed process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012. NOTE: the primary affected ...
CVEs:CVE-2012-1846
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2012-03-10
The GPU process in Google Chrome before 17.0.963.79 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) by leveraging an error in the plug-in loading mechanism.
CVEs:CVE-2011-3047
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%HIGH2012-03-28
Google Chrome before 18.0.1025.142 does not properly handle text fragments, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
CVEs:CVE-2011-3060
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
GoogleEPSS <= 49%CRITICAL2012-03-21
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the :first-letter ...
CVEs:CVE-2011-3050
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| safari |
affected |
apple |
— |
— |
GoogleEPSS <= 49%CRITICAL2012-03-28
Use-after-free vulnerability in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG clipping.
CVEs:CVE-2011-3064
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
GoogleEPSS <= 49%HIGH2012-03-23
Google Chrome before 17.0.963.83 does not properly restrict the extension web request API, which allows remote attackers to cause a denial of service (disrupted system requests) via a crafted extension.
CVEs:CVE-2011-3049
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2012-03-22
The WebGL implementation in Google Chrome before 17.0.963.83 does not properly handle CANVAS elements, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
CVEs:CVE-2011-3052
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2012-03-30
Skia, as used in Google Chrome before 18.0.1025.142, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
CVEs:CVE-2011-3065
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2012-03-28
Google Chrome before 18.0.1025.142 does not properly handle SVG text elements, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
CVEs:CVE-2011-3059
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
GoogleEPSS <= 49%MEDIUM2012-03-22
The WebUI privilege implementation in Google Chrome before 17.0.963.83 does not properly perform isolation, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
CVEs:CVE-2011-3054
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2012-03-22
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the cross-fade fun...
CVEs:CVE-2011-3051
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2012-03-21
Use-after-free vulnerability in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to block splitting.
CVEs:CVE-2011-3053
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| safari |
affected |
apple |
— |
— |
GoogleEPSS <= 49%HIGH2012-03-22
Google V8, as used in Google Chrome before 17.0.963.83, allows remote attackers to cause a denial of service via vectors that trigger an invalid read operation.
CVEs:CVE-2011-3057
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2012-03-30
Off-by-one error in the OpenType Sanitizer in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted OpenType file.
CVEs:CVE-2011-3062
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| firefox |
affected |
mozilla |
— |
— |
| seamonkey |
affected |
mozilla |
— |
— |
| thunderbird |
affected |
mozilla |
— |
— |
| thunderbird_esr |
affected |
mozilla |
— |
— |
GoogleEPSS <= 49%MEDIUM2012-03-22
The browser native UI in Google Chrome before 17.0.963.83 does not require user confirmation before an unpacked extension installation, which allows user-assisted remote attackers to have an unspecified impact via a crafted extension.
CVEs:CVE-2011-3055
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2012-03-30
Google Chrome before 18.0.1025.142 does not properly handle the EUC-JP encoding system, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
CVEs:CVE-2011-3058
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
Open SourceEPSS <= 49%HIGH2012-03-02
The Cookpad 1.5.16 and earlier and Cookpad Noseru 1.1.1 and earlier applications for Android do not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.
CVEs:CVE-2012-0316
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android_activities |
affected |
cookpad |
— |
— |
| android_mykitchen |
affected |
cookpad |
— |
— |
GoogleEPSS <= 49%MEDIUM2012-03-21
Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."
CVEs:CVE-2011-3056
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| safari |
affected |
apple |
— |
— |
GoogleEPSS <= 49%MEDIUM2012-03-30
Google Chrome before 18.0.1025.142 does not properly validate the renderer's navigation requests, which has unspecified impact and remote attack vectors.
CVEs:CVE-2011-3063
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2012-03-30
Google Chrome before 18.0.1025.142 does not properly check X.509 certificates before use of a SPDY proxy, which might allow man-in-the-middle attackers to spoof servers or obtain sensitive information via a crafted certificate.
CVEs:CVE-2011-3061
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |