Google Security Advisories · April 2012 — Google Security Advisories
16 advisories 16 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2012-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2014-9322

Open SourceWeaponized exploitHIGH2012-04-24

arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to ...

CVEs:CVE-2014-9322

Affected products

ProductStatusVendorPackageEcosystem
android affected google
enterprise_linux_eus affected redhat
evergreen affected opensuse
linux_kernel affected linux
suse_linux_enterprise_server affected suse
ubuntu_linux affected canonical
Upstream advisory

CVE-2012-0724

GooglePoC exploitHIGH2012-04-06

Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2012-0725.

CVEs:CVE-2012-0724

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
chrome affected google
flash_player affected adobe
Upstream advisory

CVE-2012-0725

GooglePoC exploitHIGH2012-04-06

Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2012-0724.

CVEs:CVE-2012-0725

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
chrome affected google
flash_player affected adobe
Upstream advisory

CVE-2011-2478

GoogleEPSS <= 49%HIGH2012-04-17

Google SketchUp before 8 does not properly handle edge geometry in SketchUp (aka .SKP) files, which allows remote attackers to execute arbitrary code via a crafted file.

CVEs:CVE-2011-2478

Affected products

ProductStatusVendorPackageEcosystem
sketchup affected google
Upstream advisory

CVE-2011-3075

GoogleEPSS <= 49%CRITICAL2012-04-05

Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to style-application commands.

CVEs:CVE-2011-3075

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3070

GoogleEPSS <= 49%CRITICAL2012-04-05

Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the Google V8 bindings.

CVEs:CVE-2011-3070

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3069

GoogleEPSS <= 49%CRITICAL2012-04-05

Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to line boxes.

CVEs:CVE-2011-3069

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3073

GoogleEPSS <= 49%CRITICAL2012-04-05

Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of SVG resources.

CVEs:CVE-2011-3073

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3074

GoogleEPSS <= 49%CRITICAL2012-04-05

Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of media.

CVEs:CVE-2011-3074

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3076

GoogleEPSS <= 49%CRITICAL2012-04-05

Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to focus handling.

CVEs:CVE-2011-3076

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3077

GoogleEPSS <= 49%CRITICAL2012-04-05

Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving the script bindings, related to a "read-after-free" issue.

CVEs:CVE-2011-3077

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3068

GoogleEPSS <= 49%CRITICAL2012-04-05

Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to run-in boxes.

CVEs:CVE-2011-3068

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3066

GoogleEPSS <= 49%HIGH2012-04-05

Skia, as used in Google Chrome before 18.0.1025.151, does not properly perform clipping, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2011-3066

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-1243

Open SourceEPSS <= 49%HIGH2012-04-22

The TwitRocker2 application before 1.0.23 for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.

CVEs:CVE-2012-1243

Affected products

ProductStatusVendorPackageEcosystem
twitrocker2_android affected studiohitori
Upstream advisory

CVE-2011-3072

GoogleEPSS <= 49%MEDIUM2012-04-05

Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to pop-up windows.

CVEs:CVE-2011-3072

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-1244

Open SourceEPSS <= 49%HIGH2012-04-27

The NTT DOCOMO sp mode mail application 5400 and earlier for Android does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVEs:CVE-2012-1244

Affected products

ProductStatusVendorPackageEcosystem
spmode_mail_android affected nttdocomo
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.