Google Security Advisories · May 2012 — Google Security Advisories
39 advisories 39 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2012-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2011-3102

GooglePoC exploitCRITICAL2012-05-15

Off-by-one error in libxml2, as used in Google Chrome before 19.0.1084.46 and other products, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-3102

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
Upstream advisory

CVE-2011-3106

GoogleEPSS <= 49%HIGH2012-05-24

The WebSockets implementation in Google Chrome before 19.0.1084.52 does not properly handle use of SSL, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

CVEs:CVE-2011-3106

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3108

GoogleEPSS <= 49%HIGH2012-05-24

Use-after-free vulnerability in Google Chrome before 19.0.1084.52 allows remote attackers to execute arbitrary code via vectors related to the browser cache.

CVEs:CVE-2011-3108

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3086

GoogleEPSS <= 49%HIGH2012-05-16

Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a STYLE element.

CVEs:CVE-2011-3086

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3081

GoogleEPSS <= 49%HIGH2012-05-01

Use-after-free vulnerability in Google Chrome before 18.0.1025.168 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the floating of elements, a different vulnerability than CVE-2011-3...

CVEs:CVE-2011-3081

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3089

GoogleEPSS <= 49%HIGH2012-05-16

Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving tables.

CVEs:CVE-2011-3089

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3097

GoogleEPSS <= 49%HIGH2012-05-16

The PDF functionality in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging an out-of-bounds write error in the implementation of sampled functions.

CVEs:CVE-2011-3097

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3099

GoogleEPSS <= 49%HIGH2012-05-16

Use-after-free vulnerability in the PDF functionality in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a malformed name for the font encoding.

CVEs:CVE-2011-3099

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3091

GoogleEPSS <= 49%HIGH2012-05-16

Use-after-free vulnerability in the IndexedDB implementation in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-3091

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3078

GoogleEPSS <= 49%CRITICAL2012-05-01

Use-after-free vulnerability in Google Chrome before 18.0.1025.168 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the floating of elements, a different vulnerability than CVE-2011-3...

CVEs:CVE-2011-3078

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2012-1521

GoogleEPSS <= 49%CRITICAL2012-05-01

Use-after-free vulnerability in the XML parser in Google Chrome before 18.0.1025.168 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2012-1521

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
itunes affected apple
safari affected apple
Upstream advisory

CVE-2011-3092

GoogleEPSS <= 49%HIGH2012-05-16

The regex implementation in Google V8, as used in Google Chrome before 19.0.1084.46, allows remote attackers to cause a denial of service (invalid write operation) or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-3092

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3095

GoogleEPSS <= 49%HIGH2012-05-16

The OGG container in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.

CVEs:CVE-2011-3095

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3090

GoogleEPSS <= 49%HIGH2012-05-16

Race condition in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to worker processes.

CVEs:CVE-2011-3090

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3101

GoogleEPSS <= 49%HIGH2012-05-16

Google Chrome before 19.0.1084.46 on Linux does not properly mitigate an unspecified flaw in an NVIDIA driver, which has unknown impact and attack vectors. NOTE: see CVE-2012-3105 for the related MFSA 2012-34 issue in Mozilla products.

CVEs:CVE-2011-3101

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3105

GoogleEPSS <= 49%CRITICAL2012-05-24

Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 19.0.1084.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the :first-letter...

CVEs:CVE-2011-3105

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3115

GoogleEPSS <= 49%HIGH2012-05-24

Google V8, as used in Google Chrome before 19.0.1084.52, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger "type corruption."

CVEs:CVE-2011-3115

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3103

GoogleEPSS <= 49%HIGH2012-05-24

Google V8, as used in Google Chrome before 19.0.1084.52, does not properly perform garbage collection, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code.

CVEs:CVE-2011-3103

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3110

GoogleEPSS <= 49%CRITICAL2012-05-24

The PDF functionality in Google Chrome before 19.0.1084.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger out-of-bounds write operations.

CVEs:CVE-2011-3110

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3107

GoogleEPSS <= 49%HIGH2012-05-24

Google Chrome before 19.0.1084.52 does not properly implement JavaScript bindings for plug-ins, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2011-3107

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-1249

Open SourceEPSS <= 49%MEDIUM2012-05-21

The iLunascape application 1.0.4.0 and earlier for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive stored information via a crafted application.

CVEs:CVE-2012-1249

Affected products

ProductStatusVendorPackageEcosystem
ilunascape_android affected lunascape
Upstream advisory

CVE-2011-3114

GoogleEPSS <= 49%CRITICAL2012-05-24

Multiple buffer overflows in the PDF functionality in Google Chrome before 19.0.1084.52 allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger unknown function calls.

CVEs:CVE-2011-3114

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3100

GoogleEPSS <= 49%HIGH2012-05-16

Google Chrome before 19.0.1084.46 does not properly draw dash paths, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2011-3100

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3104

GoogleEPSS <= 49%HIGH2012-05-24

Skia, as used in Google Chrome before 19.0.1084.52, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2011-3104

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3111

GoogleEPSS <= 49%HIGH2012-05-24

Google V8, as used in Google Chrome before 19.0.1084.52, allows remote attackers to cause a denial of service (invalid read operation) via unspecified vectors.

CVEs:CVE-2011-3111

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3093

GoogleEPSS <= 49%HIGH2012-05-16

Google Chrome before 19.0.1084.46 does not properly handle glyphs, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2011-3093

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3094

GoogleEPSS <= 49%HIGH2012-05-16

Google Chrome before 19.0.1084.46 does not properly handle Tibetan text, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2011-3094

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3112

GoogleEPSS <= 49%CRITICAL2012-05-24

Use-after-free vulnerability in the PDF functionality in Google Chrome before 19.0.1084.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via an invalid encrypted document.

CVEs:CVE-2011-3112

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3113

GoogleEPSS <= 49%HIGH2012-05-24

The PDF functionality in Google Chrome before 19.0.1084.52 does not properly perform a cast of an unspecified variable during handling of color spaces, which allows remote attackers to cause a denial of service or possibly have unknown other impact via...

CVEs:CVE-2011-3113

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3109

GoogleEPSS <= 49%HIGH2012-05-24

Google Chrome before 19.0.1084.52 on Linux does not properly perform a cast of an unspecified variable, which allows remote attackers to cause a denial of service or possibly have unknown other impact by leveraging an error in the GTK implementation of...

CVEs:CVE-2011-3109

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3088

GoogleEPSS <= 49%HIGH2012-05-16

Google Chrome before 19.0.1084.46 does not properly draw hairlines, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2011-3088

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3085

GoogleEPSS <= 49%HIGH2012-05-16

The Autofill feature in Google Chrome before 19.0.1084.46 does not properly restrict field values, which allows remote attackers to cause a denial of service (UI corruption) and possibly conduct spoofing attacks via vectors involving long values.

CVEs:CVE-2011-3085

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3096

GoogleEPSS <= 49%CRITICAL2012-05-16

Use-after-free vulnerability in Google Chrome before 19.0.1084.46 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging an error in the GTK implementation of the omnibox.

CVEs:CVE-2011-3096

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3079

GoogleEPSS <= 49%HIGH2012-05-01

The Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168, as used in Mozilla Firefox before 38.0 and other products, does not properly validate messages, which has unspecified impact and attack vectors.

CVEs:CVE-2011-3079

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
firefox affected mozilla
opensuse affected opensuse
seamonkey affected mozilla
thunderbird affected mozilla
Upstream advisory

CVE-2011-3083

GoogleEPSS <= 49%HIGH2012-05-16

browser/profiles/profile_impl_io_data.cc in Google Chrome before 19.0.1084.46 does not properly handle a malformed ftp URL in the SRC attribute of a VIDEO element, which allows remote attackers to cause a denial of service (NULL pointer dereference and...

CVEs:CVE-2011-3083

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3087

GoogleEPSS <= 49%HIGH2012-05-16

Google Chrome before 19.0.1084.46 does not properly perform window navigation, which has unspecified impact and remote attack vectors.

CVEs:CVE-2011-3087

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3084

GoogleEPSS <= 49%HIGH2012-05-16

Google Chrome before 19.0.1084.46 does not use a dedicated process for the loading of links found on an internal page, which might allow attackers to bypass intended sandbox restrictions via a crafted page.

CVEs:CVE-2011-3084

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3080

GoogleEPSS <= 49%HIGH2012-05-01

Race condition in the Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168 allows attackers to bypass intended sandbox restrictions via unspecified vectors.

CVEs:CVE-2011-3080

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-3098

GoogleEPSS <= 49%HIGH2012-05-16

Google Chrome before 19.0.1084.46 on Windows uses an incorrect search path for the Windows Media Player plug-in, which might allow local users to gain privileges via a Trojan horse plug-in in an unspecified directory.

CVEs:CVE-2011-3098

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.