Google Security Advisories · June 2012 — Google Security Advisories
24 advisories 24 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2012-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2012-2825

GooglePoC exploitHIGH2012-06-27

The XSL implementation in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service (incorrect read operation) via unspecified vectors.

CVEs:CVE-2012-2825

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2807

GooglePoC exploitCRITICAL2012-06-26

Multiple integer overflows in libxml2, as used in Google Chrome before 20.0.1132.43 and other products, on 64-bit Linux platforms allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2012-2807

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
Upstream advisory

CVE-2012-2818

GoogleEPSS <= 49%CRITICAL2012-06-27

Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the layout of documents that use the Cascading Style Sheets (CSS) co...

CVEs:CVE-2012-2818

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2816

GoogleEPSS <= 49%HIGH2012-06-27

Google Chrome before 20.0.1132.43 on Windows does not properly isolate sandboxed processes, which might allow remote attackers to cause a denial of service (process interference) via unspecified vectors.

CVEs:CVE-2012-2816

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2834

GoogleEPSS <= 49%HIGH2012-06-27

Integer overflow in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted data in the Matroska container format.

CVEs:CVE-2012-2834

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2817

GoogleEPSS <= 49%CRITICAL2012-06-27

Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to tables that have sections.

CVEs:CVE-2012-2817

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2829

GoogleEPSS <= 49%CRITICAL2012-06-27

Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the :first-letter...

CVEs:CVE-2012-2829

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2831

GoogleEPSS <= 49%CRITICAL2012-06-27

Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG references.

CVEs:CVE-2012-2831

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2824

GoogleEPSS <= 49%CRITICAL2012-06-27

Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG painting.

CVEs:CVE-2012-2824

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
Upstream advisory

CVE-2012-2828

GoogleEPSS <= 49%CRITICAL2012-06-27

Multiple integer overflows in the PDF functionality in Google Chrome before 20.0.1132.43 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.

CVEs:CVE-2012-2828

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2832

GoogleEPSS <= 49%HIGH2012-06-27

The image-codec implementation in the PDF functionality in Google Chrome before 20.0.1132.43 does not initialize an unspecified pointer, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted docu...

CVEs:CVE-2012-2832

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2815

GoogleEPSS <= 49%HIGH2012-06-27

Google Chrome before 20.0.1132.43 allows remote attackers to obtain potentially sensitive information from a fragment identifier by leveraging access to an IFRAME element associated with a different domain.

CVEs:CVE-2012-2815

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2830

GoogleEPSS <= 49%HIGH2012-06-27

Google Chrome before 20.0.1132.43 does not properly set array values, which allows remote attackers to cause a denial of service (incorrect pointer use) or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2012-2830

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2833

GoogleEPSS <= 49%CRITICAL2012-06-27

Buffer overflow in the JS API in the PDF functionality in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2012-2833

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2820

GoogleEPSS <= 49%HIGH2012-06-27

Google Chrome before 20.0.1132.43 does not properly implement SVG filters, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2012-2820

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2826

GoogleEPSS <= 49%HIGH2012-06-27

Google Chrome before 20.0.1132.43 does not properly implement texture conversion, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2012-2826

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2823

GoogleEPSS <= 49%CRITICAL2012-06-27

Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG resources.

CVEs:CVE-2012-2823

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2630

Open SourceEPSS <= 49%HIGH2012-06-04

The Puella Magi Madoka Magica iP application 1.05 and earlier for Android places cleartext Twitter credentials in a log file, which allows remote attackers to obtain sensitive information via a crafted application.

CVEs:CVE-2012-2630

Affected products

ProductStatusVendorPackageEcosystem
madomagi-ip_android affected bandainamcogames
Upstream advisory

CVE-2012-2819

GoogleEPSS <= 49%HIGH2012-06-27

The texSubImage2D implementation in the WebGL subsystem in Google Chrome before 20.0.1132.43 does not properly handle uploads to floating-point textures, which allows remote attackers to cause a denial of service (assertion failure and application cras...

CVEs:CVE-2012-2819

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2821

GoogleEPSS <= 49%HIGH2012-06-27

The autofill implementation in Google Chrome before 20.0.1132.43 does not properly display text, which has unspecified impact and remote attack vectors.

CVEs:CVE-2012-2821

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2822

GoogleEPSS <= 49%HIGH2012-06-27

The PDF functionality in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2012-2822

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-3290

GoogleEPSS <= 49%HIGH2012-06-07

Multiple unspecified vulnerabilities in Google Chrome before 20.0.1132.22 on the Acer AC700; Samsung Series 5, 5 550, and Chromebox 3; and Cr-48 Chromebook platforms have unknown impact and attack vectors.

CVEs:CVE-2012-3290

Affected products

ProductStatusVendorPackageEcosystem
ac700_chromebook affected acer
chromebox_3 affected samsung
chrome_os affected google
cr-48_chromebook affected google
series_5_550_chromebook affected samsung
series_5_chromebook affected samsung
Upstream advisory

CVE-2012-2827

GoogleEPSS <= 49%CRITICAL2012-06-27

Use-after-free vulnerability in the UI in Google Chrome before 20.0.1132.43 on Mac OS X allows attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2012-2827

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2764

GoogleEPSS <= 49%HIGH2012-06-27

Untrusted search path vulnerability in Google Chrome before 20.0.1132.43 on Windows might allow local users to gain privileges via a Trojan horse Metro DLL in the current working directory.

CVEs:CVE-2012-2764

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.