Google Security Advisories · July 2012 — Google Security Advisories
6 advisories 6 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2012-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2012-2844

GoogleEPSS <= 49%HIGH2012-07-12

The PDF functionality in Google Chrome before 20.0.1132.57 does not properly handle JavaScript code, which allows remote attackers to cause a denial of service (incorrect object access) or possibly have unspecified other impact via a crafted document.

CVEs:CVE-2012-2844

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2843

GoogleEPSS <= 49%CRITICAL2012-07-12

Use-after-free vulnerability in Google Chrome before 20.0.1132.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to layout height tracking.

CVEs:CVE-2012-2843

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2842

GoogleEPSS <= 49%CRITICAL2012-07-12

Use-after-free vulnerability in Google Chrome before 20.0.1132.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to counter handling.

CVEs:CVE-2012-2842

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2005-4895

GoogleEPSS <= 49%CRITICAL2012-07-25

DEBIAN-CVE-2005-4895

Affected products

ProductStatusVendorPackageEcosystem
google-perftools affected Debian:14 google-perftools
google-perftools affected Debian:11 google-perftools
google-perftools affected Debian:12 google-perftools
google-perftools affected Debian:13 google-perftools
Upstream advisory

CVE-2012-2674

GoogleEPSS <= 49%CRITICAL2012-07-25

Multiple integer overflows in the (1) chk_malloc, (2) leak_malloc, and (3) leak_memalign functions in libc/bionic/malloc_debug_leak.c in Bionic (libc) for Android, when libc.debug.malloc is set, make it easier for context-dependent attackers to perform...

CVEs:CVE-2012-2674

Affected products

ProductStatusVendorPackageEcosystem
bionic affected google
Upstream advisory

CVE-2012-4050

GoogleEPSS <= 49%HIGH2012-07-24

Multiple unspecified vulnerabilities in Google Chrome OS before 21.0.1180.50 on the Cr-48 and Samsung Series 5 and 5 550 Chromebook platforms, and the Samsung Chromebox Series 3, have unknown impact and attack vectors.

CVEs:CVE-2012-4050

Affected products

ProductStatusVendorPackageEcosystem
chrome_os affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.