Google Security Advisories · August 2012 — Google Security Advisories
36 advisories 36 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2012-08. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2015-4000

GoogleWeaponized exploitMEDIUM2012-08-30

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a Client...

CVEs:CVE-2015-4000

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
content_manager affected ibm
debian_linux affected debian
firefox affected mozilla
firefox_esr affected mozilla
firefox_os affected mozilla
hp-ux affected hp
internet_explorer affected microsoft
iphone_os affected apple
jdk affected oracle
jre affected oracle
jrockit affected oracle
linux_enterprise_desktop affected suse
linux_enterprise_server affected suse
linux_enterprise_software_development_kit affected suse
mac_os_x affected apple
network_security_services affected mozilla
openssl affected openssl
opera_browser affected opera
safari affected apple
seamonkey affected mozilla
sparc-opl_service_processor affected oracle
suse_linux_enterprise_server affected suse
thunderbird affected mozilla
ubuntu_linux affected canonical
Upstream advisory

CVE-2012-3485

GoogleWeaponized exploitHIGH2012-08-26

Tunnelblick 3.3beta20 and earlier relies on argv[0] to determine the name of an appropriate (1) kernel module pathname or (2) executable file pathname, which allows local users to gain privileges via an execl system call.

CVEs:CVE-2012-3485

Affected products

ProductStatusVendorPackageEcosystem
tunnelblick affected google
Upstream advisory

CVE-2012-4171

Open SourcePoC exploitHIGH2012-08-22

Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x before 11.2.202.238 on Linux, before 11.1.111.16 on Android 2.x and 3.x, and before 11.1.115.17 on Android 4.x; Adobe AIR before 3.4...

CVEs:CVE-2012-4171

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-2870

GooglePoC exploitHIGH2012-08-30

libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression that is not properly identified...

CVEs:CVE-2012-2870

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
libxslt affected xmlsoft
Upstream advisory

CVE-2012-2871

GooglePoC exploitHIGH2012-08-30

libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly support a cast of an unspecified variable during handling of XSL transforms, which allows remote attackers to cause a denial of service or possibly have unkn...

CVEs:CVE-2012-2871

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
libxml2 affected xmlsoft
Upstream advisory

CVE-2012-2864

GoogleEPSS <= 49%HIGH2012-08-22

Mesa, as used in Google Chrome before 21.0.1183.0 on the Acer AC700, Cr-48, and Samsung Series 5 and 5 550 Chromebook platforms, and the Samsung Chromebox Series 3, allows remote attackers to execute arbitrary code via unspecified vectors that trigger ...

CVEs:CVE-2012-2864

Affected products

ProductStatusVendorPackageEcosystem
chrome_os affected google
Upstream advisory

CVE-2012-3979

Open SourceEPSS <= 49%CRITICAL2012-08-29

Mozilla Firefox before 15.0 on Android does not properly implement unspecified callers of the __android_log_print function, which allows remote attackers to execute arbitrary code via a crafted web page that calls the JavaScript dump function.

CVEs:CVE-2012-3979

Affected products

ProductStatusVendorPackageEcosystem
android affected google
firefox affected mozilla
firefox_mobile affected mozilla
Upstream advisory

CVE-2012-2869

GoogleEPSS <= 49%HIGH2012-08-31

Google Chrome before 21.0.1180.89 does not properly load URLs, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a "stale buffer."

CVEs:CVE-2012-2869

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2012-2850

GoogleEPSS <= 49%MEDIUM2012-08-02

Multiple unspecified vulnerabilities in the PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allow remote attackers to have an unknown impact via a crafted document.

CVEs:CVE-2012-2850

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2859

GoogleEPSS <= 49%CRITICAL2012-08-02

Google Chrome before 21.0.1180.57 on Linux does not properly handle tabs, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

CVEs:CVE-2012-2859

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2867

GoogleEPSS <= 49%HIGH2012-08-31

The SPDY implementation in Google Chrome before 21.0.1180.89 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

CVEs:CVE-2012-2867

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2012-2866

GoogleEPSS <= 49%HIGH2012-08-31

Google Chrome before 21.0.1180.89 does not properly perform a cast of an unspecified variable during handling of run-in elements, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.

CVEs:CVE-2012-2866

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2012-2849

GoogleEPSS <= 49%HIGH2012-08-02

Off-by-one error in the GIF decoder in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image.

CVEs:CVE-2012-2849

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2855

GoogleEPSS <= 49%CRITICAL2012-08-02

Use-after-free vulnerability in the PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified oth...

CVEs:CVE-2012-2855

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2857

GoogleEPSS <= 49%CRITICAL2012-08-02

Use-after-free vulnerability in the Cascading Style Sheets (CSS) DOM implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or...

CVEs:CVE-2012-2857

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
Upstream advisory

CVE-2012-2852

GoogleEPSS <= 49%CRITICAL2012-08-02

The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not properly handle object linkage, which allows remote attackers to cause a denial of service (use-after-free) ...

CVEs:CVE-2012-2852

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2862

GoogleEPSS <= 49%CRITICAL2012-08-09

Use-after-free vulnerability in the PDF functionality in Google Chrome before 21.0.1180.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.

CVEs:CVE-2012-2862

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2865

GoogleEPSS <= 49%HIGH2012-08-31

Google Chrome before 21.0.1180.89 does not properly perform line breaking, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.

CVEs:CVE-2012-2865

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2012-2851

GoogleEPSS <= 49%CRITICAL2012-08-02

Multiple integer overflows in the PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allow remote attackers to cause a denial of service or possibly have unspecified other ...

CVEs:CVE-2012-2851

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2856

GoogleEPSS <= 49%CRITICAL2012-08-02

The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigg...

CVEs:CVE-2012-2856

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2863

GoogleEPSS <= 49%CRITICAL2012-08-09

The PDF functionality in Google Chrome before 21.0.1180.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger out-of-bounds write operations.

CVEs:CVE-2012-2863

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2872

GoogleEPSS <= 49%CRITICAL2012-08-31

Cross-site scripting (XSS) vulnerability in an SSL interstitial page in Google Chrome before 21.0.1180.89 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVEs:CVE-2012-2872

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2012-2854

GoogleEPSS <= 49%HIGH2012-08-02

Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to obtain potentially sensitive information about pointer values by leveraging access to a WebUI renderer process.

CVEs:CVE-2012-2854

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2868

GoogleEPSS <= 49%HIGH2012-08-31

Race condition in Google Chrome before 21.0.1180.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving improper interaction between worker processes and an XMLHttpRequest (aka XHR) object.

CVEs:CVE-2012-2868

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2012-2848

GoogleEPSS <= 49%MEDIUM2012-08-02

The drag-and-drop implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows user-assisted remote attackers to bypass intended file access restrictions via a crafted web site.

CVEs:CVE-2012-2848

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2846

GoogleEPSS <= 49%HIGH2012-08-02

Google Chrome before 21.0.1180.57 on Linux does not properly isolate renderer processes, which allows remote attackers to cause a denial of service (cross-process interference) via unspecified vectors.

CVEs:CVE-2012-2846

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2858

GoogleEPSS <= 49%CRITICAL2012-08-02

Buffer overflow in the WebP decoder in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a cr...

CVEs:CVE-2012-2858

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2860

GoogleEPSS <= 49%HIGH2012-08-02

The date-picker implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact...

CVEs:CVE-2012-2860

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2847

GoogleEPSS <= 49%CRITICAL2012-08-02

Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not request user confirmation before continuing a large series of downloads, which allows user-assisted remote attackers to cause a denia...

CVEs:CVE-2012-2847

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2853

GoogleEPSS <= 49%HIGH2012-08-02

The webRequest API in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not properly interact with the Chrome Web Store, which allows remote attackers to cause a denial of service or poss...

CVEs:CVE-2012-2853

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-3486

GoogleEPSS <= 49%MEDIUM2012-08-26

Tunnelblick 3.3beta20 and earlier allows local users to gain privileges via an OpenVPN configuration file that specifies execution of a script upon occurrence of an OpenVPN event.

CVEs:CVE-2012-3486

Affected products

ProductStatusVendorPackageEcosystem
tunnelblick affected google
Upstream advisory

CVE-2012-3483

GoogleEPSS <= 49%MEDIUM2012-08-26

Race condition in the runScript function in Tunnelblick 3.3beta20 and earlier allows local users to gain privileges by replacing a script file.

CVEs:CVE-2012-3483

Affected products

ProductStatusVendorPackageEcosystem
tunnelblick affected google
Upstream advisory

CVE-2012-4676

GoogleEPSS <= 49%LOW2012-08-26

The errorExitIfAttackViaString function in Tunnelblick 3.3beta20 and earlier allows local users to delete arbitrary files by constructing a (1) symlink or (2) hard link, a different vulnerability than CVE-2012-3485.

CVEs:CVE-2012-4676

Affected products

ProductStatusVendorPackageEcosystem
tunnelblick affected google
Upstream advisory

CVE-2012-3484

GoogleEPSS <= 49%HIGH2012-08-26

Tunnelblick 3.3beta20 and earlier relies on a test for specific ownership and permissions to determine whether a program can be safely executed, which allows local users to bypass intended access restrictions and gain privileges via a (1) user-mountabl...

CVEs:CVE-2012-3484

Affected products

ProductStatusVendorPackageEcosystem
tunnelblick affected google
Upstream advisory

CVE-2012-4677

GoogleEPSS <= 49%MEDIUM2012-08-26

Tunnelblick 3.3beta20 and earlier allows local users to gain privileges by using a crafted Info.plist file to control the gOkIfNotSecure value.

CVEs:CVE-2012-4677

Affected products

ProductStatusVendorPackageEcosystem
tunnelblick affected google
Upstream advisory

CVE-2012-3487

GoogleEPSS <= 49%LOW2012-08-26

Race condition in Tunnelblick 3.3beta20 and earlier allows local users to kill unintended processes by waiting for a specific PID value to be assigned to a target process.

CVEs:CVE-2012-3487

Affected products

ProductStatusVendorPackageEcosystem
tunnelblick affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.