Google Security Advisories · October 2012 — Google Security Advisories
34 advisories 34 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2012-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2011-3918

Open SourceWeaponized exploitHIGH2012-10-07

The Zygote process in Android 4.0.3 and earlier accepts fork requests from processes with arbitrary UIDs, which allows remote attackers to cause a denial of service (reboot loop) via a crafted application.

CVEs:CVE-2011-3918

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2012-5248

Open SourceEPSS <= 49%HIGH2012-10-09

Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; A...

CVEs:CVE-2012-5248

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5249

Open SourceEPSS <= 49%HIGH2012-10-09

Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; A...

CVEs:CVE-2012-5249

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5250

Open SourceEPSS <= 49%HIGH2012-10-09

Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; A...

CVEs:CVE-2012-5250

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5251

Open SourceEPSS <= 49%HIGH2012-10-09

Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; A...

CVEs:CVE-2012-5251

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5253

Open SourceEPSS <= 49%HIGH2012-10-09

Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; A...

CVEs:CVE-2012-5253

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5254

Open SourceEPSS <= 49%HIGH2012-10-09

Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; A...

CVEs:CVE-2012-5254

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5255

Open SourceEPSS <= 49%HIGH2012-10-09

Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; A...

CVEs:CVE-2012-5255

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5257

Open SourceEPSS <= 49%HIGH2012-10-09

Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; A...

CVEs:CVE-2012-5257

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5259

Open SourceEPSS <= 49%HIGH2012-10-09

Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; A...

CVEs:CVE-2012-5259

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5260

Open SourceEPSS <= 49%HIGH2012-10-09

Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; A...

CVEs:CVE-2012-5260

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5262

Open SourceEPSS <= 49%HIGH2012-10-09

Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; A...

CVEs:CVE-2012-5262

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5264

Open SourceEPSS <= 49%HIGH2012-10-09

Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; A...

CVEs:CVE-2012-5264

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5265

Open SourceEPSS <= 49%HIGH2012-10-09

Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; A...

CVEs:CVE-2012-5265

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5266

Open SourceEPSS <= 49%HIGH2012-10-09

Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; A...

CVEs:CVE-2012-5266

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5252

Open SourceEPSS <= 49%HIGH2012-10-09

Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4...

CVEs:CVE-2012-5252

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-4894

GoogleEPSS <= 49%HIGH2012-10-05

Google SketchUp before 8.0.14346 (aka 8 Maintenance 3) allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted SKP file.

CVEs:CVE-2012-4894

Affected products

ProductStatusVendorPackageEcosystem
sketchup affected google
Upstream advisory

CVE-2012-5270

Open SourceEPSS <= 49%HIGH2012-10-09

Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4...

CVEs:CVE-2012-5270

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5272

Open SourceEPSS <= 49%HIGH2012-10-09

Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4...

CVEs:CVE-2012-5272

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5256

Open SourceEPSS <= 49%HIGH2012-10-09

Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4...

CVEs:CVE-2012-5256

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5261

Open SourceEPSS <= 49%HIGH2012-10-09

Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4...

CVEs:CVE-2012-5261

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5263

Open SourceEPSS <= 49%HIGH2012-10-09

Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4...

CVEs:CVE-2012-5263

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5267

Open SourceEPSS <= 49%HIGH2012-10-09

Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4...

CVEs:CVE-2012-5267

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5268

Open SourceEPSS <= 49%HIGH2012-10-09

Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4...

CVEs:CVE-2012-5268

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5269

Open SourceEPSS <= 49%HIGH2012-10-09

Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4...

CVEs:CVE-2012-5269

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5271

Open SourceEPSS <= 49%HIGH2012-10-09

Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4...

CVEs:CVE-2012-5271

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5258

Open SourceEPSS <= 49%HIGH2012-10-08

Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4...

CVEs:CVE-2012-5258

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2012-5112

GoogleEPSS <= 49%HIGH2012-10-11

Use-after-free vulnerability in the SVG implementation in WebKit, as used in Google Chrome before 22.0.1229.94, allows remote attackers to execute arbitrary code via unspecified vectors.

CVEs:CVE-2012-5112

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
iphone_os affected apple
Upstream advisory

CVE-2012-5376

GoogleEPSS <= 49%CRITICAL2012-10-11

The Inter-process Communication (IPC) implementation in Google Chrome before 22.0.1229.94 allows remote attackers to bypass intended sandbox restrictions and write to arbitrary files by leveraging access to a renderer process, a different vulnerability...

CVEs:CVE-2012-5376

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-5108

GoogleEPSS <= 49%HIGH2012-10-09

Race condition in Google Chrome before 22.0.1229.92 allows remote attackers to execute arbitrary code via vectors related to audio devices.

CVEs:CVE-2012-5108

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-5109

GoogleEPSS <= 49%HIGH2012-10-09

The International Components for Unicode (ICU) functionality in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to a regular expression.

CVEs:CVE-2012-5109

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-5110

GoogleEPSS <= 49%HIGH2012-10-09

The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2012-5110

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-2900

GoogleEPSS <= 49%HIGH2012-10-09

Skia, as used in Google Chrome before 22.0.1229.92, does not properly render text, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2012-2900

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2012-5111

GoogleEPSS <= 49%HIGH2012-10-09

Google Chrome before 22.0.1229.92 does not monitor for crashes of Pepper plug-ins, which has unspecified impact and remote attack vectors.

CVEs:CVE-2012-5111

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.