Advisories
Open SourceActive exploitation (sightings)CRITICAL2012-11-30
diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 allows attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference) via an application th...
CVEs:CVE-2012-4220
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitCRITICAL2012-11-27
Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbi...
CVEs:CVE-2012-5134
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| libxml2 |
affected |
xmlsoft |
— |
— |
GooglePoC exploitCRITICAL2012-11-20
Cross-site scripting (XSS) vulnerability in Google Web Toolkit (GWT) 2.4 through 2.5 Final, as used in JBoss Operations Network (ON) 3.1.1 and possibly other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vecto...
CVEs:CVE-2012-5920
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| web_toolkit |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2012-11-13
Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; A...
CVEs:CVE-2012-5286
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| adobe_air |
affected |
adobe |
— |
— |
| adobe_air_sdk |
affected |
adobe |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
| flash_player_for_android |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%HIGH2012-11-13
Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; A...
CVEs:CVE-2012-5287
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| adobe_air |
affected |
adobe |
— |
— |
| adobe_air_sdk |
affected |
adobe |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
| flash_player_for_android |
affected |
adobe |
— |
— |
GoogleEPSS <= 49%HIGH2012-11-30
Use-after-free vulnerability in Google Chrome before 23.0.1271.95 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the Media Source API.
CVEs:CVE-2012-5137
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2012-11-15
html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) p...
CVEs:CVE-2012-5851
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| safari |
affected |
apple |
— |
— |
| webkit |
affected |
apple |
— |
— |
Open SourceEPSS <= 49%CRITICAL2012-11-30
Integer overflow in diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 allows attackers to execute arbitrary code or cause a denial of service via an application that uses craf...
CVEs:CVE-2012-4221
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2012-11-07
Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to video layout.
CVEs:CVE-2012-5121
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2012-11-07
Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, on 64-bit Linux platforms allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds...
CVEs:CVE-2012-5120
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| v8 |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2012-11-30
Google Chrome before 23.0.1271.95 does not properly handle file paths, which has unspecified impact and attack vectors.
CVEs:CVE-2012-5138
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%HIGH2012-11-27
Skia, as used in Google Chrome before 23.0.1271.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
CVEs:CVE-2012-5130
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%HIGH2012-11-27
Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service (application crash) via a response with chunked transfer coding.
CVEs:CVE-2012-5132
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%HIGH2012-11-07
Skia, as used in Google Chrome before 23.0.1271.64, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
CVEs:CVE-2012-5123
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2012-11-27
Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG filters.
CVEs:CVE-2012-5133
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2012-11-27
Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to printing.
CVEs:CVE-2012-5135
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2012-11-07
Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of SVG filters.
CVEs:CVE-2012-5116
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2012-11-07
Google Chrome before 23.0.1271.64 does not properly handle textures, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
CVEs:CVE-2012-5124
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2012-11-07
Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of extension tabs.
CVEs:CVE-2012-5125
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2012-11-07
Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of plug-in placeholders.
CVEs:CVE-2012-5126
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2012-11-07
Google Chrome before 23.0.1271.64 does not properly perform a cast of an unspecified variable during handling of input, which allows remote attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2012-5122
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2012-11-27
Google Chrome before 23.0.1271.91 does not properly perform a cast of an unspecified variable during handling of the INPUT element, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted HTML docu...
CVEs:CVE-2012-5136
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%HIGH2012-11-07
Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, does not properly perform write operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
CVEs:CVE-2012-5128
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| v8 |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2012-11-27
Google Chrome before 23.0.1271.91 on Mac OS X does not properly mitigate improper rendering behavior in the Intel GPU driver, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
CVEs:CVE-2012-5131
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2012-11-07
Google Chrome before 23.0.1271.64 on Mac OS X does not properly mitigate improper write behavior in graphics drivers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger ...
CVEs:CVE-2012-5115
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2012-11-07
Google Chrome before 23.0.1271.64 on Mac OS X does not properly validate an integer value during the handling of GPU command buffers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
CVEs:CVE-2012-5118
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2012-11-07
Integer overflow in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted WebP image.
CVEs:CVE-2012-5127
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2012-11-20
Cross-site scripting (XSS) vulnerability in Google Web Toolkit (GWT) 2.4 Beta and release candidates before 2.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVEs:CVE-2012-4563
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| web_toolkit |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2012-11-07
Google Chrome before 23.0.1271.64 does not properly restrict the loading of an SVG subresource in the context of an IMG element, which has unspecified impact and remote attack vectors.
CVEs:CVE-2012-5117
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2012-11-07
Race condition in Pepper, as used in Google Chrome before 23.0.1271.64, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to buffers.
CVEs:CVE-2012-5119
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2012-11-30
drivers/gpu/msm/kgsl.c in the Qualcomm Innovation Center (QuIC) Graphics KGSL kernel-mode driver for Android 2.3 through 4.2 allows attackers to cause a denial of service (NULL pointer dereference) via an application that uses crafted arguments in a lo...
CVEs:CVE-2012-4222
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2012-11-28
Google CityHash computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maint...
CVEs:CVE-2012-6051
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cityhash |
affected |
google |
— |
— |
Open SourceEPSS <= 49%MEDIUM2012-11-04
The Android_Pusher library for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via ...
CVEs:CVE-2012-5813
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android_pusher |
affected |
emorym |
— |
— |
GoogleEPSS <= 49%MEDIUM2012-11-06
google-checkout-php-sample-code before 1.3.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL server...
CVEs:CVE-2011-5238
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| checkout-php |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2012-11-04
The developer-account sample code in Google AdMob does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL s...
CVEs:CVE-2012-5820
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| admob |
affected |
google |
— |
— |