Google Security Advisories · December 2012 — Google Security Advisories
8 advisories 8 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2012-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2012-6301

Open SourceActive exploitation (sightings)HIGH2012-12-10

The Browser application in Android 4.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted market: URI in the SRC attribute of an IFRAME element.

CVEs:CVE-2012-6301

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2012-5144

GoogleEPSS <= 49%HIGH2012-12-12

Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact...

CVEs:CVE-2012-5144

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
libav affected libav
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2012-5142

GoogleEPSS <= 49%HIGH2012-12-12

Google Chrome before 23.0.1271.97 does not properly handle history navigation, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

CVEs:CVE-2012-5142

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2012-5139

GoogleEPSS <= 49%HIGH2012-12-12

Use-after-free vulnerability in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to visibility events.

CVEs:CVE-2012-5139

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2012-5140

GoogleEPSS <= 49%HIGH2012-12-12

Use-after-free vulnerability in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the URL loader.

CVEs:CVE-2012-5140

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2012-5143

GoogleEPSS <= 49%HIGH2012-12-12

Integer overflow in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to PPAPI image buffers.

CVEs:CVE-2012-5143

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2012-5129

GoogleEPSS <= 49%CRITICAL2012-12-03

Heap-based buffer overflow in the WebGL subsystem in Google Chrome OS before 23.0.1271.94 allows remote attackers to cause a denial of service (GPU process crash) or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2012-5129

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
Upstream advisory

CVE-2012-5141

GoogleEPSS <= 49%HIGH2012-12-12

Google Chrome before 23.0.1271.97 does not properly restrict instantiation of the Chromoting client plug-in, which has unspecified impact and attack vectors.

CVEs:CVE-2012-5141

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.