Google Security Advisories · February 2013 — Google Security Advisories
27 advisories 27 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2013-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2011-1350

Open SourceActive exploitation (sightings)HIGH2013-02-05

The PowerVR SGX driver in Android before 2.3.6 allows attackers to obtain potentially sensitive information from kernel stack memory via an application that uses a crafted length parameter in a request to the pvrsrvkm device.

CVEs:CVE-2011-1350

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2013-0879

GooglePoC exploitCRITICAL2013-02-22

Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly implement web audio nodes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other ...

CVEs:CVE-2013-0879

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0892

GoogleEPSS <= 49%HIGH2013-02-22

Multiple unspecified vulnerabilities in the IPC layer in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allow remote attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2013-0892

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2013-0894

GoogleEPSS <= 49%CRITICAL2013-02-22

Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis decoder in vorbisdec.c in libavcodec in FFmpeg through 1.1.3, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other pr...

CVEs:CVE-2013-0894

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
ffmpeg affected ffmpeg
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2013-0899

GoogleEPSS <= 49%CRITICAL2013-02-22

Integer overflow in the padding implementation in the opus_packet_parse_impl function in src/opus_decoder.c in Opus before 1.0.2, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, ...

CVEs:CVE-2013-0899

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
opus affected opus-codec
Upstream advisory

CVE-2013-0889

GoogleEPSS <= 49%CRITICAL2013-02-22

Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly enforce a user gesture requirement before proceeding with a file download, which might make it easier for remote attackers to execute arbitra...

CVEs:CVE-2013-0889

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2013-0888

GoogleEPSS <= 49%HIGH2013-02-22

Skia, as used in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to a "user gesture check for dangerous file down...

CVEs:CVE-2013-0888

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2013-0897

GoogleEPSS <= 49%HIGH2013-02-22

Off-by-one error in the PDF functionality in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service via a crafted document.

CVEs:CVE-2013-0897

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2013-0882

GoogleEPSS <= 49%HIGH2013-02-22

Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (incorrect memory access) or possibly have unspecified other impact via a large number of SVG parameters.

CVEs:CVE-2013-0882

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2013-0890

GoogleEPSS <= 49%CRITICAL2013-02-22

Multiple unspecified vulnerabilities in the IPC layer in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allow remote attackers to cause a denial of service (memory corruption) or possibly have other impact ...

CVEs:CVE-2013-0890

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2013-0891

GoogleEPSS <= 49%CRITICAL2013-02-22

Integer overflow in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a blob.

CVEs:CVE-2013-0891

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2013-0895

GoogleEPSS <= 49%CRITICAL2013-02-22

Google Chrome before 25.0.1364.97 on Linux, and before 25.0.1364.99 on Mac OS X, does not properly handle pathnames during copy operations, which might make it easier for remote attackers to execute arbitrary programs via unspecified vectors.

CVEs:CVE-2013-0895

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0900

GoogleEPSS <= 49%HIGH2013-02-22

Race condition in the International Components for Unicode (ICU) functionality in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspeci...

CVEs:CVE-2013-0900

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2013-0880

GoogleEPSS <= 49%CRITICAL2013-02-22

Use-after-free vulnerability in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to databases.

CVEs:CVE-2013-0880

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2013-0896

GoogleEPSS <= 49%HIGH2013-02-22

Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly manage memory during message handling for plug-ins, which allows remote attackers to cause a denial of service or possibly have unspecified o...

CVEs:CVE-2013-0896

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2013-0881

GoogleEPSS <= 49%HIGH2013-02-22

Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (incorrect read operation) via crafted data in the Matroska container format.

CVEs:CVE-2013-0881

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2013-0883

GoogleEPSS <= 49%HIGH2013-02-22

Skia, as used in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (incorrect read operation) via unspecified vectors.

CVEs:CVE-2013-0883

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2013-0898

GoogleEPSS <= 49%CRITICAL2013-02-22

Use-after-free vulnerability in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a URL.

CVEs:CVE-2013-0898

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2013-0884

GoogleEPSS <= 49%MEDIUM2013-02-22

Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly load Native Client (aka NaCl) code, which has unspecified impact and attack vectors.

CVEs:CVE-2013-0884

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2013-0893

GoogleEPSS <= 49%HIGH2013-02-22

Race condition in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to media.

CVEs:CVE-2013-0893

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2013-0885

GoogleEPSS <= 49%HIGH2013-02-22

Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict API privileges during interaction with the Chrome Web Store, which has unspecified impact and attack vectors.

CVEs:CVE-2013-0885

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2013-0887

GoogleEPSS <= 49%HIGH2013-02-22

The developer-tools process in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict privileges during interaction with a connected server, which has unspecified impact and attack vectors.

CVEs:CVE-2013-0887

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2268

GoogleEPSS <= 49%HIGH2013-02-23

Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, has unknown impact and remote attack vectors, related to a "high severity security issue."

CVEs:CVE-2013-2268

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0886

GoogleEPSS <= 49%HIGH2013-02-22

Google Chrome before 25.0.1364.99 on Mac OS X does not properly implement signal handling for Native Client (aka NaCl) code, which has unspecified impact and attack vectors.

CVEs:CVE-2013-0886

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
mac_os_x affected apple
Upstream advisory

DEBIAN-CVE-2012-5564

Open SourceEPSS <= 49%MEDIUM2013-02-14

DEBIAN-CVE-2012-5564

Affected products

ProductStatusVendorPackageEcosystem
android-platform-system-core affected Debian:11 android-platform-system-core
Upstream advisory

CVE-2012-5564

Open SourceEPSS <= 49%MEDIUM2013-02-14

android-tools 4.1.1 in Android Debug Bridge (ADB) allows local users to overwrite arbitrary files via a symlink attack on /tmp/adb.log.

CVEs:CVE-2012-5564

Affected products

ProductStatusVendorPackageEcosystem
android_debug_bridge affected google
Upstream advisory

CVE-2011-1352

Open SourceEPSS <= 49%CRITICAL2013-02-05

The PowerVR SGX driver in Android before 2.3.6 allows attackers to gain root privileges via an application that triggers kernel memory corruption using crafted user data to the pvrsrvkm device.

CVEs:CVE-2011-1352

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.