Google Security Advisories · March 2013 — Google Security Advisories
31 advisories 31 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2013-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2013-0926

GooglePoC exploitMEDIUM2013-03-28

Google Chrome before 26.0.1410.43 does not properly handle active content in an EMBED element during a copy-and-paste operation, which allows user-assisted remote attackers to have an unspecified impact via a crafted web site.

CVEs:CVE-2013-0926

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-1375

Open SourceEPSS <= 49%HIGH2013-03-12

Heap-based buffer overflow in Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on Windows and Mac OS X, before 10.3.183.68 and 11.x before 11.2.202.275 on Linux, before 11.1.111.44 on Android 2.x and 3.x, and before 11.1.115.48 on And...

CVEs:CVE-2013-1375

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
adobe_air_sdk_and_compiler affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2013-0646

Open SourceEPSS <= 49%HIGH2013-03-12

Integer overflow in Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on Windows and Mac OS X, before 10.3.183.68 and 11.x before 11.2.202.275 on Linux, before 11.1.111.44 on Android 2.x and 3.x, and before 11.1.115.48 on Android 4.x; ...

CVEs:CVE-2013-0646

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
adobe_air_sdk_and_compiler affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2013-0650

Open SourceEPSS <= 49%HIGH2013-03-12

Use-after-free vulnerability in Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on Windows and Mac OS X, before 10.3.183.68 and 11.x before 11.2.202.275 on Linux, before 11.1.111.44 on Android 2.x and 3.x, and before 11.1.115.48 on A...

CVEs:CVE-2013-0650

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
adobe_air_sdk_and_compiler affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2013-1371

Open SourceEPSS <= 49%HIGH2013-03-12

Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on Windows and Mac OS X, before 10.3.183.68 and 11.x before 11.2.202.275 on Linux, before 11.1.111.44 on Android 2.x and 3.x, and before 11.1.115.48 on Android 4.x; Adobe AIR before 3.6...

CVEs:CVE-2013-1371

Affected products

ProductStatusVendorPackageEcosystem
adobe_air affected adobe
adobe_air_sdk affected adobe
adobe_air_sdk_and_compiler affected adobe
flash_player affected adobe
flash_player_for_android affected adobe
Upstream advisory

CVE-2013-0912

GoogleEPSS <= 49%CRITICAL2013-03-08

WebKit in Google Chrome before 25.0.1364.160 allows remote attackers to execute arbitrary code via vectors that leverage "type confusion."

CVEs:CVE-2013-0912

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0123

Open SourceEPSS <= 49%CRITICAL2013-03-21

Multiple SQL injection vulnerabilities in the administration interface in ASKIA askiaweb allow remote attackers to execute arbitrary SQL commands via (1) the nHistoryId parameter to WebProd/pages/pgHistory.asp or (2) the OrderBy parameter to WebProd/pa...

CVEs:CVE-2013-0123

Affected products

ProductStatusVendorPackageEcosystem
askiaweb affected askia
Upstream advisory

CVE-2013-0910

GoogleEPSS <= 49%HIGH2013-03-04

Google Chrome before 25.0.1364.152 does not properly manage the interaction between the browser process and renderer processes during authorization of the loading of a plug-in, which makes it easier for remote attackers to bypass intended access restri...

CVEs:CVE-2013-0910

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0923

GoogleEPSS <= 49%CRITICAL2013-03-28

The USB Apps API in Google Chrome before 26.0.1410.43 allows remote attackers to cause a denial of service (memory corruption) via unspecified vectors.

CVEs:CVE-2013-0923

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0911

GoogleEPSS <= 49%HIGH2013-03-04

Directory traversal vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to have an unspecified impact via vectors related to databases.

CVEs:CVE-2013-0911

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0124

Open SourceEPSS <= 49%CRITICAL2013-03-21

Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in ASKIA askiaweb allow remote attackers to inject arbitrary web script or HTML via the (1) Number or (2) UpdatePage parameter to WebProd/cgi-bin/AskiaExt.dll.

CVEs:CVE-2013-0124

Affected products

ProductStatusVendorPackageEcosystem
askiaweb affected askia
Upstream advisory

CVE-2013-0924

GoogleEPSS <= 49%HIGH2013-03-28

The extension functionality in Google Chrome before 26.0.1410.43 does not verify that use of the permissions API is consistent with file permissions, which has unspecified impact and attack vectors.

CVEs:CVE-2013-0924

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-2493

GoogleEPSS <= 49%HIGH2013-03-07

The Hook_Terminate function in chrome_frame/protocol_sink_wrap.cc in the Google Chrome Frame plugin before 26.0.1410.28 for Internet Explorer does not properly handle attach tab requests, which allows user-assisted remote attackers to cause a denial of...

CVEs:CVE-2013-2493

Affected products

ProductStatusVendorPackageEcosystem
chrome_frame affected google
Upstream advisory

CVE-2013-2632

GoogleEPSS <= 49%HIGH2013-03-21

Google V8 before 3.17.13, as used in Google Chrome before 27.0.1444.3, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code, as demonstrated by the Bejeweled game.

CVEs:CVE-2013-2632

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
v8 affected google
Upstream advisory

CVE-2013-0917

GoogleEPSS <= 49%HIGH2013-03-28

The URL loader in Google Chrome before 26.0.1410.43 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2013-0917

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0916

GoogleEPSS <= 49%CRITICAL2013-03-28

Use-after-free vulnerability in the Web Audio implementation in Google Chrome before 26.0.1410.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2013-0916

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0920

GoogleEPSS <= 49%CRITICAL2013-03-28

Use-after-free vulnerability in the extension bookmarks API in Google Chrome before 26.0.1410.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2013-0920

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0902

GoogleEPSS <= 49%CRITICAL2013-03-04

Use-after-free vulnerability in the frame-loader implementation in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2013-0902

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0903

GoogleEPSS <= 49%CRITICAL2013-03-04

Use-after-free vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of browser navigation.

CVEs:CVE-2013-0903

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0905

GoogleEPSS <= 49%CRITICAL2013-03-04

Use-after-free vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving an SVG animation.

CVEs:CVE-2013-0905

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0906

GoogleEPSS <= 49%CRITICAL2013-03-04

The IndexedDB implementation in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2013-0906

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0904

GoogleEPSS <= 49%CRITICAL2013-03-04

The Web Audio implementation in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2013-0904

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0909

GoogleEPSS <= 49%CRITICAL2013-03-04

The XSS Auditor in Google Chrome before 25.0.1364.152 allows remote attackers to obtain sensitive HTTP Referer information via unspecified vectors.

CVEs:CVE-2013-0909

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0919

GoogleEPSS <= 49%CRITICAL2013-03-28

Use-after-free vulnerability in Google Chrome before 26.0.1410.43 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging the presence of an extension that creates a pop-up window.

CVEs:CVE-2013-0919

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0907

GoogleEPSS <= 49%HIGH2013-03-04

Race condition in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of media threads.

CVEs:CVE-2013-0907

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0922

GoogleEPSS <= 49%CRITICAL2013-03-28

Google Chrome before 26.0.1410.43 does not properly restrict brute-force access attempts against web sites that require HTTP Basic Authentication, which has unspecified impact and attack vectors.

CVEs:CVE-2013-0922

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0925

GoogleEPSS <= 49%HIGH2013-03-28

Google Chrome before 26.0.1410.43 does not ensure that an extension has the tabs (aka APIPermission::kTab) permission before providing a URL to this extension, which has unspecified impact and remote attack vectors.

CVEs:CVE-2013-0925

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0908

GoogleEPSS <= 49%HIGH2013-03-04

Google Chrome before 25.0.1364.152 does not properly manage bindings of extension processes, which has unspecified impact and attack vectors.

CVEs:CVE-2013-0908

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0918

GoogleEPSS <= 49%MEDIUM2013-03-28

Google Chrome before 26.0.1410.43 does not prevent navigation to developer tools in response to a drag-and-drop operation, which allows user-assisted remote attackers to have an unspecified impact via a crafted web site.

CVEs:CVE-2013-0918

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0921

GoogleEPSS <= 49%CRITICAL2013-03-28

The Isolated Sites feature in Google Chrome before 26.0.1410.43 does not properly enforce the use of separate processes, which makes it easier for remote attackers to bypass intended access restrictions via a crafted web site.

CVEs:CVE-2013-0921

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-0915

GoogleEPSS <= 49%HIGH2013-03-18

The GPU process in Google Chrome OS before 25.0.1364.173 allows attackers to cause a denial of service or possibly have unspecified other impact via vectors related to an "overflow."

CVEs:CVE-2013-0915

Affected products

ProductStatusVendorPackageEcosystem
chrome_os affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.