Google Security Advisories · April 2013 — Google Security Advisories
9 advisories 9 CVEs 1 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2013-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2013-2596

Open SourceExploitedCISA KEV listedHIGH2013-04-13

Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of ke...

CVEs:CVE-2013-2596

Affected products

ProductStatusVendorPackageEcosystem
android affected motorola
linux_kernel affected linux
Upstream advisory

CVE-2013-3051

Open SourcePoC exploitMEDIUM2013-04-13

The TrustZone kernel, when used in conjunction with a certain Motorola build of Android 4.1.2, on Motorola Razr HD, Razr M, and Atrix HD devices with the Qualcomm MSM8960 chipset does not verify the association between a certain physical-address argume...

CVEs:CVE-2013-3051

Affected products

ProductStatusVendorPackageEcosystem
android affected motorola
atrix_hd affected motorola
msm8960 affected qualcomm
razr_hd affected motorola
razr_m affected motorola
Upstream advisory

CVE-2013-2833

GoogleEPSS <= 49%HIGH2013-04-16

Use-after-free vulnerability in the O3D plug-in in Google Chrome OS before 26.0.1410.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to improper management of ownership relationships...

CVEs:CVE-2013-2833

Affected products

ProductStatusVendorPackageEcosystem
chrome_os affected google
Upstream advisory

CVE-2013-2832

GoogleEPSS <= 49%HIGH2013-04-16

The Buffer::Set function in core/cross/buffer.cc in the O3D plug-in in Google Chrome OS before 26.0.1410.57 does not prevent uninitialized data from remaining in a buffer, which might allow remote attackers to obtain sensitive information via unspecifi...

CVEs:CVE-2013-2832

Affected products

ProductStatusVendorPackageEcosystem
chrome_os affected google
Upstream advisory

CVE-2013-2834

GoogleEPSS <= 49%CRITICAL2013-04-16

Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attackers to bypass the domain-whitelist protection mechanism via a crafted web site, a different vulnerability...

CVEs:CVE-2013-2834

Affected products

ProductStatusVendorPackageEcosystem
chrome_os affected google
Upstream advisory

CVE-2013-0927

GoogleEPSS <= 49%HIGH2013-04-10

Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the user's home directory, and the file referenced by the PANGO_RC_FILE environment variable, which allows a...

CVEs:CVE-2013-0927

Affected products

ProductStatusVendorPackageEcosystem
chrome_os affected google
Upstream advisory

CVE-2013-2835

GoogleEPSS <= 49%CRITICAL2013-04-16

Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attackers to bypass the domain-whitelist protection mechanism via a crafted web site, a different vulnerability...

CVEs:CVE-2013-2835

Affected products

ProductStatusVendorPackageEcosystem
chrome_os affected google
Upstream advisory

DEBIAN-CVE-2012-6140

GoogleEPSS <= 49%NONE2013-04-24

DEBIAN-CVE-2012-6140

Affected products

ProductStatusVendorPackageEcosystem
google-authenticator affected Debian:11 google-authenticator
google-authenticator affected Debian:12 google-authenticator
google-authenticator affected Debian:13 google-authenticator
google-authenticator affected Debian:14 google-authenticator
Upstream advisory

CVE-2012-6140

GoogleEPSS <= 49%LOW2013-04-24

pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret via standard filesystem...

CVEs:CVE-2012-6140

Affected products

ProductStatusVendorPackageEcosystem
authenticator affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.