Advisories
Open SourceExploitedCISA KEV listedHIGH2013-04-13
Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of ke...
CVEs:CVE-2013-2596
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
motorola |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
Open SourcePoC exploitMEDIUM2013-04-13
The TrustZone kernel, when used in conjunction with a certain Motorola build of Android 4.1.2, on Motorola Razr HD, Razr M, and Atrix HD devices with the Qualcomm MSM8960 chipset does not verify the association between a certain physical-address argume...
CVEs:CVE-2013-3051
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
motorola |
— |
— |
| atrix_hd |
affected |
motorola |
— |
— |
| msm8960 |
affected |
qualcomm |
— |
— |
| razr_hd |
affected |
motorola |
— |
— |
| razr_m |
affected |
motorola |
— |
— |
GoogleEPSS <= 49%HIGH2013-04-16
Use-after-free vulnerability in the O3D plug-in in Google Chrome OS before 26.0.1410.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to improper management of ownership relationships...
CVEs:CVE-2013-2833
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome_os |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2013-04-16
The Buffer::Set function in core/cross/buffer.cc in the O3D plug-in in Google Chrome OS before 26.0.1410.57 does not prevent uninitialized data from remaining in a buffer, which might allow remote attackers to obtain sensitive information via unspecifi...
CVEs:CVE-2013-2832
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome_os |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2013-04-16
Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attackers to bypass the domain-whitelist protection mechanism via a crafted web site, a different vulnerability...
CVEs:CVE-2013-2834
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome_os |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2013-04-10
Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the user's home directory, and the file referenced by the PANGO_RC_FILE environment variable, which allows a...
CVEs:CVE-2013-0927
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome_os |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2013-04-16
Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attackers to bypass the domain-whitelist protection mechanism via a crafted web site, a different vulnerability...
CVEs:CVE-2013-2835
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome_os |
affected |
google |
— |
— |
GoogleEPSS <= 49%NONE2013-04-24
DEBIAN-CVE-2012-6140
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google-authenticator |
affected |
Debian:11 |
google-authenticator |
— |
| google-authenticator |
affected |
Debian:12 |
google-authenticator |
— |
| google-authenticator |
affected |
Debian:13 |
google-authenticator |
— |
| google-authenticator |
affected |
Debian:14 |
google-authenticator |
— |
GoogleEPSS <= 49%LOW2013-04-24
pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret via standard filesystem...
CVEs:CVE-2012-6140
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| authenticator |
affected |
google |
— |
— |