Advisories
Project ZeroExploitedCISA KEV listed2014-11-14
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.
CVEs:CVE-2015-3113
GoogleExploitedCISA KEV listedHIGH2014-11-14
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in t...
CVEs:CVE-2015-3113
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_eus |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| evergreen |
affected |
opensuse |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
| insight_orchestration |
affected |
hp |
— |
— |
| linux_enterprise_desktop |
affected |
suse |
— |
— |
| linux_enterprise_workstation_extension |
affected |
suse |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| system_management_homepage |
affected |
hp |
— |
— |
| systems_insight_manager |
affected |
hp |
— |
— |
| version_control_agent |
affected |
hp |
— |
— |
| version_control_repository_manager |
affected |
hp |
— |
— |
| virtual_connect_enterprise_manager |
affected |
hp |
— |
— |
GoogleExploitedCISA KEV listedHIGH2014-11-14
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in...
CVEs:CVE-2015-0313
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge |
affected |
microsoft |
— |
— |
| evergreen |
affected |
opensuse |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
| internet_explorer |
affected |
microsoft |
— |
— |
| linux_enterprise_desktop |
affected |
suse |
— |
— |
| linux_enterprise_workstation_extension |
affected |
suse |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
Project ZeroExploitedCISA KEV listed2014-11-14
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
CVEs:CVE-2015-0313
GoogleExploitedCISA KEV listedHIGH2014-11-18
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users ...
CVEs:CVE-2014-6324
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| windows_7 |
affected |
microsoft |
— |
— |
| windows_8 |
affected |
microsoft |
— |
— |
| windows_8.1 |
affected |
microsoft |
— |
— |
| windows_server_2003 |
affected |
microsoft |
— |
— |
| windows_server_2008 |
affected |
microsoft |
— |
— |
| windows_server_2012 |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2014-11-11
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users to obtain domain administrator privileges via a forged signature in a ticket, as exploited in the wild in November 2014, aka "Kerberos Checksum Vulnerability."
CVEs:CVE-2014-6324
Project ZeroExploitedCISA KEV listed2014-11-14
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.
CVEs:CVE-2015-0311
GoogleExploitedCISA KEV listedHIGH2014-11-14
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in ...
CVEs:CVE-2015-0311
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge |
affected |
microsoft |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
| internet_explorer |
affected |
microsoft |
— |
— |
| linux_enterprise_desktop |
affected |
suse |
— |
— |
| linux_enterprise_workstation_extension |
affected |
suse |
— |
— |
GoogleExploitedCISA KEV listedHIGH2014-11-14
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as ex...
CVEs:CVE-2015-3043
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_eus |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_server_aus |
affected |
redhat |
— |
— |
| enterprise_linux_server_from_rhui |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| evergreen |
affected |
opensuse |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| suse_linux_enterprise_desktop |
affected |
novell |
— |
— |
| suse_linux_enterprise_workstation_extension |
affected |
novell |
— |
— |
Project ZeroExploitedCISA KEV listed2014-11-14
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042.
CVEs:CVE-2015-3043
Project ZeroExploitedCISA KEV listed2014-11-11
Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IME for Japanese) is installed, allow remote attackers to bypass a sandbox protection mechanism via a crafted PDF document, aka "Microsoft IME (Japanese) Elevation of Privilege Vulnerability," as exploited in the wild in 2014.
CVEs:CVE-2014-4077
GoogleExploitedCISA KEV listedHIGH2014-11-11
Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IME for Japanese) is installed, allow remote attackers to bypass a sandbox protection mechanism via a cr...
CVEs:CVE-2014-4077
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| office_2007_ime |
affected |
microsoft |
— |
— |
| windows_7 |
affected |
microsoft |
— |
— |
| windows_server_2003 |
affected |
microsoft |
— |
— |
| windows_server_2008 |
affected |
microsoft |
— |
— |
| windows_vista |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2014-11-14
Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in December 2014.
CVEs:CVE-2014-9163
GoogleExploitedCISA KEV listedHIGH2014-11-14
Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in...
CVEs:CVE-2014-9163
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| flash_player |
affected |
adobe |
— |
— |
Project ZeroExploitedCISA KEV listed2014-11-14
Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.
CVEs:CVE-2014-8439
GoogleExploitedCISA KEV listedHIGH2014-11-14
Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers ...
CVEs:CVE-2014-8439
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
GoogleExploitedCISA KEV listedHIGH2014-11-14
Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism o...
CVEs:CVE-2015-0310
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| flash_player |
affected |
adobe |
— |
— |
Project ZeroExploitedCISA KEV listed2014-11-14
Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.
CVEs:CVE-2015-0310
Open SourcePoC exploitHIGH2014-11-14
Stack-based buffer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AI...
CVEs:CVE-2015-3100
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourcePoC exploitCRITICAL2014-11-25
Updated chromium-browser-stable fixes multiple security vulnerabilities
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:3 |
chromium-browser-stable |
— |
| chromium-browser-stable |
affected |
Mageia:4 |
chromium-browser-stable |
— |
GooglePoC exploitHIGH2014-11-19
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2014-7910
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2014-11-14
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe A...
CVEs:CVE-2015-3103
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
GooglePoC exploitCRITICAL2014-11-11
SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote attackers to execute arbitrary SQL commands via the gpid parameter.
CVEs:CVE-2014-9173
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_doc_embedder |
affected |
google_doc_embedder_project |
— |
— |
Open SourceEPSS <= 49%HIGH2014-11-14
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe A...
CVEs:CVE-2015-3106
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%HIGH2014-11-14
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe A...
CVEs:CVE-2015-3107
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| evergreen |
affected |
opensuse |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%MEDIUM2014-11-14
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Wind...
CVEs:CVE-2015-3108
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%MEDIUM2014-11-14
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Wind...
CVEs:CVE-2015-3102
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%MEDIUM2014-11-14
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Wind...
CVEs:CVE-2015-3098
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%MEDIUM2014-11-14
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Wind...
CVEs:CVE-2015-3099
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%MEDIUM2014-11-14
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Wind...
CVEs:CVE-2015-3096
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
GoogleEPSS <= 49%CRITICAL2014-11-19
Use-after-free vulnerability in the Pepper plugins in Google Chrome before 39.0.2171.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted Flash content that triggers an attempted PepperMediaDevic...
CVEs:CVE-2014-7906
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2014-11-19
Buffer overflow in Skia, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
CVEs:CVE-2014-7904
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2014-11-19
effects/SkDashPathEffect.cpp in Skia, as used in Google Chrome before 39.0.2171.65, computes a hash key using uninitialized integer values, which might allow remote attackers to cause a denial of service by rendering crafted data.
CVEs:CVE-2014-7909
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2014-11-19
Multiple use-after-free vulnerabilities in modules/screen_orientation/ScreenOrientationController.cpp in Blink, as used in Google Chrome before 39.0.2171.65, allow remote attackers to cause a denial of service or possibly have unspecified other impact ...
CVEs:CVE-2014-7907
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2014-11-19
Multiple integer overflows in the CheckMov function in media/base/container_names.cc in Google Chrome before 39.0.2171.65 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a large atom in (1) MPEG-4 or (2...
CVEs:CVE-2014-7908
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2014-11-19
Buffer overflow in OpenJPEG before r2911 in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted JPEG image.
CVEs:CVE-2014-7903
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2014-11-19
Use-after-free vulnerability in the CPDF_Parser::IsLinearizedFile function in fpdfapi/fpdf_parser/fpdf_parser_parser.cpp in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unsp...
CVEs:CVE-2014-7900
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2014-11-19
Integer overflow in the opj_t2_read_packet_data function in fxcodec/fx_libopenjpeg/libopenjpeg20/t2.c in OpenJPEG in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified...
CVEs:CVE-2014-7901
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2014-11-19
Google Chrome before 38.0.2125.101 allows remote attackers to spoof the address bar by placing a blob: substring at the beginning of the URL, followed by the original URI scheme and a long username string.
CVEs:CVE-2014-7899
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2014-11-19
Use-after-free vulnerability in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.
CVEs:CVE-2014-7902
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2014-11-19
Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL lacks CATEGORY_BROWSABLE, which allows remote attackers to bypass intended access restrictions via a crafted web site.
CVEs:CVE-2014-7905
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |