Advisories
GoogleExploitedCISA KEV listedMEDIUM2015-02-11
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."
CVEs:CVE-2015-0071
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| internet_explorer |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2015-02-11
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."
CVEs:CVE-2015-0071
Open SourcePoC exploitHIGH2015-02-16
Multiple integer overflows in the GraphicBuffer::unflatten function in platform/frameworks/native/libs/ui/GraphicBuffer.cpp in Android through 5.0 allow attackers to gain privileges or cause a denial of service (memory corruption) via vectors that trig...
CVEs:CVE-2015-1474
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%CRITICAL2015-02-11
Updated chromium-browser-stable packages fix security vulnerabilities
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:4 |
chromium-browser-stable |
— |
GoogleEPSS <= 49%CRITICAL2015-02-06
Use-after-free vulnerability in the VisibleSelection::nonBoundaryShadowTreeRootNode function in core/editing/VisibleSelection.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 4...
CVEs:CVE-2015-1209
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_eus |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_server_aus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleEPSS <= 49%HIGH2015-02-06
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2015-1212
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_eus |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_server_aus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleEPSS <= 49%HIGH2015-02-06
The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatcher_host.cc in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android does not properly restrict the URI sche...
CVEs:CVE-2015-1211
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_eus |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_server_aus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-02-09
Cross-site scripting (XSS) vulnerability in the Google Doc Embedder plugin before 2.5.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the profile parameter in an edit action in the gde-settings page to wp-admin/optio...
CVEs:CVE-2015-1879
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_doc_embedder |
affected |
google_doc_embedder |
— |
— |
GoogleEPSS <= 49%MEDIUM2015-02-06
The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, does not properly con...
CVEs:CVE-2015-1210
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_eus |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_server_aus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleEPSS <= 49%HIGH2015-02-15
The Google Email application 4.2.2.0200 for Android allows remote attackers to cause a denial of service (persistent application crash) via a "Content-Disposition: ;" header in an e-mail message.
CVEs:CVE-2015-1574
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| email |
affected |
google |
— |
— |
Open SourceEPSS <= 49%CRITICAL2015-02-20
Cross-site scripting (XSS) vulnerability in textAngular-sanitize.js in textAngular before 1.3.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to the editor.
CVEs:CVE-2015-0167
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| textangular |
affected |
textangular |
— |
— |
GoogleEPSS <= 49%MEDIUM2015-02-23
The GoogleAuthUtil.getToken method in the Google Play services SDK before 2015 sets parameters in OAuth token requests upon finding a corresponding _opt_ parameter in the Bundle extras argument, which allows attackers to bypass an intended consent dial...
CVEs:CVE-2014-7922
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| play_services_sdk |
affected |
google |
— |
— |