Google Security Advisories · March 2015 — Google Security Advisories
27 advisories 27 CVEs 1 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2015-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2014-9654

GooglePoC exploitCRITICAL2015-03-02

The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrome before 40.0.2214.91, calculates certain values without ensuring that they can be represented in a 24-bit field, which al...

CVEs:CVE-2014-9654

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
international_components_for_unicode affected icu-project
Upstream advisory

CVE-2015-1221

GoogleEPSS <= 49%CRITICAL2015-03-04

Use-after-free vulnerability in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect ordering of operations in the Web SQL Database t...

CVEs:CVE-2015-1221

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-0890

GoogleEPSS <= 49%MEDIUM2015-03-03

The BestWebSoft Google Captcha (aka reCAPTCHA) plugin before 1.13 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.

CVEs:CVE-2015-0890

Affected products

ProductStatusVendorPackageEcosystem
google_captcha affected bestwebsoft
Upstream advisory

CVE-2015-1217

GoogleEPSS <= 49%HIGH2015-03-04

The V8LazyEventListener::prepareListenerObject function in bindings/core/v8/V8LazyEventListener.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, does not properly compile listeners, which allows remote attackers to cause a...

CVEs:CVE-2015-1217

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
ubuntu_linux affected canonical
Upstream advisory

CVE-2015-1230

GoogleEPSS <= 49%HIGH2015-03-04

The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the AudioContext class, which allows remote attackers to cause a denial of service or possibly hav...

CVEs:CVE-2015-1230

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
ubuntu_linux affected canonical
Upstream advisory

CVE-2015-1220

GoogleEPSS <= 49%CRITICAL2015-03-04

Use-after-free vulnerability in the GIFImageReader::parseData function in platform/image-decoders/gif/GIFImageReader.cpp in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspe...

CVEs:CVE-2015-1220

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
ubuntu_linux affected canonical
Upstream advisory

CVE-2015-1223

GoogleEPSS <= 49%CRITICAL2015-03-04

Multiple use-after-free vulnerabilities in core/html/HTMLInputElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 41.0.2272.76, allow remote attackers to cause a denial of service or possibly have unspecified other impact vi...

CVEs:CVE-2015-1223

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1224

GoogleEPSS <= 49%HIGH2015-03-04

The VpxVideoDecoder::VpxDecode function in media/filters/vpx_video_decoder.cc in the vpxdecoder implementation in Google Chrome before 41.0.2272.76 does not ensure that alpha-plane dimensions are identical to image dimensions, which allows remote attac...

CVEs:CVE-2015-1224

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1215

GoogleEPSS <= 49%CRITICAL2015-03-04

The filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation.

CVEs:CVE-2015-1215

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
ubuntu_linux affected canonical
Upstream advisory

CVE-2015-1213

GoogleEPSS <= 49%CRITICAL2015-03-04

The SkBitmap::ReadRawPixels function in core/SkBitmap.cpp in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors th...

CVEs:CVE-2015-1213

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1214

GoogleEPSS <= 49%CRITICAL2015-03-04

Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified ot...

CVEs:CVE-2015-1214

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
ubuntu_linux affected canonical
Upstream advisory

CVE-2015-1227

GoogleEPSS <= 49%HIGH2015-03-04

The DragImage::create function in platform/DragImage.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not initialize memory for image drawing, which allows remote attackers to have an unspecified impact by triggering a failed image deco...

CVEs:CVE-2015-1227

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1216

GoogleEPSS <= 49%CRITICAL2015-03-04

Use-after-free vulnerability in the V8Window::namedPropertyGetterCustom function in bindings/core/v8/custom/V8WindowCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of servi...

CVEs:CVE-2015-1216

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
ubuntu_linux affected canonical
Upstream advisory

CVE-2015-1218

GoogleEPSS <= 49%CRITICAL2015-03-04

Multiple use-after-free vulnerabilities in the DOM implementation in Blink, as used in Google Chrome before 41.0.2272.76, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger movement of...

CVEs:CVE-2015-1218

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
ubuntu_linux affected canonical
Upstream advisory

CVE-2015-1219

GoogleEPSS <= 49%CRITICAL2015-03-04

Integer overflow in the SkMallocPixelRef::NewAllocate function in core/SkMallocPixelRef.cpp in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vector...

CVEs:CVE-2015-1219

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
ubuntu_linux affected canonical
Upstream advisory

CVE-2015-1222

GoogleEPSS <= 49%CRITICAL2015-03-04

Multiple use-after-free vulnerabilities in the ServiceWorkerScriptCacheMap implementation in content/browser/service_worker/service_worker_script_cache_map.cc in Google Chrome before 41.0.2272.76 allow remote attackers to cause a denial of service or p...

CVEs:CVE-2015-1222

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1228

GoogleEPSS <= 49%CRITICAL2015-03-04

The RenderCounter::updateCounter function in core/rendering/RenderCounter.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not force a relayout operation and consequently does not initialize memory for a data structure, which allows rem...

CVEs:CVE-2015-1228

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
ubuntu_linux affected canonical
Upstream advisory

CVE-2015-1231

GoogleEPSS <= 49%HIGH2015-03-04

Multiple unspecified vulnerabilities in Google Chrome before 41.0.2272.76 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2015-1231

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
ubuntu_linux affected canonical
Upstream advisory

CVE-2015-1225

GoogleEPSS <= 49%HIGH2015-03-04

PDFium, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVEs:CVE-2015-1225

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1226

GoogleEPSS <= 49%MEDIUM2015-03-04

The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 41.0.2272.76 does not properly restrict what URLs are available as debugger targets, which allows remote attackers to bypass intende...

CVEs:CVE-2015-1226

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2014-9689

GoogleEPSS <= 49%MEDIUM2015-03-09

content/renderer/device_sensors/device_orientation_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate gyroscope data, which makes it easier for remote attackers to obtain speech signals from a device's phy...

CVEs:CVE-2014-9689

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-2239

GoogleEPSS <= 49%CRITICAL2015-03-09

Google Chrome before 41.0.2272.76, when Instant Extended mode is used, does not properly consider the interaction between the "1993 search" features and restore-from-disk RELOAD transitions, which makes it easier for remote attackers to spoof the addre...

CVEs:CVE-2015-2239

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1232

GoogleEPSS <= 49%CRITICAL2015-03-09

Array index error in the MidiManagerUsb::DispatchSendMidiData function in media/midi/midi_manager_usb.cc in Google Chrome before 41.0.2272.76 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging r...

CVEs:CVE-2015-1232

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-5319

GoogleEPSS <= 49%MEDIUM2015-03-09

content/renderer/device_sensors/device_motion_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate accelerometer data, which makes it easier for remote attackers to capture keystrokes via a crafted web site ...

CVEs:CVE-2011-5319

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1229

GoogleEPSS <= 49%MEDIUM2015-03-04

net/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allows remote proxy servers to conduct cookie-injection a...

CVEs:CVE-2015-1229

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
ubuntu_linux affected canonical
Upstream advisory

CVE-2015-2238

GoogleEPSS <= 49%HIGH2015-03-09

Multiple unspecified vulnerabilities in Google V8 before 4.1.0.21, as used in Google Chrome before 41.0.2272.76, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2015-2238

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
ubuntu_linux affected canonical
v8 affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.