Advisories
Project ZeroExploitedCISA KEV listed2015-04-14
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allow remote attackers to execute arbitrary code via a crafted RTF document, aka "Microsoft Office Memory Corruption Vulnerability."
CVEs:CVE-2015-1641
GoogleExploitedCISA KEV listedHIGH2015-04-14
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 201...
CVEs:CVE-2015-1641
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| office |
affected |
microsoft |
— |
— |
| office_compatibility_pack |
affected |
microsoft |
— |
— |
| office_web_apps |
affected |
microsoft |
— |
— |
| outlook |
affected |
microsoft |
— |
— |
| sharepoint_server |
affected |
microsoft |
— |
— |
| word |
affected |
microsoft |
— |
— |
GoogleExploitedCISA KEV listedHIGH2015-04-21
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulne...
CVEs:CVE-2015-1701
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| windows_2003_server |
affected |
microsoft |
— |
— |
| windows_2003_server |
affected |
microsoft |
— |
— |
| windows_7 |
affected |
microsoft |
— |
— |
| windows_server_2008 |
affected |
microsoft |
— |
— |
| windows_vista |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2015-04-21
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability."
CVEs:CVE-2015-1701
GoogleWeaponized exploitMEDIUM2015-04-01
Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) a...
CVEs:CVE-2015-2755
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ab_google_map_travel |
affected |
ab_google_map_travel_project |
— |
— |
Open SourceEPSS <= 49%CRITICAL2015-04-09
Updated chromium-browser-stable packages fix security vulnerabilities
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:4 |
chromium-browser-stable |
— |
GoogleEPSS <= 49%CRITICAL2015-04-01
Google Chrome before 41.0.2272.118 does not properly handle the interaction of IPC, the Gamepad API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors.
CVEs:CVE-2015-1233
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceEPSS <= 49%2015-04-26
chromium-browser - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser |
affected |
Debian:8 |
chromium-browser |
— |
Open SourceEPSS <= 49%CRITICAL2015-04-23
Updated chromium-browser-stable packages fix security vulnerabilities
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:4 |
chromium-browser-stable |
— |
GoogleEPSS <= 49%HIGH2015-04-15
The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service or possibly have unspecified other impact via cr...
CVEs:CVE-2015-1242
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
| v8 |
affected |
google |
— |
— |
Open SourceEPSS <= 49%CRITICAL2015-04-01
Updated chromium-browser-stable packages fix security vulnerabilities
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:4 |
chromium-browser-stable |
— |
Open SourceEPSS <= 49%2015-04-30
chromium-browser - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser |
affected |
Debian:8 |
chromium-browser |
— |
GoogleEPSS <= 49%CRITICAL2015-04-29
Use-after-free vulnerability in the MutationObserver::disconnect function in core/dom/MutationObserver.cpp in the DOM implementation in Blink, as used in Google Chrome before 42.0.2311.135, allows remote attackers to cause a denial of service or possib...
CVEs:CVE-2015-1243
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleEPSS <= 49%MEDIUM2015-04-15
Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a ...
CVEs:CVE-2015-1241
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_eus |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_server_aus |
affected |
redhat |
— |
— |
| enterprise_linux_server_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| linux_enterprise |
affected |
suse |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleEPSS <= 49%HIGH2015-04-19
The NaClSandbox::InitializeLayerTwoSandbox function in components/nacl/loader/sandbox_linux/nacl_sandbox_linux.cc in Google Chrome before 42.0.2311.90 does not have RLIMIT_AS and RLIMIT_DATA limits for Native Client (aka NaCl) processes, which might ma...
CVEs:CVE-2015-3335
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-04-15
Use-after-free vulnerability in the OpenPDFInReaderView::Update function in browser/ui/views/location_bar/open_pdf_in_reader_view.cc in Google Chrome before 41.0.2272.76 might allow user-assisted remote attackers to cause a denial of service (heap memo...
CVEs:CVE-2015-1245
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleEPSS <= 49%MEDIUM2015-04-19
browser/ui/website_settings/website_settings.cc in Google Chrome before 42.0.2311.90 does not always display "Media: Allowed by you" in a Permissions table after the user has granted camera permission to a web site, which might make it easier for user-...
CVEs:CVE-2015-3334
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%HIGH2015-04-29
Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.135 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2015-1250
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-04-15
Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service or possibly have unspecified other impact...
CVEs:CVE-2015-1237
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleEPSS <= 49%MEDIUM2015-04-15
The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy via a crafted HTML document with an IFRAME e...
CVEs:CVE-2015-1235
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleEPSS <= 49%HIGH2015-04-15
Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
CVEs:CVE-2015-1246
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-04-15
Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.
CVEs:CVE-2015-1238
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleEPSS <= 49%MEDIUM2015-04-15
The FileSystem API in Google Chrome before 40.0.2214.91 allows remote attackers to bypass the SafeBrowsing for Executable Files protection mechanism by creating a .exe file in a temporary filesystem and then referencing this file with a filesystem:http...
CVEs:CVE-2015-1248
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-04-15
The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy a...
CVEs:CVE-2015-1236
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleEPSS <= 49%HIGH2015-04-19
Google Chrome before 42.0.2311.90 does not always ask the user before proceeding with CONTENT_SETTINGS_TYPE_FULLSCREEN and CONTENT_SETTINGS_TYPE_MOUSELOCK changes, which allows user-assisted remote attackers to cause a denial of service (UI disruption)...
CVEs:CVE-2015-3336
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-04-01
Race condition in gpu/command_buffer/service/gles2_cmd_decoder.cc in Google Chrome before 41.0.2272.118 allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact by manipulating OpenGL ES commands.
CVEs:CVE-2015-1234
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2015-04-15
The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for remote attackers to obtain sensi...
CVEs:CVE-2015-1244
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleEPSS <= 49%HIGH2015-04-15
The SearchEngineTabHelper::OnPageHasOSDD function in browser/ui/search_engines/search_engine_tab_helper.cc in Google Chrome before 42.0.2311.90 does not prevent use of a file: URL for an OpenSearch descriptor XML document, which might allow remote atta...
CVEs:CVE-2015-1247
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleEPSS <= 49%HIGH2015-04-15
Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.90 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2015-1249
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-04-01
The PRNG implementation in the DNS resolver in Bionic in Android before 4.1.1 incorrectly uses time and PID information during the generation of random numbers for query ID values and UDP source ports, which makes it easier for remote attackers to spoo...
CVEs:CVE-2012-2808
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| bionic |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2015-04-15
gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebGL program that triggers a state inconsistency.
CVEs:CVE-2015-1240
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleEPSS <= 49%HIGH2015-04-19
Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before 42.0.2311.90, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2015-3333
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
| v8 |
affected |
google |
— |
— |