Advisories
Project ZeroExploitedCISA KEV listed2015-06-10
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
CVEs:CVE-2015-2360
GoogleExploitedCISA KEV listedHIGH2015-06-10
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows loc...
CVEs:CVE-2015-2360
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| windows_7 |
affected |
microsoft |
— |
— |
| windows_8 |
affected |
microsoft |
— |
— |
| windows_8.1 |
affected |
microsoft |
— |
— |
| windows_rt |
affected |
microsoft |
— |
— |
| windows_rt_8.1 |
affected |
microsoft |
— |
— |
| windows_server_2003 |
affected |
microsoft |
— |
— |
| windows_server_2008 |
affected |
microsoft |
— |
— |
| windows_server_2012 |
affected |
microsoft |
— |
— |
| windows_vista |
affected |
microsoft |
— |
— |
Open SourceExploitedVulnCheck KEV listedHIGH2015-06-10
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Wind...
CVEs:CVE-2015-3105
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceExploitedVulnCheck KEV listedHIGH2015-06-10
Integer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK befor...
CVEs:CVE-2015-3104
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceExploitedVulnCheck KEV listedHIGH2015-06-09
The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a denia...
CVEs:CVE-2015-1805
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
GoogleEPSS <= 49%MEDIUM2015-06-26
bindings/scripts/v8_types.py in Blink, as used in Google Chrome before 43.0.2357.130, does not properly select a creation context for a return value's DOM wrapper, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript co...
CVEs:CVE-2015-1268
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2015-06-26
The DecodeHSTSPreloadRaw function in net/http/transport_security_state.cc in Google Chrome before 43.0.2357.130 does not properly canonicalize DNS hostnames before making comparisons to HSTS or HPKP preload entries, which allows remote attackers to byp...
CVEs:CVE-2015-1269
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2015-06-26
content/browser/webui/content_web_ui_controller_factory.cc in Google Chrome before 43.0.2357.130 does not properly consider the scheme in determining whether a URL is associated with a WebUI SiteInstance, which allows remote attackers to bypass intende...
CVEs:CVE-2015-1266
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2015-06-26
Blink, as used in Google Chrome before 43.0.2357.130, does not properly restrict the creation context during creation of a DOM wrapper, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that uses a Blink public ...
CVEs:CVE-2015-1267
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceEPSS <= 49%MEDIUM2015-06-10
The Flash broker in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK befor...
CVEs:CVE-2015-3101
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |