Google Security Advisories · June 2015 — Google Security Advisories
10 advisories 9 CVEs 5 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2015-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 5 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2015-2360

Project ZeroExploitedCISA KEV listed2015-06-10

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

CVEs:CVE-2015-2360

Upstream advisory

CVE-2015-2360

GoogleExploitedCISA KEV listedHIGH2015-06-10

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows loc...

CVEs:CVE-2015-2360

Affected products

ProductStatusVendorPackageEcosystem
windows_7 affected microsoft
windows_8 affected microsoft
windows_8.1 affected microsoft
windows_rt affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2003 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_vista affected microsoft
Upstream advisory

CVE-2015-3105

Open SourceExploitedVulnCheck KEV listedHIGH2015-06-10

Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Wind...

CVEs:CVE-2015-3105

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

CVE-2015-3104

Open SourceExploitedVulnCheck KEV listedHIGH2015-06-10

Integer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK befor...

CVEs:CVE-2015-3104

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

CVE-2015-1805

Open SourceExploitedVulnCheck KEV listedHIGH2015-06-09

The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a denia...

CVEs:CVE-2015-1805

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2015-1268

GoogleEPSS <= 49%MEDIUM2015-06-26

bindings/scripts/v8_types.py in Blink, as used in Google Chrome before 43.0.2357.130, does not properly select a creation context for a return value's DOM wrapper, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript co...

CVEs:CVE-2015-1268

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1269

GoogleEPSS <= 49%MEDIUM2015-06-26

The DecodeHSTSPreloadRaw function in net/http/transport_security_state.cc in Google Chrome before 43.0.2357.130 does not properly canonicalize DNS hostnames before making comparisons to HSTS or HPKP preload entries, which allows remote attackers to byp...

CVEs:CVE-2015-1269

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1266

GoogleEPSS <= 49%MEDIUM2015-06-26

content/browser/webui/content_web_ui_controller_factory.cc in Google Chrome before 43.0.2357.130 does not properly consider the scheme in determining whether a URL is associated with a WebUI SiteInstance, which allows remote attackers to bypass intende...

CVEs:CVE-2015-1266

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1267

GoogleEPSS <= 49%MEDIUM2015-06-26

Blink, as used in Google Chrome before 43.0.2357.130, does not properly restrict the creation context during creation of a DOM wrapper, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that uses a Blink public ...

CVEs:CVE-2015-1267

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-3101

Open SourceEPSS <= 49%MEDIUM2015-06-10

The Flash broker in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK befor...

CVEs:CVE-2015-3101

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.