Advisories
GoogleExploitedCISA KEV listedHIGH2015-07-08
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers ...
CVEs:CVE-2015-5119
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_eus |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_server_aus |
affected |
redhat |
— |
— |
| enterprise_linux_server_from_rhui |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| evergreen |
affected |
opensuse |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
| linux_enterprise_desktop |
affected |
suse |
— |
— |
| linux_enterprise_workstation_extension |
affected |
suse |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
Project ZeroExploitedCISA KEV listed2015-07-08
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.
CVEs:CVE-2015-5119
Open SourceExploitedCISA KEV listedHIGH2015-07-28
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code via crafted atoms in MP4 data that trigger an unchecked multiplic...
CVEs:CVE-2015-1538
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Project ZeroExploitedCISA KEV listed2015-07-07
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as
CVEs:CVE-2015-5122
GoogleExploitedCISA KEV listedHIGH2015-07-07
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 1...
CVEs:CVE-2015-5122
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_server_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| evergreen |
affected |
opensuse |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
| flash_player_desktop_runtime |
affected |
adobe |
— |
— |
| linux_enterprise_desktop |
affected |
suse |
— |
— |
| linux_enterprise_workstation_extension |
affected |
suse |
— |
— |
GoogleExploitedCISA KEV listedHIGH2015-07-20
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remot...
CVEs:CVE-2015-2426
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| windows_10 |
affected |
microsoft |
— |
— |
| windows_7 |
affected |
microsoft |
— |
— |
| windows_8 |
affected |
microsoft |
— |
— |
| windows_8.1 |
affected |
microsoft |
— |
— |
| windows_rt |
affected |
microsoft |
— |
— |
| windows_rt_8.1 |
affected |
microsoft |
— |
— |
| windows_server_2008 |
affected |
microsoft |
— |
— |
| windows_server_2012 |
affected |
microsoft |
— |
— |
| windows_vista |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2015-07-20
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Driver Vulnerability."
CVEs:CVE-2015-2426
GoogleExploitedCISA KEV listedHIGH2015-07-14
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2...
CVEs:CVE-2015-2425
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| internet_explorer |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2015-07-14
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2383 and CVE-2015-2384.
CVEs:CVE-2015-2425
Project ZeroExploitedCISA KEV listed2015-07-14
Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
CVEs:CVE-2015-2424
GoogleExploitedCISA KEV listedHIGH2015-07-14
Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a cra...
CVEs:CVE-2015-2424
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| excel_viewer |
affected |
microsoft |
— |
— |
| office |
affected |
microsoft |
— |
— |
| office_compatibility_pack |
affected |
microsoft |
— |
— |
| powerpoint |
affected |
microsoft |
— |
— |
| word |
affected |
microsoft |
— |
— |
| word_viewer |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2015-07-14
ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "ATMFD.DLL Memory Corruption Vulnerability."
CVEs:CVE-2015-2387
GoogleExploitedCISA KEV listedHIGH2015-07-14
ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows loca...
CVEs:CVE-2015-2387
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| windows_7 |
affected |
microsoft |
— |
— |
| windows_8 |
affected |
microsoft |
— |
— |
| windows_8.1 |
affected |
microsoft |
— |
— |
| windows_rt |
affected |
microsoft |
— |
— |
| windows_rt_8.1 |
affected |
microsoft |
— |
— |
| windows_server_2003 |
affected |
microsoft |
— |
— |
| windows_server_2008 |
affected |
microsoft |
— |
— |
| windows_server_2012 |
affected |
microsoft |
— |
— |
| windows_vista |
affected |
microsoft |
— |
— |
GoogleExploitedCISA KEV listedHIGH2015-07-15
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than...
CVEs:CVE-2015-2590
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_eus |
affected |
redhat |
— |
— |
| enterprise_linux_for_ibm_z_systems |
affected |
redhat |
— |
— |
| enterprise_linux_for_ibm_z_systems_eus |
affected |
redhat |
— |
— |
| enterprise_linux_for_power_big_endian |
affected |
redhat |
— |
— |
| enterprise_linux_for_power_big_endian_eus |
affected |
redhat |
— |
— |
| enterprise_linux_for_power_little_endian |
affected |
redhat |
— |
— |
| enterprise_linux_for_power_little_endian_eus |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_server_aus |
affected |
redhat |
— |
— |
| enterprise_linux_server_tus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| jdk |
affected |
oracle |
— |
— |
| jre |
affected |
oracle |
— |
— |
| linux_enterprise_debuginfo |
affected |
suse |
— |
— |
| linux_enterprise_desktop |
affected |
suse |
— |
— |
| linux_enterprise_server |
affected |
suse |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| satellite |
affected |
redhat |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
Project ZeroExploitedCISA KEV listed2015-07-15
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.
CVEs:CVE-2015-2590
GoogleExploitedCISA KEV listedHIGH2015-07-11
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x...
CVEs:CVE-2015-5123
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_server_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| evergreen |
affected |
opensuse |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
| flash_player_desktop_runtime |
affected |
adobe |
— |
— |
| linux_enterprise_desktop |
affected |
suse |
— |
— |
| linux_enterprise_workstation_extension |
affected |
suse |
— |
— |
Project ZeroExploitedCISA KEV listed2015-07-11
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.
CVEs:CVE-2015-5123
Open SourceWeaponized exploit2015-07-23
chromium-browser - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser |
affected |
Debian:8 |
chromium-browser |
— |
Open SourceWeaponized exploitCRITICAL2015-07-27
Updated chromium-browser package fixes security vulnerabilities
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:4 |
chromium-browser-stable |
— |
| chromium-browser-stable |
affected |
Mageia:5 |
chromium-browser-stable |
— |
GoogleWeaponized exploitCRITICAL2015-07-22
Use-after-free vulnerability in the accessibility implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging lack of certain validity checks for acces...
CVEs:CVE-2015-1277
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
Open SourcePoC exploitHIGH2015-07-28
Off-by-one error in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow and memory corruption) v...
CVEs:CVE-2015-3829
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitCRITICAL2015-07-22
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecif...
CVEs:CVE-2015-1283
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| leap |
affected |
opensuse |
— |
— |
| libexpat |
affected |
libexpat_project |
— |
— |
| linux_enterprise_debuginfo |
affected |
suse |
— |
— |
| linux_enterprise_desktop |
affected |
suse |
— |
— |
| linux_enterprise_server |
affected |
suse |
— |
— |
| linux_enterprise_software_development_kit |
affected |
suse |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| python |
affected |
python |
— |
— |
| solaris |
affected |
oracle |
— |
— |
| studio_onsite |
affected |
suse |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
Open SourceEPSS > 79%HIGH2015-07-28
The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not properly restrict size addition, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overf...
CVEs:CVE-2015-3824
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS > 79%HIGH2015-07-28
Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in libstagefright in Android before 5.1.1 LMY48I allow remote attackers to execute arbitrary code via crafted ESDS atoms, aka internal bug 20139950, a related issue to CVE-...
CVEs:CVE-2015-1539
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS > 79%HIGH2015-07-28
The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size for UTF-16 strings containing a Byte Order Mark (BOM), which allows remote attackers to execute arbitr...
CVEs:CVE-2015-3828
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS > 79%HIGH2015-07-28
The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not validate the relationship between chunk sizes and skip sizes, which allows remote attackers to execute arbitrary code or cause a den...
CVEs:CVE-2015-3827
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS 49-79%CRITICAL2015-07-28
The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size for UTF-16 strings containing a Byte Order Mark (BOM), which allows remote attackers to cause a denial...
CVEs:CVE-2015-3826
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-07-22
Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it easier for remote attackers to execute arbitrary code by providing a crafted file and leveraging a user's previous "Always open fil...
CVEs:CVE-2015-1274
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-07-09
The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, ...
CVEs:CVE-2015-5380
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| io.js |
affected |
iojs |
— |
— |
| node.js |
affected |
nodejs |
— |
— |
| v8 |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2015-07-22
The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names with initial x- substrings, which allows remote attackers to cause a den...
CVEs:CVE-2015-1270
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| solaris |
affected |
oracle |
— |
— |
Open SourceEPSS <= 49%NONE2015-07-05
Updated chromium-browser package fixes security vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:4 |
chromium-browser-stable |
— |
| chromium-browser-stable |
affected |
Mageia:5 |
chromium-browser-stable |
— |
GoogleEPSS <= 49%CRITICAL2015-07-22
Integer overflow in the CJBig2_Image::expand function in fxcodec/jbig2/JBig2_Image.cpp in PDFium, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecifi...
CVEs:CVE-2015-1279
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-07-22
The LocalFrame::isURLAllowed function in core/frame/LocalFrame.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly check for a page's maximum number of frames, which allows remote attackers to cause a denial of service (invali...
CVEs:CVE-2015-1284
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-07-22
PDFium, as used in Google Chrome before 44.0.2403.89, does not properly handle certain out-of-memory conditions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a cra...
CVEs:CVE-2015-1271
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-07-22
Cross-site scripting (XSS) vulnerability in the V8ContextNativeHandler::GetModuleSystem function in extensions/renderer/v8_context_native_handler.cc in Google Chrome before 44.0.2403.89 allows remote attackers to inject arbitrary web script or HTML by ...
CVEs:CVE-2015-1286
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%MEDIUM2015-07-22
content/browser/web_contents/web_contents_impl.cc in Google Chrome before 44.0.2403.89 does not ensure that a PDF document's modal dialog is closed upon navigation to an interstitial page, which allows remote attackers to spoof URLs via a crafted docum...
CVEs:CVE-2015-1278
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-07-22
core/loader/ImageLoader.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly determine the V8 context of a microtask, which allows remote attackers to bypass Content Security Policy (CSP) restrictions by providing an image from...
CVEs:CVE-2015-1281
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-07-22
Use-after-free vulnerability in the GPU process implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging the continued availability of a GPUChannelH...
CVEs:CVE-2015-1272
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-07-22
Use-after-free vulnerability in content/browser/indexed_db/indexed_db_backing_store.cc in the IndexedDB implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact b...
CVEs:CVE-2015-1276
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-07-22
Multiple use-after-free vulnerabilities in fpdfsdk/src/javascript/Document.cpp in PDFium, as used in Google Chrome before 44.0.2403.89, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF docu...
CVEs:CVE-2015-1282
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-07-22
SkPictureShader.cpp in Skia, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging access to a renderer process and providing craft...
CVEs:CVE-2015-1280
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-07-22
Cross-site scripting (XSS) vulnerability in org/chromium/chrome/browser/UrlUtilities.java in Google Chrome before 44.0.2403.89 on Android allows remote attackers to inject arbitrary web script or HTML via a crafted intent: URL, as demonstrated by a tra...
CVEs:CVE-2015-1275
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-07-22
Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid JPEG2000 data in a PDF docu...
CVEs:CVE-2015-1273
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%HIGH2015-07-23
The regular-expression implementation in Google V8, as used in Google Chrome before 44.0.2403.89, mishandles interrupts, which allows remote attackers to cause a denial of service (application crash) via crafted JavaScript code, as demonstrated by an e...
CVEs:CVE-2015-5605
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-07-22
Blink, as used in Google Chrome before 44.0.2403.89, enables a quirks-mode exception that limits the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote attackers to bypass the Same ...
CVEs:CVE-2015-1287
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-07-22
The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for remote attackers to obtain sensit...
CVEs:CVE-2015-1285
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%HIGH2015-07-22
Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2015-1289
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%MEDIUM2015-07-22
The Spellcheck API implementation in Google Chrome before 44.0.2403.89 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified ...
CVEs:CVE-2015-1288
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |