Advisories
GoogleExploitedCISA KEV listedHIGH2015-09-09
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Microsoft Office Malformed EPS File Vulnerability."
CVEs:CVE-2015-2545
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| office |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2015-09-09
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Microsoft Office Malformed EPS File Vulnerability."
CVEs:CVE-2015-2545
GoogleExploitedCISA KEV listedHIGH2015-09-09
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a craft...
CVEs:CVE-2015-2546
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| windows |
affected |
microsoft |
— |
— |
| windows_10_1507 |
affected |
microsoft |
— |
— |
| windows_7 |
affected |
microsoft |
— |
— |
| windows_8 |
affected |
microsoft |
— |
— |
| windows_8.1 |
affected |
microsoft |
— |
— |
| windows_rt |
affected |
microsoft |
— |
— |
| windows_rt_8.1 |
affected |
microsoft |
— |
— |
| windows_server_2008 |
affected |
microsoft |
— |
— |
| windows_server_2012 |
affected |
microsoft |
— |
— |
| windows_vista |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2015-09-09
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518.
CVEs:CVE-2015-2546
Open SourceWeaponized exploitHIGH2015-09-22
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to cause ...
CVEs:CVE-2015-5568
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%HIGH2015-09-22
Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows...
CVEs:CVE-2015-6678
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%HIGH2015-09-22
Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows...
CVEs:CVE-2015-6676
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%HIGH2015-09-22
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0...
CVEs:CVE-2015-5570
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%HIGH2015-09-22
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execut...
CVEs:CVE-2015-5573
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%HIGH2015-09-22
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0...
CVEs:CVE-2015-5584
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%HIGH2015-09-22
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0...
CVEs:CVE-2015-5581
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%HIGH2015-09-22
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0...
CVEs:CVE-2015-6682
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%HIGH2015-09-22
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execut...
CVEs:CVE-2015-6677
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%HIGH2015-09-22
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execut...
CVEs:CVE-2015-5575
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%HIGH2015-09-22
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execut...
CVEs:CVE-2015-5577
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%HIGH2015-09-22
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execut...
CVEs:CVE-2015-5578
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%HIGH2015-09-22
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execut...
CVEs:CVE-2015-5582
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%HIGH2015-09-22
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execut...
CVEs:CVE-2015-5588
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%HIGH2015-09-22
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execut...
CVEs:CVE-2015-5580
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%HIGH2015-09-22
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execut...
CVEs:CVE-2015-5567
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
Open SourceEPSS <= 49%HIGH2015-09-22
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to bypass...
CVEs:CVE-2015-5572
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| air |
affected |
adobe |
— |
— |
| air_sdk |
affected |
adobe |
— |
— |
| air_sdk_\&_compiler |
affected |
adobe |
— |
— |
| android |
affected |
google |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-09-03
Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 45.0.2454.85, allows remote attackers to execute arbitrary code or cause a denial of service ...
CVEs:CVE-2015-6581
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-09-21
Multiple cross-site scripting (XSS) vulnerabilities in the Google Analyticator plugin before 6.4.9.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) ga_adsense, (2) ga_admin_disable_DimentionIndex, (3) ga_downloa...
CVEs:CVE-2015-6238
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_analyticator |
affected |
sumome |
— |
— |
Open SourceEPSS <= 49%CRITICAL2015-09-08
Updated chromium-browser packages fix security vulnerabilities
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:4 |
chromium-browser-stable |
— |
| chromium-browser-stable |
affected |
Mageia:5 |
chromium-browser-stable |
— |
Open SourceEPSS <= 49%2015-09-03
chromium-browser - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser |
affected |
Debian:8 |
chromium-browser |
— |
GoogleEPSS <= 49%CRITICAL2015-09-02
The WebRequest API implementation in extensions/browser/api/web_request/web_request_api.cc in Google Chrome before 45.0.2454.85 does not properly consider a request's source before accepting the request, which allows remote attackers to bypass intended...
CVEs:CVE-2015-1297
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2015-09-25
object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, which allows remote attackers to bypass the Same Origin Policy via a (1) observe or (2) getNotifier call.
CVEs:CVE-2015-1304
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-09-02
The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not properly restrict the availability of IFRAME Resource Timing API times, which allo...
CVEs:CVE-2015-1300
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2015-09-25
bindings/core/v8/V8DOMWrapper.h in Blink, as used in Google Chrome before 45.0.2454.101, does not perform a rethrow action to propagate information about a cross-context exception, which allows remote attackers to bypass the Same Origin Policy via a cr...
CVEs:CVE-2015-1303
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2015-09-02
The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not check whether a node is expected, which allows remote attackers to bypass the Same Origin Policy or cause a den...
CVEs:CVE-2015-1291
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-09-02
Use-after-free vulnerability in the shared-timer implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging erroneous timer firing,...
CVEs:CVE-2015-1299
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-09-02
Use-after-free vulnerability in the SkMatrix::invertNonIdentity function in core/SkMatrix.cpp in Skia, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by trigg...
CVEs:CVE-2015-1294
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-09-02
Multiple use-after-free vulnerabilities in the PrintWebViewHelper class in components/printing/renderer/print_web_view_helper.cc in Google Chrome before 45.0.2454.85 allow user-assisted remote attackers to cause a denial of service or possibly have uns...
CVEs:CVE-2015-1295
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2015-09-02
The NavigatorServiceWorker::serviceWorker function in modules/serviceworkers/NavigatorServiceWorker.cpp in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy by accessing a Service Worker.
CVEs:CVE-2015-1292
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2015-09-02
The DOM implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
CVEs:CVE-2015-1293
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2015-09-02
The UnescapeURLWithAdjustmentsImpl implementation in net/base/escape.cc in Google Chrome before 45.0.2454.85 does not prevent display of Unicode LOCK characters in the omnibox, which makes it easier for remote attackers to spoof the SSL lock icon by pl...
CVEs:CVE-2015-1296
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2015-09-03
Multiple unspecified vulnerabilities in Google Chrome before 45.0.2454.85 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2015-1301
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2015-09-03
Google Chrome before 45.0.2454.85 does not display a location bar for a hosted app's window after navigation away from the installation site, which might make it easier for remote attackers to spoof content via a crafted app, related to browser.cc and ...
CVEs:CVE-2015-6583
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2015-09-02
The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api.cc in Google Chrome before 45.0.2454.85 does not ensure that the setUninstallURL preference corresponds to the URL of a web site, which allows user-as...
CVEs:CVE-2015-1298
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2015-09-11
Cross-site scripting (XSS) vulnerability in the googleSearch (CSE) (com_googlesearch_cse) component 3.0.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the q parameter to index.php.
CVEs:CVE-2015-6919
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| googlesearch |
affected |
googlesearch_project |
— |
— |
GoogleEPSS <= 49%HIGH2015-09-03
The decompose function in platform/transforms/TransformationMatrix.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not verify that a matrix inversion succeeded, which allows remote attackers to cause a denial of service (uninitialized ...
CVEs:CVE-2015-6582
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2015-09-03
Multiple unspecified vulnerabilities in Google V8 before 4.5.103.29, as used in Google Chrome before 45.0.2454.85, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2015-6580
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| v8 |
affected |
google |
— |
— |