Google Security Advisories · September 2015 — Google Security Advisories
42 advisories 40 CVEs 4 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2015-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 4 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2015-2545

GoogleExploitedCISA KEV listedHIGH2015-09-09

Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Microsoft Office Malformed EPS File Vulnerability."

CVEs:CVE-2015-2545

Affected products

ProductStatusVendorPackageEcosystem
office affected microsoft
Upstream advisory

CVE-2015-2545

Project ZeroExploitedCISA KEV listed2015-09-09

Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Microsoft Office Malformed EPS File Vulnerability."

CVEs:CVE-2015-2545

Upstream advisory

CVE-2015-2546

GoogleExploitedCISA KEV listedHIGH2015-09-09

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a craft...

CVEs:CVE-2015-2546

Affected products

ProductStatusVendorPackageEcosystem
windows affected microsoft
windows_10_1507 affected microsoft
windows_7 affected microsoft
windows_8 affected microsoft
windows_8.1 affected microsoft
windows_rt affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_vista affected microsoft
Upstream advisory

CVE-2015-2546

Project ZeroExploitedCISA KEV listed2015-09-09

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518.

CVEs:CVE-2015-2546

Upstream advisory

CVE-2015-5568

Open SourceWeaponized exploitHIGH2015-09-22

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to cause ...

CVEs:CVE-2015-5568

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

CVE-2015-6678

Open SourceEPSS <= 49%HIGH2015-09-22

Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows...

CVEs:CVE-2015-6678

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

CVE-2015-6676

Open SourceEPSS <= 49%HIGH2015-09-22

Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows...

CVEs:CVE-2015-6676

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

CVE-2015-5570

Open SourceEPSS <= 49%HIGH2015-09-22

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0...

CVEs:CVE-2015-5570

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

CVE-2015-5573

Open SourceEPSS <= 49%HIGH2015-09-22

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execut...

CVEs:CVE-2015-5573

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

CVE-2015-5584

Open SourceEPSS <= 49%HIGH2015-09-22

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0...

CVEs:CVE-2015-5584

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

CVE-2015-5581

Open SourceEPSS <= 49%HIGH2015-09-22

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0...

CVEs:CVE-2015-5581

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

CVE-2015-6682

Open SourceEPSS <= 49%HIGH2015-09-22

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0...

CVEs:CVE-2015-6682

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

CVE-2015-6677

Open SourceEPSS <= 49%HIGH2015-09-22

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execut...

CVEs:CVE-2015-6677

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

CVE-2015-5575

Open SourceEPSS <= 49%HIGH2015-09-22

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execut...

CVEs:CVE-2015-5575

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

CVE-2015-5577

Open SourceEPSS <= 49%HIGH2015-09-22

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execut...

CVEs:CVE-2015-5577

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

CVE-2015-5578

Open SourceEPSS <= 49%HIGH2015-09-22

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execut...

CVEs:CVE-2015-5578

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

CVE-2015-5582

Open SourceEPSS <= 49%HIGH2015-09-22

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execut...

CVEs:CVE-2015-5582

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

CVE-2015-5588

Open SourceEPSS <= 49%HIGH2015-09-22

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execut...

CVEs:CVE-2015-5588

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

CVE-2015-5580

Open SourceEPSS <= 49%HIGH2015-09-22

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execut...

CVEs:CVE-2015-5580

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

CVE-2015-5567

Open SourceEPSS <= 49%HIGH2015-09-22

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execut...

CVEs:CVE-2015-5567

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

CVE-2015-5572

Open SourceEPSS <= 49%HIGH2015-09-22

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to bypass...

CVEs:CVE-2015-5572

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
android affected google
flash_player affected adobe
Upstream advisory

CVE-2015-6581

GoogleEPSS <= 49%CRITICAL2015-09-03

Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 45.0.2454.85, allows remote attackers to execute arbitrary code or cause a denial of service ...

CVEs:CVE-2015-6581

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6238

GoogleEPSS <= 49%CRITICAL2015-09-21

Multiple cross-site scripting (XSS) vulnerabilities in the Google Analyticator plugin before 6.4.9.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) ga_adsense, (2) ga_admin_disable_DimentionIndex, (3) ga_downloa...

CVEs:CVE-2015-6238

Affected products

ProductStatusVendorPackageEcosystem
google_analyticator affected sumome
Upstream advisory

MGASA-2015-0356

Open SourceEPSS <= 49%CRITICAL2015-09-08

Updated chromium-browser packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:4 chromium-browser-stable
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

DSA-3351-1

Open SourceEPSS <= 49%2015-09-03

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:8 chromium-browser
Upstream advisory

CVE-2015-1297

GoogleEPSS <= 49%CRITICAL2015-09-02

The WebRequest API implementation in extensions/browser/api/web_request/web_request_api.cc in Google Chrome before 45.0.2454.85 does not properly consider a request's source before accepting the request, which allows remote attackers to bypass intended...

CVEs:CVE-2015-1297

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1304

GoogleEPSS <= 49%HIGH2015-09-25

object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, which allows remote attackers to bypass the Same Origin Policy via a (1) observe or (2) getNotifier call.

CVEs:CVE-2015-1304

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1300

GoogleEPSS <= 49%CRITICAL2015-09-02

The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not properly restrict the availability of IFRAME Resource Timing API times, which allo...

CVEs:CVE-2015-1300

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1303

GoogleEPSS <= 49%HIGH2015-09-25

bindings/core/v8/V8DOMWrapper.h in Blink, as used in Google Chrome before 45.0.2454.101, does not perform a rethrow action to propagate information about a cross-context exception, which allows remote attackers to bypass the Same Origin Policy via a cr...

CVEs:CVE-2015-1303

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1291

GoogleEPSS <= 49%HIGH2015-09-02

The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not check whether a node is expected, which allows remote attackers to bypass the Same Origin Policy or cause a den...

CVEs:CVE-2015-1291

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1299

GoogleEPSS <= 49%CRITICAL2015-09-02

Use-after-free vulnerability in the shared-timer implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging erroneous timer firing,...

CVEs:CVE-2015-1299

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1294

GoogleEPSS <= 49%CRITICAL2015-09-02

Use-after-free vulnerability in the SkMatrix::invertNonIdentity function in core/SkMatrix.cpp in Skia, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by trigg...

CVEs:CVE-2015-1294

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1295

GoogleEPSS <= 49%CRITICAL2015-09-02

Multiple use-after-free vulnerabilities in the PrintWebViewHelper class in components/printing/renderer/print_web_view_helper.cc in Google Chrome before 45.0.2454.85 allow user-assisted remote attackers to cause a denial of service or possibly have uns...

CVEs:CVE-2015-1295

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1292

GoogleEPSS <= 49%MEDIUM2015-09-02

The NavigatorServiceWorker::serviceWorker function in modules/serviceworkers/NavigatorServiceWorker.cpp in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy by accessing a Service Worker.

CVEs:CVE-2015-1292

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1293

GoogleEPSS <= 49%HIGH2015-09-02

The DOM implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

CVEs:CVE-2015-1293

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1296

GoogleEPSS <= 49%MEDIUM2015-09-02

The UnescapeURLWithAdjustmentsImpl implementation in net/base/escape.cc in Google Chrome before 45.0.2454.85 does not prevent display of Unicode LOCK characters in the omnibox, which makes it easier for remote attackers to spoof the SSL lock icon by pl...

CVEs:CVE-2015-1296

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1301

GoogleEPSS <= 49%HIGH2015-09-03

Multiple unspecified vulnerabilities in Google Chrome before 45.0.2454.85 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2015-1301

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6583

GoogleEPSS <= 49%MEDIUM2015-09-03

Google Chrome before 45.0.2454.85 does not display a location bar for a hosted app's window after navigation away from the installation site, which might make it easier for remote attackers to spoof content via a crafted app, related to browser.cc and ...

CVEs:CVE-2015-6583

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-1298

GoogleEPSS <= 49%MEDIUM2015-09-02

The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api.cc in Google Chrome before 45.0.2454.85 does not ensure that the setUninstallURL preference corresponds to the URL of a web site, which allows user-as...

CVEs:CVE-2015-1298

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6919

GoogleEPSS <= 49%CRITICAL2015-09-11

Cross-site scripting (XSS) vulnerability in the googleSearch (CSE) (com_googlesearch_cse) component 3.0.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the q parameter to index.php.

CVEs:CVE-2015-6919

Affected products

ProductStatusVendorPackageEcosystem
googlesearch affected googlesearch_project
Upstream advisory

CVE-2015-6582

GoogleEPSS <= 49%HIGH2015-09-03

The decompose function in platform/transforms/TransformationMatrix.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not verify that a matrix inversion succeeded, which allows remote attackers to cause a denial of service (uninitialized ...

CVEs:CVE-2015-6582

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6580

GoogleEPSS <= 49%HIGH2015-09-03

Multiple unspecified vulnerabilities in Google V8 before 4.5.103.29, as used in Google Chrome before 45.0.2454.85, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2015-6580

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
v8 affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.