Google Security Advisories · October 2015 — Google Security Advisories
74 advisories 72 CVEs 5 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2015-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 5 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2015-3864

Open SourceExploitedCISA KEV listedHIGH2015-10-01

Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted MPEG-4 data, aka internal bug 23034759. NO...

CVEs:CVE-2015-3864

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-7645

Project ZeroExploitedCISA KEV listed2015-10-14

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.

CVEs:CVE-2015-7645

Upstream advisory

CVE-2015-7645

GoogleExploitedCISA KEV listedHIGH2015-10-14

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.

CVEs:CVE-2015-7645

Affected products

ProductStatusVendorPackageEcosystem
enterprise_linux_desktop affected redhat
enterprise_linux_eus affected redhat
enterprise_linux_server affected redhat
enterprise_linux_server_from_rhui affected redhat
enterprise_linux_workstation affected redhat
evergreen affected opensuse
flash_player affected adobe
linux_enterprise_desktop affected suse
linux_enterprise_workstation_extension affected suse
opensuse affected opensuse
Upstream advisory

CVE-2015-4902

GoogleExploitedCISA KEV listedMEDIUM2015-10-21

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.

CVEs:CVE-2015-4902

Affected products

ProductStatusVendorPackageEcosystem
enterprise_linux_desktop affected redhat
enterprise_linux_eus affected redhat
enterprise_linux_eus_compute_node affected redhat
enterprise_linux_for_ibm_z_systems affected redhat
enterprise_linux_for_ibm_z_systems_eus affected redhat
enterprise_linux_for_power_big_endian affected redhat
enterprise_linux_for_power_big_endian_eus affected redhat
enterprise_linux_for_power_little_endian affected redhat
enterprise_linux_for_power_little_endian_eus affected redhat
enterprise_linux_for_scientific_computing affected redhat
enterprise_linux_server affected redhat
enterprise_linux_server_from_rhui affected redhat
enterprise_linux_workstation affected redhat
jdk affected oracle
jre affected oracle
leap affected opensuse
linux_enterprise_module_for_legacy affected suse
linux_enterprise_server affected suse
linux_enterprise_software_development_kit affected suse
opensuse affected opensuse
satellite affected redhat
Upstream advisory

CVE-2015-4902

Project ZeroExploitedCISA KEV listed2015-10-21

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.

CVEs:CVE-2015-4902

Upstream advisory

MGASA-2015-0410

Open SourceWeaponized exploitHIGH2015-10-25

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

DSA-3376-1

Open SourceWeaponized exploit2015-10-20

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:8 chromium-browser
Upstream advisory

CVE-2015-6763

GoogleWeaponized exploitHIGH2015-10-14

Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2015-6763

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-7889

Open SourceActive exploitation (sightings)HIGH2015-10-28

The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions for the com.samsung.android.email.intent.action.QUICK_REPLY_BACKGROUND service action, which might allow remote attackers with knowle...

CVEs:CVE-2015-7889

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2015-3875

Open SourceActive exploitation (sightings)CRITICAL2015-10-06

DEBIAN-CVE-2015-3875

Affected products

ProductStatusVendorPackageEcosystem
android-platform-frameworks-native affected Debian:11 android-platform-frameworks-native
android-platform-frameworks-native affected Debian:12 android-platform-frameworks-native
Upstream advisory

CVE-2015-3875

Open SourceActive exploitation (sightings)HIGH2015-10-06

libutils in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted audio file, aka internal bug 22952485.

CVEs:CVE-2015-3875

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2015-6602

Open SourcePoC exploitCRITICAL2015-10-02

DEBIAN-CVE-2015-6602

Affected products

ProductStatusVendorPackageEcosystem
android-platform-frameworks-native affected Debian:11 android-platform-frameworks-native
android-platform-frameworks-native affected Debian:12 android-platform-frameworks-native
Upstream advisory

CVE-2015-6602

Open SourcePoC exploitHIGH2015-10-02

libutils in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file, as demonstrated by an attack against use of libutils by libstagefright in Android 5.x.

CVEs:CVE-2015-6602

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3876

Open SourcePoC exploitHIGH2015-10-02

libstagefright in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file.

CVEs:CVE-2015-3876

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-1528

Open SourcePoC exploitHIGH2015-10-01

Integer overflow in the native_handle_create function in libcutils/native_handle.c in Android before 5.1.1 LMY48M allows attackers to obtain a different application's privileges or cause a denial of service (Binder heap memory corruption) via a crafted...

CVEs:CVE-2015-1528

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3868

Open SourcePoC exploitHIGH2015-10-06

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23270724.

CVEs:CVE-2015-3868

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3823

Open SourcePoC exploitHIGH2015-10-06

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 21335999.

CVEs:CVE-2015-3823

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3869

Open SourcePoC exploitHIGH2015-10-06

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23036083.

CVEs:CVE-2015-3869

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3870

Open SourcePoC exploitHIGH2015-10-06

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 22771132.

CVEs:CVE-2015-3870

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3873

Open SourcePoC exploitHIGH2015-10-06

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 23016072, 23248776, 23247055, 22845824, 22008959, 21814993, 210...

CVEs:CVE-2015-3873

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6604

Open SourcePoC exploitHIGH2015-10-06

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23129786.

CVEs:CVE-2015-6604

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3867

Open SourcePoC exploitHIGH2015-10-06

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23213430.

CVEs:CVE-2015-3867

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3871

Open SourcePoC exploitHIGH2015-10-06

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23031033.

CVEs:CVE-2015-3871

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3872

Open SourcePoC exploitHIGH2015-10-06

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23346388.

CVEs:CVE-2015-3872

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6598

Open SourcePoC exploitHIGH2015-10-06

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23306638.

CVEs:CVE-2015-6598

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6599

Open SourcePoC exploitHIGH2015-10-06

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23416608.

CVEs:CVE-2015-6599

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6601

Open SourcePoC exploitHIGH2015-10-06

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 22935234.

CVEs:CVE-2015-6601

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3874

Open SourcePoC exploitHIGH2015-10-06

The Sonivox components in Android before 5.1.1 LMY48T allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 23335715, 23307276, and 23286323.

CVEs:CVE-2015-3874

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3877

Open SourcePoC exploitHIGH2015-10-06

Skia, as used in Android before 5.1.1 LMY48T, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 20723696.

CVEs:CVE-2015-3877

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6600

Open SourcePoC exploitHIGH2015-10-06

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 22882938.

CVEs:CVE-2015-6600

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3837

Open SourcePoC exploitHIGH2015-10-01

The OpenSSLX509Certificate class in org/conscrypt/OpenSSLX509Certificate.java in Android before 5.1.1 LMY48I improperly includes certain context data during serialization and deserialization, which allows attackers to execute arbitrary code via an appl...

CVEs:CVE-2015-3837

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3863

Open SourcePoC exploitHIGH2015-10-01

Multiple integer overflows in the Blob class in keystore/keystore.cpp in Keystore in Android before 5.1.1 LMY48M allow attackers to execute arbitrary code and read arbitrary Keystore keys via an application that uses a crafted blob in an insert operati...

CVEs:CVE-2015-3863

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3878

Open SourcePoC exploitMEDIUM2015-10-06

Media Projection in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to bypass an intended screen-recording warning feature and obtain sensitive screen-snapshot information via a crafted application that references a long appl...

CVEs:CVE-2015-3878

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6606

Open SourcePoC exploitHIGH2015-10-06

The Secure Element Evaluation Kit (aka SEEK or SmartCard API) plugin in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 2230...

CVEs:CVE-2015-6606

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3865

Open SourcePoC exploitHIGH2015-10-06

The Runtime subsystem in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23050463.

CVEs:CVE-2015-3865

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3879

Open SourcePoC exploitHIGH2015-10-06

Media Player Framework in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, aka internal bug 23223325.

CVEs:CVE-2015-3879

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6596

Open SourcePoC exploitHIGH2015-10-06

mediaserver in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, aka internal bugs 20731946 and 20719651, a different vulnerability than CVE-2015-7717.

CVEs:CVE-2015-6596

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6605

Open SourcePoC exploitHIGH2015-10-06

mediaserver in Android before 5.1.1 LMY48T allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bugs 20915134 and 23142203, a different vulnerability than CVE-2015-7718.

CVEs:CVE-2015-6605

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3862

Open SourcePoC exploitHIGH2015-10-06

mediaserver in Android before 5.1.1 LMY48T allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bug 22954006.

CVEs:CVE-2015-3862

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3847

Open SourcePoC exploitMEDIUM2015-10-06

Bluetooth in Android before 5.1.1 LMY48T allows attackers to remove stored SMS messages via a crafted application, aka internal bug 22343270.

CVEs:CVE-2015-3847

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3832

Open SourceEPSS <= 49%HIGH2015-10-01

Multiple buffer overflows in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I allow remote attackers to execute arbitrary code via invalid size values of NAL units in MP4 data, aka internal bug 19641538.

CVEs:CVE-2015-3832

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3836

Open SourceEPSS <= 49%HIGH2015-10-01

The Parse_wave function in arm-wt-22k/lib_src/eas_mdls.c in the Sonivox DLS-to-EAS converter in Android before 5.1.1 LMY48I does not reject a negative value for a certain size field, which allows remote attackers to execute arbitrary code or cause a de...

CVEs:CVE-2015-3836

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6575

Open SourceEPSS <= 49%HIGH2015-10-01

SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I does not properly consider integer promotion, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow and memory corruption) via crafted ato...

CVEs:CVE-2015-6575

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6755

GoogleEPSS <= 49%HIGH2015-10-14

The ContainerNode::parserInsertBefore function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 46.0.2490.71, proceeds with a DOM tree insertion in certain cases where a parent node no longer contains a child node, which allows r...

CVEs:CVE-2015-6755

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6603

Open SourceEPSS <= 49%HIGH2015-10-06

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23227354.

CVEs:CVE-2015-6603

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-7716

Open SourceEPSS <= 49%HIGH2015-10-06

libstagefright in Android 5.x before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 20721050, a different vulnerability than CVE-2015-3873.

CVEs:CVE-2015-7716

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3835

Open SourceEPSS <= 49%HIGH2015-10-01

Buffer overflow in the OMXNodeInstance::emptyBuffer function in omx/OMXNodeInstance.cpp in libstagefright in Android before 5.1.1 LMY48I allows attackers to execute arbitrary code via a crafted application, aka internal bug 20634516.

CVEs:CVE-2015-3835

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MGASA-2015-0389

Open SourceEPSS <= 49%NONE2015-10-03

Updated chromium-browser packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

CVE-2015-6757

GoogleEPSS <= 49%CRITICAL2015-10-14

Use-after-free vulnerability in content/browser/service_worker/embedded_worker_instance.cc in the ServiceWorker implementation in Google Chrome before 46.0.2490.71 allows remote attackers to cause a denial of service or possibly have unspecified other ...

CVEs:CVE-2015-6757

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6762

GoogleEPSS <= 49%HIGH2015-10-14

The CSSFontFaceSrcValue::fetch function in core/css/CSSFontFaceSrcValue.cpp in the Cascading Style Sheets (CSS) implementation in Blink, as used in Google Chrome before 46.0.2490.71, does not use the CORS cross-origin request algorithm when a font's UR...

CVEs:CVE-2015-6762

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-3843

Open SourceEPSS <= 49%HIGH2015-10-01

The SIM Toolkit (STK) framework in Android before 5.1.1 LMY48I allows attackers to (1) intercept or (2) emulate unspecified Telephony STK SIM commands via an application that sends a crafted Intent, related to com/android/internal/telephony/cat/AppInte...

CVEs:CVE-2015-3843

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3849

Open SourceEPSS <= 49%HIGH2015-10-01

The Region_createFromParcel function in core/jni/android/graphics/Region.cpp in Region in Android before 5.1.1 LMY48M does not check the return values of certain read operations, which allows attackers to execute arbitrary code via an application that ...

CVEs:CVE-2015-3849

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3831

Open SourceEPSS <= 49%HIGH2015-10-01

Buffer overflow in the readAt function in BpMediaHTTPConnection in media/libmedia/IMediaHTTPConnection.cpp in the mediaserver service in Android before 5.1.1 LMY48I allows attackers to execute arbitrary code via a crafted application, aka internal bug ...

CVEs:CVE-2015-3831

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3842

Open SourceEPSS <= 49%HIGH2015-10-01

Multiple heap-based buffer overflows in libeffects in the Audio Policy Service in mediaserver in Android before 5.1.1 LMY48I allow attackers to execute arbitrary code via a crafted application, aka internal bug 21953516.

CVEs:CVE-2015-3842

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6758

GoogleEPSS <= 49%HIGH2015-10-14

The CPDF_Document::GetPage function in fpdfapi/fpdf_parser/fpdf_parser_document.cpp in PDFium, as used in Google Chrome before 46.0.2490.71, does not properly perform a cast of a dictionary object, which allows remote attackers to cause a denial of ser...

CVEs:CVE-2015-6758

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6759

GoogleEPSS <= 49%CRITICAL2015-10-14

The shouldTreatAsUniqueOrigin function in platform/weborigin/SecurityOrigin.cpp in Blink, as used in Google Chrome before 46.0.2490.71, does not ensure that the origin of a LocalStorage resource is considered unique, which allows remote attackers to ob...

CVEs:CVE-2015-6759

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6760

GoogleEPSS <= 49%HIGH2015-10-14

The Image11::map function in renderer/d3d/d3d11/Image11.cpp in libANGLE, as used in Google Chrome before 46.0.2490.71, mishandles mapping failures after device-lost events, which allows remote attackers to cause a denial of service (invalid read or wri...

CVEs:CVE-2015-6760

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6756

GoogleEPSS <= 49%CRITICAL2015-10-14

Use-after-free vulnerability in the CPDFSDK_PageView implementation in fpdfsdk/src/fsdk_mgr.cpp in PDFium, as used in Google Chrome before 46.0.2490.71, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unsp...

CVEs:CVE-2015-6756

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-3834

Open SourceEPSS <= 49%HIGH2015-10-01

Multiple integer overflows in the BnHDCP::onTransact function in media/libmedia/IHDCP.cpp in libstagefright in Android before 5.1.1 LMY48I allow attackers to execute arbitrary code via a crafted application that uses HDCP encryption, leading to a heap-...

CVEs:CVE-2015-3834

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6761

GoogleEPSS <= 49%CRITICAL2015-10-14

The update_dimensions function in libavcodec/vp8.c in FFmpeg through 2.8.1, as used in Google Chrome before 46.0.2490.71 and other products, relies on a coefficient-partition count during multi-threaded operation, which allows remote attackers to cause...

CVEs:CVE-2015-6761

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
ffmpeg affected ffmpeg
Upstream advisory

CVE-2015-7834

GoogleEPSS <= 49%HIGH2015-10-15

Multiple unspecified vulnerabilities in Google V8 before 4.6.85.23, as used in Google Chrome before 46.0.2490.71, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2015-7834

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
v8 affected google
Upstream advisory

CVE-2015-3861

Open SourceEPSS <= 49%CRITICAL2015-10-01

Multiple integer overflows in the addVorbisCodecInfo function in matroska/MatroskaExtractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allow remote attackers to cause a denial of service (device inoperability) via crafted Matro...

CVEs:CVE-2015-3861

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3833

Open SourceEPSS <= 49%MEDIUM2015-10-01

The getRunningAppProcesses function in services/core/java/com/android/server/am/ActivityManagerService.java in Android before 5.1.1 LMY48I allows attackers to bypass intended getRecentTasks restrictions and discover the name of the foreground applicati...

CVEs:CVE-2015-3833

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3858

Open SourceEPSS <= 49%HIGH2015-10-01

The checkDestination function in internal/telephony/SMSDispatcher.java in Android before 5.1.1 LMY48M relies on an obsolete permission name for an authorization check, which allows attackers to bypass an intended user-confirmation requirement for SMS s...

CVEs:CVE-2015-3858

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-1536

Open SourceEPSS <= 49%CRITICAL2015-10-01

Integer overflow in the Bitmap_createFromParcel function in core/jni/android/graphics/Bitmap.cpp in Android before 5.1.1 LMY48I allows attackers to cause a denial of service (system_server crash) or obtain sensitive system_server memory-content informa...

CVEs:CVE-2015-1536

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-7915

Open SourceEPSS <= 49%HIGH2015-10-01

Integer overflow in SampleTable.cpp in libstagefright in Android before 5.0.0 has unspecified impact and attack vectors, aka internal bug 15328708.

CVEs:CVE-2014-7915

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-7916

Open SourceEPSS <= 49%HIGH2015-10-01

Integer overflow in SampleTable.cpp in libstagefright in Android before 5.0.0 has unspecified impact and attack vectors, aka internal bug 15342751.

CVEs:CVE-2014-7916

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-7917

Open SourceEPSS <= 49%HIGH2015-10-01

Integer overflow in SampleTable.cpp in libstagefright in Android before 5.0.0 has unspecified impact and attack vectors, aka internal bug 15342615.

CVEs:CVE-2014-7917

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-7717

Open SourceEPSS <= 49%HIGH2015-10-06

mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 19573085, a different vulnerability than CVE-2015-6596.

CVEs:CVE-2015-7717

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3845

Open SourceEPSS <= 49%CRITICAL2015-10-01

The Parcel::appendFrom function in libs/binder/Parcel.cpp in Binder in Android before 5.1.1 LMY48M does not consider parcel boundaries during identification of binder objects in an append operation, which allows attackers to obtain a different applicat...

CVEs:CVE-2015-3845

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3844

Open SourceEPSS <= 49%MEDIUM2015-10-01

The getProcessRecordLocked method in services/core/java/com/android/server/am/ActivityManagerService.java in ActivityManager in Android before 5.1.1 LMY48I allows attackers to trigger incorrect process loading via a crafted application, as demonstrated...

CVEs:CVE-2015-3844

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-1541

Open SourceEPSS <= 49%MEDIUM2015-10-01

The AppWidgetServiceImpl implementation in com/android/server/appwidget/AppWidgetServiceImpl.java in the Settings application in Android before 5.1.1 LMY48I allows attackers to obtain a URI permission via an application that sends an Intent with a (1) ...

CVEs:CVE-2015-1541

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-7718

Open SourceEPSS <= 49%HIGH2015-10-06

mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bug 22278703, a different vulnerability than CVE-2015-6605.

CVEs:CVE-2015-7718

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3860

Open SourceEPSS <= 49%HIGH2015-10-01

packages/Keyguard/res/layout/keyguard_password_view.xml in Lockscreen in Android 5.x before 5.1.1 LMY48M does not restrict the number of characters in the passwordEntry input field, which allows physically proximate attackers to bypass intended access ...

CVEs:CVE-2015-3860

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.