Google Security Advisories · November 2015 — Google Security Advisories
30 advisories 16 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2015-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2015-6612

Open SourcePoC exploitHIGH2015-11-03

libmedia in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privileges via a crafted application, aka internal bug 23540426.

CVEs:CVE-2015-6612

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2015-6609

Open SourcePoC exploitCRITICAL2015-11-03

DEBIAN-CVE-2015-6609

Affected products

ProductStatusVendorPackageEcosystem
android-platform-frameworks-native affected Debian:11 android-platform-frameworks-native
android-platform-frameworks-native affected Debian:12 android-platform-frameworks-native
Upstream advisory

CVE-2015-6609

Open SourcePoC exploitHIGH2015-11-03

libutils in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted audio file, aka internal bug 22953624.

CVEs:CVE-2015-6609

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6613

Open SourcePoC exploitMEDIUM2015-11-03

Bluetooth in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to send commands to a debugging port, and consequently gain privileges, via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, a...

CVEs:CVE-2015-6613

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6614

Open SourcePoC exploitHIGH2015-11-03

Telephony in Android 5.x before 5.1.1 LMY48X allows attackers to gain privileges, and consequently bypass intended network-interface restrictions, perform expensive data transfers, or cause a denial of service (call-reception outage or mute manipulatio...

CVEs:CVE-2015-6614

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8096

GoogleEPSS <= 49%HIGH2015-11-09

Integer overflow in Google Picasa 3.9.140 Build 239 and Build 248 allows remote attackers to execute arbitrary code via unspecified vectors related to "phase one 0x412 tag," which triggers a heap-based buffer overflow.

CVEs:CVE-2015-8096

Affected products

ProductStatusVendorPackageEcosystem
picasa affected google
Upstream advisory

CVE-2015-8221

GoogleEPSS <= 49%HIGH2015-11-17

Integer overflow in Google Picasa before 3.9.140 Build 259 allows remote attackers to execute arbitrary code via the CAMF section in a FOVb image, which triggers a heap-based buffer overflow.

CVEs:CVE-2015-8221

Affected products

ProductStatusVendorPackageEcosystem
picasa affected google
Upstream advisory

CVE-2015-6608

Open SourceEPSS <= 49%HIGH2015-11-03

mediaserver in Android 5.x before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 19779574, 23680780, 23876444, and 23...

CVEs:CVE-2015-6608

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8072

Open SourceEPSS <= 49%HIGH2015-11-03

mediaserver in Android 4.4 through 5.x before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23881715, a different vul...

CVEs:CVE-2015-8072

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8073

Open SourceEPSS <= 49%HIGH2015-11-03

mediaserver in Android 4.4 and 5.1 before 5.1.1 LMY48X allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 14388161, a different vulnerability than CVE-2015-6608 ...

CVEs:CVE-2015-8073

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MGASA-2015-0448

Open SourceEPSS <= 49%NONE2015-11-16

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

CVE-2015-1302

GoogleEPSS <= 49%HIGH2015-11-11

The PDF viewer in Google Chrome before 46.0.2490.86 does not properly restrict scripting messages and API exposure, which allows remote attackers to bypass the Same Origin Policy via an unintended embedder or unintended plugin loading, related to pdf.j...

CVEs:CVE-2015-1302

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-5305

GoogleEPSS <= 49%HIGH2015-11-06

Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows attackers to write to arbitrary files via a crafted object type name, which is not properly handled before passing it to etcd.

CVEs:CVE-2015-5305

Affected products

ProductStatusVendorPackageEcosystem
openshift affected redhat
Upstream advisory

CVE-2015-5305

Open SourceEPSS <= 49%MEDIUM2015-11-06

Directory Traversal in Kubernetes

CVEs:CVE-2015-5305

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

CVE-2015-6611

Open SourceEPSS <= 49%HIGH2015-11-03

mediaserver in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, aka internal bugs 23905951, 23912202, 239539...

CVEs:CVE-2015-6611

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8074

Open SourceEPSS <= 49%HIGH2015-11-03

mediaserver in Android before 5.1.1 LMY48X allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, aka internal bugs 23540907 and 23515142, a different vulnerability tha...

CVEs:CVE-2015-8074

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6610

Open SourceEPSS <= 49%HIGH2015-11-03

libstagefright in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka internal bug 23707088.

CVEs:CVE-2015-6610

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.