Google Security Advisories · December 2015 — Google Security Advisories
65 advisories 63 CVEs 4 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2015-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 4 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2015-8651

GoogleExploitedCISA KEV listedHIGH2015-12-28

Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0....

CVEs:CVE-2015-8651

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
evergreen affected opensuse
flash_player affected adobe
insight_control affected hp
insight_control_server_provisioning affected hp
linux_enterprise_desktop affected suse
linux_enterprise_workstation_extension affected suse
matrix_operating_environment affected hp
opensuse affected opensuse
system_management_homepage affected hp
systems_insight_manager affected hp
version_control_repository_manager affected hp
Upstream advisory

CVE-2015-8651

Project ZeroExploitedCISA KEV listed2015-12-28

Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.

CVEs:CVE-2015-8651

Upstream advisory

CVE-2015-6175

Project ZeroExploitedCISA KEV listed2015-12-09

The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability."

CVEs:CVE-2015-6175

Upstream advisory

CVE-2015-6175

GoogleExploitedCISA KEV listedHIGH2015-12-09

The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability."

CVEs:CVE-2015-6175

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
Upstream advisory

MGASA-2015-0467

Open SourceWeaponized exploitCRITICAL2015-12-09

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

CVE-2015-6787

GoogleWeaponized exploitHIGH2015-12-02

Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2015-6787

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-8664

GoogleWeaponized exploitCRITICAL2015-12-24

Integer overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Google Chrome before 47.0.2526.106 allows remote attackers to cause a denial of service or possibly have unspecified other impact via an RGBA pixel array ...

CVEs:CVE-2015-8664

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6634

Open SourcePoC exploitHIGH2015-12-08

The display drivers in Android before 5.1.1 LMY48Z allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 24163261.

CVEs:CVE-2015-6634

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6620

Open SourcePoC exploitHIGH2015-12-08

libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bugs 24123723 and 24445127.

CVEs:CVE-2015-6620

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6621

Open SourcePoC exploitHIGH2015-12-08

SystemUI in Android 5.x before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23909438.

CVEs:CVE-2015-6621

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6623

Open SourcePoC exploitHIGH2015-12-08

Wi-Fi in Android 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24872703.

CVEs:CVE-2015-6623

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6629

Open SourcePoC exploitHIGH2015-12-08

Wi-Fi in Android 5.x before 5.1.1 LMY48Z allows attackers to obtain sensitive information via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 22667667.

CVEs:CVE-2015-6629

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6624

Open SourcePoC exploitHIGH2015-12-08

System Server in Android 6.0 before 2015-12-01 allows attackers to obtain sensitive information via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23999740.

CVEs:CVE-2015-6624

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6625

Open SourcePoC exploitHIGH2015-12-08

System Server in Android 6.0 before 2015-12-01 allows attackers to obtain sensitive information and consequently gain privileges via a crafted application, aka internal bug 23936840.

CVEs:CVE-2015-6625

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6618

Open SourcePoC exploitCRITICAL2015-12-08

Bluetooth in Android 4.4 and 5.x before 5.1.1 LMY48Z allows user-assisted remote attackers to execute arbitrary code by leveraging access to the local physical environment, aka internal bug 24595992.

CVEs:CVE-2015-6618

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DSA-3415-1

Open SourceEPSS <= 49%2015-12-09

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:8 chromium-browser
Upstream advisory

CVE-2015-6764

GoogleEPSS <= 49%CRITICAL2015-12-02

The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (o...

CVEs:CVE-2015-6764

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
node.js affected nodejs
Upstream advisory

CVE-2015-6765

GoogleEPSS <= 49%HIGH2015-12-02

Use-after-free vulnerability in content/browser/appcache/appcache_update_job.cc in Google Chrome before 47.0.2526.73 allows remote attackers to execute arbitrary code or cause a denial of service by leveraging the mishandling of AppCache update jobs.

CVEs:CVE-2015-6765

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MGASA-2015-0479

Open SourceEPSS <= 49%2015-12-17

Updated chromium-browser-stable packages fix CVE-2015-6792

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

CVE-2015-6792

GoogleEPSS <= 49%HIGH2015-12-16

The MIDI subsystem in Google Chrome before 47.0.2526.106 does not properly handle the sending of data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, related to midi_man...

CVEs:CVE-2015-6792

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DSA-3418-1

Open SourceEPSS <= 49%2015-12-14

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:8 chromium-browser
Upstream advisory

MGASA-2015-0470

Open SourceEPSS <= 49%CRITICAL2015-12-10

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

CVE-2015-6788

GoogleEPSS <= 49%HIGH2015-12-09

The ObjectBackedNativeHandler class in extensions/renderer/object_backed_native_handler.cc in the extensions subsystem in Google Chrome before 47.0.2526.80 improperly implements handler functions, which allows remote attackers to cause a denial of serv...

CVEs:CVE-2015-6788

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6617

Open SourceEPSS <= 49%HIGH2015-12-08

Skia, as used in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23648740.

CVEs:CVE-2015-6617

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6771

GoogleEPSS <= 49%HIGH2015-12-02

js/array.js in Google V8, as used in Google Chrome before 47.0.2526.73, improperly implements certain map and filter operations for arrays, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspec...

CVEs:CVE-2015-6771

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6779

GoogleEPSS <= 49%MEDIUM2015-12-02

PDFium, as used in Google Chrome before 47.0.2526.73, does not properly restrict use of chrome: URLs, which allows remote attackers to bypass intended scheme restrictions via a crafted PDF document, as demonstrated by a document with a link to a chrome...

CVEs:CVE-2015-6779

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6775

GoogleEPSS <= 49%HIGH2015-12-02

fpdfsdk/src/jsapi/fxjs_v8.cpp in PDFium, as used in Google Chrome before 47.0.2526.73, does not use signatures, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusi...

CVEs:CVE-2015-6775

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-8507

Open SourceEPSS <= 49%HIGH2015-12-08

mediaserver in Android 6.0 before 2015-12-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 24157524, a different vulnerability than CVE-2015-6616, CVE-2015-...

CVEs:CVE-2015-8507

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6769

GoogleEPSS <= 49%CRITICAL2015-12-02

The provisional-load commit implementation in WebKit/Source/bindings/core/v8/WindowProxy.cpp in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy by leveraging a delay in window proxy clearing.

CVEs:CVE-2015-6769

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-8505

Open SourceEPSS <= 49%HIGH2015-12-08

mediaserver in Android before 5.1.1 LMY48Z allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 17769851, a different vulnerability than CVE-2015-6616, CVE-2015-85...

CVEs:CVE-2015-8505

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8506

Open SourceEPSS <= 49%HIGH2015-12-08

mediaserver in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 24441553, a different vulnerability than ...

CVEs:CVE-2015-8506

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6770

GoogleEPSS <= 49%HIGH2015-12-02

The DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, a different vulnerability than CVE-2015-6768.

CVEs:CVE-2015-6770

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6768

GoogleEPSS <= 49%HIGH2015-12-02

The DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, a different vulnerability than CVE-2015-6770.

CVEs:CVE-2015-6768

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6766

GoogleEPSS <= 49%CRITICAL2015-12-02

Use-after-free vulnerability in the AppCache implementation in Google Chrome before 47.0.2526.73 allows remote attackers with renderer access to cause a denial of service or possibly have unspecified other impact by leveraging incorrect AppCacheUpdateJ...

CVEs:CVE-2015-6766

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6767

GoogleEPSS <= 49%CRITICAL2015-12-02

Use-after-free vulnerability in content/browser/appcache/appcache_dispatcher_host.cc in the AppCache implementation in Google Chrome before 47.0.2526.73 allows remote attackers to cause a denial of service or possibly have unspecified other impact by l...

CVEs:CVE-2015-6767

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6616

Open SourceEPSS <= 49%HIGH2015-12-08

mediaserver in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 24630158 and 23882800, a different vulne...

CVEs:CVE-2015-6616

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6633

Open SourceEPSS <= 49%HIGH2015-12-08

The display drivers in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23987307.

CVEs:CVE-2015-6633

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6773

GoogleEPSS <= 49%HIGH2015-12-02

The convolution implementation in Skia, as used in Google Chrome before 47.0.2526.73, does not properly constrain row lengths, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other i...

CVEs:CVE-2015-6773

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6785

GoogleEPSS <= 49%CRITICAL2015-12-02

The CSPSource::hostMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Google Chrome before 47.0.2526.73 accepts an x.y hostname as a match for a *.x.y pattern, which might allow remote ...

CVEs:CVE-2015-6785

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6786

GoogleEPSS <= 49%CRITICAL2015-12-02

The CSPSourceList::matches function in WebKit/Source/core/frame/csp/CSPSourceList.cpp in the Content Security Policy (CSP) implementation in Google Chrome before 47.0.2526.73 accepts a blob:, data:, or filesystem: URL as a match for a * pattern, which ...

CVEs:CVE-2015-6786

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6789

GoogleEPSS <= 49%HIGH2015-12-09

Race condition in the MutationObserver implementation in Blink, as used in Google Chrome before 47.0.2526.80, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact by leveraging unanticipated ob...

CVEs:CVE-2015-6789

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6784

GoogleEPSS <= 49%MEDIUM2015-12-02

The page serializer in Google Chrome before 47.0.2526.73 mishandles Mark of the Web (MOTW) comments for URLs containing a "--" sequence, which might allow remote attackers to inject HTML via a crafted URL, as demonstrated by an initial http://example.c...

CVEs:CVE-2015-6784

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6778

GoogleEPSS <= 49%HIGH2015-12-02

The CJBig2_SymbolDict class in fxcodec/jbig2/JBig2_SymbolDict.cpp in PDFium, as used in Google Chrome before 47.0.2526.73, allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via ...

CVEs:CVE-2015-6778

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6772

GoogleEPSS <= 49%HIGH2015-12-02

The DOM implementation in Blink, as used in Google Chrome before 47.0.2526.73, does not prevent javascript: URL navigation while a document is being detached, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code th...

CVEs:CVE-2015-6772

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6781

GoogleEPSS <= 49%CRITICAL2015-12-02

Integer overflow in the FontData::Bound function in data/font_data.cc in Google sfntly, as used in Google Chrome before 47.0.2526.73, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted offset or...

CVEs:CVE-2015-6781

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6791

GoogleEPSS <= 49%HIGH2015-12-09

Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.80 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2015-6791

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6777

GoogleEPSS <= 49%CRITICAL2015-12-02

Use-after-free vulnerability in the ContainerNode::notifyNodeInsertedInternal function in WebKit/Source/core/dom/ContainerNode.cpp in the DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to cause a denial of service or po...

CVEs:CVE-2015-6777

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6774

GoogleEPSS <= 49%CRITICAL2015-12-02

Use-after-free vulnerability in the GetLoadTimes function in renderer/loadtimes_extension_bindings.cc in the Extensions implementation in Google Chrome before 47.0.2526.73 allows remote attackers to cause a denial of service or possibly have unspecifie...

CVEs:CVE-2015-6774

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6776

GoogleEPSS <= 49%HIGH2015-12-02

The opj_dwt_decode_1* functions in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 47.0.2526.73, allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG 20...

CVEs:CVE-2015-6776

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6790

GoogleEPSS <= 49%CRITICAL2015-12-09

The WebPageSerializerImpl::openTagToString function in WebKit/Source/web/WebPageSerializerImpl.cpp in the page serializer in Google Chrome before 47.0.2526.80 does not properly use HTML entities, which might allow remote attackers to inject arbitrary w...

CVEs:CVE-2015-6790

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-8480

GoogleEPSS <= 49%HIGH2015-12-06

The VideoFramePool::PoolImpl::CreateFrame function in media/base/video_frame_pool.cc in Google Chrome before 47.0.2526.73 does not initialize memory for a video-frame data structure, which might allow remote attackers to cause a denial of service (out-...

CVEs:CVE-2015-8480

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6783

Open SourceEPSS <= 49%MEDIUM2015-12-02

The FindStartOffsetOfFileInZipFile function in crazy_linker_zip.cpp in crazy_linker (aka Crazy Linker) in Android 5.x and 6.x, as used in Google Chrome before 47.0.2526.73, improperly searches for an EOCD record, which allows attackers to bypass a sign...

CVEs:CVE-2015-6783

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8548

GoogleEPSS <= 49%HIGH2015-12-14

Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before 47.0.2526.80, allow attackers to cause a denial of service or possibly have other impact via unknown vectors, a different issue than CVE-2015-8478.

CVEs:CVE-2015-8548

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
v8 affected google
Upstream advisory

CVE-2015-6780

GoogleEPSS <= 49%CRITICAL2015-12-02

Use-after-free vulnerability in the Infobars implementation in Google Chrome before 47.0.2526.73 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site, related to browser/ui/views/website_...

CVEs:CVE-2015-6780

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6782

GoogleEPSS <= 49%CRITICAL2015-12-02

The Document::open function in WebKit/Source/core/dom/Document.cpp in Google Chrome before 47.0.2526.73 does not ensure that page-dismissal event handling is compatible with modal-dialog blocking, which makes it easier for remote attackers to spoof Omn...

CVEs:CVE-2015-6782

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6631

Open SourceEPSS <= 49%HIGH2015-12-08

libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or...

CVEs:CVE-2015-6631

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6619

Open SourceEPSS <= 49%HIGH2015-12-08

The kernel in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, aka internal bug 23520714.

CVEs:CVE-2015-6619

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6632

Open SourceEPSS <= 49%HIGH2015-12-08

libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or...

CVEs:CVE-2015-6632

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6626

Open SourceEPSS <= 49%HIGH2015-12-08

libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or...

CVEs:CVE-2015-6626

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8478

GoogleEPSS <= 49%HIGH2015-12-06

Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before 47.0.2526.73, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2015-8478

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
v8 affected google
Upstream advisory

CVE-2015-8479

GoogleEPSS <= 49%CRITICAL2015-12-06

Use-after-free vulnerability in the AudioOutputDevice::OnDeviceAuthorized function in media/audio/audio_output_device.cc in Google Chrome before 47.0.2526.73 allows attackers to cause a denial of service (heap memory corruption) or possibly have unspec...

CVEs:CVE-2015-8479

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2015-6627

Open SourceEPSS <= 49%HIGH2015-12-08

The Audio component in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to obtain sensitive information via a crafted audio file, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24211743.

CVEs:CVE-2015-6627

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6622

Open SourceEPSS <= 49%HIGH2015-12-08

The Native Frameworks Library in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Sign...

CVEs:CVE-2015-6622

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6628

Open SourceEPSS <= 49%HIGH2015-12-08

Media Framework in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or Signa...

CVEs:CVE-2015-6628

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6630

Open SourceEPSS <= 49%MEDIUM2015-12-08

SystemUI in Android 5.x before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to read screenshots and consequently gain privileges via a crafted application, aka internal bug 19121797.

CVEs:CVE-2015-6630

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.