Advisories
GoogleExploitedCISA KEV listedHIGH2016-01-13
Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Rem...
CVEs:CVE-2016-0034
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| silverlight |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2016-01-13
Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."
CVEs:CVE-2016-0034
Open SourceExploitedVulnCheck KEV listedHIGH2016-01-19
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-...
CVEs:CVE-2016-0728
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| server_migration_pack |
affected |
hp |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
Open SourceWeaponized exploitHIGH2016-01-05
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24446875.
CVEs:CVE-2015-6639
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceWeaponized exploit2016-01-27
chromium-browser - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser |
affected |
Debian:8 |
chromium-browser |
— |
Open SourceWeaponized exploitCRITICAL2016-01-29
Updated chromium-browser-stable packages fix security vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:5 |
chromium-browser-stable |
— |
GoogleWeaponized exploitHIGH2016-01-25
The LoadIC::UpdateCaches function in ic/ic.cc in Google V8, as used in Google Chrome before 48.0.2564.82, does not ensure receiver compatibility before performing a cast of an unspecified variable, which allows remote attackers to cause a denial of ser...
CVEs:CVE-2016-1612
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GooglePoC exploitCRITICAL2016-01-25
Recommended update for LibreOffice
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google-carlito-fonts |
affected |
SUSE:Linux Enterprise Software Development Kit 11 SP4 |
google-carlito-fonts |
— |
| google-carlito-fonts |
affected |
SUSE:Linux Enterprise Desktop 11 SP4 |
google-carlito-fonts |
— |
| hyphen |
affected |
SUSE:Linux Enterprise Software Development Kit 11 SP4 |
hyphen |
— |
| hyphen |
affected |
SUSE:Linux Enterprise Desktop 11 SP4 |
hyphen |
— |
| libreoffice |
affected |
SUSE:Linux Enterprise Software Development Kit 11 SP4 |
libreoffice |
— |
| libreoffice |
affected |
SUSE:Linux Enterprise Desktop 11 SP4 |
libreoffice |
— |
| libreoffice-share-linker |
affected |
SUSE:Linux Enterprise Software Development Kit 11 SP4 |
libreoffice-share-linker |
— |
| libreoffice-share-linker |
affected |
SUSE:Linux Enterprise Desktop 11 SP4 |
libreoffice-share-linker |
— |
| libreoffice-voikko |
affected |
SUSE:Linux Enterprise Software Development Kit 11 SP4 |
libreoffice-voikko |
— |
| libreoffice-voikko |
affected |
SUSE:Linux Enterprise Desktop 11 SP4 |
libreoffice-voikko |
— |
| libvoikko |
affected |
SUSE:Linux Enterprise Desktop 11 SP4 |
libvoikko |
— |
| libvoikko |
affected |
SUSE:Linux Enterprise Software Development Kit 11 SP4 |
libvoikko |
— |
| myspell-dictionaries |
affected |
SUSE:Linux Enterprise Software Development Kit 11 SP4 |
myspell-dictionaries |
— |
| myspell-dictionaries |
affected |
SUSE:Linux Enterprise Desktop 11 SP4 |
myspell-dictionaries |
— |
| mythes |
affected |
SUSE:Linux Enterprise Software Development Kit 11 SP4 |
mythes |
— |
| mythes |
affected |
SUSE:Linux Enterprise Desktop 11 SP4 |
mythes |
— |
| python-importlib |
affected |
SUSE:Linux Enterprise Software Development Kit 11 SP4 |
python-importlib |
— |
| python-importlib |
affected |
SUSE:Linux Enterprise Desktop 11 SP4 |
python-importlib |
— |
Open SourcePoC exploitHIGH2016-01-05
mediaserver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 25070493 and 24686670.
CVEs:CVE-2015-6636
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2016-01-05
The WNM Sleep Mode code in wpa_supplicant 2.x before 2.6 does not properly ignore key data in response frames when management frame protection (MFP) was not negotiated, which allows remote attackers to inject arbitrary broadcast or multicast packets or...
CVEs:CVE-2015-5310
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2016-01-25
Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting fr...
CVEs:CVE-2016-2052
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| harfbuzz |
affected |
harfbuzz_project |
— |
— |
Open SourcePoC exploitHIGH2016-01-05
Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.
CVEs:CVE-2015-6644
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2016-01-05
The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privileges or cause a denial of servi...
CVEs:CVE-2015-6640
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitCRITICAL2016-01-05
The kernel in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureO...
CVEs:CVE-2015-6642
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2016-01-05
The MediaTek misc-sd driver in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application, aka internal bug 25307013.
CVEs:CVE-2015-6637
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitCRITICAL2016-01-05
The System V IPC implementation in the kernel in Android before 6.0 2016-01-01 allows attackers to cause a denial of service (global kernel resource consumption) by leveraging improper interaction between IPC resource allocation and the memory manager,...
CVEs:CVE-2015-6646
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2016-01-05
The Imagination Technologies driver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application, aka internal bug 24673908.
CVEs:CVE-2015-6638
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitLOW2016-01-05
Bluetooth in Android 6.0 before 2016-01-01 allows remote attackers to obtain sensitive Contacts information by leveraging pairing, aka internal bug 23607427.
CVEs:CVE-2015-6641
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2016-01-05
SyncManager in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to cause a denial of service (continuous rebooting) via a crafted application, aka internal bug 23591205.
CVEs:CVE-2015-6645
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2016-01-05
Setup Wizard in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows physically proximate attackers to modify settings or bypass a reset protection mechanism via unspecified vectors, aka internal bug 25290269.
CVEs:CVE-2015-6643
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2016-01-27
The Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propagation and produces incorrect output, which makes it easier for attackers to obtain private RSA keys via unspecified vectors.
CVEs:CVE-2015-8618
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleEPSS <= 49%MEDIUM2016-01-25
The Omnibox implementation in Google Chrome before 48.0.2564.82 allows remote attackers to spoof a document's origin via unspecified vectors.
CVEs:CVE-2016-1615
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2016-01-25
Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified v...
CVEs:CVE-2016-1618
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2016-01-25
Multiple unspecified vulnerabilities in Google Chrome before 48.0.2564.82 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2016-1620
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2016-01-25
The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not appl...
CVEs:CVE-2016-1617
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2016-01-25
The CustomButton::AcceleratorPressed function in ui/views/controls/button/custom_button.cc in Google Chrome before 48.0.2564.82 allows remote attackers to spoof URLs via vectors involving an unfocused custom button.
CVEs:CVE-2016-1616
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2016-01-25
Multiple integer overflows in the (1) sycc422_to_rgb and (2) sycc444_to_rgb functions in fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 48.0.2564.82, allow remote attackers to cause a denial of service (out-of-bounds read...
CVEs:CVE-2016-1619
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2016-01-25
Multiple use-after-free vulnerabilities in the formfiller implementation in PDFium, as used in Google Chrome before 48.0.2564.82, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document, ...
CVEs:CVE-2016-1613
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2016-01-25
The UnacceleratedImageBufferSurface class in WebKit/Source/platform/graphics/UnacceleratedImageBufferSurface.cpp in Blink, as used in Google Chrome before 48.0.2564.82, mishandles the initialization mode, which allows remote attackers to obtain sensiti...
CVEs:CVE-2016-1614
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2016-01-25
Multiple unspecified vulnerabilities in Google V8 before 4.8.271.17, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVEs:CVE-2016-2051
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| enterprise_linux_desktop_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary |
affected |
redhat |
— |
— |
| enterprise_linux_server_supplementary_eus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation_supplementary |
affected |
redhat |
— |
— |
Open SourceEPSS <= 49%MEDIUM2016-01-27
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method.
CVEs:CVE-2016-1943
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| firefox |
affected |
mozilla |
— |
— |
| leap |
affected |
opensuse |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
Open SourceEPSS <= 49%HIGH2016-01-06
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24441554.
CVEs:CVE-2015-6647
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%MEDIUM2016-01-27
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via a data: URL that is mishandled during (1) shortcut opening or (2) BOOKMARK intent processing.
CVEs:CVE-2016-1940
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| firefox |
affected |
mozilla |
— |
— |
Open SourceEPSS <= 49%MEDIUM2016-01-27
Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attackers to replace a theme's images and colors by modifying the client-server data stream.
CVEs:CVE-2016-1948
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| firefox |
affected |
mozilla |
— |
— |