Google Security Advisories · January 2016 — Google Security Advisories
34 advisories 33 CVEs 3 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2016-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 3 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2016-0034

GoogleExploitedCISA KEV listedHIGH2016-01-13

Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Rem...

CVEs:CVE-2016-0034

Affected products

ProductStatusVendorPackageEcosystem
silverlight affected microsoft
Upstream advisory

CVE-2016-0034

Project ZeroExploitedCISA KEV listed2016-01-13

Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."

CVEs:CVE-2016-0034

Upstream advisory

CVE-2016-0728

Open SourceExploitedVulnCheck KEV listedHIGH2016-01-19

The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-...

CVEs:CVE-2016-0728

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
linux_kernel affected linux
server_migration_pack affected hp
ubuntu_linux affected canonical
Upstream advisory

CVE-2015-6639

Open SourceWeaponized exploitHIGH2016-01-05

The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24446875.

CVEs:CVE-2015-6639

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DSA-3456-1

Open SourceWeaponized exploit2016-01-27

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:8 chromium-browser
Upstream advisory

MGASA-2016-0042

Open SourceWeaponized exploitCRITICAL2016-01-29

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

CVE-2016-1612

GoogleWeaponized exploitHIGH2016-01-25

The LoadIC::UpdateCaches function in ic/ic.cc in Google V8, as used in Google Chrome before 48.0.2564.82, does not ensure receiver compatibility before performing a cast of an unspecified variable, which allows remote attackers to cause a denial of ser...

CVEs:CVE-2016-1612

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

SUSE-SU-2016:0324-1

GooglePoC exploitCRITICAL2016-01-25

Recommended update for LibreOffice

Affected products

ProductStatusVendorPackageEcosystem
google-carlito-fonts affected SUSE:Linux Enterprise Software Development Kit 11 SP4 google-carlito-fonts
google-carlito-fonts affected SUSE:Linux Enterprise Desktop 11 SP4 google-carlito-fonts
hyphen affected SUSE:Linux Enterprise Software Development Kit 11 SP4 hyphen
hyphen affected SUSE:Linux Enterprise Desktop 11 SP4 hyphen
libreoffice affected SUSE:Linux Enterprise Software Development Kit 11 SP4 libreoffice
libreoffice affected SUSE:Linux Enterprise Desktop 11 SP4 libreoffice
libreoffice-share-linker affected SUSE:Linux Enterprise Software Development Kit 11 SP4 libreoffice-share-linker
libreoffice-share-linker affected SUSE:Linux Enterprise Desktop 11 SP4 libreoffice-share-linker
libreoffice-voikko affected SUSE:Linux Enterprise Software Development Kit 11 SP4 libreoffice-voikko
libreoffice-voikko affected SUSE:Linux Enterprise Desktop 11 SP4 libreoffice-voikko
libvoikko affected SUSE:Linux Enterprise Desktop 11 SP4 libvoikko
libvoikko affected SUSE:Linux Enterprise Software Development Kit 11 SP4 libvoikko
myspell-dictionaries affected SUSE:Linux Enterprise Software Development Kit 11 SP4 myspell-dictionaries
myspell-dictionaries affected SUSE:Linux Enterprise Desktop 11 SP4 myspell-dictionaries
mythes affected SUSE:Linux Enterprise Software Development Kit 11 SP4 mythes
mythes affected SUSE:Linux Enterprise Desktop 11 SP4 mythes
python-importlib affected SUSE:Linux Enterprise Software Development Kit 11 SP4 python-importlib
python-importlib affected SUSE:Linux Enterprise Desktop 11 SP4 python-importlib
Upstream advisory

CVE-2015-6636

Open SourcePoC exploitHIGH2016-01-05

mediaserver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 25070493 and 24686670.

CVEs:CVE-2015-6636

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-5310

Open SourcePoC exploitHIGH2016-01-05

The WNM Sleep Mode code in wpa_supplicant 2.x before 2.6 does not properly ignore key data in response frames when management frame protection (MFP) was not negotiated, which allows remote attackers to inject arbitrary broadcast or multicast packets or...

CVEs:CVE-2015-5310

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2052

GooglePoC exploitHIGH2016-01-25

Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting fr...

CVEs:CVE-2016-2052

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
harfbuzz affected harfbuzz_project
Upstream advisory

CVE-2015-6644

Open SourcePoC exploitHIGH2016-01-05

Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.

CVEs:CVE-2015-6644

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6640

Open SourcePoC exploitHIGH2016-01-05

The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privileges or cause a denial of servi...

CVEs:CVE-2015-6640

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6642

Open SourcePoC exploitCRITICAL2016-01-05

The kernel in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureO...

CVEs:CVE-2015-6642

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6637

Open SourcePoC exploitHIGH2016-01-05

The MediaTek misc-sd driver in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application, aka internal bug 25307013.

CVEs:CVE-2015-6637

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6646

Open SourcePoC exploitCRITICAL2016-01-05

The System V IPC implementation in the kernel in Android before 6.0 2016-01-01 allows attackers to cause a denial of service (global kernel resource consumption) by leveraging improper interaction between IPC resource allocation and the memory manager,...

CVEs:CVE-2015-6646

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6638

Open SourcePoC exploitHIGH2016-01-05

The Imagination Technologies driver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application, aka internal bug 24673908.

CVEs:CVE-2015-6638

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6641

Open SourcePoC exploitLOW2016-01-05

Bluetooth in Android 6.0 before 2016-01-01 allows remote attackers to obtain sensitive Contacts information by leveraging pairing, aka internal bug 23607427.

CVEs:CVE-2015-6641

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6645

Open SourcePoC exploitHIGH2016-01-05

SyncManager in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to cause a denial of service (continuous rebooting) via a crafted application, aka internal bug 23591205.

CVEs:CVE-2015-6645

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-6643

Open SourcePoC exploitHIGH2016-01-05

Setup Wizard in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows physically proximate attackers to modify settings or bypass a reset protection mechanism via unspecified vectors, aka internal bug 25290269.

CVEs:CVE-2015-6643

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8618

GoogleEPSS <= 49%HIGH2016-01-27

The Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propagation and produces incorrect output, which makes it easier for attackers to obtain private RSA keys via unspecified vectors.

CVEs:CVE-2015-8618

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
leap affected opensuse
Upstream advisory

CVE-2016-1615

GoogleEPSS <= 49%MEDIUM2016-01-25

The Omnibox implementation in Google Chrome before 48.0.2564.82 allows remote attackers to spoof a document's origin via unspecified vectors.

CVEs:CVE-2016-1615

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1618

GoogleEPSS <= 49%MEDIUM2016-01-25

Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified v...

CVEs:CVE-2016-1618

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1620

GoogleEPSS <= 49%HIGH2016-01-25

Multiple unspecified vulnerabilities in Google Chrome before 48.0.2564.82 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2016-1620

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1617

GoogleEPSS <= 49%CRITICAL2016-01-25

The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not appl...

CVEs:CVE-2016-1617

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1616

GoogleEPSS <= 49%MEDIUM2016-01-25

The CustomButton::AcceleratorPressed function in ui/views/controls/button/custom_button.cc in Google Chrome before 48.0.2564.82 allows remote attackers to spoof URLs via vectors involving an unfocused custom button.

CVEs:CVE-2016-1616

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1619

GoogleEPSS <= 49%CRITICAL2016-01-25

Multiple integer overflows in the (1) sycc422_to_rgb and (2) sycc444_to_rgb functions in fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 48.0.2564.82, allow remote attackers to cause a denial of service (out-of-bounds read...

CVEs:CVE-2016-1619

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1613

GoogleEPSS <= 49%CRITICAL2016-01-25

Multiple use-after-free vulnerabilities in the formfiller implementation in PDFium, as used in Google Chrome before 48.0.2564.82, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document, ...

CVEs:CVE-2016-1613

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1614

GoogleEPSS <= 49%CRITICAL2016-01-25

The UnacceleratedImageBufferSurface class in WebKit/Source/platform/graphics/UnacceleratedImageBufferSurface.cpp in Blink, as used in Google Chrome before 48.0.2564.82, mishandles the initialization mode, which allows remote attackers to obtain sensiti...

CVEs:CVE-2016-1614

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-2051

GoogleEPSS <= 49%CRITICAL2016-01-25

Multiple unspecified vulnerabilities in Google V8 before 4.8.271.17, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2016-2051

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
Upstream advisory

CVE-2016-1943

Open SourceEPSS <= 49%MEDIUM2016-01-27

Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method.

CVEs:CVE-2016-1943

Affected products

ProductStatusVendorPackageEcosystem
android affected google
firefox affected mozilla
leap affected opensuse
opensuse affected opensuse
Upstream advisory

CVE-2015-6647

Open SourceEPSS <= 49%HIGH2016-01-06

The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24441554.

CVEs:CVE-2015-6647

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-1940

Open SourceEPSS <= 49%MEDIUM2016-01-27

Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via a data: URL that is mishandled during (1) shortcut opening or (2) BOOKMARK intent processing.

CVEs:CVE-2016-1940

Affected products

ProductStatusVendorPackageEcosystem
android affected google
firefox affected mozilla
Upstream advisory

CVE-2016-1948

Open SourceEPSS <= 49%MEDIUM2016-01-27

Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attackers to replace a theme's images and colors by modifying the client-server data stream.

CVEs:CVE-2016-1948

Affected products

ProductStatusVendorPackageEcosystem
android affected google
firefox affected mozilla
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.