Google Security Advisories · February 2016 — Google Security Advisories
55 advisories 29 CVEs 4 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2016-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 4 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2016-0984

Project ZeroExploitedCISA KEV listed2016-02-10

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0983.

CVEs:CVE-2016-0984

Upstream advisory

CVE-2016-0984

GoogleExploitedCISA KEV listedHIGH2016-02-10

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler be...

CVEs:CVE-2016-0984

Affected products

ProductStatusVendorPackageEcosystem
air_desktop_runtime affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
flash_player affected adobe
flash_player_desktop_runtime affected adobe
Upstream advisory

CVE-2016-0801

Open SourceWeaponized exploitCRITICAL2016-02-07

The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control mess...

CVEs:CVE-2016-0801

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2016-0802

Open SourcePoC exploitCRITICAL2016-02-07

The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control mess...

CVEs:CVE-2016-0802

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2016-1905

Open SourcePoC exploitHIGH2016-02-03

The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a crafted patched object.

CVEs:CVE-2016-1905

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2016-1905

Open SourcePoC exploitHIGH2016-02-03

Access Restriction Bypass in kubernetes

CVEs:CVE-2016-1905

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

CVE-2016-0805

Open SourcePoC exploitHIGH2016-02-07

The performance event manager for Qualcomm ARM processors in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application, aka internal bug 25773204.

CVEs:CVE-2016-0805

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-1906

GoogleEPSS <= 49%CRITICAL2016-02-03

Authorization bypass in Openshift

CVEs:CVE-2016-1906

Affected products

ProductStatusVendorPackageEcosystem
openshift/origin affected github.com github.com/openshift/origin
Upstream advisory

CVE-2016-1906

Open SourceEPSS <= 49%HIGH2016-02-03

Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that is not allowed.

CVEs:CVE-2016-1906

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2016-2536

GoogleEPSS <= 49%CRITICAL2016-02-18

Multiple use-after-free vulnerabilities in SAP 3D Visual Enterprise Viewer allow remote attackers to execute arbitrary code via a crafted SketchUp document. NOTE: the primary affected product may be SketchUp.

CVEs:CVE-2016-2536

Affected products

ProductStatusVendorPackageEcosystem
3d_visual_enterprise_viewer affected sap
sketchup affected google
Upstream advisory

MGASA-2016-0043

Open SourceEPSS <= 49%2016-02-05

Updated docker/golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
docker affected Mageia:5 docker
golang affected Mageia:5 golang
Upstream advisory

DSA-3486-1

Open SourceEPSS <= 49%2016-02-21

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:8 chromium-browser
Upstream advisory

CVE-2016-1629

GoogleEPSS <= 49%HIGH2016-02-19

Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified vectors.

CVEs:CVE-2016-1629

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
leap affected opensuse
opensuse affected opensuse
suse_package_hub_for_suse_linux_enterprise affected novell
Upstream advisory

CVE-2016-0803

Open SourceEPSS <= 49%HIGH2016-02-07

libstagefright in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file that triggers a la...

CVEs:CVE-2016-0803

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0804

Open SourceEPSS <= 49%HIGH2016-02-07

The NuPlayer::GenericSource::notifyPreparedAndCleanup function in media/libmediaplayerservice/nuplayer/GenericSource.cpp in mediaserver in Android 5.x before 5.1.1 LMY49G and 6.x before 2016-02-01 improperly manages mDrmManagerClient objects, which all...

CVEs:CVE-2016-0804

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-1628

GoogleEPSS <= 49%CRITICAL2016-02-21

pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, does not validate a certain precision value, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a crafted JPEG 2000 im...

CVEs:CVE-2016-1628

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2016-1624

GoogleEPSS <= 49%CRITICAL2016-02-10

Integer underflow in the ProcessCommandsInternal function in dec/decode.c in Brotli, as used in Google Chrome before 48.0.2564.109, allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via cra...

CVEs:CVE-2016-1624

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2016-1626

GoogleEPSS <= 49%HIGH2016-02-10

The opj_pi_update_decode_poc function in pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, miscalculates a certain layer index value, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted...

CVEs:CVE-2016-1626

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2016-1622

GoogleEPSS <= 49%HIGH2016-02-10

The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.

CVEs:CVE-2016-1622

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2016-1627

GoogleEPSS <= 49%CRITICAL2016-02-10

The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to by...

CVEs:CVE-2016-1627

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2016-1625

GoogleEPSS <= 49%MEDIUM2016-02-10

The Chrome Instant feature in Google Chrome before 48.0.2564.109 does not ensure that a New Tab Page (NTP) navigation target is on the most-visited or suggestions list, which allows remote attackers to bypass intended restrictions via unspecified vecto...

CVEs:CVE-2016-1625

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2016-1623

GoogleEPSS <= 49%HIGH2016-02-10

The DOM implementation in Google Chrome before 48.0.2564.109 does not properly restrict frame-attach operations from occurring during or after frame-detach operations, which allows remote attackers to bypass the Same Origin Policy via a crafted web sit...

CVEs:CVE-2016-1623

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2016-0811

Open SourceEPSS <= 49%CRITICAL2016-02-07

Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto.cpp in libmediaplayerservice in Android 6.x before 2016-02-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism,...

CVEs:CVE-2016-0811

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0809

Open SourceEPSS <= 49%CRITICAL2016-02-07

Use-after-free vulnerability in the wifi_cleanup function in bcmdhd/wifi_hal/wifi_hal.cpp in Wi-Fi in Android 6.x before 2016-02-01 allows attackers to gain privileges by leveraging access to the local physical environment during execution of a crafted...

CVEs:CVE-2016-0809

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0810

Open SourceEPSS <= 49%HIGH2016-02-07

media/libmedia/SoundPool.cpp in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 mishandles locking requirements, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaini...

CVEs:CVE-2016-0810

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2016-0807

Open SourceEPSS <= 49%HIGH2016-02-07

DEBIAN-CVE-2016-0807

Affected products

ProductStatusVendorPackageEcosystem
android-platform-system-core affected Debian:11 android-platform-system-core
Upstream advisory

CVE-2016-0807

Open SourceEPSS <= 49%HIGH2016-02-07

The get_build_id function in elf_utils.cpp in Debuggerd in Android 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application that mishandles a Desc Size element in an ELF Note, aka internal bug 25187394.

CVEs:CVE-2016-0807

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0806

Open SourceEPSS <= 49%HIGH2016-02-07

The Qualcomm Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application, aka internal bug 25344453.

CVEs:CVE-2016-0806

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0808

Open SourceEPSS <= 49%CRITICAL2016-02-07

Integer overflow in the getCoverageFormat12 function in CmapCoverage.cpp in the Minikin library in Android 5.x before 5.1.1 LMY49G and 6.x before 2016-02-01 allows attackers to cause a denial of service (continuous rebooting) via an application that tr...

CVEs:CVE-2016-0808

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0812

Open SourceEPSS <= 49%CRITICAL2016-02-07

The interceptKeyBeforeDispatching function in policy/src/com/android/internal/policy/impl/PhoneWindowManager.java in Setup Wizard in Android 5.1.x before 5.1.1 LMY49G and 6.0 before 2016-02-01 does not properly check for setup completion, which allows ...

CVEs:CVE-2016-0812

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0813

Open SourceEPSS <= 49%MEDIUM2016-02-07

packages/SystemUI/src/com/android/systemui/recents/AlternateRecentsComponent.java in Setup Wizard in Android 5.1.x before 5.1.1 LMY49G and 6.x before 2016-02-01 does not properly check for device provisioning, which allows physically proximate attacker...

CVEs:CVE-2016-0813

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.