Google Security Advisories · March 2016 — Google Security Advisories
51 advisories 50 CVEs 5 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2016-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 5 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

MGASA-2016-0127

Open SourceExploitedCISA KEV listedHIGH2016-03-31

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

CVE-2016-1646

GoogleExploitedCISA KEV listedHIGH2016-03-25

The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or poss...

CVEs:CVE-2016-1646

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_eus affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
opensuse affected opensuse
package_hub affected suse
ubuntu_linux affected canonical
Upstream advisory

DSA-3531-1

Open SourceExploitedCISA KEV listed2016-03-25

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:8 chromium-browser
Upstream advisory

CVE-2016-1010

Project ZeroExploitedCISA KEV listed2016-03-10

Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.

CVEs:CVE-2016-1010

Upstream advisory

CVE-2016-1010

GoogleExploitedCISA KEV listedHIGH2016-03-10

Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21....

CVEs:CVE-2016-1010

Affected products

ProductStatusVendorPackageEcosystem
air affected adobe
air_desktop_runtime affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
flash_player affected adobe
flash_player_desktop_runtime affected adobe
x14j_firmware affected samsung
Upstream advisory

CVE-2016-1647

GoogleActive exploitation (sightings)HIGH2016-03-25

Use-after-free vulnerability in the RenderWidgetHostImpl::Destroy function in content/browser/renderer_host/render_widget_host_impl.cc in the Navigation implementation in Google Chrome before 49.0.2623.108 allows remote attackers to cause a denial of s...

CVEs:CVE-2016-1647

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-1648

GoogleActive exploitation (sightings)HIGH2016-03-25

Use-after-free vulnerability in the GetLoadTimes function in renderer/loadtimes_extension_bindings.cc in the Extensions implementation in Google Chrome before 49.0.2623.108 allows remote attackers to cause a denial of service or possibly have unspecifi...

CVEs:CVE-2016-1648

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2016-0705

Open SourcePoC exploitHIGH2016-03-01

Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impac...

CVEs:CVE-2016-0705

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
mysql affected oracle
openssl affected openssl
ubuntu_linux affected canonical
Upstream advisory

DSA-3507-1

Open SourcePoC exploit2016-03-05

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:8 chromium-browser
Upstream advisory

CVE-2016-1621

Open SourcePoC exploitHIGH2016-03-08

libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to libwebm/mkvpar...

CVEs:CVE-2016-1621

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0815

Open SourcePoC exploitHIGH2016-03-08

The MPEG4Source::fragmentedRead function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of servi...

CVEs:CVE-2016-0815

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0816

Open SourcePoC exploitHIGH2016-03-08

mediaserver in Android 6.x before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to decoder/ih264d_parse_islice.c and decoder/ih264d_parse_pslice.c, aka in...

CVEs:CVE-2016-0816

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0828

Open SourcePoC exploitHIGH2016-03-08

The BnGraphicBufferConsumer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 5.x before 5.1.1 LMY49H and 6.x before 2016-03-01 does not initialize a certain slot variable, which allows attackers to obtain sensitive ...

CVEs:CVE-2016-0828

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0829

Open SourcePoC exploitHIGH2016-03-08

The BnGraphicBufferProducer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 does not initialize a certain output data structure, which allows att...

CVEs:CVE-2016-0829

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0824

Open SourcePoC exploitHIGH2016-03-08

libmpeg2 in libstagefright in Android 6.x before 2016-03-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via crafted Bitstream data, as demonstrated by obtaining Signature or SignatureOr...

CVEs:CVE-2016-0824

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0826

Open SourcePoC exploitHIGH2016-03-08

libcameraservice in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 does not require use of the ICameraService::dump method for a camera service dump, which allows attackers to gain privileges via a crafted a...

CVEs:CVE-2016-0826

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0827

Open SourcePoC exploitHIGH2016-03-08

Multiple integer overflows in libeffects in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 allow attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrS...

CVEs:CVE-2016-0827

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0830

Open SourcePoC exploitCRITICAL2016-03-08

btif_config.c in Bluetooth in Android 6.x before 2016-03-01 allows remote attackers to cause a denial of service (memory corruption and persistent daemon crash) by triggering a large number of configuration entries, and consequently exceeding the maxim...

CVEs:CVE-2016-0830

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0820

Open SourcePoC exploitHIGH2016-03-08

The MediaTek Wi-Fi kernel driver in Android 6.0.1 before 2016-03-01 allows attackers to gain privileges via a crafted application, aka internal bug 26267358.

CVEs:CVE-2016-0820

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0819

Open SourcePoC exploitHIGH2016-03-08

The Qualcomm performance component in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 allows attackers to gain privileges via a crafted application, aka internal bug 25364034.

CVEs:CVE-2016-0819

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0825

Open SourcePoC exploitMEDIUM2016-03-08

The Widevine Trusted Application in Android 6.0.1 before 2016-03-01 allows attackers to obtain sensitive TrustZone secure-storage information by leveraging kernel access, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal ...

CVEs:CVE-2016-0825

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0831

Open SourcePoC exploitHIGH2016-03-08

The getDeviceIdForPhone function in internal/telephony/PhoneSubInfoController.java in Telephony in Android 5.x before 5.1.1 LMY49H and 6.x before 2016-03-01 does not check for the READ_PHONE_STATE permission, which allows attackers to obtain sensitive ...

CVEs:CVE-2016-0831

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0822

Open SourcePoC exploitHIGH2016-03-08

The MediaTek connectivity kernel driver in Android 6.0.1 before 2016-03-01 allows attackers to gain privileges via a crafted application that leverages conn_launcher access, aka internal bug 25873324.

CVEs:CVE-2016-0822

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0821

Open SourcePoC exploitMEDIUM2016-03-08

The LIST_POISON feature in include/linux/poison.h in the Linux kernel before 4.3, as used in Android 6.0.1 before 2016-03-01, does not properly consider the relationship to the mmap_min_addr value, which makes it easier for attackers to bypass a poison...

CVEs:CVE-2016-0821

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2016-0823

Open SourcePoC exploitMEDIUM2016-03-08

The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19.3, as used in Android 6.0.1 before 2016-03-01, allows local users to obtain sensitive physical-address information by reading a pagemap file, aka Android internal bug 25739...

CVEs:CVE-2016-0823

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2016-0818

Open SourcePoC exploitMEDIUM2016-03-08

The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 mishandles the distinction between an intermediate CA and a trusted root CA, w...

CVEs:CVE-2016-0818

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0832

Open SourcePoC exploitMEDIUM2016-03-08

Setup Wizard in Android 5.1.x before LMY49H and 6.x before 2016-03-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 25955042.

CVEs:CVE-2016-0832

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-1649

GoogleEPSS <= 49%HIGH2016-03-25

The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before 49.0.2623.108, does not properly handle a certain data-type mismatch, which allows remote attackers to cause a denial of service (buffer overflow) or p...

CVEs:CVE-2016-1649

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

DSA-3513-1

Open SourceEPSS <= 49%2016-03-10

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:8 chromium-browser
Upstream advisory

CVE-2016-1643

GoogleEPSS <= 49%HIGH2016-03-09

The ImageInputType::ensurePrimaryContent function in WebKit/Source/core/html/forms/ImageInputType.cpp in Blink, as used in Google Chrome before 49.0.2623.87, does not properly maintain the user agent shadow DOM, which allows remote attackers to cause a...

CVEs:CVE-2016-1643

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1633

GoogleEPSS <= 49%HIGH2016-03-03

Use-after-free vulnerability in Blink, as used in Google Chrome before 49.0.2623.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2016-1633

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1635

GoogleEPSS <= 49%HIGH2016-03-03

extensions/renderer/render_frame_observer_natives.cc in Google Chrome before 49.0.2623.75 does not properly consider object lifetimes and re-entrancy issues during OnDocumentElementCreated handling, which allows remote attackers to cause a denial of se...

CVEs:CVE-2016-1635

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1639

GoogleEPSS <= 49%HIGH2016-03-03

Use-after-free vulnerability in browser/extensions/api/webrtc_audio_private/webrtc_audio_private_api.cc in the WebRTC Audio Private API implementation in Google Chrome before 49.0.2623.75 allows remote attackers to cause a denial of service or possibly...

CVEs:CVE-2016-1639

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-2845

GoogleEPSS <= 49%CRITICAL2016-03-06

The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49.0.2623.75, does not ignore a URL's path component in the case of a ServiceWorker fetch, which allows remote attackers to obtain sensitive information about vi...

CVEs:CVE-2016-2845

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-2844

GoogleEPSS <= 49%HIGH2016-03-06

WebKit/Source/core/layout/LayoutBlock.cpp in Blink, as used in Google Chrome before 49.0.2623.75, does not properly determine when anonymous block wrappers may exist, which allows remote attackers to cause a denial of service (incorrect cast and assert...

CVEs:CVE-2016-2844

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1644

GoogleEPSS <= 49%HIGH2016-03-09

WebKit/Source/core/layout/LayoutObject.cpp in Blink, as used in Google Chrome before 49.0.2623.87, does not properly restrict relayout scheduling, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified ...

CVEs:CVE-2016-1644

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1645

GoogleEPSS <= 49%HIGH2016-03-09

Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87, allow remote attackers to cause a denial of service (incorrect cast and out-of-bounds write) or p...

CVEs:CVE-2016-1645

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
leap affected opensuse
opensuse affected opensuse
suse_linux_enterprise_server affected opensuse
Upstream advisory

CVE-2016-1641

GoogleEPSS <= 49%HIGH2016-03-03

Use-after-free vulnerability in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 49.0.2623.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering an image download after ...

CVEs:CVE-2016-1641

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1636

GoogleEPSS <= 49%CRITICAL2016-03-03

The PendingScript::notifyFinished function in WebKit/Source/core/dom/PendingScript.cpp in Google Chrome before 49.0.2623.75 relies on memory-cache information about integrity-check occurrences instead of integrity-check successes, which allows remote a...

CVEs:CVE-2016-1636

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1634

GoogleEPSS <= 49%HIGH2016-03-03

Use-after-free vulnerability in the StyleResolver::appendCSSStyleSheet function in WebKit/Source/core/css/resolver/StyleResolver.cpp in Blink, as used in Google Chrome before 49.0.2623.75, allows remote attackers to cause a denial of service or possibl...

CVEs:CVE-2016-1634

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1642

GoogleEPSS <= 49%HIGH2016-03-03

Multiple unspecified vulnerabilities in Google Chrome before 49.0.2623.75 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2016-1642

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1632

GoogleEPSS <= 49%HIGH2016-03-03

The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code that triggers an incorrect cast, related to extens...

CVEs:CVE-2016-1632

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1631

GoogleEPSS <= 49%HIGH2016-03-03

The PPB_Flash_MessageLoop_Impl::InternalRun function in content/renderer/pepper/ppb_flash_message_loop_impl.cc in the Pepper plugin in Google Chrome before 49.0.2623.75 mishandles nested message loops, which allows remote attackers to bypass the Same O...

CVEs:CVE-2016-1631

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-3679

GoogleEPSS <= 49%HIGH2016-03-29

Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before 49.0.2623.108, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2016-3679

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
ubuntu_linux affected canonical
v8 affected google
Upstream advisory

CVE-2016-1650

GoogleEPSS <= 49%HIGH2016-03-25

The PageCaptureSaveAsMHTMLFunction::ReturnFailure function in browser/extensions/api/page_capture/page_capture_api.cc in Google Chrome before 49.0.2623.108 allows attackers to cause a denial of service or possibly have unspecified other impact by trigg...

CVEs:CVE-2016-1650

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2016-1640

GoogleEPSS <= 49%MEDIUM2016-03-03

The Web Store inline-installer implementation in the Extensions UI in Google Chrome before 49.0.2623.75 does not block installations upon deletion of an installation frame, which makes it easier for remote attackers to trick a user into believing that ...

CVEs:CVE-2016-1640

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1637

GoogleEPSS <= 49%HIGH2016-03-03

The SkATan2_255 function in effects/gradients/SkSweepGradient.cpp in Skia, as used in Google Chrome before 49.0.2623.75, mishandles arctangent calculations, which allows remote attackers to obtain sensitive information via a crafted web site.

CVEs:CVE-2016-1637

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-2843

GoogleEPSS <= 49%HIGH2016-03-06

Multiple unspecified vulnerabilities in Google V8 before 4.9.385.26, as used in Google Chrome before 49.0.2623.75, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2016-2843

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
v8 affected google
Upstream advisory

CVE-2016-1630

GoogleEPSS <= 49%CRITICAL2016-03-03

The ContainerNode::parserRemoveChild function in WebKit/Source/core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 49.0.2623.75, mishandles widget updates, which makes it easier for remote attackers to bypass the Same Origin Policy via...

CVEs:CVE-2016-1630

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1638

GoogleEPSS <= 49%CRITICAL2016-03-03

extensions/renderer/resources/platform_app.js in the Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly restrict use of Web APIs, which allows remote attackers to bypass intended access restrictions via a crafted platform app.

CVEs:CVE-2016-1638

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-0774

Open SourceEPSS <= 49%MEDIUM2016-03-07

The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in a certain Linux kernel backport in the linux package before 3.2.73-2+deb7u3 on Debian wheezy and the kernel package before 3.10.0-229.26.2 on Red Hat Enterprise Linux (RHEL) 7.1 do no...

CVEs:CVE-2016-0774

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.