Google Security Advisories · April 2016 — Google Security Advisories
123 advisories 61 CVEs 12 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2016-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 12 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2016-1019

Project ZeroExploitedCISA KEV listed2016-04-06

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

CVEs:CVE-2016-1019

Upstream advisory

CVE-2016-1019

GoogleExploitedCISA KEV listedHIGH2016-04-06

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

CVEs:CVE-2016-1019

Affected products

ProductStatusVendorPackageEcosystem
air_desktop_runtime affected adobe
air_sdk affected adobe
air_sdk_\&_compiler affected adobe
flash_player affected adobe
flash_player_desktop_runtime affected adobe
Upstream advisory

CVE-2016-0162

Project ZeroExploitedCISA KEV listed2016-04-12

Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability."

CVEs:CVE-2016-0162

Upstream advisory

CVE-2016-0162

GoogleExploitedCISA KEV listedHIGH2016-04-12

Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability."

CVEs:CVE-2016-0162

Affected products

ProductStatusVendorPackageEcosystem
internet_explorer affected microsoft
Upstream advisory

CVE-2016-0165

Project ZeroExploitedCISA KEV listed2016-04-12

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0143 and CVE-2016-0167.

CVEs:CVE-2016-0165

Upstream advisory

CVE-2016-0165

GoogleExploitedCISA KEV listedHIGH2016-04-12

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted app...

CVEs:CVE-2016-0165

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1511 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_vista affected microsoft
Upstream advisory

CVE-2016-0167

Project ZeroExploitedCISA KEV listed2016-04-12

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0143 and CVE-2016-0165.

CVEs:CVE-2016-0167

Upstream advisory

CVE-2016-0167

GoogleExploitedCISA KEV listedHIGH2016-04-12

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted app...

CVEs:CVE-2016-0167

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1511 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_vista affected microsoft
Upstream advisory

CVE-2016-2417

Open SourceWeaponized exploitHIGH2016-04-05

media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a parameter data structure, which allows attackers to obtain sensitive information from process me...

CVEs:CVE-2016-2417

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0846

Open SourceWeaponized exploitHIGH2016-04-05

libs/binder/IMemory.cpp in the IMemory Native Interface in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider the heap size, which allows attackers to gain privileges via a crafted app...

CVEs:CVE-2016-0846

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3959

GooglePoC exploitHIGH2016-04-21

The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted publi...

CVEs:CVE-2016-3959

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
go affected golang
leap affected opensuse
Upstream advisory

CVE-2016-0835

Open SourcePoC exploitHIGH2016-04-05

decoder/impeg2d_dec_hdr.c in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file that triggers a certain negative value, aka internal b...

CVEs:CVE-2016-0835

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0838

Open SourcePoC exploitHIGH2016-04-05

Sonivox in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not check for a negative number of samples, which allows remote attackers to execute arbitrary code or cause a denial of service ...

CVEs:CVE-2016-0838

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0836

Open SourcePoC exploitHIGH2016-04-05

Stack-based buffer overflow in decoder/impeg2d_vld.c in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25812590.

CVEs:CVE-2016-0836

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0839

Open SourcePoC exploitHIGH2016-04-05

post_proc/volume_listener.c in mediaserver in Android 6.x before 2016-04-01 mishandles deleted effect context, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka intern...

CVEs:CVE-2016-0839

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0841

Open SourcePoC exploitHIGH2016-04-05

media/libmedia/mediametadataretriever.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 mishandles cleared service binders, which allows remote attackers to execute arbitrary code or cause...

CVEs:CVE-2016-0841

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0837

Open SourcePoC exploitHIGH2016-04-05

MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and me...

CVEs:CVE-2016-0837

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0842

Open SourcePoC exploitHIGH2016-04-05

The H.264 decoder in libstagefright in Android 6.x before 2016-04-01 mishandles Memory Management Control Operation (MMCO) data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted medi...

CVEs:CVE-2016-0842

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0840

Open SourcePoC exploitHIGH2016-04-05

Multiple stack-based buffer underflows in decoder/ih264d_parse_cavlc.c in mediaserver in Android 6.x before 2016-04-01 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka inter...

CVEs:CVE-2016-0840

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2416

Open SourcePoC exploitHIGH2016-04-05

libs/gui/BufferQueueConsumer.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not check for the android.permission.DUMP permission, which allows attackers to obtain sensitive informa...

CVEs:CVE-2016-2416

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2419

Open SourcePoC exploitHIGH2016-04-05

media/libmedia/IDrm.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize a certain key-request data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protect...

CVEs:CVE-2016-2419

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2418

Open SourcePoC exploitHIGH2016-04-05

media/libmedia/IOMX.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize certain metadata buffer pointers, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection ...

CVEs:CVE-2016-2418

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0850

Open SourcePoC exploitHIGH2016-04-05

The PORCHE_PAIRING_CONFLICT feature in Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows remote attackers to bypass intended pairing restrictions via a crafted device, aka internal bug 26551...

CVEs:CVE-2016-0850

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2409

Open SourcePoC exploitHIGH2016-04-05

A Texas Instruments (TI) haptic kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that leverages control over a service that can call this driver, aka internal bug 25981545.

CVEs:CVE-2016-2409

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2411

Open SourcePoC exploitHIGH2016-04-05

A Qualcomm Power Management kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that leverages root access, aka internal bug 26866053.

CVEs:CVE-2016-2411

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2412

Open SourcePoC exploitHIGH2016-04-05

include/core/SkPostConfig.h in Skia, as used in System_server in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01, mishandles certain crashes, which allows attackers to gain privileges via a crafted applicatio...

CVEs:CVE-2016-2412

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2413

Open SourcePoC exploitHIGH2016-04-05

media/libmedia/IOMX.cpp in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a handle pointer, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining ...

CVEs:CVE-2016-2413

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2420

Open SourcePoC exploitHIGH2016-04-05

rootdir/init.rc in Android 4.x before 4.4.4 does not ensure that the /data/tombstones directory exists for the Debuggerd component, which allows attackers to gain privileges via a crafted application, aka internal bug 26403620.

CVEs:CVE-2016-2420

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2425

Open SourcePoC exploitHIGH2016-04-05

mail/compose/ComposeActivity.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 supports file:///data attachments, which allows attackers to obtain sensitive information via a crafted applic...

CVEs:CVE-2016-2425

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2415

Open SourcePoC exploitHIGH2016-04-05

exchange/eas/EasAutoDiscover.java in the Autodiscover implementation in Exchange ActiveSync in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to obtain sensitive information via a crafted application that tri...

CVEs:CVE-2016-2415

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2427

Open SourcePoC exploitMEDIUM2016-04-05

The AES-GCM specification in RFC 5084, as used in Android 5.x and 6.x, recommends 12 octets for the aes-ICVlen parameter field, which might make it easier for attackers to defeat a cryptographic protection mechanism and discover an authentication key v...

CVEs:CVE-2016-2427

Affected products

ProductStatusVendorPackageEcosystem
android affected google
bc-java affected bouncycastle
Upstream advisory

CVE-2016-2414

Open SourcePoC exploitCRITICAL2016-04-05

The Minikin library in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider negative size values in font data, which allows remote attackers to cause a denial of service (memory corruption and reboot loop...

CVEs:CVE-2016-2414

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2422

Open SourcePoC exploitHIGH2016-04-05

Wi-Fi in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not prevent use of a Wi-Fi CA certificate in an unrelated CA role, which allows attackers to gain privileges via a crafted application, as demonst...

CVEs:CVE-2016-2422

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2426

Open SourcePoC exploitHIGH2016-04-05

server/content/ContentService.java in the Framework component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not check for a GET_ACCOUNTS permission, which allows attackers to obtain sensitive inform...

CVEs:CVE-2016-2426

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2424

Open SourcePoC exploitHIGH2016-04-05

server/content/SyncStorageEngine.java in SyncStorageEngine in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 mismanages certain authority data, which allows attackers to cause a denial of service (reboot loo...

CVEs:CVE-2016-2424

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0847

Open SourcePoC exploitHIGH2016-04-05

The Telecom Component in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to spoof the originating telephone number of a call via a crafted application, as demonstrated by obtaining Signature or SignatureOrSyst...

CVEs:CVE-2016-0847

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0849

Open SourcePoC exploitCRITICAL2016-04-05

Multiple integer overflows in minzip/SysUtil.c in the Recovery Procedure in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allow attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature o...

CVEs:CVE-2016-0849

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0844

Open SourcePoC exploitHIGH2016-04-05

The Qualcomm RF driver in Android 6.x before 2016-04-01 does not properly restrict access to socket ioctl calls, which allows attackers to gain privileges via a crafted application, aka internal bug 26324307.

CVEs:CVE-2016-0844

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0843

Open SourcePoC exploitHIGH2016-04-05

The Qualcomm ARM processor performance-event manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application, aka internal bug 25801197.

CVEs:CVE-2016-0843

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2423

Open SourcePoC exploitMEDIUM2016-04-05

server/telecom/CallsManager.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider whether a device is provisioned, which allows physically proximate attackers to bypa...

CVEs:CVE-2016-2423

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2410

Open SourcePoC exploitHIGH2016-04-05

A Qualcomm video kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that leverages control over a service that can call this driver, aka internal bug 26291677.

CVEs:CVE-2016-2410

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2421

Open SourcePoC exploitMEDIUM2016-04-05

Setup Wizard in Android 5.1.x before 5.1.1 and 6.x before 2016-04-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26154410.

CVEs:CVE-2016-2421

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-0848

Open SourcePoC exploitHIGH2016-04-05

Race condition in Download Manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to bypass private-storage file-access restrictions via a crafted application that changes a symlink targe...

CVEs:CVE-2016-0848

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-1503

Open SourceEPSS <= 49%HIGH2016-04-05

dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 and other products, mismanages option lengths, which allows remote attackers to execute arbitrary code or cause a denial of ser...

CVEs:CVE-2016-1503

Affected products

ProductStatusVendorPackageEcosystem
android affected google
dhcpcd affected dhcpcd_project
Upstream advisory

MGASA-2016-0160

Open SourceEPSS <= 49%CRITICAL2016-04-29

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

CVE-2016-1662

GoogleEPSS <= 49%HIGH2016-04-29

extensions/renderer/gc_callback.cc in Google Chrome before 50.0.2661.94 does not prevent fallback execution once the Garbage Collection callback has started, which allows remote attackers to cause a denial of service (use-after-free) or possibly have u...

CVEs:CVE-2016-1662

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
opensuse affected opensuse
Upstream advisory

MGASA-2016-0143

Open SourceEPSS <= 49%CRITICAL2016-04-21

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

DSA-3549-1

Open SourceEPSS <= 49%2016-04-15

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:8 chromium-browser
Upstream advisory

CVE-2016-1653

GoogleEPSS <= 49%HIGH2016-04-14

The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that trigg...

CVEs:CVE-2016-1653

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
leap affected opensuse
linux_enterprise affected suse
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-1655

GoogleEPSS <= 49%CRITICAL2016-04-14

Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted ext...

CVEs:CVE-2016-1655

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
leap affected opensuse
linux_enterprise affected suse
ubuntu_linux affected canonical
Upstream advisory

CVE-2015-7528

Open SourceEPSS <= 49%MEDIUM2016-04-11

Information Exposure in Kubernetes

CVEs:CVE-2015-7528

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

CVE-2015-7528

Open SourceEPSS <= 49%HIGH2016-04-11

Kubernetes before 1.2.0-alpha.5 allows remote attackers to read arbitrary pod logs via a container name.

CVEs:CVE-2015-7528

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
openshift affected redhat
Upstream advisory

CVE-2016-1665

GoogleEPSS <= 49%HIGH2016-04-29

The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison operators, which allows remote attackers to obtain sensitive information via crafted JavaScript code.

CVEs:CVE-2016-1665

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
opensuse affected opensuse
Upstream advisory

CVE-2016-0834

Open SourceEPSS <= 49%HIGH2016-04-05

An unspecified media codec in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 26220548.

CVEs:CVE-2016-0834

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-1656

GoogleEPSS <= 49%HIGH2016-04-14

The download implementation in Google Chrome before 50.0.2661.75 on Android allows remote attackers to bypass intended pathname restrictions via unspecified vectors.

CVEs:CVE-2016-1656

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
linux_enterprise affected suse
Upstream advisory

CVE-2016-1659

GoogleEPSS <= 49%HIGH2016-04-14

Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.75 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2016-1659

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
leap affected opensuse
linux_enterprise affected suse
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-1666

GoogleEPSS <= 49%CRITICAL2016-04-29

Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.94 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2016-1666

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
opensuse affected opensuse
Upstream advisory

CVE-2016-1657

GoogleEPSS <= 49%MEDIUM2016-04-14

The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attackers to spoof the address bar via...

CVEs:CVE-2016-1657

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
leap affected opensuse
suse_package_hub_for_suse_linux_enterprise affected novell
Upstream advisory

CVE-2016-1658

GoogleEPSS <= 49%HIGH2016-04-14

The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.

CVEs:CVE-2016-1658

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
leap affected opensuse
suse_package_hub_for_suse_linux_enterprise affected novell
Upstream advisory

CVE-2016-1651

GoogleEPSS <= 49%HIGH2016-04-14

fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not properly implement the sycc420_to_rgb and sycc422_to_rgb functions, which allows remote attackers to obtain sensitive information from process memory o...

CVEs:CVE-2016-1651

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
leap affected opensuse
linux_enterprise affected suse
Upstream advisory

CVE-2016-1661

GoogleEPSS <= 49%CRITICAL2016-04-29

Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer process in addition to a Same Origin Policy check, which allows remote attackers to cause a denial of service (memory corruption) or ...

CVEs:CVE-2016-1661

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
opensuse affected opensuse
Upstream advisory

CVE-2016-1652

GoogleEPSS <= 49%CRITICAL2016-04-14

Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the Extensions subsystem in Google Chrome before 50.0.2661.75 allows remote attackers to inject arbitrary web script or ...

CVEs:CVE-2016-1652

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
leap affected opensuse
linux_enterprise affected suse
Upstream advisory

CVE-2016-1654

GoogleEPSS <= 49%HIGH2016-04-14

The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a denial of service (invalid read operation) via unknown vectors.

CVEs:CVE-2016-1654

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
leap affected opensuse
linux_enterprise affected suse
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-1660

GoogleEPSS <= 49%CRITICAL2016-04-29

Blink, as used in Google Chrome before 50.0.2661.94, mishandles assertions in the WTF::BitArray and WTF::double_conversion::Vector classes, which allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified ot...

CVEs:CVE-2016-1660

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
opensuse affected opensuse
Upstream advisory

CVE-2016-1663

GoogleEPSS <= 49%CRITICAL2016-04-29

The SerializedScriptValue::transferArrayBuffers function in WebKit/Source/bindings/core/v8/SerializedScriptValue.cpp in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.94, mishandles certain array-buffer data structures, which allow...

CVEs:CVE-2016-1663

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
opensuse affected opensuse
Upstream advisory

CVE-2016-1664

GoogleEPSS <= 49%MEDIUM2016-04-29

The HistoryController::UpdateForCommit function in content/renderer/history_controller.cc in Google Chrome before 50.0.2661.94 mishandles the interaction between subframe forward navigations and other forward navigations, which allows remote attackers ...

CVEs:CVE-2016-1664

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop_supplementary affected redhat
enterprise_linux_server_supplementary affected redhat
enterprise_linux_server_supplementary_eus affected redhat
enterprise_linux_workstation_supplementary affected redhat
opensuse affected opensuse
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.