Google Security Advisories · May 2016 — Google Security Advisories
75 advisories 73 CVEs 4 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2016-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 4 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2016-4117

GoogleExploitedCISA KEV listedHIGH2016-05-11

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

CVEs:CVE-2016-4117

Affected products

ProductStatusVendorPackageEcosystem
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_server_from_rhui affected redhat
enterprise_linux_workstation affected redhat
evergreen affected opensuse
flash_player affected adobe
flash_player affected adobe
linux_enterprise_desktop affected suse
linux_enterprise_workstation_extension affected suse
opensuse affected opensuse
Upstream advisory

CVE-2016-4117

Project ZeroExploitedCISA KEV listed2016-05-11

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

CVEs:CVE-2016-4117

Upstream advisory

CVE-2016-0189

Project ZeroExploitedCISA KEV listed2016-05-11

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.

CVEs:CVE-2016-0189

Upstream advisory

CVE-2016-0189

GoogleExploitedCISA KEV listedCRITICAL2016-05-11

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, ...

CVEs:CVE-2016-0189

Affected products

ProductStatusVendorPackageEcosystem
internet_explorer affected microsoft
jscript affected microsoft
vbscript affected microsoft
Upstream advisory

CVE-2016-2107

Open SourceWeaponized exploitMEDIUM2016-05-03

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against a...

CVEs:CVE-2016-2107

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_hpc_node affected redhat
enterprise_linux_hpc_node_eus affected redhat
enterprise_linux_server affected redhat
enterprise_linux_server_aus affected redhat
enterprise_linux_server_eus affected redhat
enterprise_linux_workstation affected redhat
helion_openstack affected hp
leap affected opensuse
node.js affected nodejs
openssl affected openssl
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-2108

Open SourcePoC exploitHIGH2016-05-03

The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the "nega...

CVEs:CVE-2016-2108

Affected products

ProductStatusVendorPackageEcosystem
android affected google
enterprise_linux_desktop affected redhat
enterprise_linux_hpc_node affected redhat
enterprise_linux_hpc_node_eus affected redhat
enterprise_linux_server affected redhat
enterprise_linux_server_aus affected redhat
enterprise_linux_server_eus affected redhat
enterprise_linux_workstation affected redhat
openssl affected openssl
Upstream advisory

MGASA-2016-0207

Open SourcePoC exploitHIGH2016-05-23

Updated golang package fixes CVE-2016-3959

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:5 golang
Upstream advisory

AZL-79052

Open SourcePoC exploitHIGH2016-05-23

CVE-2016-3959 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

MGASA-2016-0183

Open SourcePoC exploitCRITICAL2016-05-18

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

CVE-2016-1669

GooglePoC exploitHIGH2016-05-12

The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer ov...

CVEs:CVE-2016-1669

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
node.js affected nodejs
opensuse affected opensuse
ubuntu_linux affected canonical
v8 affected google
Upstream advisory

CVE-2016-1683

GooglePoC exploitHIGH2016-05-26

numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespace nodes, which allows remote attackers to cause a denial of service (out-of-bounds heap memory access) or possibly have unspecified other impact via a ...

CVEs:CVE-2016-1683

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
libxslt affected xmlsoft
linux_enterprise affected suse
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-2428

Open SourcePoC exploitHIGH2016-05-03

libAACdec/src/aacdec_drc.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not properly limit the number of threads, which allows remote attackers to execute arbitrary code or cause a...

CVEs:CVE-2016-2428

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2429

Open SourcePoC exploitHIGH2016-05-03

libFLAC/stream_decoder.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not prevent free operations on uninitialized memory, which allows remote attackers to execute arbitrary code or ...

CVEs:CVE-2016-2429

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2431

Open SourcePoC exploitHIGH2016-05-03

The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 5, Nexus 6, Nexus 7 (2013), and Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 24968809.

CVEs:CVE-2016-2431

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-1684

GooglePoC exploitCRITICAL2016-05-26

numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resource consumption) or possibly have ...

CVEs:CVE-2016-1684

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
libxslt affected xmlsoft
Upstream advisory

CVE-2016-2434

Open SourcePoC exploitHIGH2016-05-03

The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27251090.

CVEs:CVE-2016-2434

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2439

Open SourcePoC exploitCRITICAL2016-05-03

Buffer overflow in btif/src/btif_dm.c in Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 allows remote attackers to execute arbitrary code via a long PIN value, aka internal bug 27411268.

CVEs:CVE-2016-2439

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2435

Open SourcePoC exploitHIGH2016-05-03

The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27297988.

CVEs:CVE-2016-2435

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2437

Open SourcePoC exploitHIGH2016-05-03

The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27436822.

CVEs:CVE-2016-2437

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2452

Open SourcePoC exploitHIGH2016-05-03

codecs/amrnb/dec/SoftAMR.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate buffer sizes, which allows attackers to gain privileges via a crafted applica...

CVEs:CVE-2016-2452

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2458

Open SourcePoC exploitHIGH2016-05-03

The compose functionality in AOSP Mail in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not properly restrict attachments, which allows attackers to obtain sensitive information via a crafted application, related to Com...

CVEs:CVE-2016-2458

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2060

Open SourcePoC exploitHIGH2016-05-03

server/TetherController.cpp in the tethering controller in netd, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly validate upstream interface names, which allows attackers...

CVEs:CVE-2016-2060

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2440

Open SourcePoC exploitHIGH2016-05-03

libs/binder/IPCThreadState.cpp in Binder in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 mishandles object references, which allows attackers to gain privileges via a crafted application, aka internal bug ...

CVEs:CVE-2016-2440

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2445

Open SourcePoC exploitHIGH2016-05-03

The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27253079.

CVEs:CVE-2016-2445

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2454

Open SourcePoC exploitHIGH2016-05-03

The Qualcomm hardware video codec in Android before 2016-05-01 on Nexus 5 devices allows remote attackers to cause a denial of service (reboot) via a crafted file, aka internal bug 26221024.

CVEs:CVE-2016-2454

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2461

Open SourcePoC exploitHIGH2016-05-03

OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles resets of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspecified vectors, aka internal bugs 27324690 and 27696681.

CVEs:CVE-2016-2461

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2441

Open SourcePoC exploitHIGH2016-05-03

The Qualcomm buspm driver in Android before 2016-05-01 on Nexus 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 26354602.

CVEs:CVE-2016-2441

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2436

Open SourcePoC exploitHIGH2016-05-03

The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27299111.

CVEs:CVE-2016-2436

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2450

Open SourcePoC exploitHIGH2016-05-03

codecs/on2/enc/SoftVPXEncoder.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate OMX buffer sizes, which allows attackers to gain privileges via a crafte...

CVEs:CVE-2016-2450

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2451

Open SourcePoC exploitHIGH2016-05-03

codecs/on2/dec/SoftVPX.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate VPX output buffer sizes, which allows attackers to gain privileges via a crafte...

CVEs:CVE-2016-2451

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2459

Open SourcePoC exploitHIGH2016-05-03

mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted application, related to IGraphi...

CVEs:CVE-2016-2459

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2430

Open SourcePoC exploitHIGH2016-05-03

libbacktrace/Backtrace.cpp in debuggerd in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 allows attackers to gain privileges via an application containing a crafted symbol name, aka internal bug 27299236.

CVEs:CVE-2016-2430

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2448

Open SourcePoC exploitHIGH2016-05-03

media/libmediaplayerservice/nuplayer/NuPlayerStreamListener.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not properly validate entry data structures, which allows attackers to ga...

CVEs:CVE-2016-2448

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2449

Open SourcePoC exploitHIGH2016-05-03

services/camera/libcameraservice/device3/Camera3Device.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate template IDs, which allows attackers to gain privileges via a cra...

CVEs:CVE-2016-2449

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2462

Open SourcePoC exploitHIGH2016-05-03

OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles updates of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspecified vectors, aka internal bug 27371173.

CVEs:CVE-2016-2462

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2432

Open SourcePoC exploitHIGH2016-05-03

The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 6 and Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 25913059.

CVEs:CVE-2016-2432

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2443

Open SourcePoC exploitHIGH2016-05-03

The Qualcomm MDP driver in Android before 2016-05-01 on Nexus 5 and Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 26404525.

CVEs:CVE-2016-2443

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2442

Open SourcePoC exploitHIGH2016-05-03

The Qualcomm buspm driver in Android before 2016-05-01 on Nexus 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 26494907.

CVEs:CVE-2016-2442

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2444

Open SourcePoC exploitHIGH2016-05-03

The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27208332.

CVEs:CVE-2016-2444

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2453

Open SourcePoC exploitHIGH2016-05-03

The MediaTek Wi-Fi driver in Android before 2016-05-01 on Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 27549705.

CVEs:CVE-2016-2453

Affected products

ProductStatusVendorPackageEcosystem
android_one affected google
Upstream advisory

CVE-2016-2456

Open SourcePoC exploitHIGH2016-05-03

The MediaTek Wi-Fi driver in Android before 2016-05-01 on Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 27275187.

CVEs:CVE-2016-2456

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2059

Open SourcePoC exploitHIGH2016-05-05

The msm_ipc_router_bind_control_port function in net/ipc_router/ipc_router_core.c in the IPC router kernel module for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not ...

CVEs:CVE-2016-2059

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2016-2062

GooglePoC exploitCRITICAL2016-05-05

The adreno_perfcounter_query_group function in drivers/gpu/msm/adreno_perfcounter.c in the Adreno GPU driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, uses an incorr...

CVEs:CVE-2016-2062

Affected products

ProductStatusVendorPackageEcosystem
linux_kernel affected linux
nexus_5x_firmware affected google
nexus_6p_firmware affected google
Upstream advisory

CVE-2016-2457

Open SourcePoC exploitHIGH2016-05-03

server/pm/UserManagerService.java in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 allows attackers to bypass intended restrictions on Wi-Fi configuration changes by leveraging guest access, aka internal bug 27411179.

CVEs:CVE-2016-2457

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DSA-3564-1

Open SourceEPSS <= 49%2016-05-02

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:8 chromium-browser
Upstream advisory

CVE-2016-1677

GoogleEPSS <= 49%HIGH2016-05-26

uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."

CVEs:CVE-2016-1677

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
ubuntu_linux affected canonical
v8 affected google
Upstream advisory

CVE-2016-1688

GoogleEPSS <= 49%HIGH2016-05-26

The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mishandles external string sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafte...

CVEs:CVE-2016-1688

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
ubuntu_linux affected canonical
v8 affected google
Upstream advisory

CVE-2016-1667

GoogleEPSS <= 49%CRITICAL2016-05-12

The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome before 50.0.2661.102, does not prevent script execution during node-adoption operations, which allows remote atta...

CVEs:CVE-2016-1667

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2016-1674

GoogleEPSS <= 49%HIGH2016-05-26

The extensions subsystem in Google Chrome before 51.0.2704.63 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

CVEs:CVE-2016-1674

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
Upstream advisory

CVE-2016-1678

GoogleEPSS <= 49%CRITICAL2016-05-26

objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not properly restrict lazy deoptimization, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified...

CVEs:CVE-2016-1678

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
ubuntu_linux affected canonical
v8 affected google
Upstream advisory

CVE-2016-1673

GoogleEPSS <= 49%HIGH2016-05-26

Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

CVEs:CVE-2016-1673

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-1672

GoogleEPSS <= 49%CRITICAL2016-05-26

The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extension bindings in Google Chrome before 51.0.2704.63 mishandles properties, which allows remote attackers to conduct bindings-interception attacks and bypass...

CVEs:CVE-2016-1672

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
Upstream advisory

CVE-2016-1675

GoogleEPSS <= 49%HIGH2016-05-26

Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Document reattachment during destruction, related to FrameLoader.cpp and LocalFrame.cpp.

CVEs:CVE-2016-1675

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-1676

GoogleEPSS <= 49%CRITICAL2016-05-26

extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prototypes, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

CVEs:CVE-2016-1676

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
Upstream advisory

CVE-2016-1681

GoogleEPSS <= 49%CRITICAL2016-05-26

Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a craft...

CVEs:CVE-2016-1681

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
Upstream advisory

CVE-2016-1671

GoogleEPSS <= 49%HIGH2016-05-12

Google Chrome before 50.0.2661.102 on Android mishandles / (slash) and \ (backslash) characters, which allows attackers to conduct directory traversal attacks via a file: URL, related to net/base/escape.cc and net/base/filename_util.cc.

CVEs:CVE-2016-1671

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-1687

GoogleEPSS <= 49%HIGH2016-05-26

The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public exposure of classes, which allows remote attackers to obtain sensitive information via vectors related to extensions.

CVEs:CVE-2016-1687

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
Upstream advisory

CVE-2016-1691

GoogleEPSS <= 49%CRITICAL2016-05-26

Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted curves, related to SkOpCoinci...

CVEs:CVE-2016-1691

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-1679

GoogleEPSS <= 49%CRITICAL2016-05-26

The ToV8Value function in content/child/v8_value_converter_impl.cc in the V8 bindings in Google Chrome before 51.0.2704.63 does not properly restrict use of getters and setters, which allows remote attackers to cause a denial of service (use-after-free...

CVEs:CVE-2016-1679

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-1668

GoogleEPSS <= 49%CRITICAL2016-05-12

The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.102, uses an improper creation context, which allows remote attackers to bypass the Same Origin Policy vi...

CVEs:CVE-2016-1668

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2016-1685

GoogleEPSS <= 49%HIGH2016-05-26

core/fxge/ge/fx_ge_text.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, miscalculates certain index values, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.

CVEs:CVE-2016-1685

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
Upstream advisory

CVE-2016-1686

GoogleEPSS <= 49%CRITICAL2016-05-26

The CPDF_DIBSource::CreateDecoder function in core/fpdfapi/fpdf_render/fpdf_render_loadimage.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, mishandles decoder-initialization failure, which allows remote attackers to cause a denial of serv...

CVEs:CVE-2016-1686

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
Upstream advisory

CVE-2016-1680

GoogleEPSS <= 49%CRITICAL2016-05-26

Use-after-free vulnerability in ports/SkFontHost_FreeType.cpp in Skia, as used in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via unknown vec...

CVEs:CVE-2016-1680

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-1693

GoogleEPSS <= 49%MEDIUM2016-05-26

browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Software Removal Tool, which allows remote attackers to spoof the chrome_cleanup_tool.exe (aka CCT) file via...

CVEs:CVE-2016-1693

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
Upstream advisory

CVE-2016-1695

GoogleEPSS <= 49%HIGH2016-05-26

Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2016-1695

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-1692

GoogleEPSS <= 49%CRITICAL2016-05-26

WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets by a ServiceWorker even when the stylesheet download has an incorrect MIME type, which allows remote a...

CVEs:CVE-2016-1692

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-1682

GoogleEPSS <= 49%CRITICAL2016-05-26

The ServiceWorkerContainer::registerServiceWorkerImpl function in WebKit/Source/modules/serviceworkers/ServiceWorkerContainer.cpp in Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Content Security Policy (CSP...

CVEs:CVE-2016-1682

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-1690

GoogleEPSS <= 49%CRITICAL2016-05-26

The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibl...

CVEs:CVE-2016-1690

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
Upstream advisory

CVE-2016-1689

GoogleEPSS <= 49%CRITICAL2016-05-26

Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome before 51.0.2704.63 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site.

CVEs:CVE-2016-1689

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-1694

GoogleEPSS <= 49%MEDIUM2016-05-26

browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which makes it easier for remote attackers to spoof web sites via a valid certificate from an arbitrary recognized Certificatio...

CVEs:CVE-2016-1694

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
Upstream advisory

CVE-2016-1670

GoogleEPSS <= 49%CRITICAL2016-05-12

Race condition in the ResourceDispatcherHostImpl::BeginRequest function in content/browser/loader/resource_dispatcher_host_impl.cc in Google Chrome before 50.0.2661.102 allows remote attackers to make arbitrary HTTP requests by leveraging access to a r...

CVEs:CVE-2016-1670

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2016-2446

Open SourceEPSS <= 49%HIGH2016-05-03

The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27441354.

CVEs:CVE-2016-2446

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2460

Open SourceEPSS <= 49%HIGH2016-05-03

mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted application, related to IGraphi...

CVEs:CVE-2016-2460

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3958

GoogleEPSS <= 49%HIGH2016-05-23

Untrusted search path vulnerability in Go before 1.5.4 and 1.6.x before 1.6.1 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, related to use of the LoadLibrary function.

CVEs:CVE-2016-3958

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

CVE-2016-4477

Open SourceEPSS <= 49%HIGH2016-05-09

wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service (daemon outage), via a crafted ...

CVEs:CVE-2016-4477

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.