Google Security Advisories · June 2016 — Google Security Advisories
56 advisories 55 CVEs 2 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2016-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2016-4171

Project ZeroExploitedCISA KEV listed2016-06-15

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.

CVEs:CVE-2016-4171

Upstream advisory

CVE-2016-4171

GoogleExploitedCISA KEV listedHIGH2016-06-15

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.

CVEs:CVE-2016-4171

Affected products

ProductStatusVendorPackageEcosystem
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
flash_player affected adobe
linux_enterprise_desktop affected suse
linux_enterprise_workstation_extension affected suse
opensuse affected opensuse
Upstream advisory

CVE-2016-2494

Open SourceWeaponized exploitHIGH2016-06-07

Off-by-one error in sdcard/sdcard.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSyste...

CVEs:CVE-2016-2494

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DSA-3590-1

Open SourcePoC exploit2016-06-01

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:8 chromium-browser
Upstream advisory

CVE-2016-2464

Open SourcePoC exploitHIGH2016-06-07

libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted mkv file, a...

CVEs:CVE-2016-2464

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2496

Open SourcePoC exploitHIGH2016-06-07

The Framework UI permission-dialog implementation in Android 6.x before 2016-06-01 allows attackers to conduct tapjacking attacks and access arbitrary private-storage files by creating a partially overlapping window, aka internal bug 26677796.

CVEs:CVE-2016-2496

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2463

Open SourcePoC exploitCRITICAL2016-06-07

Multiple integer overflows in the h264dec component in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allow remote attackers to execute arbitrary code or cause a denial of se...

CVEs:CVE-2016-2463

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2476

Open SourcePoC exploitHIGH2016-06-07

mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate OMX buffer sizes, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature o...

CVEs:CVE-2016-2476

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2468

Open SourcePoC exploitHIGH2016-06-07

The Qualcomm GPU driver in Android before 2016-06-01 on Nexus 5, 5X, 6, 6P, and 7 devices allows attackers to gain privileges via a crafted application, aka internal bug 27475454.

CVEs:CVE-2016-2468

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2473

Open SourcePoC exploitCRITICAL2016-06-07

The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 27777501.

CVEs:CVE-2016-2473

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2469

Open SourcePoC exploitHIGH2016-06-07

The Qualcomm sound driver in Android before 2016-06-01 on Nexus 5, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 27531992.

CVEs:CVE-2016-2469

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2495

Open SourcePoC exploitHIGH2016-06-07

SampleTable.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows remote attackers to cause a denial of service (device hang or reboot) via a crafted file, aka interna...

CVEs:CVE-2016-2495

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2475

Open SourcePoC exploitHIGH2016-06-07

The Broadcom Wi-Fi driver in Android before 2016-06-01 on Nexus 5, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and Pixel C devices allows attackers to gain privileges for certain system calls via a crafted application, aka internal bug 26...

CVEs:CVE-2016-2475

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2465

Open SourcePoC exploitHIGH2016-06-07

The Qualcomm video driver in Android before 2016-06-01 on Nexus 5, 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 27407865.

CVEs:CVE-2016-2465

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2474

Open SourcePoC exploitHIGH2016-06-07

The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 5X devices allows attackers to gain privileges via a crafted application, aka internal bug 27424603.

CVEs:CVE-2016-2474

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2489

Open SourcePoC exploitHIGH2016-06-07

The Qualcomm video driver in Android before 2016-06-01 on Nexus 5, 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 27407629.

CVEs:CVE-2016-2489

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2481

Open SourcePoC exploitHIGH2016-06-07

The mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 mishandles a buffer count, which allows attackers to gain privileges via a crafted application, as demonstrat...

CVEs:CVE-2016-2481

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2487

Open SourcePoC exploitHIGH2016-06-07

libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem acce...

CVEs:CVE-2016-2487

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2477

Open SourcePoC exploitHIGH2016-06-07

mm-video-v4l2/vidc/vdec/src/omx_vdec_msm8974.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 mishandles pointers, which allows attackers to gain privileges via a crafted application, as ...

CVEs:CVE-2016-2477

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2479

Open SourcePoC exploitHIGH2016-06-07

The mm-video-v4l2 vdec component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 mishandles a buffer count, which allows attackers to gain privileges via a crafted application, as demonstrat...

CVEs:CVE-2016-2479

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2466

Open SourcePoC exploitHIGH2016-06-07

The Qualcomm sound driver in Android before 2016-06-01 on Nexus 6 devices allows attackers to gain privileges via a crafted application, aka internal bug 27947307.

CVEs:CVE-2016-2466

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2467

Open SourcePoC exploitHIGH2016-06-07

The Qualcomm sound driver in Android before 2016-06-01 on Nexus 5 devices allows attackers to gain privileges via a crafted application, aka internal bug 28029010.

CVEs:CVE-2016-2467

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2470

Open SourcePoC exploitHIGH2016-06-07

The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 27662174.

CVEs:CVE-2016-2470

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2471

Open SourcePoC exploitHIGH2016-06-07

The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 27773913.

CVEs:CVE-2016-2471

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2472

Open SourcePoC exploitHIGH2016-06-07

The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 27776888.

CVEs:CVE-2016-2472

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2490

Open SourcePoC exploitHIGH2016-06-07

The NVIDIA camera driver in Android before 2016-06-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27533373.

CVEs:CVE-2016-2490

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2478

Open SourcePoC exploitHIGH2016-06-07

mm-video-v4l2/vidc/vdec/src/omx_vdec_msm8974.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 mishandles pointers, which allows attackers to gain privileges via a crafted application, as ...

CVEs:CVE-2016-2478

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2480

Open SourcePoC exploitHIGH2016-06-07

The mm-video-v4l2 vidc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate certain OMX parameter data structures, which allows attackers to gain privileges via a craf...

CVEs:CVE-2016-2480

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2482

Open SourcePoC exploitHIGH2016-06-07

The mm-video-v4l2 vdec component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 mishandles a buffer count, which allows attackers to gain privileges via a crafted application, as demonstrat...

CVEs:CVE-2016-2482

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2483

Open SourcePoC exploitHIGH2016-06-07

The mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 mishandles a buffer count, which allows attackers to gain privileges via a crafted application, as demonstrat...

CVEs:CVE-2016-2483

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2484

Open SourcePoC exploitHIGH2016-06-07

libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate OMX buffer sizes for the GSM and G711 codecs, which allows attackers to gain privileges via a crafted applica...

CVEs:CVE-2016-2484

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2485

Open SourcePoC exploitHIGH2016-06-07

libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate OMX buffer sizes for the GSM and G711 codecs, which allows attackers to gain privileges via a crafted applica...

CVEs:CVE-2016-2485

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2491

Open SourcePoC exploitHIGH2016-06-07

The NVIDIA camera driver in Android before 2016-06-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27556408.

CVEs:CVE-2016-2491

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2488

Open SourcePoC exploitHIGH2016-06-07

The Qualcomm camera driver in Android before 2016-06-01 on Nexus 5, 5X, 6, 6P, and 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 27600832.

CVEs:CVE-2016-2488

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2492

Open SourcePoC exploitHIGH2016-06-07

The MediaTek power-management driver in Android before 2016-06-01 on Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 28085410.

CVEs:CVE-2016-2492

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2493

Open SourcePoC exploitHIGH2016-06-07

The Broadcom Wi-Fi driver in Android before 2016-06-01 on Nexus 5, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus Player, and Pixel C devices allows attackers to gain privileges via a crafted application, aka internal bug 26571522.

CVEs:CVE-2016-2493

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2486

Open SourcePoC exploitHIGH2016-06-07

mp3dec/SoftMP3.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate the relationship between allocated memory and the frame size, which allows attackers to...

CVEs:CVE-2016-2486

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-8467

Open SourcePoC exploitHIGH2016-06-29

An elevation of privilege vulnerability in the bootloader could enable a local attacker to execute arbitrary modem commands on the device. This issue is rated as High because it is a local permanent denial of service (device interoperability: completel...

CVEs:CVE-2016-8467

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2499

Open SourcePoC exploitCRITICAL2016-06-07

AudioSource.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not initialize certain data, which allows attackers to obtain sensitive information via a crafted appli...

CVEs:CVE-2016-2499

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2500

Open SourcePoC exploitHIGH2016-06-07

Activity Manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not properly terminate process groups, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 19285814.

CVEs:CVE-2016-2500

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2498

Open SourcePoC exploitMEDIUM2016-06-07

The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to bypass intended data-access restrictions via a crafted application, aka internal bug 27777162.

CVEs:CVE-2016-2498

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5300

Open SourceEPSS <= 49%HIGH2016-06-07

The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists becaus...

CVEs:CVE-2016-5300

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
libexpat affected libexpat_project
ubuntu_linux affected canonical
Upstream advisory

MGASA-2016-0214

Open SourceEPSS <= 49%CRITICAL2016-06-02

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

CVE-2012-6702

Open SourceEPSS <= 49%MEDIUM2016-06-16

Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.

CVEs:CVE-2012-6702

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
libexpat affected libexpat_project
ubuntu_linux affected canonical
Upstream advisory

MGASA-2016-0218

Open SourceEPSS <= 49%CRITICAL2016-06-07

Updated chromium-browser-stable/libpng packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
libpng affected Mageia:5 libpng
Upstream advisory

DSA-3594-1

Open SourceEPSS <= 49%2016-06-04

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:8 chromium-browser
Upstream advisory

CVE-2016-1697

GoogleEPSS <= 49%CRITICAL2016-06-02

The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass...

CVEs:CVE-2016-1697

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-1699

GoogleEPSS <= 49%CRITICAL2016-06-02

WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl parameter is associated with a chrome-devtools-frontend.apps...

CVEs:CVE-2016-1699

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-1696

GoogleEPSS <= 49%HIGH2016-06-02

The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

CVEs:CVE-2016-1696

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
Upstream advisory

CVE-2016-1702

GoogleEPSS <= 49%HIGH2016-06-02

The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval count, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted serializ...

CVEs:CVE-2016-1702

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-1703

GoogleEPSS <= 49%HIGH2016-06-02

Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2016-1703

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-1700

GoogleEPSS <= 49%CRITICAL2016-06-02

extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not consider side effects during creation of an array of extension views, which allows remote attackers to cause a denial of service (use-after-free) or possibly h...

CVEs:CVE-2016-1700

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
Upstream advisory

MGASA-2016-0231

Open SourceEPSS <= 49%2016-06-22

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

CVE-2016-1704

GoogleEPSS <= 49%HIGH2016-06-17

Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.103 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2016-1704

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
opensuse affected opensuse
suse_package_hub_for_suse_linux_enterprise affected novell
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-1698

GoogleEPSS <= 49%CRITICAL2016-06-02

The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which might allow attackers to load arbitrary modules or obtain sensitive informati...

CVEs:CVE-2016-1698

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
Upstream advisory

CVE-2016-1701

GoogleEPSS <= 49%CRITICAL2016-06-02

The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibl...

CVEs:CVE-2016-1701

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected opensuse
linux_enterprise affected suse
opensuse affected opensuse
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.