Google Security Advisories · September 2016 — Google Security Advisories
87 advisories 86 CVEs 8 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2016-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 8 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2016-3351

Project ZeroExploitedCISA KEV listed2016-09-14

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

CVEs:CVE-2016-3351

Upstream advisory

CVE-2016-3351

GoogleExploitedCISA KEV listedHIGH2016-09-14

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

CVEs:CVE-2016-3351

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
internet_explorer affected microsoft
Upstream advisory

MGASA-2016-0309

Open SourceExploitedVulnCheck KEV listedHIGH2016-09-21

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

DSA-3660-1

Open SourceExploitedVulnCheck KEV listed2016-09-05

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:8 chromium-browser
Upstream advisory

openSUSE-SU-2016:2250-1

Open SourceExploitedVulnCheck KEV listedCRITICAL2016-09-01

Security update for Chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 chromium
Upstream advisory

SUSE-SU-2016:2250-1

Open SourceExploitedVulnCheck KEV listedCRITICAL2016-09-01

Security update for Chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 chromium
Upstream advisory

SUSE-SU-2016:2251-1

Open SourceExploitedVulnCheck KEV listedCRITICAL2016-09-01

Security update for Chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 chromium
Upstream advisory

CVE-2016-5165

GoogleExploitedVulnCheck KEV listedCRITICAL2016-09-01

Cross-site scripting (XSS) vulnerability in the Developer Tools (aka DevTools) subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allows remote attackers to inject arbitrary web script or HTML via the se...

CVEs:CVE-2016-5165

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2016-3861

Open SourceWeaponized exploitCRITICAL2016-09-11

DEBIAN-CVE-2016-3861

Affected products

ProductStatusVendorPackageEcosystem
android-platform-system-core affected Debian:11 android-platform-system-core
Upstream advisory

CVE-2016-3861

Open SourceWeaponized exploitHIGH2016-09-07

LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 mishandles conversions between Unicode character encodings with different encoding widths, which allows remote attackers to e...

CVEs:CVE-2016-3861

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MGASA-2016-0317

Open SourceWeaponized exploit2016-09-23

Updated golang package fixes security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:5 golang
Upstream advisory

CVE-2016-5157

GooglePoC exploitCRITICAL2016-09-01

Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to execute arbitrary code via cra...

CVEs:CVE-2016-5157

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2016-3862

Open SourcePoC exploitHIGH2016-09-07

media/ExifInterface.java in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 does not properly interact with the use of static variables in libjhead_jni, which allows remote attackers to execute...

CVEs:CVE-2016-3862

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3885

Open SourcePoC exploitHIGH2016-09-07

debuggerd/debuggerd.cpp in Debuggerd in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 mishandles the interaction between PTRACE_ATTACH operations and thread exits, which allows attackers to gain privil...

CVEs:CVE-2016-3885

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3863

Open SourcePoC exploitCRITICAL2016-09-07

Multiple stack-based buffer overflows in the AVCC reassembly implementation in Utils.cpp in libstagefright in MediaMuxer in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allow remote ...

CVEs:CVE-2016-3863

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3871

Open SourcePoC exploitHIGH2016-09-07

Multiple buffer overflows in codecs/mp3dec/SoftMP3.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allow attackers to gain privileges via a craft...

CVEs:CVE-2016-3871

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3881

Open SourcePoC exploitHIGH2016-09-07

The decoder_peek_si_internal function in vp9/vp9_dx_iface.c in libvpx in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows remote attackers to cause a denial of serv...

CVEs:CVE-2016-3881

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3874

Open SourcePoC exploitHIGH2016-09-07

CORE/HDD/src/wlan_hdd_wext.c in the Qualcomm Wi-Fi driver in Android before 2016-09-05 on Nexus 5X devices does not properly validate the arguments array, which allows attackers to gain privileges via a crafted application that sends a WE_UNIT_TEST_CMD...

CVEs:CVE-2016-3874

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3867

Open SourcePoC exploitHIGH2016-09-07

The Qualcomm IPA driver in Android before 2016-09-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28919863 and Qualcomm internal bug CR1037897.

CVEs:CVE-2016-3867

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3880

Open SourcePoC exploitCRITICAL2016-09-07

Multiple buffer overflows in rtsp/ASessionDescription.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allow remote attackers to cause a denial of...

CVEs:CVE-2016-3880

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2016-3890

Open SourcePoC exploitHIGH2016-09-11

DEBIAN-CVE-2016-3890

Affected products

ProductStatusVendorPackageEcosystem
android-platform-system-core affected Debian:11 android-platform-system-core
Upstream advisory

CVE-2016-3890

Open SourcePoC exploitHIGH2016-09-07

The Java Debug Wire Protocol (JDWP) implementation in adb/sockets.cpp in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 mishandles socket close operations, which allows attackers to gain privileges via a cra...

CVEs:CVE-2016-3890

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3879

Open SourcePoC exploitHIGH2016-09-07

arm-wt-22k/lib_src/eas_mdls.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 allows remote attackers to cause a denial of service (NULL pointer dereference, and device hang or reboot) via a...

CVEs:CVE-2016-3879

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3878

Open SourcePoC exploitHIGH2016-09-07

decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-09-01 mishandles the case of decoding zero MBs, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 29493002.

CVEs:CVE-2016-3878

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3899

Open SourcePoC exploitHIGH2016-09-07

OMXCodec.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 does not validate a certain pointer, which allows remote attackers to cause a denial of ...

CVEs:CVE-2016-3899

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3873

Open SourcePoC exploitHIGH2016-09-07

The NVIDIA kernel in Android before 2016-09-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 29518457.

CVEs:CVE-2016-3873

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3868

Open SourcePoC exploitHIGH2016-09-07

The Qualcomm power driver in Android before 2016-09-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28967028 and Qualcomm internal bug CR1032875.

CVEs:CVE-2016-3868

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3869

Open SourcePoC exploitHIGH2016-09-07

The Broadcom Wi-Fi driver in Android before 2016-09-05 on Nexus 5, Nexus 6, Nexus 6P, Nexus 9, Nexus Player, and Pixel C devices allows attackers to gain privileges via a crafted application, aka Android internal bug 29009982 and Broadcom internal bug ...

CVEs:CVE-2016-3869

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3897

Open SourcePoC exploitHIGH2016-09-07

The WifiEnterpriseConfig class in net/wifi/WifiEnterpriseConfig.java in Wi-Fi in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 includes a password in the return value of a toString method call, which allows...

CVEs:CVE-2016-3897

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3872

Open SourcePoC exploitHIGH2016-09-07

Buffer overflow in codecs/on2/dec/SoftVPX.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows attackers to gain privileges via a crafted appli...

CVEs:CVE-2016-3872

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3865

Open SourcePoC exploitHIGH2016-09-07

The Synaptics touchscreen driver in Android before 2016-09-05 on Nexus 5X and 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28799389.

CVEs:CVE-2016-3865

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3858

Open SourcePoC exploitHIGH2016-09-07

Buffer overflow in drivers/soc/qcom/subsystem_restart.c in the Qualcomm subsystem driver in Android before 2016-09-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application that provides a long string, aka Android inte...

CVEs:CVE-2016-3858

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3870

Open SourcePoC exploitHIGH2016-09-07

omx/SimpleSoftOMXComponent.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 does not prevent input-port changes, which allows attackers to gain pr...

CVEs:CVE-2016-3870

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3893

Open SourcePoC exploitHIGH2016-09-07

The wcdcal_hwdep_ioctl_shared function in sound/soc/codecs/wcdcal-hwdep.c in the Qualcomm sound codec in Android before 2016-09-05 on Nexus 6P devices does not properly copy firmware data, which allows attackers to obtain sensitive information via a cr...

CVEs:CVE-2016-3893

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3892

Open SourcePoC exploitHIGH2016-09-07

The Qualcomm SPMI driver in Android before 2016-09-05 on Nexus 5, 5X, 6, and 6P devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28760543 and Qualcomm internal bug CR1024197.

CVEs:CVE-2016-3892

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3896

Open SourcePoC exploitMEDIUM2016-09-07

AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 allows attackers to obtain sensitive EmailAccountCacheProvider information via a crafted application, aka internal bug 29767043.

CVEs:CVE-2016-3896

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3887

Open SourcePoC exploitCRITICAL2016-09-07

providers/settings/SettingsProvider.java in Android 7.0 before 2016-09-01 does not properly enforce the DISALLOW_CONFIG_VPN setting, which allows attackers to bypass an intended always-on VPN state via a crafted application, aka internal bug 29899712.

CVEs:CVE-2016-3887

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3859

Open SourcePoC exploitHIGH2016-09-07

The Qualcomm camera driver in Android before 2016-09-05 on Nexus 5, 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28815326 and Qualcomm internal bug CR1034641.

CVEs:CVE-2016-3859

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3864

Open SourcePoC exploitHIGH2016-09-07

The Qualcomm radio interface layer in Android before 2016-09-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28823714 and Qualcomm internal bug ...

CVEs:CVE-2016-3864

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3866

Open SourcePoC exploitHIGH2016-09-07

The Qualcomm sound driver in Android before 2016-09-05 on Nexus 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28868303 and Qualcomm internal bug CR1032820.

CVEs:CVE-2016-3866

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3895

Open SourcePoC exploitCRITICAL2016-09-07

Integer overflow in the Region::unflatten function in libs/ui/Region.cpp in mediaserver in Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 29983260.

CVEs:CVE-2016-3895

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3883

Open SourcePoC exploitMEDIUM2016-09-07

internal/telephony/SMSDispatcher.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 does not properly construct warnings about premium SMS messages, which allows attac...

CVEs:CVE-2016-3883

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3884

Open SourcePoC exploitMEDIUM2016-09-07

server/notification/NotificationManagerService.java in the Notification Manager Service in Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 lacks uid checks, which allows attackers to bypass intended restrictions on method calls via a crafted ap...

CVEs:CVE-2016-3884

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3898

Open SourcePoC exploitHIGH2016-09-07

Telephony in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows attackers to cause a denial of service (loss of locked-screen 911 TTY functionality) via a crafted application that modifies the TTY mo...

CVEs:CVE-2016-3898

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3894

Open SourcePoC exploitHIGH2016-09-07

The Qualcomm DMA component in Android before 2016-09-05 on Nexus 6 devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 29618014 and Qualcomm internal bug CR1042033.

CVEs:CVE-2016-3894

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3889

Open SourcePoC exploitHIGH2016-09-07

Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism by accessing (1) an external tile from a system application, (2) the help feature, or (3) the Sett...

CVEs:CVE-2016-3889

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3876

Open SourcePoC exploitHIGH2016-09-07

providers/settings/SettingsProvider.java in Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 allows physically proximate attackers to bypass the SAFE_BOOT_DISALLOWED protection mechanism and boot to safe mode via the Android Debug Bridge (adb) t...

CVEs:CVE-2016-3876

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3886

Open SourcePoC exploitHIGH2016-09-07

systemui/statusbar/phone/QuickStatusBarHeader.java in the System UI Tuner in Android 7.0 before 2016-09-01 does not prevent tuner changes on the lockscreen, which allows physically proximate attackers to gain privileges by modifying a setting, aka inte...

CVEs:CVE-2016-3886

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3875

Open SourcePoC exploitCRITICAL2016-09-07

server/wm/WindowManagerService.java in Android 6.x before 2016-09-01 does not enforce the DISALLOW_SAFE_BOOT setting, which allows physically proximate attackers to bypass intended access restrictions and boot to safe mode via unspecified vectors, aka ...

CVEs:CVE-2016-3875

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3888

Open SourcePoC exploitLOW2016-09-07

internal/telephony/SMSDispatcher.java in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanis...

CVEs:CVE-2016-3888

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-7152

GoogleEPSS <= 49%CRITICAL2016-09-06

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party...

CVEs:CVE-2016-7152

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge affected microsoft
firefox affected mozilla
internet_explorer affected microsoft
opera affected opera
safari affected apple
Upstream advisory

CVE-2016-7153

GoogleEPSS <= 49%CRITICAL2016-09-06

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-part...

CVEs:CVE-2016-7153

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge affected microsoft
firefox affected mozilla
internet_explorer affected microsoft
opera_browser affected opera
safari affected apple
Upstream advisory

CVE-2016-5159

GoogleEPSS <= 49%CRITICAL2016-09-01

Multiple integer overflows in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspe...

CVEs:CVE-2016-5159

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
Upstream advisory

DSA-3667-1

Open SourceEPSS <= 49%2016-09-15

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:8 chromium-browser
Upstream advisory

openSUSE-SU-2016:2309-1

Open SourceEPSS <= 49%CRITICAL2016-09-14

Recommended update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 chromium
Upstream advisory

openSUSE-SU-2016:2311-1

Open SourceEPSS <= 49%CRITICAL2016-09-14

Recommended update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 chromium
Upstream advisory

CVE-2016-5172

GoogleEPSS <= 49%HIGH2016-09-14

The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code.

CVEs:CVE-2016-5172

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
node.js affected nodejs
Upstream advisory

CVE-2016-5178

GoogleEPSS <= 49%CRITICAL2016-09-30

Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.143 allow remote attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2016-5178

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_server_supplementary affected redhat
enterprise_linux_workstation_supplementary affected redhat
fedora affected fedoraproject
leap affected opensuse
opensuse affected opensuse
Upstream advisory

CVE-2016-5152

GoogleEPSS <= 49%CRITICAL2016-09-01

Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to cause a denial of service (heap...

CVEs:CVE-2016-5152

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
Upstream advisory

CVE-2016-5158

GoogleEPSS <= 49%CRITICAL2016-09-01

Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service (heap-ba...

CVEs:CVE-2016-5158

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
Upstream advisory

CVE-2016-5160

GoogleEPSS <= 49%HIGH2016-09-01

The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly use an extension's manifest.json web_accessible_resources ...

CVEs:CVE-2016-5160

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
Upstream advisory

CVE-2016-5154

GoogleEPSS <= 49%CRITICAL2016-09-01

Multiple heap-based buffer overflows in PDFium, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a craft...

CVEs:CVE-2016-5154

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
Upstream advisory

CVE-2016-5161

GoogleEPSS <= 49%CRITICAL2016-09-01

The EditingStyle::mergeStyle function in WebKit/Source/core/editing/EditingStyle.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles custom properties, which allows remote attacker...

CVEs:CVE-2016-5161

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
Upstream advisory

CVE-2016-5162

GoogleEPSS <= 49%HIGH2016-09-01

The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly use an extension's manifest.json web_accessible_resources ...

CVEs:CVE-2016-5162

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
Upstream advisory

CVE-2016-5151

GoogleEPSS <= 49%CRITICAL2016-09-01

PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux mishandles timers, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted PDF ...

CVEs:CVE-2016-5151

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
Upstream advisory

CVE-2016-5167

GoogleEPSS <= 49%HIGH2016-09-05

Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2016-5167

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
Upstream advisory

CVE-2016-5149

GoogleEPSS <= 49%CRITICAL2016-09-01

The extensions subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux relies on an IFRAME source URL to identify an associated extension, which allows remote attackers to conduct extension-bindings injection...

CVEs:CVE-2016-5149

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
Upstream advisory

CVE-2016-5147

GoogleEPSS <= 49%CRITICAL2016-09-01

Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles deferred page loads, which allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (U...

CVEs:CVE-2016-5147

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5150

GoogleEPSS <= 49%CRITICAL2016-09-01

WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, has an Indexed Database (aka IndexedDB) API implementation that does not properly res...

CVEs:CVE-2016-5150

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
Upstream advisory

CVE-2016-5156

GoogleEPSS <= 49%CRITICAL2016-09-01

extensions/renderer/event_bindings.cc in the event bindings in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux attempts to process filtered events after failure to add an event matcher, which allows remote attacke...

CVEs:CVE-2016-5156

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
Upstream advisory

CVE-2016-5177

GoogleEPSS <= 49%CRITICAL2016-09-30

Use-after-free vulnerability in V8 in Google Chrome before 53.0.2785.143 allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2016-5177

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_server_supplementary affected redhat
enterprise_linux_workstation_supplementary affected redhat
fedora affected fedoraproject
leap affected opensuse
opensuse affected opensuse
Upstream advisory

CVE-2016-5166

GoogleEPSS <= 49%LOW2016-09-01

The download implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly restrict saving a file:// URL that is referenced by an http:// URL, which makes it easier for user-assisted remote a...

CVEs:CVE-2016-5166

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
Upstream advisory

CVE-2016-5148

GoogleEPSS <= 49%CRITICAL2016-09-01

Cross-site scripting (XSS) vulnerability in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web script or HTML via vectors related to widget updates, ...

CVEs:CVE-2016-5148

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5163

GoogleEPSS <= 49%MEDIUM2016-09-01

The bidirectional-text implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not ensure left-to-right (LTR) rendering of URLs, which allows remote attackers to spoof the address bar via crafted ri...

CVEs:CVE-2016-5163

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
Upstream advisory

CVE-2016-5155

GoogleEPSS <= 49%MEDIUM2016-09-01

Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly validate access to the initial document, which allows remote attackers to spoof the address bar via a crafted web site.

CVEs:CVE-2016-5155

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
Upstream advisory

CVE-2016-5170

GoogleEPSS <= 49%CRITICAL2016-09-14

WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not properly consider getter side effects during array key conversion, which allows remote attackers to cause a denial of service (u...

CVEs:CVE-2016-5170

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5171

GoogleEPSS <= 49%CRITICAL2016-09-14

WebKit/Source/bindings/templates/interface.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not prevent certain constructor calls, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified...

CVEs:CVE-2016-5171

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5153

GoogleEPSS <= 49%HIGH2016-09-01

The Web Animations implementation in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, improperly relies on list iteration, which allows remote attackers to cause a denial of service (use-after-de...

CVEs:CVE-2016-5153

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
Upstream advisory

CVE-2016-7395

GoogleEPSS <= 49%HIGH2016-09-11

SkPath.cpp in Skia, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, does not properly validate the return values of ChopMonoAtY calls, which allows remote attackers to cause a denial of service (uninit...

CVEs:CVE-2016-7395

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-7549

GoogleEPSS <= 49%HIGH2016-09-25

Google Chrome before 53.0.2785.113 does not ensure that the recipient of a certain IPC message is a valid RenderFrame or RenderWidget, which allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) or pos...

CVEs:CVE-2016-7549

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5164

GoogleEPSS <= 49%CRITICAL2016-09-01

Cross-site scripting (XSS) vulnerability in WebKit/Source/platform/v8_inspector/V8Debugger.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web ...

CVEs:CVE-2016-5164

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
Upstream advisory

CVE-2016-5175

GoogleEPSS <= 49%HIGH2016-09-14

Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.113 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2016-5175

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5173

GoogleEPSS <= 49%CRITICAL2016-09-14

The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers to load unintended resources, and consequently trigger unintended JavaScript function calls and bypass t...

CVEs:CVE-2016-5173

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5169

GoogleEPSS <= 49%HIGH2016-09-25

Format string vulnerability in Google Chrome OS before 53.0.2785.103 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2016-5169

Affected products

ProductStatusVendorPackageEcosystem
chrome_os affected google
Upstream advisory

CVE-2016-5174

GoogleEPSS <= 49%HIGH2016-09-14

browser/ui/cocoa/browser_window_controller_private.mm in Google Chrome before 53.0.2785.113 does not process fullscreen toggle requests during a fullscreen transition, which allows remote attackers to cause a denial of service (unsuppressed popup) via ...

CVEs:CVE-2016-5174

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5176

GoogleEPSS <= 49%MEDIUM2016-09-29

Google Chrome before 53.0.2785.113 allows remote attackers to bypass the SafeBrowsing protection mechanism via unspecified vectors.

CVEs:CVE-2016-5176

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-3877

Open SourceEPSS <= 49%HIGH2016-09-11

Unspecified vulnerability in Android before 2016-09-01 has unknown impact and attack vectors.

CVEs:CVE-2016-3877

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.