Google Security Advisories · October 2016 — Google Security Advisories
108 advisories 103 CVEs 11 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2016-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 11 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2016-5195

GoogleExploitedCISA KEV listedHIGH2016-10-19

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in Octo...

CVEs:CVE-2016-5195

Affected products

ProductStatusVendorPackageEcosystem
cloud_backup affected netapp
debian_linux affected debian
enterprise_linux affected redhat
enterprise_linux_aus affected redhat
enterprise_linux_eus affected redhat
enterprise_linux_long_life affected redhat
enterprise_linux_tus affected redhat
fedora affected fedoraproject
hci_storage_nodes affected netapp
linux_kernel affected linux
oncommand_balance affected netapp
oncommand_performance_manager affected netapp
oncommand_unified_manager_for_clustered_data_ontap affected netapp
ontap_select_deploy_administration_utility affected netapp
pan-os affected paloaltonetworks
snapprotect affected netapp
solidfire affected netapp
ubuntu_linux affected canonical
Upstream advisory

CVE-2016-5195

Project ZeroExploitedCISA KEV listed2016-10-19

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."

CVEs:CVE-2016-5195

Upstream advisory

CVE-2016-3393

GoogleExploitedCISA KEV listedHIGH2016-10-12

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to ...

CVEs:CVE-2016-3393

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1511 affected microsoft
windows_10_1607 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_vista affected microsoft
Upstream advisory

CVE-2016-3393

Project ZeroExploitedCISA KEV listed2016-10-12

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Component RCE Vulnerability."

CVEs:CVE-2016-3393

Upstream advisory

CVE-2016-7193

Project ZeroExploitedCISA KEV listed2016-10-12

Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, Office Web Apps Server 2013 SP1, and Office Online Server allow remote attackers to execute arbitrary code via a crafted RTF document, aka "Microsoft Office Memory Corruption Vulnerability."

CVEs:CVE-2016-7193

Upstream advisory

CVE-2016-7193

GoogleExploitedCISA KEV listedHIGH2016-10-12

Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on ...

CVEs:CVE-2016-7193

Affected products

ProductStatusVendorPackageEcosystem
office affected microsoft
office_compatibility_pack affected microsoft
word affected microsoft
word_viewer affected microsoft
Upstream advisory

CVE-2016-3298

GoogleExploitedCISA KEV listedHIGH2016-10-12

Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka "Intern...

CVEs:CVE-2016-3298

Affected products

ProductStatusVendorPackageEcosystem
internet_explorer affected microsoft
windows_7 affected microsoft
windows_server_2008 affected microsoft
windows_vista affected microsoft
Upstream advisory

CVE-2016-3298

Project ZeroExploitedCISA KEV listed2016-10-12

Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."

CVEs:CVE-2016-3298

Upstream advisory

CVE-2016-7855

Project ZeroExploitedCISA KEV listed2016-10-27

Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.

CVEs:CVE-2016-7855

Upstream advisory

CVE-2016-7855

GoogleExploitedCISA KEV listedHIGH2016-10-27

Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.

CVEs:CVE-2016-7855

Affected products

ProductStatusVendorPackageEcosystem
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
flash_player affected adobe
Upstream advisory

CVE-2016-5348

Open SourceWeaponized exploitHIGH2016-10-04

The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows man-in-the-middle attackers to cause a denial of service (memory consumption, and device hang or reboot) via ...

CVEs:CVE-2016-5348

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6689

Open SourceWeaponized exploitHIGH2016-10-04

Binder in the kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30768347.

CVEs:CVE-2016-6689

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3926

Open SourcePoC exploitHIGH2016-10-04

Unspecified vulnerability in a Qualcomm component in Android before 2016-10-05 on Nexus 5, 5X, 6, and 6P devices has unknown impact and attack vectors, aka internal bug 28823953.

CVEs:CVE-2016-3926

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3920

Open SourcePoC exploitHIGH2016-10-04

id3/ID3.cpp in libstagefright in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows remote attackers to cause a denial of service (device hang or reboot) via a crafted file, aka intern...

CVEs:CVE-2016-3920

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3927

Open SourcePoC exploitHIGH2016-10-04

Unspecified vulnerability in a Qualcomm component in Android before 2016-10-05 on Nexus 5X and 6P devices has unknown impact and attack vectors, aka internal bug 28823244.

CVEs:CVE-2016-3927

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3929

Open SourcePoC exploitHIGH2016-10-04

Unspecified vulnerability in a Qualcomm component in Android before 2016-10-05 on Nexus 5X and 6P devices has unknown impact and attack vectors, aka internal bug 28823675.

CVEs:CVE-2016-3929

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3934

Open SourcePoC exploitHIGH2016-10-04

drivers/media/platform/msm/camera_v2/sensor/io/msm_camera_cci_i2c.c in the Qualcomm camera driver in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, and Android One devices relies on variable-length arrays, which allows attackers to ...

CVEs:CVE-2016-3934

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3903

Open SourcePoC exploitHIGH2016-10-04

drivers/media/platform/msm/camera_v2/sensor/csid/msm_csid.c in the Qualcomm camera driver in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allows attackers to gain privileges via a crafted application, aka A...

CVEs:CVE-2016-3903

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3931

Open SourcePoC exploitHIGH2016-10-04

drivers/misc/qseecom.c in the Qualcomm QSEE Communicator driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 29157595 and Qu...

CVEs:CVE-2016-3931

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3900

Open SourcePoC exploitHIGH2016-10-04

cmds/servicemanager/service_manager.c in ServiceManager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 does not properly restrict service registration, which allows attackers to gain privileges via a...

CVEs:CVE-2016-3900

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3909

Open SourcePoC exploitHIGH2016-10-04

The SoftMPEG4 component in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application, aka internal b...

CVEs:CVE-2016-3909

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3935

Open SourcePoC exploitHIGH2016-10-04

Multiple integer overflows in drivers/crypto/msm/qcedev.c in the Qualcomm cryptographic engine driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allow attackers to gain privileges via a crafted application, aka...

CVEs:CVE-2016-3935

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3938

Open SourcePoC exploitHIGH2016-10-04

drivers/video/msm/mdss/mdss_mdp_overlay.c in the Qualcomm video driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 30019716...

CVEs:CVE-2016-3938

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3912

Open SourcePoC exploitHIGH2016-10-04

The framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allow attackers to gain privileges via a crafted application, aka internal bug 30202481.

CVEs:CVE-2016-3912

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3913

Open SourcePoC exploitHIGH2016-10-04

media/libmediaplayerservice/MediaPlayerService.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 does not validate a certain static_cast operation, which allows atta...

CVEs:CVE-2016-3913

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3915

Open SourcePoC exploitHIGH2016-10-04

camera/src/camera_metadata.c in the Camera service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 305...

CVEs:CVE-2016-3915

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3916

Open SourcePoC exploitHIGH2016-10-04

camera/src/camera_metadata.c in the Camera service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 307...

CVEs:CVE-2016-3916

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3921

Open SourcePoC exploitHIGH2016-10-04

libsysutils/src/FrameworkListener.cpp in Framework Listener in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application, aka interna...

CVEs:CVE-2016-3921

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3911

Open SourcePoC exploitHIGH2016-10-04

core/java/android/os/Process.java in Zygote in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 30143607.

CVEs:CVE-2016-3911

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3901

Open SourcePoC exploitHIGH2016-10-04

Multiple integer overflows in drivers/crypto/msm/qcedev.c in the Qualcomm cryptographic engine driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allow attackers to gain privileges via a crafted application, aka...

CVEs:CVE-2016-3901

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3905

Open SourcePoC exploitHIGH2016-10-04

CORE/HDD/src/wlan_hdd_main.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X devices allows attackers to gain privileges via a crafted application that sends a SENDACTIONFRAME command, aka Android internal bug 28061823 and Qualcom...

CVEs:CVE-2016-3905

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3928

Open SourcePoC exploitHIGH2016-10-04

The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 30019362 and MediaTek internal bug ALPS02829384.

CVEs:CVE-2016-3928

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3936

Open SourcePoC exploitHIGH2016-10-04

The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 30019037 and MediaTek internal bug ALPS02829568.

CVEs:CVE-2016-3936

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3937

Open SourcePoC exploitHIGH2016-10-04

The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 30030994 and MediaTek internal bug ALPS02834874.

CVEs:CVE-2016-3937

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8951

Open SourcePoC exploitHIGH2016-10-04

Multiple use-after-free vulnerabilities in sound/soc/msm/qdsp6v2/msm-lsm-client.c in the Qualcomm sound driver in Android before 2016-10-05 on Nexus 5X, Nexus 6P, and Android One devices allow attackers to gain privileges via a crafted application, aka...

CVEs:CVE-2015-8951

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3902

Open SourcePoC exploitHIGH2016-10-04

drivers/platform/msm/ipa/ipa_qmi_service.c in the Qualcomm IPA driver in Android before 2016-10-05 on Nexus 5X and 6P devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 29953313 and Qualcomm int...

CVEs:CVE-2016-3902

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3923

Open SourcePoC exploitMEDIUM2016-10-04

The Accessibility services in Android 7.0 before 2016-10-01 mishandle motion events, which allows attackers to conduct touchjacking attacks and consequently gain privileges via a crafted application, aka internal bug 30647115.

CVEs:CVE-2016-3923

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3918

Open SourcePoC exploitHIGH2016-10-03

email/provider/AttachmentProvider.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 does not ensure that certain values are integers, which allows attackers to read a...

CVEs:CVE-2016-3918

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3910

Open SourcePoC exploitHIGH2016-10-04

services/soundtrigger/SoundTriggerHwService.cpp in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 30148546.

CVEs:CVE-2016-3910

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3924

Open SourcePoC exploitHIGH2016-10-04

services/audioflinger/Effects.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 does not validate EFFECT_CMD_SET_PARAM and EFFECT_CMD_SET_PARAM_DEFERRED commands, wh...

CVEs:CVE-2016-3924

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3860

Open SourcePoC exploitHIGH2016-10-04

sound/soc/msm/qdsp6v2/audio_calibration.c in the Qualcomm sound driver in Android before 2016-10-05 on Nexus 5X, Nexus 6P, and Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 2932...

CVEs:CVE-2016-3860

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3882

Open SourcePoC exploitHIGH2016-10-04

Off-by-one error in server/wifi/anqp/VenueNameElement.java in Wi-Fi in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows remote attackers to cause a denial of service (reboot) via an access point that provides a crafted (1) Venue Group or ...

CVEs:CVE-2016-3882

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3939

Open SourcePoC exploitHIGH2016-10-04

drivers/video/msm/mdss/mdss_debug.c in the Qualcomm video driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 30874196 and Q...

CVEs:CVE-2016-3939

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3914

Open SourcePoC exploitHIGH2016-10-04

Race condition in providers/telephony/MmsProvider.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application that...

CVEs:CVE-2016-3914

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3932

Open SourcePoC exploitHIGH2016-10-04

mediaserver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 29161895 and MediaTek internal bug ALPS02770870.

CVEs:CVE-2016-3932

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3933

Open SourcePoC exploitHIGH2016-10-04

mediaserver in Android before 2016-10-05 on Nexus 9 and Pixel C devices allows attackers to gain privileges via a crafted application, aka internal bug 29421408.

CVEs:CVE-2016-3933

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6674

Open SourcePoC exploitHIGH2016-10-04

system_server in Android before 2016-10-05 on Nexus devices allows attackers to gain privileges via a crafted application, aka internal bug 30445380.

CVEs:CVE-2016-6674

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3940

Open SourcePoC exploitHIGH2016-10-04

The Synaptics touchscreen driver in Android before 2016-10-05 on Nexus 6P and Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 30141991.

CVEs:CVE-2016-3940

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6672

Open SourcePoC exploitHIGH2016-10-04

The Synaptics touchscreen driver in Android before 2016-10-05 on Nexus 5X devices allows attackers to gain privileges via a crafted application, aka internal bug 30537088.

CVEs:CVE-2016-6672

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6673

Open SourcePoC exploitHIGH2016-10-04

The NVIDIA camera driver in Android before 2016-10-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 30204201.

CVEs:CVE-2016-6673

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3922

Open SourcePoC exploitHIGH2016-10-04

libril/RilSapSocket.cpp in Telephony in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 relies on variable-length arrays, which allows attackers to gain privileges via a crafted application, aka internal bug 30202619.

CVEs:CVE-2016-3922

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3908

Open SourcePoC exploitMEDIUM2016-10-04

The Lock Settings Service in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows attackers to remove a device's PIN or password, and consequently gain privileges, via a crafted application, aka internal bug 30003944.

CVEs:CVE-2016-3908

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3925

Open SourcePoC exploitHIGH2016-10-04

server/wifi/anqp/ANQPFactory.java in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows attackers to cause a denial of service (blocked Wi-Fi usage) via a crafted application, aka internal bug 30230534.

CVEs:CVE-2016-3925

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3917

Open SourcePoC exploitHIGH2016-10-04

The fingerprint login feature in Android 6.0.1 before 2016-10-01 and 7.0 before 2016-10-01 does not track the user account during the authentication process, which allows physically proximate attackers to authenticate as an arbitrary user by leveraging...

CVEs:CVE-2016-3917

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-1000009

GoogleEPSS <= 49%CRITICAL2016-10-06

Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05

CVEs:CVE-2015-1000009

Affected products

ProductStatusVendorPackageEcosystem
google-adsense-and-hotel-booking affected google-adsense-and-hotel-booking_project
Upstream advisory

CVE-2016-7990

Open SourceEPSS <= 49%HIGH2016-10-31

On Samsung Galaxy S4 through S7 devices, an integer overflow condition exists within libomacp.so when parsing OMACP messages (within WAP Push SMS messages) leading to a heap corruption that can result in Denial of Service and potentially remote code ex...

CVEs:CVE-2016-7990

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

openSUSE-SU-2016:2597-1

Open SourceEPSS <= 49%CRITICAL2016-10-19

Security update for Chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 chromium
Upstream advisory

SUSE-SU-2016:2597-1

Open SourceEPSS <= 49%CRITICAL2016-10-19

Security update for Chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 chromium
Upstream advisory

SUSE-SU-2016:2598-1

Open SourceEPSS <= 49%CRITICAL2016-10-19

Security update for Chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 chromium
Upstream advisory

CVE-2016-5181

GoogleEPSS <= 49%CRITICAL2016-10-13

Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android permitted execution of v8 microtasks while the DOM was in an inconsistent state, which allowed a remote attacker to inject arbitrary scripts or HTML (UXS...

CVEs:CVE-2016-5181

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

RHSA-2016:2007

Open SourceEPSS <= 49%HIGH2016-10-05

Red Hat Security Advisory: chromium-browser security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Red Hat:rhel_extras:6 chromium-browser
chromium-browser-debuginfo affected Red Hat:rhel_extras:6 chromium-browser-debuginfo
Upstream advisory

MGASA-2016-0335

Open SourceEPSS <= 49%CRITICAL2016-10-04

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

openSUSE-SU-2016:2429-1

Open SourceEPSS <= 49%CRITICAL2016-10-04

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 chromium
Upstream advisory

openSUSE-SU-2016:2432-1

Open SourceEPSS <= 49%CRITICAL2016-10-04

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 chromium
Upstream advisory

DSA-3683-1

Open SourceEPSS <= 49%2016-10-02

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:8 chromium-browser
Upstream advisory

CVE-2016-5191

GoogleEPSS <= 49%CRITICAL2016-10-13

Bookmark handling in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android had insufficient validation of supplied data, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via crafted HTML pag...

CVEs:CVE-2016-5191

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-6691

Open SourceEPSS <= 49%CRITICAL2016-10-04

service/jni/com_android_server_wifi_Gbk2Utf.cpp in the Qualcomm Wi-Fi gbk2utf module in Android before 2016-10-05 allows remote attackers to cause a denial of service (framework crash) or possibly have unspecified other impact via an access point that ...

CVEs:CVE-2016-6691

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5182

GoogleEPSS <= 49%HIGH2016-10-13

Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android had insufficient validation in bitmap handling, which allowed a remote attacker to potentially exploit heap corruption via crafted HTML pages.

CVEs:CVE-2016-5182

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-6695

Open SourceEPSS <= 49%CRITICAL2016-10-04

sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted visualizer data length, aka Qualcomm internal bug...

CVEs:CVE-2016-6695

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5187

GoogleEPSS <= 49%MEDIUM2016-10-13

Google Chrome prior to 54.0.2840.85 for Android incorrectly handled rapid transition into and out of full screen mode, which allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via crafted HTML pages.

CVEs:CVE-2016-5187

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5193

GoogleEPSS <= 49%MEDIUM2016-10-13

Google Chrome prior to 54.0 for iOS had insufficient validation of URLs for windows open by DOM, which allowed a remote attacker to bypass restrictions on navigation to certain URL schemes via crafted HTML pages.

CVEs:CVE-2016-5193

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5192

GoogleEPSS <= 49%MEDIUM2016-10-13

Blink in Google Chrome prior to 54.0.2840.59 for Windows missed a CORS check on redirect in TextTrackLoader, which allowed a remote attacker to bypass cross-origin restrictions via crafted HTML pages.

CVEs:CVE-2016-5192

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5183

GoogleEPSS <= 49%CRITICAL2016-10-13

A heap use after free in PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android allows a remote attacker to potentially exploit heap corruption via crafted PDF files.

CVEs:CVE-2016-5183

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5184

GoogleEPSS <= 49%HIGH2016-10-13

PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled object lifecycles in CFFL_FormFillter::KillFocusForAnnot, which allowed a remote attacker to potentially exploit heap corruption via...

CVEs:CVE-2016-5184

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5185

GoogleEPSS <= 49%HIGH2016-10-13

Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly allowed reentrance of FrameView::updateLifecyclePhasesInternal(), which allowed a remote attacker to perform an out of bounds memory read via...

CVEs:CVE-2016-5185

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5189

GoogleEPSS <= 49%MEDIUM2016-10-13

Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android permitted navigation to blob URLs with non-canonical origins, which allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via crafted HTML pages.

CVEs:CVE-2016-5189

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5188

GoogleEPSS <= 49%MEDIUM2016-10-13

Multiple issues in Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux allow a remote attacker to spoof various parts of browser UI via crafted HTML pages.

CVEs:CVE-2016-5188

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-6692

Open SourceEPSS <= 49%CRITICAL2016-10-04

drivers/video/msm/mdss/mdss_mdp_pp.c in the Qualcomm MDSS driver in Android before 2016-10-05 allows attackers to cause a denial of service (invalid pointer access) or possibly have unspecified other impact via unknown vectors, aka Qualcomm internal bu...

CVEs:CVE-2016-6692

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6693

Open SourceEPSS <= 49%CRITICAL2016-10-04

sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via an invalid data length, aka Qualcomm internal bug CR 1027585.

CVEs:CVE-2016-6693

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6694

Open SourceEPSS <= 49%CRITICAL2016-10-04

sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via crafted parameter data, aka Qualcomm internal bug CR 1033525.

CVEs:CVE-2016-6694

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6696

Open SourceEPSS <= 49%CRITICAL2016-10-04

sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via a large negative value for the data length, aka Qualcomm in...

CVEs:CVE-2016-6696

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2005-4900

GoogleEPSS <= 49%MEDIUM2016-10-14

SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this S...

CVEs:CVE-2005-4900

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5190

GoogleEPSS <= 49%MEDIUM2016-10-13

Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled object lifecycles during shutdown, which allowed a remote attacker to perform an out of bounds memory read via crafted HTML pages.

CVEs:CVE-2016-5190

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5186

GoogleEPSS <= 49%HIGH2016-10-13

Devtools in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled objects after a tab crash, which allowed a remote attacker to perform an out of bounds memory read via crafted PDF files.

CVEs:CVE-2016-5186

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5194

GoogleEPSS <= 49%HIGH2016-10-13

Unspecified vulnerabilities in Google Chrome before 54.0.2840.59.

CVEs:CVE-2016-5194

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-6675

Open SourceEPSS <= 49%HIGH2016-10-04

Off-by-one error in CORE/HDD/src/wlan_hdd_hostapd.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X and Android One devices allows attackers to gain privileges or cause a denial of service (buffer overflow) via a crafted applicati...

CVEs:CVE-2016-6675

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6676

Open SourceEPSS <= 49%HIGH2016-10-04

Off-by-one error in CORE/HDD/src/wlan_hdd_cfg.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X and Android One devices allows attackers to gain privileges or cause a denial of service (buffer overflow) via a crafted application t...

CVEs:CVE-2016-6676

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-7988

Open SourceEPSS <= 49%HIGH2016-10-31

On Samsung Galaxy S4 through S7 devices, absence of permissions on the BroadcastReceiver responsible for handling the com.[Samsung].android.intent.action.SET_WIFI intent leads to unsolicited configuration messages being handled by wifi-service.jar with...

CVEs:CVE-2016-7988

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-7989

Open SourceEPSS <= 49%HIGH2016-10-31

On Samsung Galaxy S4 through S7 devices, a malformed OTA WAP PUSH SMS containing an OMACP message sent remotely triggers an unhandled ArrayIndexOutOfBoundsException in Samsung's implementation of the WifiServiceImpl class within wifi-service.jar. This ...

CVEs:CVE-2016-7989

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6681

Open SourceEPSS <= 49%HIGH2016-10-10

drivers/misc/qcom/qdsp6v2/audio_utils.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 on Nexus 5X, Nexus 6P, and Android One devices does not initialize certain data structures, which allows attackers to obtain sensitive information via a c...

CVEs:CVE-2016-6681

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6682

Open SourceEPSS <= 49%HIGH2016-10-04

drivers/misc/qcom/qdsp6v2/audio_utils.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 on Nexus 5X, Nexus 6P, and Android One devices does not initialize certain data structures, which allows attackers to obtain sensitive information via a c...

CVEs:CVE-2016-6682

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6679

Open SourceEPSS <= 49%HIGH2016-10-04

CORE/HDD/src/wlan_hdd_hostapd.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X and Android One devices allows attackers to obtain sensitive information via a crafted application that makes a setwpaie ioctl call, aka Android inter...

CVEs:CVE-2016-6679

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6680

Open SourceEPSS <= 49%HIGH2016-10-04

CORE/HDD/src/wlan_hdd_wext.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X and Android One devices allows attackers to obtain sensitive information via a crafted application that makes an iw_set_priv ioctl call, aka Android inte...

CVEs:CVE-2016-6680

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-7991

Open SourceEPSS <= 49%HIGH2016-10-31

On Samsung Galaxy S4 through S7 devices, the "omacp" app ignores security information embedded in the OMACP messages resulting in remote unsolicited WAP Push SMS messages being accepted, parsed, and handled by the device, leading to unauthorized config...

CVEs:CVE-2016-7991

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6678

Open SourceEPSS <= 49%HIGH2016-10-04

The Motorola USBNet driver in Android before 2016-10-05 on Nexus 6 devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 29914434.

CVEs:CVE-2016-6678

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3930

Open SourceEPSS <= 49%HIGH2016-10-04

The NVIDIA MMC test driver in Android before 2016-10-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28760138.

CVEs:CVE-2016-3930

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6683

Open SourceEPSS <= 49%HIGH2016-10-04

The kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30143283.

CVEs:CVE-2016-6683

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6677

Open SourceEPSS <= 49%HIGH2016-10-04

The NVIDIA GPU driver in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30259955.

CVEs:CVE-2016-6677

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6684

Open SourceEPSS <= 49%HIGH2016-10-04

The kernel in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 9, Nexus Player, and Android One devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30148243.

CVEs:CVE-2016-6684

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6685

Open SourceEPSS <= 49%HIGH2016-10-04

The kernel in Android before 2016-10-05 on Nexus 6P devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30402628.

CVEs:CVE-2016-6685

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6686

Open SourceEPSS <= 49%HIGH2016-10-04

The NVIDIA profiler in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30163101.

CVEs:CVE-2016-6686

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6687

Open SourceEPSS <= 49%HIGH2016-10-04

The NVIDIA profiler in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30162222.

CVEs:CVE-2016-6687

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6688

Open SourceEPSS <= 49%HIGH2016-10-04

The NVIDIA profiler in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30593080.

CVEs:CVE-2016-6688

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2016-8579

Open SourceEPSS <= 49%HIGH2016-10-28

DEBIAN-CVE-2016-8579

Affected products

ProductStatusVendorPackageEcosystem
golang-github-appc-docker2aci affected Debian:11 golang-github-appc-docker2aci
Upstream advisory

CVE-2016-6690

Open SourceEPSS <= 49%HIGH2016-10-04

The sound driver in the kernel in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, and Nexus Player devices allows attackers to cause a denial of service (reboot) via a crafted application, aka internal bug 28838221.

CVEs:CVE-2016-6690

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8956

Open SourceEPSS <= 49%HIGH2016-10-04

The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c in the Linux kernel before 4.2 allows local users to obtain sensitive information or cause a denial of service (NULL pointer dereference) via vectors involving a bind system call on a Bluetoo...

CVEs:CVE-2015-8956

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2015-8955

Open SourceEPSS <= 49%HIGH2016-10-04

arch/arm64/kernel/perf_event.c in the Linux kernel before 4.1 on arm64 platforms allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via vectors involving events that are mishandled during a span of multiple...

CVEs:CVE-2015-8955

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.