Google Security Advisories · December 2016 — Google Security Advisories
60 advisories 58 CVEs 5 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2016-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 5 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2016-9079

Project ZeroExploitedCISA KEV listed2016-12-01

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.

CVEs:CVE-2016-9079

Upstream advisory

CVE-2016-9079

GoogleExploitedCISA KEV listedCRITICAL2016-12-01

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 4...

CVEs:CVE-2016-9079

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
enterprise_linux affected redhat
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_server_aus affected redhat
enterprise_linux_server_eus affected redhat
enterprise_linux_workstation affected redhat
firefox affected mozilla
thunderbird affected mozilla
tor affected torproject
Upstream advisory

DSA-3731-1

Open SourceExploitedCISA KEV listed2016-12-11

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:8 chromium-browser
Upstream advisory

CVE-2016-7892

GoogleExploitedCISA KEV listedHIGH2016-12-13

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.

CVEs:CVE-2016-7892

Affected products

ProductStatusVendorPackageEcosystem
flash_player affected adobe
flash_player_desktop_runtime affected adobe
Upstream advisory

CVE-2016-7892

Project ZeroExploitedCISA KEV listed2016-12-13

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.

CVEs:CVE-2016-7892

Upstream advisory

openSUSE-SU-2017:0563-1

Open SourceWeaponized exploitCRITICAL2016-12-16

Security update for Chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP2 chromium
Upstream advisory

MGASA-2016-0419

Open SourceWeaponized exploitCRITICAL2016-12-15

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

RHSA-2016:2919

Open SourceWeaponized exploitHIGH2016-12-07

Red Hat Security Advisory: chromium-browser security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Red Hat:rhel_extras:6 chromium-browser
chromium-browser-debuginfo affected Red Hat:rhel_extras:6 chromium-browser-debuginfo
Upstream advisory

CVE-2016-9651

GoogleWeaponized exploitCRITICAL2016-12-02

A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVEs:CVE-2016-9651

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2016-6772

Open SourceWeaponized exploitHIGH2016-12-06

An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it first requires compromising a privileged proces...

CVEs:CVE-2016-6772

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-9652

GoogleActive exploitation (sightings)HIGH2016-12-02

Multiple unspecified vulnerabilities in Google Chrome before 55.0.2883.75.

CVEs:CVE-2016-9652

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5207

GoogleEPSS <= 49%CRITICAL2016-12-02

In Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android, corruption of the DOM tree could occur during the removal of a full screen element, which allowed a remote attacker to achieve arbitrary code exec...

CVEs:CVE-2016-5207

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5210

GoogleEPSS <= 49%CRITICAL2016-12-02

Heap buffer overflow during TIFF image parsing in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2016-5210

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5214

GoogleEPSS <= 49%MEDIUM2016-12-02

Google Chrome prior to 55.0.2883.75 for Windows mishandled downloaded files, which allowed a remote attacker to prevent the downloaded file from receiving the Mark of the Web via a crafted HTML page.

CVEs:CVE-2016-5214

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5212

GoogleEPSS <= 49%MEDIUM2016-12-02

Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android insufficiently sanitized DevTools URLs, which allowed a remote attacker to read local files via a crafted HTML page.

CVEs:CVE-2016-5212

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5209

GoogleEPSS <= 49%HIGH2016-12-02

Bad casting in bitmap manipulation in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2016-5209

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5206

GoogleEPSS <= 49%HIGH2016-12-02

The PDF plugin in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly followed redirects, which allowed a remote attacker to bypass the Same Origin Policy via a crafted HTML page.

CVEs:CVE-2016-5206

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5217

GoogleEPSS <= 49%MEDIUM2016-12-02

The extensions API in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly permitted access to privileged plugins, which allowed a remote attacker to bypass site isolation via a crafted HTML page.

CVEs:CVE-2016-5217

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5218

GoogleEPSS <= 49%MEDIUM2016-12-02

The extensions API in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled navigation within PDFs, which allowed a remote attacker to temporarily spoof the contents of the Omnibox (URL bar) vi...

CVEs:CVE-2016-5218

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5213

GoogleEPSS <= 49%CRITICAL2016-12-02

A use after free in V8 in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2016-5213

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5204

GoogleEPSS <= 49%CRITICAL2016-12-02

Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a craf...

CVEs:CVE-2016-5204

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-6492

Open SourceEPSS <= 49%HIGH2016-12-06

The MT6573FDVT_SetRegHW function in camera_fdvt.c in the MediaTek driver for Linux allows local users to gain privileges via a crafted application that makes an MT6573FDVTIOC_T_SET_FDCONF_CMD IOCTL call.

CVEs:CVE-2016-6492

Affected products

ProductStatusVendorPackageEcosystem
android affected google
android affected google
Upstream advisory

CVE-2016-5220

GoogleEPSS <= 49%MEDIUM2016-12-02

PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled navigation within PDFs, which allowed a remote attacker to read local files via a crafted PDF file.

CVEs:CVE-2016-5220

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5222

GoogleEPSS <= 49%MEDIUM2016-12-02

Incorrect handling of invalid URLs in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2016-5222

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5203

GoogleEPSS <= 49%CRITICAL2016-12-02

A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2016-5203

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5211

GoogleEPSS <= 49%CRITICAL2016-12-02

A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2016-5211

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5208

GoogleEPSS <= 49%CRITICAL2016-12-02

Blink in Google Chrome prior to 55.0.2883.75 for Linux and Windows, and 55.0.2883.84 for Android allowed possible corruption of the DOM tree during synchronous event handling, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) v...

CVEs:CVE-2016-5208

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5221

GoogleEPSS <= 49%MEDIUM2016-12-02

Type confusion in libGLESv2 in ANGLE in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android possibly allowed a remote attacker to bypass buffer validation via a crafted HTML page.

CVEs:CVE-2016-5221

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5224

GoogleEPSS <= 49%MEDIUM2016-12-02

A timing attack on denormalized floating point arithmetic in SVG filters in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to bypass the Same Origin Policy via a crafted H...

CVEs:CVE-2016-5224

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5225

GoogleEPSS <= 49%MEDIUM2016-12-02

Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled form actions, which allowed a remote attacker to bypass Content Security Policy via a crafted HTML page.

CVEs:CVE-2016-5225

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-9650

GoogleEPSS <= 49%MEDIUM2016-12-02

Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled iframes, which allowed a remote attacker to bypass a no-referrer policy via a crafted HTML page.

CVEs:CVE-2016-9650

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5223

GoogleEPSS <= 49%CRITICAL2016-12-02

Integer overflow in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption or DoS via a crafted PDF file.

CVEs:CVE-2016-5223

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5205

GoogleEPSS <= 49%CRITICAL2016-12-02

Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac, incorrectly handles deferred page loads, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.

CVEs:CVE-2016-5205

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5215

GoogleEPSS <= 49%CRITICAL2016-12-02

A use after free in webaudio in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2016-5215

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome affected google
Upstream advisory

CVE-2016-5219

GoogleEPSS <= 49%CRITICAL2016-12-02

A heap use after free in V8 in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2016-5219

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-6762

Open SourceEPSS <= 49%HIGH2016-12-06

An elevation of privilege vulnerability in the libziparchive library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local acc...

CVEs:CVE-2016-6762

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-8411

Open SourceEPSS <= 49%HIGH2016-12-06

Buffer overflow vulnerability while processing QMI QOS TLVs. Product: Android. Versions: versions that have qmi_qos_srvc.c. Android ID: 31805216. References: QC CR#912775.

CVEs:CVE-2016-8411

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5341

Open SourceEPSS <= 49%HIGH2016-12-06

The GPS component in Android before 2016-12-05 allows man-in-the-middle attackers to cause a denial of service (GPS signal-acquisition delay) via an incorrect xtra.bin or xtra2.bin file on a spoofed Qualcomm gpsonextra.net or izatcloud.net host, aka in...

CVEs:CVE-2016-5341

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8967

Open SourceEPSS <= 49%HIGH2016-12-06

arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page permissions" protection mechanism and modify the system-call table, and consequently gain privileges, by leveraging write access.

CVEs:CVE-2015-8967

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2016-6768

Open SourceEPSS <= 49%HIGH2016-12-06

A remote code execution vulnerability in the Framesequence library could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote...

CVEs:CVE-2016-6768

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5216

GoogleEPSS <= 49%CRITICAL2016-12-02

A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.

CVEs:CVE-2016-5216

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2017-0509

Open SourceEPSS <= 49%HIGH2016-12-14

An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent devi...

CVEs:CVE-2017-0509

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5226

GoogleEPSS <= 49%CRITICAL2016-12-02

Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac executed javascript: URLs entered in the URL bar in the context of the current tab, which allowed a socially engineered user to XSS themselves by dragging and dropping a javascript...

CVEs:CVE-2016-5226

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-6766

Open SourceEPSS <= 49%HIGH2016-12-06

A denial of service vulnerability in libmedia and libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. P...

CVEs:CVE-2016-6766

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6788

Open SourceEPSS <= 49%HIGH2016-12-06

An elevation of privilege vulnerability in the MediaTek I2C driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pr...

CVEs:CVE-2016-6788

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6783

Open SourceEPSS <= 49%HIGH2016-12-06

An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged proces...

CVEs:CVE-2016-6783

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9910

Open SourceEPSS <= 49%HIGH2016-12-06

An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged ...

CVEs:CVE-2014-9910

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6765

Open SourceEPSS <= 49%HIGH2016-12-06

A denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Andro...

CVEs:CVE-2016-6765

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6767

Open SourceEPSS <= 49%HIGH2016-12-06

A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4....

CVEs:CVE-2016-6767

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9909

Open SourceEPSS <= 49%HIGH2016-12-06

An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged ...

CVEs:CVE-2014-9909

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6764

Open SourceEPSS <= 49%HIGH2016-12-06

A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4....

CVEs:CVE-2016-6764

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6784

Open SourceEPSS <= 49%HIGH2016-12-06

An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged proces...

CVEs:CVE-2016-6784

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6773

Open SourceEPSS <= 49%HIGH2016-12-06

An information disclosure vulnerability in the ih264d decoder in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data w...

CVEs:CVE-2016-6773

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-8396

Open SourceEPSS <= 49%HIGH2016-12-06

An information disclosure vulnerability in the MediaTek video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without expli...

CVEs:CVE-2016-8396

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6910

Open SourceEPSS <= 49%HIGH2016-12-23

The non-existent notification listener vulnerability was introduced in the initial Android 5.0.2 builds for the Samsung Galaxy S6 Edge devices, but the vulnerability can persist on the device even after the device has been upgraded to an Android 5.1.1 ...

CVEs:CVE-2016-6910

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6763

Open SourceEPSS <= 49%HIGH2016-12-06

A denial of service vulnerability in Telephony could enable a local malicious application to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of local permanent denial of service. Product...

CVEs:CVE-2016-6763

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6774

Open SourceEPSS <= 49%MEDIUM2016-12-06

An information disclosure vulnerability in Package Manager could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Moderate because it first require...

CVEs:CVE-2016-6774

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6770

Open SourceEPSS <= 49%CRITICAL2016-12-06

An elevation of privilege vulnerability in the Framework API could enable a local malicious application to access system functions beyond its access level. This issue is rated as Moderate because it is a local bypass of restrictions on a constrained pr...

CVEs:CVE-2016-6770

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6771

Open SourceEPSS <= 49%CRITICAL2016-12-06

An elevation of privilege vulnerability in Telephony could enable a local malicious application to access system functions beyond its access level. This issue is rated as Moderate because it is a local bypass of restrictions on a constrained process. P...

CVEs:CVE-2016-6771

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6769

Open SourceEPSS <= 49%HIGH2016-12-06

An elevation of privilege vulnerability in Smart Lock could enable a local malicious user to access Smart Lock settings without a PIN. This issue is rated as Moderate because it first requires physical access to an unlocked device where Smart Lock was ...

CVEs:CVE-2016-6769

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.