DSA-3776-1
chromium-browser - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser | affected | Debian:8 | chromium-browser | — |
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
chromium-browser - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser | affected | Debian:8 | chromium-browser | — |
Red Hat Security Advisory: chromium-browser security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser | affected | Red Hat:rhel_extras:6 | chromium-browser | — |
| chromium-browser-debuginfo | affected | Red Hat:rhel_extras:6 | chromium-browser-debuginfo | — |
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled the sequence of events when closing a page, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a craf...
CVEs:CVE-2017-5007
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to e...
CVEs:CVE-2017-0386
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An information disclosure vulnerability in silk/NLSF_stabilize.c in libopus in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access se...
CVEs:CVE-2017-0381
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
A remote code execution vulnerability in the Framesequence library could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote...
CVEs:CVE-2017-0382
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
A denial of service vulnerability in libvpx in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android...
CVEs:CVE-2017-0393
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An elevation of privilege vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High bec...
CVEs:CVE-2017-0384
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
A denial of service vulnerability in Telephony could enable a remote attacker to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7...
CVEs:CVE-2017-0394
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An elevation of privilege vulnerability in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevate...
CVEs:CVE-2017-0387
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to ...
CVEs:CVE-2017-0383
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevate...
CVEs:CVE-2017-0385
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
A denial of service vulnerability in decoder/ihevcd_decode.c in libhevc in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial ...
CVEs:CVE-2017-0391
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent devi...
CVEs:CVE-2016-8436
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| linux_kernel | affected | linux | — | — |
A denial of service vulnerability in Tremolo/dpen.s in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product:...
CVEs:CVE-2017-0390
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
A denial of service vulnerability in VBRISeeker.cpp in libstagefright in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of...
CVEs:CVE-2017-0392
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
A denial of service vulnerability in core networking could enable a remote attacker to use specially crafted network packet to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Andro...
CVEs:CVE-2017-0389
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An elevation of privilege vulnerability in MediaTek components, including the thermal driver and video driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it...
CVEs:CVE-2016-8445
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device...
CVEs:CVE-2016-8422
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device...
CVEs:CVE-2016-8423
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device com...
CVEs:CVE-2016-8433
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An elevation of privilege vulnerability in MediaTek components, including the thermal driver and video driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it...
CVEs:CVE-2016-8448
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An elevation of privilege vulnerability in MediaTek components, including the thermal driver and video driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it...
CVEs:CVE-2016-8446
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An elevation of privilege vulnerability in MediaTek components, including the thermal driver and video driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it...
CVEs:CVE-2016-8447
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be ...
CVEs:CVE-2017-0402
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Pro...
CVEs:CVE-2017-0398
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post processor could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderat...
CVEs:CVE-2017-0401
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An information disclosure vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensi...
CVEs:CVE-2017-0397
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post processor could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderat...
CVEs:CVE-2017-0399
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An information disclosure vulnerability in visualizer/EffectVisualizer.cpp in libeffects in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used...
CVEs:CVE-2017-0396
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be ...
CVEs:CVE-2017-0400
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Buffer overflow in the Qualcomm radio driver in Android before 2017-01-05 on Android One devices allows local users to gain privileges via a crafted application, aka Android internal bug 32639452 and Qualcomm internal bug CR1079713.
CVEs:CVE-2016-5345
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An elevation of privilege vulnerability in Contacts could enable a local malicious application to silently create contact information. This issue is rated as Moderate because it is a local bypass of user interaction requirements (access to functionalit...
CVEs:CVE-2017-0395
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An information disclosure vulnerability in the MediaTek driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Prod...
CVEs:CVE-2016-8470
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An information disclosure vulnerability in the MediaTek driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Prod...
CVEs:CVE-2016-8471
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An information disclosure vulnerability in the MediaTek driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Prod...
CVEs:CVE-2016-8472
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An information disclosure vulnerability in the bootloader could enable a local attacker to access data outside of its permission level. This issue is rated as High because it could be used to access sensitive data. Product: Android. Versions: N/A. Andr...
CVEs:CVE-2016-8462
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An elevation of privilege vulnerability in the NVIDIA GPU driver. Product: Android. Versions: Android kernel. Android ID: A-31799863. References: N-CVE-2016-8482.
CVEs:CVE-2016-8482
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An elevation of privilege vulnerability in the External Storage Provider could enable a local secondary user to read data from an external storage SD card inserted by the primary user. This issue is rated as High because it is a general bypass for oper...
CVEs:CVE-2017-0388
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
DEBIAN-CVE-2016-7569
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-appc-docker2aci | affected | Debian:11 | golang-github-appc-docker2aci | — |
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to require a user gesture for powerful download operations, which allowed a remote attacker who convinced a user to install a malicious extension to ex...
CVEs:CVE-2017-5020
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
A heap buffer overflow in V8 in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2017-5012
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Google Chrome prior to 56.0.2924.76 for Windows insufficiently sanitized DevTools URLs, which allowed a remote attacker who convinced a user to install a malicious extension to read filesystem contents via a crafted HTML page.
CVEs:CVE-2017-5011
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled object owner relationships, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
CVEs:CVE-2017-5006
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed attacker controlled JavaScript to be run during the invocation of a private script method, which allowed a remote attacker to inject arbitrar...
CVEs:CVE-2017-5008
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
WebRTC in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to perform proper bounds checking, which allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2017-5009
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Type confusion in Histogram in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to potentially exploit a near null dereference via a crafted HTML page.
CVEs:CVE-2017-5023
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to prevent alerts from being displayed by swapped out frames, which allowed a remote attacker to show alerts on a page they don't control via a crafted HTML page.
CVEs:CVE-2017-5026
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Heap buffer overflow during image processing in Skia in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVEs:CVE-2017-5014
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled Unicode glyphs, which allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
CVEs:CVE-2017-5015
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Google Chrome prior to 56.0.2924.76 for Linux incorrectly handled new tab page navigations in non-selected tabs, which allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2017-5013
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
A use after free in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVEs:CVE-2017-5021
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
FFmpeg in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to perform proper bounds checking, which allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
CVEs:CVE-2017-5024
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
FFmpeg in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to perform proper bounds checking, which allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
CVEs:CVE-2017-5025
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
A use after free in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2017-5019
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to prevent certain UI elements from being displayed by non-visible pages, which allowed a remote attacker to show certain UI elements on a pag...
CVEs:CVE-2017-5016
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Interactions with the OS in Google Chrome prior to 56.0.2924.76 for Mac insufficiently cleared video memory, which allowed a remote attacker to possibly extract image fragments on systems with GeForce 8600M graphics chips via a crafted HTML page.
CVEs:CVE-2017-5017
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to properly enforce unsafe-inline content security policy, which allowed a remote attacker to bypass content security policy via a crafted HTM...
CVEs:CVE-2017-5022
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, resolved promises in an inappropriate context, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
CVEs:CVE-2017-5010
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, had an insufficiently strict content security policy on the Chrome app launcher page, which allowed a remote attacker to inject scripts or HTML into a privile...
CVEs:CVE-2017-5018
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
The content renderer client in Google Chrome prior to 54.0.2840.85 for Android insufficiently enforced the Same Origin Policy amongst downloaded files, which allowed a remote attacker to access any downloaded file and interact with sites, including tho...
CVEs:CVE-2016-5196
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
The content view client in Google Chrome prior to 54.0.2840.85 for Android insufficiently validated intent URLs, which allowed a remote attacker who had compromised the renderer process to start arbitrary activity on the system via a crafted HTML page.
CVEs:CVE-2016-5197
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2016-6762
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android-platform-system-core | affected | Debian:11 | android-platform-system-core | — |
Updated golang package fixes security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Mageia:5 | golang | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.