Google Security Advisories · March 2017 — Google Security Advisories
106 advisories 97 CVEs 23 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2017-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 23 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2017-0147

Project ZeroExploitedCISA KEV listed2017-03-15

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka "Windows SMB Information Disclosure Vulnerability."

CVEs:CVE-2017-0147

Upstream advisory

CVE-2017-0147

GoogleExploitedCISA KEV listedHIGH2017-03-15

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to ob...

CVEs:CVE-2017-0147

Affected products

ProductStatusVendorPackageEcosystem
acuson_p300_firmware affected siemens
acuson_p500_firmware affected siemens
acuson_sc2000_firmware affected siemens
acuson_x700_firmware affected siemens
syngo_sc2000_firmware affected siemens
tissue_preparation_system_firmware affected siemens
versant_kpcr_molecular_system_firmware affected siemens
versant_kpcr_sample_prep_firmware affected siemens
windows_10_1507 affected microsoft
windows_10_1511 affected microsoft
windows_10_1607 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_vista affected microsoft
Upstream advisory

CVE-2017-0144

Project ZeroExploitedCISA KEV listed2017-03-15

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.

CVEs:CVE-2017-0144

Upstream advisory

CVE-2017-0144

GoogleExploitedCISA KEV listedHIGH2017-03-15

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to ex...

CVEs:CVE-2017-0144

Affected products

ProductStatusVendorPackageEcosystem
acuson_p300_firmware affected siemens
acuson_p500_firmware affected siemens
acuson_sc2000_firmware affected siemens
acuson_x700_firmware affected siemens
server_message_block affected microsoft
syngo_sc2000_firmware affected siemens
tissue_preparation_system_firmware affected siemens
versant_kpcr_molecular_system_firmware affected siemens
versant_kpcr_sample_prep_firmware affected siemens
Upstream advisory

CVE-2017-3881

GoogleExploitedCISA KEV listedHIGH2017-03-17

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privile...

CVEs:CVE-2017-3881

Affected products

ProductStatusVendorPackageEcosystem
ios affected cisco
ios_xe affected cisco
Upstream advisory

CVE-2017-3881

Project ZeroExploitedCISA KEV listed2017-03-17

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors: (1) the failure to restrict the use of CMP-specific Telnet opti

CVEs:CVE-2017-3881

Upstream advisory

CVE-2017-0143

GoogleExploitedCISA KEV listedHIGH2017-03-15

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to ex...

CVEs:CVE-2017-0143

Affected products

ProductStatusVendorPackageEcosystem
acuson_p300_firmware affected siemens
acuson_p500_firmware affected siemens
acuson_sc2000_firmware affected siemens
acuson_x700_firmware affected siemens
intellispace_portal affected philips
server_message_block affected microsoft
syngo_sc2000_firmware affected siemens
tissue_preparation_system_firmware affected siemens
versant_kpcr_molecular_system_firmware affected siemens
versant_kpcr_sample_prep_firmware affected siemens
Upstream advisory

CVE-2017-0143

Project ZeroExploitedCISA KEV listed2017-03-15

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.

CVEs:CVE-2017-0143

Upstream advisory

CVE-2017-0146

GoogleExploitedCISA KEV listedHIGH2017-03-15

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to ex...

CVEs:CVE-2017-0146

Affected products

ProductStatusVendorPackageEcosystem
acuson_p300_firmware affected siemens
acuson_p500_firmware affected siemens
acuson_sc2000_firmware affected siemens
acuson_x700_firmware affected siemens
server_message_block affected microsoft
syngo_sc2000_firmware affected siemens
tissue_preparation_system_firmware affected siemens
versant_kpcr_molecular_system_firmware affected siemens
versant_kpcr_sample_prep_firmware affected siemens
Upstream advisory

CVE-2017-0146

Project ZeroExploitedCISA KEV listed2017-03-15

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148.

CVEs:CVE-2017-0146

Upstream advisory

CVE-2017-0145

Project ZeroExploitedCISA KEV listed2017-03-15

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0146, and CVE-2017-0148.

CVEs:CVE-2017-0145

Upstream advisory

CVE-2017-0145

GoogleExploitedCISA KEV listedHIGH2017-03-15

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to ex...

CVEs:CVE-2017-0145

Affected products

ProductStatusVendorPackageEcosystem
acuson_p300_firmware affected siemens
acuson_p500_firmware affected siemens
acuson_sc2000_firmware affected siemens
acuson_x700_firmware affected siemens
server_message_block affected microsoft
syngo_sc2000_firmware affected siemens
tissue_preparation_system_firmware affected siemens
versant_kpcr_molecular_system_firmware affected siemens
versant_kpcr_sample_prep_firmware affected siemens
Upstream advisory

openSUSE-SU-2017:0738-1

Open SourceExploitedCISA KEV listedCRITICAL2017-03-17

Security update for Chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP2 chromium
Upstream advisory

openSUSE-SU-2017:0740-1

Open SourceExploitedCISA KEV listedCRITICAL2017-03-17

Security update for Chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP2 chromium
Upstream advisory

DSA-3810-1

Open SourceExploitedCISA KEV listed2017-03-15

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:8 chromium-browser
Upstream advisory

RHSA-2017:0499

Open SourceExploitedCISA KEV listedHIGH2017-03-14

Red Hat Security Advisory: chromium-browser security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Red Hat:rhel_extras:6 chromium-browser
chromium-browser-debuginfo affected Red Hat:rhel_extras:6 chromium-browser-debuginfo
Upstream advisory

CVE-2017-5030

GoogleExploitedCISA KEV listedCRITICAL2017-03-10

Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page.

CVEs:CVE-2017-5030

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-0149

GoogleExploitedCISA KEV listedCRITICAL2017-03-15

Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different ...

CVEs:CVE-2017-0149

Affected products

ProductStatusVendorPackageEcosystem
internet_explorer affected microsoft
Upstream advisory

CVE-2017-0149

Project ZeroExploitedCISA KEV listed2017-03-15

Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0018 and CVE-2017-0037.

CVEs:CVE-2017-0149

Upstream advisory

CVE-2017-0022

GoogleExploitedCISA KEV listedHIGH2017-03-15

Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2 improperly handles objec...

CVEs:CVE-2017-0022

Affected products

ProductStatusVendorPackageEcosystem
windows_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
xml_core_services affected microsoft
Upstream advisory

CVE-2017-0022

Project ZeroExploitedCISA KEV listed2017-03-15

Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2 improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site, aka "Microsoft XML Information Disclosure Vulnerability."

CVEs:CVE-2017-0022

Upstream advisory

CVE-2017-0005

Project ZeroExploitedCISA KEV listed2017-03-15

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka "Windows GDI Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0001, CVE-2017-0025, and CVE-2017-0047.

CVEs:CVE-2017-0005

Upstream advisory

CVE-2017-0005

GoogleExploitedCISA KEV listedHIGH2017-03-15

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileg...

CVEs:CVE-2017-0005

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1511 affected microsoft
windows_10_1607 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_vista affected microsoft
Upstream advisory

CVE-2017-5029

GooglePoC exploitCRITICAL2017-03-10

The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which all...

CVEs:CVE-2017-5029

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
libxslt affected xmlsoft
Upstream advisory

CVE-2017-0478

Open SourcePoC exploitHIGH2017-03-07

A remote code execution vulnerability in the Framesequence library could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote...

CVEs:CVE-2017-0478

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0505

Open SourcePoC exploitHIGH2017-03-07

An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of...

CVEs:CVE-2017-0505

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5856

Open SourcePoC exploitHIGH2017-03-07

Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local users to gain privileges, a different vulnerability than CVE-2016-5857.

CVEs:CVE-2016-5856

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2017-6425

Open SourcePoC exploitHIGH2017-03-02

An information disclosure vulnerability in the Qualcomm video driver. Product: Android. Versions: Android kernel. Android ID: A-32577085. References: QC-CR#1103689.

CVEs:CVE-2017-6425

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10200

Open SourcePoC exploitHIGH2017-03-07

Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a soc...

CVEs:CVE-2016-10200

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2017-5040

GoogleEPSS <= 49%MEDIUM2017-03-10

V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android was missing a neutering check, which allowed a remote attacker to read values in memory via a crafted HTML page.

CVEs:CVE-2017-5040

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

RHSA-2017:0860

Open SourceEPSS <= 49%CRITICAL2017-03-31

Red Hat Security Advisory: chromium-browser security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Red Hat:rhel_extras:6 chromium-browser
chromium-browser-debuginfo affected Red Hat:rhel_extras:6 chromium-browser-debuginfo
Upstream advisory

CVE-2017-5053

GoogleEPSS <= 49%CRITICAL2017-03-30

An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to Array.prototype.ind...

CVEs:CVE-2017-5053

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5055

GoogleEPSS <= 49%HIGH2017-03-30

A use after free in printing in Google Chrome prior to 57.0.2987.133 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2017-5055

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2017-5044

GoogleEPSS <= 49%CRITICAL2017-03-10

Heap buffer overflow in filter processing in Skia in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2017-5044

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

DEBIAN-CVE-2016-9123

Open SourceEPSS <= 49%CRITICAL2017-03-28

DEBIAN-CVE-2016-9123

Affected products

ProductStatusVendorPackageEcosystem
golang-gopkg-square-go-jose.v1 affected Debian:11 golang-gopkg-square-go-jose.v1
golang-gopkg-square-go-jose.v1 affected Debian:12 golang-gopkg-square-go-jose.v1
golang-gopkg-square-go-jose.v1 affected Debian:13 golang-gopkg-square-go-jose.v1
golang-gopkg-square-go-jose.v1 affected Debian:14 golang-gopkg-square-go-jose.v1
Upstream advisory

CVE-2017-0474

Open SourceEPSS <= 49%HIGH2017-03-07

A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code executi...

CVEs:CVE-2017-0474

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2016-9122

Open SourceEPSS <= 49%HIGH2017-03-28

DEBIAN-CVE-2016-9122

Affected products

ProductStatusVendorPackageEcosystem
golang-gopkg-square-go-jose.v1 affected Debian:11 golang-gopkg-square-go-jose.v1
golang-gopkg-square-go-jose.v1 affected Debian:12 golang-gopkg-square-go-jose.v1
golang-gopkg-square-go-jose.v1 affected Debian:13 golang-gopkg-square-go-jose.v1
golang-gopkg-square-go-jose.v1 affected Debian:14 golang-gopkg-square-go-jose.v1
Upstream advisory

CVE-2017-5052

GoogleEPSS <= 49%CRITICAL2017-03-30

An incorrect assumption about block structure in Blink in Google Chrome prior to 57.0.2987.133 for Mac, Windows, and Linux, and 57.0.2987.132 for Android, allowed a remote attacker to potentially exploit memory corruption via a crafted HTML page that t...

CVEs:CVE-2017-5052

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5033

GoogleEPSS <= 49%MEDIUM2017-03-10

Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android failed to correctly propagate CSP restrictions to local scheme pages, which allowed a remote attacker to bypass content security policy via a crafted...

CVEs:CVE-2017-5033

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5054

GoogleEPSS <= 49%HIGH2017-03-30

An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to obtain heap memory contents via a crafted HTML page.

CVEs:CVE-2017-5054

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-0466

Open SourceEPSS <= 49%HIGH2017-03-07

A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code executi...

CVEs:CVE-2017-0466

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0467

Open SourceEPSS <= 49%HIGH2017-03-07

A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code executi...

CVEs:CVE-2017-0467

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0468

Open SourceEPSS <= 49%HIGH2017-03-07

A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code executi...

CVEs:CVE-2017-0468

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0469

Open SourceEPSS <= 49%HIGH2017-03-07

A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code executi...

CVEs:CVE-2017-0469

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0470

Open SourceEPSS <= 49%HIGH2017-03-07

A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code executi...

CVEs:CVE-2017-0470

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0471

Open SourceEPSS <= 49%HIGH2017-03-07

A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code executi...

CVEs:CVE-2017-0471

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0472

Open SourceEPSS <= 49%HIGH2017-03-07

A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code executi...

CVEs:CVE-2017-0472

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0473

Open SourceEPSS <= 49%HIGH2017-03-07

A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code executi...

CVEs:CVE-2017-0473

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2016-9121

Open SourceEPSS <= 49%CRITICAL2017-03-28

DEBIAN-CVE-2016-9121

Affected products

ProductStatusVendorPackageEcosystem
golang-gopkg-square-go-jose.v1 affected Debian:11 golang-gopkg-square-go-jose.v1
golang-gopkg-square-go-jose.v1 affected Debian:12 golang-gopkg-square-go-jose.v1
golang-gopkg-square-go-jose.v1 affected Debian:13 golang-gopkg-square-go-jose.v1
golang-gopkg-square-go-jose.v1 affected Debian:14 golang-gopkg-square-go-jose.v1
Upstream advisory

CVE-2017-5032

GoogleEPSS <= 49%HIGH2017-03-10

PDFium in Google Chrome prior to 57.0.2987.98 for Windows could be made to increment off the end of a buffer, which allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2017-5032

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2017-5031

GoogleEPSS <= 49%CRITICAL2017-03-10

A use after free in ANGLE in Google Chrome prior to 57.0.2987.98 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2017-5031

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2017-5043

GoogleEPSS <= 49%CRITICAL2017-03-10

Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, which allowed a remote attacker to perform an out of bounds memory read via a crafted Chrome extension.

CVEs:CVE-2017-5043

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5046

GoogleEPSS <= 49%CRITICAL2017-03-10

V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android had insufficient policy enforcement, which allowed a remote attacker to spoof the location object via a crafted HTML page, related to Blink information ...

CVEs:CVE-2017-5046

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5034

GoogleEPSS <= 49%CRITICAL2017-03-10

A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.

CVEs:CVE-2017-5034

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2017-5056

GoogleEPSS <= 49%CRITICAL2017-03-30

A use after free in Blink in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2017-5056

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5045

GoogleEPSS <= 49%CRITICAL2017-03-10

XSS Auditor in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed detection of a blocked iframe load, which allowed a remote attacker to brute force JavaScript variables via a crafted HTML page.

CVEs:CVE-2017-5045

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5041

GoogleEPSS <= 49%MEDIUM2017-03-10

Google Chrome prior to 57.0.2987.100 incorrectly handled back-forward navigation, which allowed a remote attacker to display incorrect information for a site via a crafted HTML page.

CVEs:CVE-2017-5041

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2017-5038

GoogleEPSS <= 49%CRITICAL2017-03-10

Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, which allowed a remote attacker to perform an out of bounds memory read via a crafted Chrome extension.

CVEs:CVE-2017-5038

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2016-8484

Open SourceEPSS <= 49%HIGH2017-03-07

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823575.

CVEs:CVE-2016-8484

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-8487

Open SourceEPSS <= 49%HIGH2017-03-07

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823724.

CVEs:CVE-2016-8487

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-8488

Open SourceEPSS <= 49%HIGH2017-03-07

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-31625756.

CVEs:CVE-2016-8488

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0476

Open SourceEPSS <= 49%HIGH2017-03-07

A remote code execution vulnerability in AOSP Messaging could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as High due to the possibility of remote code executio...

CVEs:CVE-2017-0476

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-5039

GoogleEPSS <= 49%CRITICAL2017-03-10

A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2017-5039

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5037

GoogleEPSS <= 49%CRITICAL2017-03-10

An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.

CVEs:CVE-2017-5037

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5036

GoogleEPSS <= 49%CRITICAL2017-03-10

A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to have an unspecified impact via a crafted PDF file.

CVEs:CVE-2017-5036

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-0477

Open SourceEPSS <= 49%HIGH2017-03-07

A remote code execution vulnerability in libgdx could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution...

CVEs:CVE-2017-0477

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0504

Open SourceEPSS <= 49%HIGH2017-03-07

An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of...

CVEs:CVE-2017-0504

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0475

Open SourceEPSS <= 49%HIGH2017-03-07

An elevation of privilege vulnerability in the recovery verifier could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device c...

CVEs:CVE-2017-0475

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0481

Open SourceEPSS <= 49%HIGH2017-03-07

An elevation of privilege vulnerability in NFC could enable a proximate attacker to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, w...

CVEs:CVE-2017-0481

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0503

Open SourceEPSS <= 49%HIGH2017-03-07

An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of...

CVEs:CVE-2017-0503

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-5035

GoogleEPSS <= 49%HIGH2017-03-10

Google Chrome prior to 57.0.2987.98 for Windows and Mac had a race condition, which could cause Chrome to display incorrect certificate information for a site.

CVEs:CVE-2017-5035

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-0480

Open SourceEPSS <= 49%HIGH2017-03-07

An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevate...

CVEs:CVE-2017-0480

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0487

Open SourceEPSS <= 49%HIGH2017-03-07

A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versi...

CVEs:CVE-2017-0487

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0488

Open SourceEPSS <= 49%HIGH2017-03-07

A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versi...

CVEs:CVE-2017-0488

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0523

Open SourceEPSS <= 49%HIGH2017-03-07

An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged ...

CVEs:CVE-2017-0523

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2017-0500

Open SourceEPSS <= 49%HIGH2017-03-07

An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of...

CVEs:CVE-2017-0500

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0501

Open SourceEPSS <= 49%HIGH2017-03-07

An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of...

CVEs:CVE-2017-0501

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0502

Open SourceEPSS <= 49%HIGH2017-03-07

An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of...

CVEs:CVE-2017-0502

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0506

Open SourceEPSS <= 49%HIGH2017-03-07

An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of...

CVEs:CVE-2017-0506

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0517

Open SourceEPSS <= 49%HIGH2017-03-07

An elevation of privilege vulnerability in the MediaTek hardware sensor driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a p...

CVEs:CVE-2017-0517

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0479

Open SourceEPSS <= 49%HIGH2017-03-07

An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevate...

CVEs:CVE-2017-0479

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-8485

Open SourceEPSS <= 49%CRITICAL2017-03-07

An information disclosure vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823681.

CVEs:CVE-2016-8485

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-8486

Open SourceEPSS <= 49%CRITICAL2017-03-07

An information disclosure vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823691.

CVEs:CVE-2016-8486

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0522

Open SourceEPSS <= 49%HIGH2017-03-07

An elevation of privilege vulnerability in a MediaTek APK could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High due to the possibility of local arbitrary code execut...

CVEs:CVE-2017-0522

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10231

Open SourceEPSS <= 49%HIGH2017-03-08

An elevation of privilege vulnerability in the Qualcomm sound codec driver. Product: Android. Versions: Android kernel. Android ID: A-33966912. References: QC-CR#1096799.

CVEs:CVE-2016-10231

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0482

Open SourceEPSS <= 49%HIGH2017-03-07

A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versi...

CVEs:CVE-2017-0482

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0483

Open SourceEPSS <= 49%HIGH2017-03-07

A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versi...

CVEs:CVE-2017-0483

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0484

Open SourceEPSS <= 49%HIGH2017-03-07

A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versi...

CVEs:CVE-2017-0484

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0485

Open SourceEPSS <= 49%HIGH2017-03-07

A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versi...

CVEs:CVE-2017-0485

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0486

Open SourceEPSS <= 49%HIGH2017-03-07

A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versi...

CVEs:CVE-2017-0486

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0494

Open SourceEPSS <= 49%HIGH2017-03-07

An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data wit...

CVEs:CVE-2017-0494

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0497

Open SourceEPSS <= 49%HIGH2017-03-07

A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Moderate because it requires an uncommon device configuration. Product: Android. Versions...

CVEs:CVE-2017-0497

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10234

Open SourceEPSS <= 49%HIGH2017-03-08

An information disclosure vulnerability in the Qualcomm IPA driver. Product: Android. Versions: Android kernel. Android ID: A-34390017. References: QC-CR#1069060.

CVEs:CVE-2016-10234

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0490

Open SourceEPSS <= 49%HIGH2017-03-07

An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to delete user data. This issue is rated as Moderate because it is a local bypass of user interaction requirements that would normally require either user initi...

CVEs:CVE-2017-0490

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0495

Open SourceEPSS <= 49%HIGH2017-03-07

An information disclosure vulnerability in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Pro...

CVEs:CVE-2017-0495

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0499

Open SourceEPSS <= 49%HIGH2017-03-07

A denial of service vulnerability in Audioserver could enable a local malicious application to cause a device hang or reboot. This issue is rated as Low due to the possibility of a temporary denial of service. Product: Android. Versions: 5.1.1, 6.0, 6....

CVEs:CVE-2017-0499

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0529

Open SourceEPSS <= 49%HIGH2017-03-07

An information disclosure vulnerability in the MediaTek driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit us...

CVEs:CVE-2017-0529

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10236

Open SourceEPSS <= 49%HIGH2017-03-07

An information disclosure vulnerability in the Qualcomm USB driver. Product: Android. Versions: Android kernel. Android ID: A-33280689. References: QC-CR#1102418.

CVEs:CVE-2016-10236

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0489

Open SourceEPSS <= 49%CRITICAL2017-03-07

An elevation of privilege vulnerability in Location Manager could enable a local malicious application to bypass operating system protections for location data. This issue is rated as Moderate because it could be used to generate inaccurate data. Produ...

CVEs:CVE-2017-0489

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0496

Open SourceEPSS <= 49%HIGH2017-03-07

A denial of service vulnerability in Setup Wizard could allow a local malicious application to temporarily block access to an affected device. This issue is rated as Moderate because it may require a factory reset to repair the device. Product: Android...

CVEs:CVE-2017-0496

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0532

Open SourceEPSS <= 49%MEDIUM2017-03-07

An information disclosure vulnerability in the MediaTek video codec driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged p...

CVEs:CVE-2017-0532

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0491

Open SourceEPSS <= 49%HIGH2017-03-07

An elevation of privilege vulnerability in Package Manager could enable a local malicious application to prevent users from uninstalling applications or removing permissions from applications. This issue is rated as Moderate because it is a local bypas...

CVEs:CVE-2017-0491

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-5042

GoogleEPSS <= 49%MEDIUM2017-03-10

Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observ...

CVEs:CVE-2017-5042

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-0492

Open SourceEPSS <= 49%HIGH2017-03-07

An elevation of privilege vulnerability in the System UI could enable a local malicious application to create a UI overlay covering the entire screen. This issue is rated as Moderate because it is a local bypass of user interaction requirements that wo...

CVEs:CVE-2017-0492

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5857

Open SourceEPSS <= 49%HIGH2017-03-07

The Qualcomm SPCom driver in Android before 7.0 allows local users to execute arbitrary code within the context of the kernel via a crafted application, aka Android internal bug 34386529 and Qualcomm internal bug CR#1094140.

CVEs:CVE-2016-5857

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0498

Open SourceEPSS <= 49%MEDIUM2017-03-07

A denial of service vulnerability in Setup Wizard could allow a local attacker to require Google account sign-in after a factory reset. This issue is rated as Moderate because it may require a factory reset to repair the device. Product: Android. Versi...

CVEs:CVE-2017-0498

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.