Advisories
Project ZeroExploitedCISA KEV listed2017-04-12
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows API."
CVEs:CVE-2017-0199
GoogleExploitedCISA KEV listedHIGH2017-04-12
CVEs:CVE-2017-0199
GoogleExploitedCISA KEV listedHIGH2017-04-12
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted docu...
CVEs:CVE-2017-0199
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| intellispace_portal |
affected |
philips |
— |
— |
| office |
affected |
microsoft |
— |
— |
| windows_7 |
affected |
microsoft |
— |
— |
| windows_server_2008 |
affected |
microsoft |
— |
— |
| windows_server_2012 |
affected |
microsoft |
— |
— |
| windows_vista |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2017-04-27
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in April 2017.
CVEs:CVE-2017-8291
GoogleExploitedCISA KEV listedHIGH2017-04-27
CVEs:CVE-2017-8291
GoogleExploitedCISA KEV listedCRITICAL2017-04-27
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in Ap...
CVEs:CVE-2017-8291
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_eus |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_server_aus |
affected |
redhat |
— |
— |
| enterprise_linux_server_tus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| ghostscript |
affected |
artifex |
— |
— |
Open SourceExploitedCISA KEV listedCRITICAL2017-04-21
Updated chromium-browser-stable packages fix security vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:5 |
chromium-browser-stable |
— |
GoogleExploitedCISA KEV listedCRITICAL2017-04-12
An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevati...
CVEs:CVE-2017-0210
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| internet_explorer |
affected |
microsoft |
— |
— |
GoogleExploitedCISA KEV listedMEDIUM2017-04-12
CVEs:CVE-2017-0210
Project ZeroExploitedCISA KEV listed2017-04-12
An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Privilege Vulnerability."
CVEs:CVE-2017-0210
Project ZeroExploitedCISA KEV listed2017-04-25
IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated attacker to execute arbitrary code by specifying a large mailbox name. IBM X-Force ID: 124749.
CVEs:CVE-2017-1274
GoogleExploitedCISA KEV listedHIGH2017-04-25
IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated attacker to execute arbitrary code by specifying a large mailbox name. IBM X-Force ID: 124749.
CVEs:CVE-2017-1274
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| domino |
affected |
ibm |
— |
— |
GoogleExploitedCISA KEV listedHIGH2017-04-25
CVEs:CVE-2017-1274
Open SourcePoC exploitHIGH2017-04-04
udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.
CVEs:CVE-2016-10229
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
GooglePoC exploitCRITICAL2017-04-04
CVEs:CVE-2016-10229
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0541
Open SourcePoC exploitHIGH2017-04-04
A remote code execution vulnerability in sonivox in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote c...
CVEs:CVE-2017-0541
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0540
Open SourcePoC exploitHIGH2017-04-04
A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote c...
CVEs:CVE-2017-0540
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0553
Open SourcePoC exploitHIGH2017-04-04
An elevation of privilege vulnerability in libnl could enable a local malicious application to execute arbitrary code within the context of the Wi-Fi service. This issue is rated as Moderate because it first requires compromising a privileged process a...
CVEs:CVE-2017-0553
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2017-04-13
mediaserver in Android 2.2 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7921.
CVEs:CVE-2014-7920
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitCRITICAL2017-04-13
CVEs:CVE-2014-7920
Open SourcePoC exploitHIGH2017-04-04
A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote co...
CVEs:CVE-2017-0538
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0538
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0539
Open SourcePoC exploitHIGH2017-04-04
A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote c...
CVEs:CVE-2017-0539
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2017-04-04
A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote co...
CVEs:CVE-2017-0542
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0542
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0543
Open SourcePoC exploitHIGH2017-04-04
A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote co...
CVEs:CVE-2017-0543
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2017-04-04
The eCryptfs subsystem in the Linux kernel before 3.18 allows local users to gain privileges via a large filesystem stack that includes an overlayfs layer, related to fs/ecryptfs/main.c and fs/overlayfs/super.c.
CVEs:CVE-2014-9922
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2014-9922
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0551
Open SourcePoC exploitHIGH2017-04-04
A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Produc...
CVEs:CVE-2017-0551
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0554
Open SourcePoC exploitCRITICAL2017-04-04
An elevation of privilege vulnerability in the Telephony component could enable a local malicious application to access capabilities outside of its permission levels. This issue is rated as Moderate because it could be used to gain access to elevated c...
CVEs:CVE-2017-0554
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2017-04-04
CVEs:CVE-2016-5349
Open SourcePoC exploitCRITICAL2017-04-04
The high level operating systems (HLOS) was not providing sufficient memory address information to ensure that secure applications inside Qualcomm Secure Execution Environment (QSEE) only write to legitimate memory ranges related to the QSEE secure app...
CVEs:CVE-2016-5349
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2017-04-04
An elevation of privilege vulnerability in CameraBase could enable a local malicious application to execute arbitrary code. This issue is rated as High because it is a local arbitrary code execution in a privileged process. Product: Android. Versions: ...
CVEs:CVE-2017-0544
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0544
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0562
Open SourcePoC exploitHIGH2017-04-04
An elevation of privilege vulnerability in the MediaTek touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanen...
CVEs:CVE-2017-0562
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0545
Open SourcePoC exploitHIGH2017-04-04
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevate...
CVEs:CVE-2017-0545
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0546
Open SourcePoC exploitHIGH2017-04-04
An elevation of privilege vulnerability in SurfaceFlinger could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elev...
CVEs:CVE-2017-0546
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2017-04-04
A remote denial of service vulnerability in libskia could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Ve...
CVEs:CVE-2017-0548
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0548
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0565
Open SourcePoC exploitHIGH2017-04-04
An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privilege...
CVEs:CVE-2017-0565
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0566
Open SourcePoC exploitHIGH2017-04-04
An elevation of privilege vulnerability in the MediaTek camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged...
CVEs:CVE-2017-0566
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0578
Open SourcePoC exploitHIGH2017-04-04
An elevation of privilege vulnerability in the DTS sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged proce...
CVEs:CVE-2017-0578
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0549
Open SourcePoC exploitHIGH2017-04-04
A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Produc...
CVEs:CVE-2017-0549
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2017-04-04
A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Produc...
CVEs:CVE-2017-0550
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0550
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-0552
Open SourcePoC exploitHIGH2017-04-04
A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Produc...
CVEs:CVE-2017-0552
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2014-9935
Open SourcePoC exploitHIGH2017-04-04
In TrustZone an integer overflow vulnerability leading to a buffer overflow could potentially occur in a DRM routine in all Android releases from CAF using the Linux kernel.
CVEs:CVE-2014-9935
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2017-04-04
A buffer overflow vulnerability in all Android releases from CAF using the Linux kernel can potentially occur if an OEM performs an app region size customization due to a hard-coded value.
CVEs:CVE-2014-9931
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2014-9931
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2014-9937
Open SourcePoC exploitHIGH2017-04-04
In TrustZone a buffer overflow vulnerability can potentially occur in a DRM routine in all Android releases from CAF using the Linux kernel.
CVEs:CVE-2014-9937
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2017-04-04
In TrustZone a buffer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel while loading an ELF file.
CVEs:CVE-2015-8999
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2015-8999
Open SourcePoC exploitHIGH2017-04-04
In TrustZone, an integer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel due to an improper address range computation.
CVEs:CVE-2014-9932
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2014-9932
Open SourcePoC exploitHIGH2017-04-04
In TrustZone an integer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel.
CVEs:CVE-2015-8995
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2015-8995
Open SourcePoC exploitHIGH2017-04-04
In TrustZone an integer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel.
CVEs:CVE-2015-8998
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2015-8998
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2014-9933
Open SourcePoC exploitHIGH2017-04-04
Due to missing input validation in all Android releases from CAF using the Linux kernel, HLOS can write to fuses for which it should not have access.
CVEs:CVE-2014-9933
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2015-9000
Open SourcePoC exploitHIGH2017-04-04
In TrustZone an untrusted pointer dereference vulnerability can potentially occur in a DRM routine in all Android releases from CAF using the Linux kernel.
CVEs:CVE-2015-9000
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2015-9002
Open SourcePoC exploitHIGH2017-04-04
In TrustZone an out-of-range pointer offset vulnerability can potentially occur in a DRM routine in all Android releases from CAF using the Linux kernel.
CVEs:CVE-2015-9002
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2015-9003
Open SourcePoC exploitHIGH2017-04-04
In TrustZone a cryptographic issue can potentially occur in all Android releases from CAF using the Linux kernel.
CVEs:CVE-2015-9003
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2017-04-04
CVEs:CVE-2017-0557
Open SourcePoC exploitHIGH2017-04-04
An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. P...
CVEs:CVE-2017-0557
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2017-04-04
An information disclosure vulnerability in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Andr...
CVEs:CVE-2017-0558
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2017-04-04
CVEs:CVE-2017-0558
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2014-9936
Open SourcePoC exploitHIGH2017-04-04
In TrustZone a time-of-check time-of-use race condition could potentially exist in an authentication routine in all Android releases from CAF using the Linux kernel.
CVEs:CVE-2014-9936
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitMEDIUM2017-04-04
In TrustZone an information exposure vulnerability can potentially occur in all Android releases from CAF using the Linux kernel.
CVEs:CVE-2015-9001
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2017-04-04
CVEs:CVE-2015-9001
Open SourcePoC exploitHIGH2017-04-04
An information disclosure vulnerability in libskia could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android....
CVEs:CVE-2017-0559
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2017-04-04
CVEs:CVE-2017-0559
GooglePoC exploitMEDIUM2017-04-04
CVEs:CVE-2017-0555
Open SourcePoC exploitHIGH2017-04-04
An information disclosure vulnerability in libavc in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Pro...
CVEs:CVE-2017-0555
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2017-04-04
An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. P...
CVEs:CVE-2017-0556
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2017-04-04
CVEs:CVE-2017-0556
Open SourcePoC exploitHIGH2017-04-04
An information disclosure vulnerability in libmedia in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it is a general bypass for operating system protections t...
CVEs:CVE-2017-0547
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2017-04-04
CVEs:CVE-2017-0547
Open SourcePoC exploitHIGH2017-04-04
An information disclosure vulnerability in the factory reset process could enable a local malicious attacker to access data from the previous owner. This issue is rated as Moderate due to the possibility of bypassing device protection. Product: Android...
CVEs:CVE-2017-0560
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2017-04-04
CVEs:CVE-2017-0560
Open SourcePoC exploitHIGH2017-04-04
In TrustZone a time-of-check time-of-use race condition could potentially exist in a QFPROM routine in all Android releases from CAF using the Linux kernel.
CVEs:CVE-2015-8996
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2015-8996
Open SourcePoC exploitHIGH2017-04-04
In TrustZone a time-of-check time-of-use race condition could potentially exist in a listener routine in all Android releases from CAF using the Linux kernel.
CVEs:CVE-2015-8997
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2015-8997
GooglePoC exploitLOW2017-04-04
CVEs:CVE-2017-6426
Open SourcePoC exploitHIGH2017-04-04
An information disclosure vulnerability in the Qualcomm SPMI driver. Product: Android. Versions: Android kernel. Android ID: A-33644474. References: QC-CR#1106842.
CVEs:CVE-2017-6426
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2017-04-04
A PKCS#1 v1.5 signature verification routine in all Android releases from CAF using the Linux kernel may not check padding.
CVEs:CVE-2014-9934
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2014-9934
Open SourcePoC exploitHIGH2017-04-04
An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointer dereference when processing an accept system call by the user process on AF_MSM_IPC sockets, which could let a local malicious use...
CVEs:CVE-2016-5346
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitLOW2017-04-04
CVEs:CVE-2016-5346
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-6424
Open SourcePoC exploitCRITICAL2017-04-04
An elevation of privilege vulnerability in the Qualcomm WiFi driver. Product: Android. Versions: Android kernel. Android ID: A-32086742. References: QC-CR#1102648.
CVEs:CVE-2017-6424
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-04-04
CVEs:CVE-2017-6423
Open SourcePoC exploitCRITICAL2017-04-04
An elevation of privilege vulnerability in the Qualcomm kyro L2 driver. Product: Android. Versions: Android kernel. Android ID: A-32831370. References: QC-CR#1103158.
CVEs:CVE-2017-6423
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-04-25
Red Hat Security Advisory: chromium-browser security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser |
affected |
Red Hat:rhel_extras:6 |
chromium-browser |
— |
| chromium-browser-debuginfo |
affected |
Red Hat:rhel_extras:6 |
chromium-browser-debuginfo |
— |
Open SourceEPSS <= 49%CRITICAL2017-04-24
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 12 SP2 |
chromium |
— |
Open SourceEPSS <= 49%CRITICAL2017-04-24
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 12 SP2 |
chromium |
— |
GoogleEPSS <= 49%CRITICAL2017-04-20
Type confusion in Blink in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Android, allowed a remote attacker to potentially obtain code execution via a crafted HTML page.
CVEs:CVE-2017-5059
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleEPSS <= 49%HIGH2017-04-20
CVEs:CVE-2017-5059
Open SourceEPSS <= 49%HIGH2017-04-04
DEBIAN-CVE-2017-3204
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-go.crypto |
affected |
Debian:11 |
golang-go.crypto |
— |
| golang-go.crypto |
affected |
Debian:13 |
golang-go.crypto |
— |
| golang-go.crypto |
affected |
Debian:14 |
golang-go.crypto |
— |
| golang-go.crypto |
affected |
Debian:12 |
golang-go.crypto |
— |
Open SourceEPSS <= 49%HIGH2017-04-04
golang.org/x/crypto/ssh Man-in-the-Middle attack
CVEs:CVE-2017-3204
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/crypto |
affected |
golang.org |
golang.org/x/crypto |
— |
GoogleEPSS <= 49%HIGH2017-04-04
The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default behavior changed in commit e4e2799 to require explicitly registering a hostkey verification mechanism.
CVEs:CVE-2017-3204
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| crypto |
affected |
golang |
— |
— |
Open SourceEPSS <= 49%CRITICAL2017-04-14
DEBIAN-CVE-2017-7860
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
Debian:11 |
grpc |
— |
| grpc |
affected |
Debian:12 |
grpc |
— |
| grpc |
affected |
Debian:13 |
grpc |
— |
| grpc |
affected |
Debian:14 |
grpc |
— |
GoogleEPSS <= 49%CRITICAL2017-04-14
CVEs:CVE-2017-7860
Open SourceEPSS <= 49%CRITICAL2017-04-14
Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/ext/client_channel/parse_address.c.
CVEs:CVE-2017-7860
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
grpc |
— |
— |
Open SourceEPSS <= 49%CRITICAL2017-04-30
DEBIAN-CVE-2017-8359
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
Debian:11 |
grpc |
— |
| grpc |
affected |
Debian:12 |
grpc |
— |
| grpc |
affected |
Debian:13 |
grpc |
— |
| grpc |
affected |
Debian:14 |
grpc |
— |
Open SourceEPSS <= 49%CRITICAL2017-04-30
PYSEC-2017-101
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpcio |
affected |
PyPI |
grpcio |
— |
Open SourceEPSS <= 49%CRITICAL2017-04-30
Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destroy function in core/lib/surface/call.c.
CVEs:CVE-2017-8359
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
grpc |
— |
— |
Open SourceEPSS <= 49%2017-04-30
PYSEC-2017-101
CVEs:CVE-2017-8359
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpcio |
affected |
PyPI |
grpcio |
— |
GoogleEPSS <= 49%CRITICAL2017-04-30
CVEs:CVE-2017-8359
Open SourceEPSS <= 49%CRITICAL2017-04-14
DEBIAN-CVE-2017-7861
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
Debian:11 |
grpc |
— |
| grpc |
affected |
Debian:12 |
grpc |
— |
| grpc |
affected |
Debian:13 |
grpc |
— |
| grpc |
affected |
Debian:14 |
grpc |
— |
Open SourceEPSS <= 49%CRITICAL2017-04-14
Google gRPC before 2017-02-22 has an out-of-bounds write related to the gpr_free function in core/lib/support/alloc.c.
CVEs:CVE-2017-7861
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
grpc |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-04-14
CVEs:CVE-2017-7861
Open SourceEPSS <= 49%CRITICAL2017-04-01
Security update for Chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 12 SP2 |
chromium |
— |
Open SourceEPSS <= 49%CRITICAL2017-04-01
Security update for Chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 12 SP2 |
chromium |
— |
Open SourceEPSS <= 49%CRITICAL2017-04-13
HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to execute arbitrary scripts or set arbitrary values in cookies.
CVEs:CVE-2016-1155
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-04-13
CVEs:CVE-2016-1155
GoogleEPSS <= 49%HIGH2017-04-21
Skia, as used in Google Chrome before 50.0.2661.94, allows remote attackers to bypass the Same Origin Policy and obtain sensitive information.
CVEs:CVE-2016-5168
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-04-21
CVEs:CVE-2016-5168
Open SourceEPSS <= 49%MEDIUM2017-04-19
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit v...
CVEs:CVE-2017-3544
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_server_aus |
affected |
redhat |
— |
— |
| enterprise_linux_server_eus |
affected |
redhat |
— |
— |
| enterprise_linux_server_tus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| icedtea |
affected |
redhat |
— |
— |
| jdk |
affected |
oracle |
— |
— |
| jre |
affected |
oracle |
— |
— |
| jrockit |
affected |
oracle |
— |
— |
| satellite |
affected |
redhat |
— |
— |
GoogleEPSS <= 49%LOW2017-04-19
CVEs:CVE-2017-3544
GoogleEPSS <= 49%HIGH2017-04-20
CVEs:CVE-2017-5057
GoogleEPSS <= 49%HIGH2017-04-20
Type confusion in PDFium in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
CVEs:CVE-2017-5057
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleEPSS <= 49%HIGH2017-04-20
A numeric overflow in Skia in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVEs:CVE-2017-5063
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleEPSS <= 49%HIGH2017-04-20
CVEs:CVE-2017-5063
GoogleEPSS <= 49%MEDIUM2017-04-20
CVEs:CVE-2017-5067
GoogleEPSS <= 49%MEDIUM2017-04-20
An insufficient watchdog timer in navigation in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2017-5067
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleEPSS <= 49%HIGH2017-04-20
Incorrect handling of DOM changes in Blink in Google Chrome prior to 58.0.3029.81 for Windows allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2017-5064
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-04-20
CVEs:CVE-2017-5064
GoogleEPSS <= 49%CRITICAL2017-04-20
A use after free in PrintPreview in Google Chrome prior to 58.0.3029.81 for Windows allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVEs:CVE-2017-5058
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-04-20
CVEs:CVE-2017-5058
GoogleEPSS <= 49%MEDIUM2017-04-20
CVEs:CVE-2017-5060
GoogleEPSS <= 49%CRITICAL2017-04-20
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
CVEs:CVE-2017-5060
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-04-20
Lack of an appropriate action on page navigation in Blink in Google Chrome prior to 58.0.3029.81 for Windows and Mac allowed a remote attacker to potentially confuse a user into making an incorrect security decision via a crafted HTML page.
CVEs:CVE-2017-5065
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-04-20
CVEs:CVE-2017-5065
GoogleEPSS <= 49%MEDIUM2017-04-20
CVEs:CVE-2017-5061
GoogleEPSS <= 49%MEDIUM2017-04-20
A race condition in navigation in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2017-5061
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-04-20
A use after free in Chrome Apps in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to potentially perform out of bounds memory access via a crafted Chrome extension.
CVEs:CVE-2017-5062
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleEPSS <= 49%HIGH2017-04-20
CVEs:CVE-2017-5062
GoogleEPSS <= 49%CRITICAL2017-04-20
Incorrect MIME type of XSS-Protection reports in Blink in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Android, allowed a remote attacker to circumvent Cross-Origin Resource Sharing checks via a crafted HTML page.
CVEs:CVE-2017-5069
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-04-20
CVEs:CVE-2017-5069
Open SourceEPSS <= 49%HIGH2017-04-13
mediaserver in Android 4.0.3 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7920.
CVEs:CVE-2014-7921
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-04-13
CVEs:CVE-2014-7921
GoogleEPSS <= 49%HIGH2017-04-25
CVEs:CVE-2017-5047
GoogleEPSS <= 49%CRITICAL2017-04-25
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
CVEs:CVE-2017-5047
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-04-25
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
CVEs:CVE-2017-5048
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-04-25
CVEs:CVE-2017-5048
GoogleEPSS <= 49%HIGH2017-04-25
CVEs:CVE-2017-5049
GoogleEPSS <= 49%CRITICAL2017-04-25
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
CVEs:CVE-2017-5049
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-04-25
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
CVEs:CVE-2017-5050
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-04-25
CVEs:CVE-2017-5050
GoogleEPSS <= 49%HIGH2017-04-25
CVEs:CVE-2017-5051
GoogleEPSS <= 49%CRITICAL2017-04-25
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
CVEs:CVE-2017-5051
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-04-20
CVEs:CVE-2017-5066
GoogleEPSS <= 49%MEDIUM2017-04-20
Insufficient consistency checks in signature handling in the networking stack in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to incorrectly accept a badly formed X.509 certifi...
CVEs:CVE-2017-5066
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleEPSS <= 49%HIGH2017-04-21
CVEs:CVE-2016-2433
Open SourceEPSS <= 49%CRITICAL2017-04-21
The Broadcom Wi-Fi driver for Android, as used by BlackBerry smartphones before Build AAE570, allows remote attackers to execute arbitrary code in the context of the kernel.
CVEs:CVE-2016-2433
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-04-13
CVEs:CVE-2013-6648
Open SourceEPSS <= 49%HIGH2017-04-13
SkRegion::setPath in Skia allows remote attackers to cause a denial of service (crash).
CVEs:CVE-2013-6648
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| skia |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-04-11
CVEs:CVE-2013-6647
GoogleEPSS <= 49%CRITICAL2017-04-11
A use-after-free in AnimationController::endAnimationUpdate in Google Chrome.
CVEs:CVE-2013-6647
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-04-21
CVEs:CVE-2016-0833
Open SourceEPSS <= 49%HIGH2017-04-21
Android allows users to cause a denial of service.
CVEs:CVE-2016-0833
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-04-13
Google Chrome caches TLS sessions before certificate validation occurs.
CVEs:CVE-2013-6662
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-04-13
CVEs:CVE-2013-6662