Google Security Advisories · May 2017 — Google Security Advisories
181 advisories 90 CVEs 12 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2017-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 12 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2017-0262

Project ZeroExploitedCISA KEV listed2017-05-10

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0261 and CVE-2017-0281.

CVEs:CVE-2017-0262

Upstream advisory

CVE-2017-0262

GoogleExploitedCISA KEV listedHIGH2017-05-10

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-...

CVEs:CVE-2017-0262

Affected products

ProductStatusVendorPackageEcosystem
office affected microsoft
Upstream advisory

CVE-2017-0261

GoogleExploitedCISA KEV listedHIGH2017-05-10

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-...

CVEs:CVE-2017-0261

Affected products

ProductStatusVendorPackageEcosystem
office affected microsoft
Upstream advisory

CVE-2017-0261

Project ZeroExploitedCISA KEV listed2017-05-10

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0262 and CVE-2017-0281.

CVEs:CVE-2017-0261

Upstream advisory

CVE-2017-0222

GoogleExploitedCISA KEV listedCRITICAL2017-05-10

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.

CVEs:CVE-2017-0222

Affected products

ProductStatusVendorPackageEcosystem
internet_explorer affected microsoft
Upstream advisory

CVE-2017-0222

Project ZeroExploitedCISA KEV listed2017-05-10

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.

CVEs:CVE-2017-0222

Upstream advisory

CVE-2017-0263

Project ZeroExploitedCISA KEV listed2017-05-10

The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

CVEs:CVE-2017-0263

Upstream advisory

CVE-2017-0263

GoogleExploitedCISA KEV listedHIGH2017-05-10

The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a ...

CVEs:CVE-2017-0263

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1511 affected microsoft
windows_10_1607 affected microsoft
windows_10_1703 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
Upstream advisory

CVE-2016-6799

Open SourceWeaponized exploitHIGH2017-05-09

Information Exposure in cordova-android

CVEs:CVE-2016-6799

Affected products

ProductStatusVendorPackageEcosystem
cordova-android affected npm cordova-android
Upstream advisory

CVE-2016-6799

Open SourceWeaponized exploitHIGH2017-05-09

Information Exposure in cordova-android

CVEs:CVE-2016-6799

Affected products

ProductStatusVendorPackageEcosystem
cordova-android affected npm cordova-android
Upstream advisory

CVE-2016-6799

GoogleWeaponized exploitHIGH2017-05-09

Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()) are stored in a series of circular buffers on the device. By default, ...

CVEs:CVE-2016-6799

Affected products

ProductStatusVendorPackageEcosystem
cordova affected apache
Upstream advisory

CVE-2015-9004

Open SourcePoC exploitHIGH2017-05-02

kernel/events/core.c in the Linux kernel before 3.19 mishandles counter grouping, which allows local users to gain privileges via a crafted application, related to the perf_pmu_register and perf_event_open functions.

CVEs:CVE-2015-9004

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2017-0331

Open SourcePoC exploitHIGH2017-05-02

An elevation of privilege vulnerability in the NVIDIA video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device...

CVEs:CVE-2017-0331

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2014-9940

Open SourceEPSS <= 49%HIGH2017-05-02

The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application.

CVEs:CVE-2014-9940

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2017-0587

Open SourceEPSS <= 49%HIGH2017-05-02

A remote code execution vulnerability in libmpeg2 in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote ...

CVEs:CVE-2017-0587

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0588

Open SourceEPSS <= 49%HIGH2017-05-02

A remote code execution vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the p...

CVEs:CVE-2017-0588

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0589

Open SourceEPSS <= 49%HIGH2017-05-02

A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote c...

CVEs:CVE-2017-0589

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0590

Open SourceEPSS <= 49%HIGH2017-05-02

A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote c...

CVEs:CVE-2017-0590

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0591

Open SourceEPSS <= 49%HIGH2017-05-02

A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote co...

CVEs:CVE-2017-0591

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0592

Open SourceEPSS <= 49%HIGH2017-05-02

A remote code execution vulnerability in FLACExtractor.cpp in libstagefright in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to...

CVEs:CVE-2017-0592

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5868

Open SourceEPSS <= 49%HIGH2017-05-02

drivers/net/ethernet/msm/rndis_ipa.c in the Qualcomm networking driver in Android allows remote attackers to execute arbitrary code via a crafted application compromising a privileged process.

CVEs:CVE-2016-5868

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

RHSA-2017:1367

GoogleEPSS <= 49%MEDIUM2017-05-31

Red Hat Security Advisory: CFME 5.8.0 security, bug, and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
ansible affected Red Hat:cloudforms_managementengine:5.8::el7 ansible
ansible-tower-server affected Red Hat:cloudforms_managementengine:5.8::el7 ansible-tower-server
ansible-tower-setup affected Red Hat:cloudforms_managementengine:5.8::el7 ansible-tower-setup
bubblewrap affected Red Hat:cloudforms_managementengine:5.8::el7 bubblewrap
bubblewrap-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 bubblewrap-debuginfo
cfme affected Red Hat:cloudforms_managementengine:5.8::el7 cfme
cfme-appliance affected Red Hat:cloudforms_managementengine:5.8::el7 cfme-appliance
cfme-appliance-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 cfme-appliance-debuginfo
cfme-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 cfme-debuginfo
cfme-gemset affected Red Hat:cloudforms_managementengine:5.8::el7 cfme-gemset
erlang affected Red Hat:cloudforms_managementengine:5.8::el7 erlang
erlang-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 erlang-debuginfo
freeipmi affected Red Hat:cloudforms_managementengine:5.8::el7 freeipmi
freeipmi-bmc-watchdog affected Red Hat:cloudforms_managementengine:5.8::el7 freeipmi-bmc-watchdog
freeipmi-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 freeipmi-debuginfo
freeipmi-devel affected Red Hat:cloudforms_managementengine:5.8::el7 freeipmi-devel
freeipmi-ipmidetectd affected Red Hat:cloudforms_managementengine:5.8::el7 freeipmi-ipmidetectd
freeipmi-ipmiseld affected Red Hat:cloudforms_managementengine:5.8::el7 freeipmi-ipmiseld
google-compute-engine affected Red Hat:cloudforms_managementengine:5.8::el7 google-compute-engine
google-config affected Red Hat:cloudforms_managementengine:5.8::el7 google-config
libtomcrypt affected Red Hat:cloudforms_managementengine:5.8::el7 libtomcrypt
libtomcrypt-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 libtomcrypt-debuginfo
libtomcrypt-devel affected Red Hat:cloudforms_managementengine:5.8::el7 libtomcrypt-devel
libtomcrypt-doc affected Red Hat:cloudforms_managementengine:5.8::el7 libtomcrypt-doc
libtommath affected Red Hat:cloudforms_managementengine:5.8::el7 libtommath
libtommath-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 libtommath-debuginfo
libtommath-devel affected Red Hat:cloudforms_managementengine:5.8::el7 libtommath-devel
libtommath-doc affected Red Hat:cloudforms_managementengine:5.8::el7 libtommath-doc
nginx affected Red Hat:cloudforms_managementengine:5.8::el7 nginx
nginx-all-modules affected Red Hat:cloudforms_managementengine:5.8::el7 nginx-all-modules
nginx-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 nginx-debuginfo
nginx-filesystem affected Red Hat:cloudforms_managementengine:5.8::el7 nginx-filesystem
nginx-mod-http-geoip affected Red Hat:cloudforms_managementengine:5.8::el7 nginx-mod-http-geoip
nginx-mod-http-image-filter affected Red Hat:cloudforms_managementengine:5.8::el7 nginx-mod-http-image-filter
nginx-mod-http-perl affected Red Hat:cloudforms_managementengine:5.8::el7 nginx-mod-http-perl
nginx-mod-http-xslt-filter affected Red Hat:cloudforms_managementengine:5.8::el7 nginx-mod-http-xslt-filter
nginx-mod-mail affected Red Hat:cloudforms_managementengine:5.8::el7 nginx-mod-mail
nginx-mod-stream affected Red Hat:cloudforms_managementengine:5.8::el7 nginx-mod-stream
postgresql94 affected Red Hat:cloudforms_managementengine:5.8::el7 postgresql94
postgresql94-contrib affected Red Hat:cloudforms_managementengine:5.8::el7 postgresql94-contrib
postgresql94-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 postgresql94-debuginfo
postgresql94-devel affected Red Hat:cloudforms_managementengine:5.8::el7 postgresql94-devel
postgresql94-docs affected Red Hat:cloudforms_managementengine:5.8::el7 postgresql94-docs
postgresql94-libs affected Red Hat:cloudforms_managementengine:5.8::el7 postgresql94-libs
postgresql94-plperl affected Red Hat:cloudforms_managementengine:5.8::el7 postgresql94-plperl
postgresql94-plpython affected Red Hat:cloudforms_managementengine:5.8::el7 postgresql94-plpython
postgresql94-pltcl affected Red Hat:cloudforms_managementengine:5.8::el7 postgresql94-pltcl
postgresql94-server affected Red Hat:cloudforms_managementengine:5.8::el7 postgresql94-server
postgresql94-test affected Red Hat:cloudforms_managementengine:5.8::el7 postgresql94-test
prince affected Red Hat:cloudforms_managementengine:5.8::el7 prince
python-crypto affected Red Hat:cloudforms_managementengine:5.8::el7 python-crypto
python-crypto-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 python-crypto-debuginfo
python-ecdsa affected Red Hat:cloudforms_managementengine:5.8::el7 python-ecdsa
python-httplib2 affected Red Hat:cloudforms_managementengine:5.8::el7 python-httplib2
python-keyczar affected Red Hat:cloudforms_managementengine:5.8::el7 python-keyczar
python-meld3 affected Red Hat:cloudforms_managementengine:5.8::el7 python-meld3
python-meld3-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 python-meld3-debuginfo
python-paramiko affected Red Hat:cloudforms_managementengine:5.8::el7 python-paramiko
python-paramiko-doc affected Red Hat:cloudforms_managementengine:5.8::el7 python-paramiko-doc
python-passlib affected Red Hat:cloudforms_managementengine:5.8::el7 python-passlib
rabbitmq-server affected Red Hat:cloudforms_managementengine:5.8::el7 rabbitmq-server
rh-postgresql95-postgresql-pglogical affected Red Hat:cloudforms_managementengine:5.8::el7 rh-postgresql95-postgresql-pglogical
rh-postgresql95-postgresql-pglogical-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-postgresql95-postgresql-pglogical-debuginfo
rh-postgresql95-repmgr affected Red Hat:cloudforms_managementengine:5.8::el7 rh-postgresql95-repmgr
rh-postgresql95-repmgr-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-postgresql95-repmgr-debuginfo
rh-ruby23-rubygem-bcrypt affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-bcrypt
rh-ruby23-rubygem-bcrypt-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-bcrypt-debuginfo
rh-ruby23-rubygem-bcrypt-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-bcrypt-doc
rh-ruby23-rubygem-eventmachine affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-eventmachine
rh-ruby23-rubygem-eventmachine-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-eventmachine-debuginfo
rh-ruby23-rubygem-eventmachine-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-eventmachine-doc
rh-ruby23-rubygem-ffi affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-ffi
rh-ruby23-rubygem-ffi-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-ffi-debuginfo
rh-ruby23-rubygem-ffi-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-ffi-doc
rh-ruby23-rubygem-hamlit affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-hamlit
rh-ruby23-rubygem-hamlit-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-hamlit-debuginfo
rh-ruby23-rubygem-hamlit-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-hamlit-doc
rh-ruby23-rubygem-http_parser.rb affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-http_parser.rb
rh-ruby23-rubygem-http_parser.rb-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-http_parser.rb-debuginfo
rh-ruby23-rubygem-http_parser.rb-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-http_parser.rb-doc
rh-ruby23-rubygem-json affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-json
rh-ruby23-rubygem-json-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-json-debuginfo
rh-ruby23-rubygem-json-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-json-doc
rh-ruby23-rubygem-linux_block_device affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-linux_block_device
rh-ruby23-rubygem-linux_block_device-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-linux_block_device-debuginfo
rh-ruby23-rubygem-linux_block_device-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-linux_block_device-doc
rh-ruby23-rubygem-memory_buffer affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-memory_buffer
rh-ruby23-rubygem-memory_buffer-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-memory_buffer-debuginfo
rh-ruby23-rubygem-memory_buffer-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-memory_buffer-doc
rh-ruby23-rubygem-net_app_manageability affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-net_app_manageability
rh-ruby23-rubygem-net_app_manageability-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-net_app_manageability-debuginfo
rh-ruby23-rubygem-net_app_manageability-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-net_app_manageability-doc
rh-ruby23-rubygem-nio4r affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-nio4r
rh-ruby23-rubygem-nio4r-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-nio4r-debuginfo
rh-ruby23-rubygem-nio4r-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-nio4r-doc
rh-ruby23-rubygem-nokogiri affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-nokogiri
rh-ruby23-rubygem-nokogiri-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-nokogiri-debuginfo
rh-ruby23-rubygem-nokogiri-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-nokogiri-doc
rh-ruby23-rubygem-ovirt-engine-sdk4 affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-ovirt-engine-sdk4
rh-ruby23-rubygem-ovirt-engine-sdk4-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-ovirt-engine-sdk4-debuginfo
rh-ruby23-rubygem-ovirt-engine-sdk4-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-ovirt-engine-sdk4-doc
rh-ruby23-rubygem-pg affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-pg
rh-ruby23-rubygem-pg-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-pg-debuginfo
rh-ruby23-rubygem-pg-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-pg-doc
rh-ruby23-rubygem-pkg-config affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-pkg-config
rh-ruby23-rubygem-pkg-config-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-pkg-config-doc
rh-ruby23-rubygem-puma affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-puma
rh-ruby23-rubygem-puma-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-puma-debuginfo
rh-ruby23-rubygem-puma-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-puma-doc
rh-ruby23-rubygem-redhat_access_cfme affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-redhat_access_cfme
rh-ruby23-rubygem-redhat_access_cfme-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-redhat_access_cfme-doc
rh-ruby23-rubygem-redhat_access_lib affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-redhat_access_lib
rh-ruby23-rubygem-rugged affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-rugged
rh-ruby23-rubygem-rugged-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-rugged-debuginfo
rh-ruby23-rubygem-rugged-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-rugged-doc
rh-ruby23-rubygem-thin affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-thin
rh-ruby23-rubygem-thin-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-thin-debuginfo
rh-ruby23-rubygem-thin-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-thin-doc
rh-ruby23-rubygem-unf_ext affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-unf_ext
rh-ruby23-rubygem-unf_ext-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-unf_ext-debuginfo
rh-ruby23-rubygem-unf_ext-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-unf_ext-doc
rh-ruby23-rubygem-websocket-driver affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-websocket-driver
rh-ruby23-rubygem-websocket-driver-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-websocket-driver-debuginfo
rh-ruby23-rubygem-websocket-driver-doc affected Red Hat:cloudforms_managementengine:5.8::el7 rh-ruby23-rubygem-websocket-driver-doc
smem affected Red Hat:cloudforms_managementengine:5.8::el7 smem
sshpass affected Red Hat:cloudforms_managementengine:5.8::el7 sshpass
sshpass-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 sshpass-debuginfo
supervisor affected Red Hat:cloudforms_managementengine:5.8::el7 supervisor
wmi affected Red Hat:cloudforms_managementengine:5.8::el7 wmi
wmi-debuginfo affected Red Hat:cloudforms_managementengine:5.8::el7 wmi-debuginfo
Upstream advisory

RHSA-2017:1228

Open SourceEPSS <= 49%HIGH2017-05-11

Red Hat Security Advisory: chromium-browser security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Red Hat:rhel_extras:6 chromium-browser
chromium-browser-debuginfo affected Red Hat:rhel_extras:6 chromium-browser-debuginfo
Upstream advisory

openSUSE-SU-2017:1190-1

Open SourceEPSS <= 49%NONE2017-05-06

Security update for Chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP2 chromium
Upstream advisory

openSUSE-SU-2017:1194-1

Open SourceEPSS <= 49%NONE2017-05-06

Security update for Chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP2 chromium
Upstream advisory

CVE-2017-5068

GoogleEPSS <= 49%HIGH2017-05-03

Incorrect handling of picture ID in WebRTC in Google Chrome prior to 58.0.3029.96 for Mac, Windows, and Linux allowed a remote attacker to trigger a race condition via a crafted HTML page.

CVEs:CVE-2017-5068

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2015-1529

Open SourceEPSS <= 49%CRITICAL2017-05-23

Integer overflow in soundtrigger/ISoundTriggerHwService.cpp in Android allows attacks to cause a denial of service via unspecified vectors.

CVEs:CVE-2015-1529

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-2171

GoogleEPSS <= 49%CRITICAL2017-05-22

Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior ...

CVEs:CVE-2017-2171

Affected products

ProductStatusVendorPackageEcosystem
captcha affected bestwebsoft
car_rental affected bestwebsoft
contact_form affected bestwebsoft
contact_form_multi affected bestwebsoft
contact_form_to_db affected bestwebsoft
custom_admin_page affected bestwebsoft
custom_fields_search affected bestwebsoft
custom_search affected bestwebsoft
donate affected bestwebsoft
email_queue affected bestwebsoft
error_log_viewer affected bestwebsoft
facebook_button affected bestwebsoft
featured_posts affected bestwebsoft
gallery affected bestwebsoft
gallery_categories affected bestwebsoft
google_\+1 affected bestwebsoft
google_adsense affected bestwebsoft
google_analytics affected bestwebsoft
google_captcha_\(recaptcha\) affected bestwebsoft
google_maps affected bestwebsoft
google_shortlink affected bestwebsoft
google_sitemap affected bestwebsoft
htaccess affected bestwebsoft
job_board affected bestwebsoft
latest_posts affected bestwebsoft
limit_attempts affected bestwebsoft
linkedin affected bestwebsoft
multilanguage affected bestwebsoft
pagination affected bestwebsoft
pdf_\&_print affected bestwebsoft
pinterest affected bestwebsoft
popular_posts affected bestwebsoft
portfolio affected bestwebsoft
post_to_csv affected bestwebsoft
profile_extra affected bestwebsoft
promobar affected bestwebsoft
quotes_and_tips affected bestwebsoft
realty affected bestwebsoft
re-attacher affected bestwebsoft
relevant_-_related_posts affected bestwebsoft
sender affected bestwebsoft
smtp affected bestwebsoft
social_buttons_pack affected bestwebsoft
subscriber affected bestwebsoft
testimonials affected bestwebsoft
timesheet affected bestwebsoft
twitter_button affected bestwebsoft
updater affected bestwebsoft
user_role affected bestwebsoft
visitors_online affected bestwebsoft
zendesk_help_center affected bestwebsoft
Upstream advisory

CVE-2017-0594

Open SourceEPSS <= 49%HIGH2017-05-02

An elevation of privilege vulnerability in codecs/aacenc/SoftAACEncoder2.cpp in libstagefright in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High b...

CVEs:CVE-2017-0594

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0595

Open SourceEPSS <= 49%HIGH2017-05-02

An elevation of privilege vulnerability in libstagefright in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local...

CVEs:CVE-2017-0595

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0596

Open SourceEPSS <= 49%HIGH2017-05-02

An elevation of privilege vulnerability in libstagefright in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local...

CVEs:CVE-2017-0596

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5853

Open SourceEPSS <= 49%CRITICAL2017-05-02

In an audio driver in all Qualcomm products with Android releases from CAF using the Linux kernel, when a sanity check encounters a length value not in the correct range, an error message is printed, but code execution continues in the same way as for ...

CVEs:CVE-2016-5853

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0597

Open SourceEPSS <= 49%HIGH2017-05-02

An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevate...

CVEs:CVE-2017-0597

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10239

Open SourceEPSS <= 49%HIGH2017-05-16

In TrustZone access control policy may potentially be bypassed in all Android releases from CAF using the Linux kernel due to improper input validation an integer overflow vulnerability leading to a buffer overflow could potentially occur and a buffer ...

CVEs:CVE-2016-10239

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0599

Open SourceEPSS <= 49%HIGH2017-05-02

A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Produ...

CVEs:CVE-2017-0599

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0620

Open SourceEPSS <= 49%HIGH2017-05-02

An elevation of privilege vulnerability in the Qualcomm Secure Channel Manager driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromis...

CVEs:CVE-2017-0620

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2016-10275

Open SourceEPSS <= 49%HIGH2017-05-12

An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device...

CVEs:CVE-2016-10275

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0465

Open SourceEPSS <= 49%HIGH2017-05-02

An elevation of privilege vulnerability in the Qualcomm ADSPRPC driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privilege...

CVEs:CVE-2017-0465

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2016-10238

Open SourceEPSS <= 49%HIGH2017-05-16

In QSEE in all Android releases from CAF using the Linux kernel access control may potentially be bypassed due to a page alignment issue.

CVEs:CVE-2016-10238

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5859

Open SourceEPSS <= 49%CRITICAL2017-05-02

In a sound driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is called with a very large length, an integer overflow could occur followed by a buffer overflow.

CVEs:CVE-2016-5859

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5860

Open SourceEPSS <= 49%CRITICAL2017-05-02

In an audio driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is called with a very large length, an integer overflow could occur followed by a heap buffer overflow.

CVEs:CVE-2016-5860

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10276

Open SourceEPSS <= 49%HIGH2017-05-12

An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device...

CVEs:CVE-2016-10276

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10237

Open SourceEPSS <= 49%HIGH2017-05-16

If shared content protection memory were passed as the secure camera memory buffer by the HLOS to a trusted application (TA) in all Android releases from CAF using the Linux kernel, the TA would not detect an issue and it would be treated as secure mem...

CVEs:CVE-2016-10237

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10274

Open SourceEPSS <= 49%HIGH2017-05-12

An elevation of privilege vulnerability in the MediaTek touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanen...

CVEs:CVE-2016-10274

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0604

Open SourceEPSS <= 49%HIGH2017-05-02

An elevation of privilege vulnerability in the kernel Qualcomm power driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permane...

CVEs:CVE-2017-0604

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5867

Open SourceEPSS <= 49%CRITICAL2017-05-02

In a sound driver in Android for MSM, Firefox OS for MSM, QRD Android, some variables are from userspace and values can be chosen that could result in stack overflow.

CVEs:CVE-2016-5867

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0615

Open SourceEPSS <= 49%HIGH2017-05-02

An elevation of privilege vulnerability in the MediaTek power driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged ...

CVEs:CVE-2017-0615

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0616

Open SourceEPSS <= 49%HIGH2017-05-02

An elevation of privilege vulnerability in the MediaTek system management interrupt driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires comp...

CVEs:CVE-2017-0616

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0617

Open SourceEPSS <= 49%HIGH2017-05-02

An elevation of privilege vulnerability in the MediaTek video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged ...

CVEs:CVE-2017-0617

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0619

Open SourceEPSS <= 49%HIGH2017-05-02

An elevation of privilege vulnerability in the Qualcomm pin controller driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a pr...

CVEs:CVE-2017-0619

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2014-9944

Open SourceEPSS <= 49%HIGH2017-05-02

In the Secure File System in all Android releases from CAF using the Linux kernel, an Integer Overflow to Buffer Overflow vulnerability could potentially exist.

CVEs:CVE-2014-9944

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9005

Open SourceEPSS <= 49%HIGH2017-05-02

In TrustZone in all Android releases from CAF using the Linux kernel, an Integer Overflow to Buffer Overflow vulnerability could potentially exist.

CVEs:CVE-2015-9005

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5347

Open SourceEPSS <= 49%MEDIUM2017-05-02

In all Qualcomm products with Android releases from CAF using the Linux kernel, kernel stack data can be leaked to userspace by an audio driver.

CVEs:CVE-2016-5347

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5858

Open SourceEPSS <= 49%MEDIUM2017-05-02

In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a user supplies a value too large, then an out-of-bounds read occurs.

CVEs:CVE-2016-5858

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10280

Open SourceEPSS <= 49%HIGH2017-05-12

An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privilege...

CVEs:CVE-2016-10280

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10281

Open SourceEPSS <= 49%HIGH2017-05-12

An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privilege...

CVEs:CVE-2016-10281

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10282

Open SourceEPSS <= 49%HIGH2017-05-12

An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privilege...

CVEs:CVE-2016-10282

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0618

Open SourceEPSS <= 49%HIGH2017-05-02

An elevation of privilege vulnerability in the MediaTek command queue driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a pri...

CVEs:CVE-2017-0618

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5862

Open SourceEPSS <= 49%HIGH2017-05-02

When a control related to codec is issued from userspace in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, the type casting is done to the container structure instead of the codec's individual structure, resulting in a ...

CVEs:CVE-2016-5862

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9945

Open SourceEPSS <= 49%HIGH2017-05-02

In TrustZone in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist.

CVEs:CVE-2014-9945

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9943

Open SourceEPSS <= 49%HIGH2017-05-02

In Core Kernel in all Android releases from CAF using the Linux kernel, a Null Pointer Dereference vulnerability could potentially exist.

CVEs:CVE-2014-9943

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9923

Open SourceEPSS <= 49%HIGH2017-05-02

In NAS in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentially exist.

CVEs:CVE-2014-9923

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9924

Open SourceEPSS <= 49%HIGH2017-05-02

In 1x in all Android releases from CAF using the Linux kernel, a Signed to Unsigned Conversion Error could potentially occur.

CVEs:CVE-2014-9924

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9925

Open SourceEPSS <= 49%HIGH2017-05-02

In HDR in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentially exist.

CVEs:CVE-2014-9925

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9926

Open SourceEPSS <= 49%HIGH2017-05-02

In GNSS in all Android releases from CAF using the Linux kernel, a Use After Free vulnerability could potentially exist.

CVEs:CVE-2014-9926

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9928

Open SourceEPSS <= 49%HIGH2017-05-02

In GERAN in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentially exist.

CVEs:CVE-2014-9928

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9929

Open SourceEPSS <= 49%HIGH2017-05-02

In WCDMA in all Android releases from CAF using the Linux kernel, a Use of Out-of-range Pointer Offset vulnerability could potentially exist.

CVEs:CVE-2014-9929

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9930

Open SourceEPSS <= 49%HIGH2017-05-02

In WCDMA in all Android releases from CAF using the Linux kernel, a Use After Free vulnerability could potentially exist.

CVEs:CVE-2014-9930

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9942

Open SourceEPSS <= 49%HIGH2017-05-02

In Boot in all Android releases from CAF using the Linux kernel, a Use of Uninitialized Variable vulnerability could potentially exist.

CVEs:CVE-2014-9942

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9946

Open SourceEPSS <= 49%HIGH2017-05-02

In Core Kernel in all Android releases from CAF using the Linux kernel, a Use After Free vulnerability could potentially exist.

CVEs:CVE-2014-9946

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9948

Open SourceEPSS <= 49%HIGH2017-05-02

In TrustZone in all Android releases from CAF using the Linux kernel, an Improper Validation of Array Index vulnerability could potentially exist.

CVEs:CVE-2014-9948

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9949

Open SourceEPSS <= 49%HIGH2017-05-02

In TrustZone in all Android releases from CAF using the Linux kernel, an Untrusted Pointer Dereference vulnerability could potentially exist.

CVEs:CVE-2014-9949

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9007

Open SourceEPSS <= 49%HIGH2017-05-02

In TrustZone in all Android releases from CAF using the Linux kernel, a Double Free vulnerability could potentially exist.

CVEs:CVE-2015-9007

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9950

Open SourceEPSS <= 49%HIGH2017-05-02

In Core Kernel in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist.

CVEs:CVE-2014-9950

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9952

Open SourceEPSS <= 49%HIGH2017-05-02

In the Secure File System in all Android releases from CAF using the Linux kernel, a capture-replay vulnerability could potentially exist.

CVEs:CVE-2014-9952

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9006

Open SourceEPSS <= 49%HIGH2017-05-02

In Resource Power Manager (RPM) in all Android releases from CAF using the Linux kernel, an Improper Access Control vulnerability could potentially exist.

CVEs:CVE-2015-9006

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0603

Open SourceEPSS <= 49%HIGH2017-05-02

A denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Moderate because it requires an uncommon device configuration. Product:...

CVEs:CVE-2017-0603

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5854

Open SourceEPSS <= 49%MEDIUM2017-05-02

In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, kernel heap memory can be exposed to userspace.

CVEs:CVE-2016-5854

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5855

Open SourceEPSS <= 49%CRITICAL2017-05-02

In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a user-supplied buffer is casted to a structure without checking if the source buffer is large enough.

CVEs:CVE-2016-5855

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0593

Open SourceEPSS <= 49%HIGH2017-05-02

An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to obtain access to custom permissions. This issue is rated as High because it is a general bypass for operating system protections that isolate ap...

CVEs:CVE-2017-0593

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0635

Open SourceEPSS <= 49%HIGH2017-05-02

A remote denial of service vulnerability in HevcUtils.cpp in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Low due to details specific to the vulnerabilit...

CVEs:CVE-2017-0635

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0600

Open SourceEPSS <= 49%HIGH2017-05-02

A remote denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service...

CVEs:CVE-2017-0600

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9947

Open SourceEPSS <= 49%MEDIUM2017-05-02

In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure vulnerability could potentially exist.

CVEs:CVE-2014-9947

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9951

Open SourceEPSS <= 49%MEDIUM2017-05-02

In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure Through Timing Discrepancy vulnerability could potentially exist.

CVEs:CVE-2014-9951

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9927

Open SourceEPSS <= 49%HIGH2017-05-02

In UIM in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentially exist.

CVEs:CVE-2014-9927

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0598

Open SourceEPSS <= 49%HIGH2017-05-02

An information disclosure vulnerability in the Framework APIs could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used ...

CVEs:CVE-2017-0598

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0602

Open SourceEPSS <= 49%HIGH2017-05-02

An information disclosure vulnerability in Bluetooth could allow a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Moderate due to details specific to the ...

CVEs:CVE-2017-0602

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10242

Open SourceEPSS <= 49%HIGH2017-05-16

A time-of-check time-of-use race condition could potentially exist in the secure file system in all Android releases from CAF using the Linux kernel.

CVEs:CVE-2016-10242

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0601

Open SourceEPSS <= 49%HIGH2017-05-02

An Elevation of Privilege vulnerability in Bluetooth could potentially enable a local malicious application to accept harmful files shared via bluetooth without user permission. This issue is rated as Moderate due to local bypass of user interaction re...

CVEs:CVE-2017-0601

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9941

Open SourceEPSS <= 49%HIGH2017-05-02

In the Embedded File System in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnerability could potentially exist.

CVEs:CVE-2014-9941

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0625

Open SourceEPSS <= 49%HIGH2017-05-02

An information disclosure vulnerability in the MediaTek command queue driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data witho...

CVEs:CVE-2017-0625

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0493

Open SourceEPSS <= 49%HIGH2017-05-02

An information disclosure vulnerability in File-Based Encryption could enable a local malicious attacker to bypass operating system protections for the lock screen. This issue is rated as Moderate due to the possibility of bypassing the lock screen. Pr...

CVEs:CVE-2017-0493

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9045

GoogleEPSS <= 49%MEDIUM2017-05-18

The Google I/O 2017 application before 5.1.4 for Android downloads multiple .json files from http://storage.googleapis.com without SSL, which makes it easier for man-in-the-middle attackers to spoof Feed and Schedule data by creating a modified blocks_...

CVEs:CVE-2017-9045

Affected products

ProductStatusVendorPackageEcosystem
google_i\/o_2017 affected google
Upstream advisory

CVE-2017-8245

Open SourceEPSS <= 49%HIGH2017-05-12

In all Android releases from CAF using the Linux kernel, while processing a voice SVC request which is nonstandard by specifying a payload size that will overflow its own declared size, an out of bounds memory copy occurs.

CVEs:CVE-2017-8245

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8246

Open SourceEPSS <= 49%HIGH2017-05-12

In function msm_pcm_playback_close() in all Android releases from CAF using the Linux kernel, prtd is assigned substream->runtime->private_data. Later, prtd is freed. However, prtd is not sanitized and set to NULL, resulting in a dangling pointer. Ther...

CVEs:CVE-2017-8246

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8244

Open SourceEPSS <= 49%CRITICAL2017-05-12

In core_info_read and inst_info_read in all Android releases from CAF using the Linux kernel, variable "dbg_buf", "dbg_buf->curr" and "dbg_buf->filled_size" could be modified by different threads at the same time, but they are not protected with mutex ...

CVEs:CVE-2017-8244

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.