Google Security Advisories · June 2017 — Google Security Advisories
135 advisories 133 CVEs 8 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2017-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 8 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2017-8464

GoogleExploitedCISA KEV listedHIGH2017-06-06

Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows local users or remote attackers to ...

CVEs:CVE-2017-8464

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1511 affected microsoft
windows_10_1607 affected microsoft
windows_10_1703 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
Upstream advisory

CVE-2017-8464

Project ZeroExploitedCISA KEV listed2017-06-06

Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows local users or remote attackers to execute arbitrary code via a crafted .LNK file, which is not properly handled during icon display in Windows Explorer or any other application that parses the icon of the shortcut. aka "LNK Remote Code Execution Vulnerability."

CVEs:CVE-2017-8464

Upstream advisory

CVE-2017-8543

Project ZeroExploitedCISA KEV listed2017-06-06

Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to take control of the affected system when Windows Search fails to handle objects in memory, aka "Windows Search Remote Code Execution Vulnerability".

CVEs:CVE-2017-8543

Upstream advisory

CVE-2017-8543

GoogleExploitedCISA KEV listedHIGH2017-06-06

Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and W...

CVEs:CVE-2017-8543

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1511 affected microsoft
windows_10_1607 affected microsoft
windows_10_1703 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
Upstream advisory

openSUSE-SU-2017:1501-1

Open SourceExploitedCISA KEV listedCRITICAL2017-06-07

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP2 chromium
Upstream advisory

openSUSE-SU-2017:1502-1

Open SourceExploitedCISA KEV listedCRITICAL2017-06-07

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP2 chromium
Upstream advisory

RHSA-2017:1399

Open SourceExploitedCISA KEV listedHIGH2017-06-06

Red Hat Security Advisory: chromium-browser security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Red Hat:rhel_extras:6 chromium-browser
chromium-browser-debuginfo affected Red Hat:rhel_extras:6 chromium-browser-debuginfo
Upstream advisory

CVE-2017-5070

GoogleExploitedCISA KEV listedCRITICAL2017-06-06

Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVEs:CVE-2017-5070

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-7376

Open SourcePoC exploitHIGH2017-06-06

Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.

CVEs:CVE-2017-7376

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
libxml2 affected xmlsoft
Upstream advisory

CVE-2017-7375

Open SourcePoC exploitCRITICAL2017-06-06

A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expos...

CVEs:CVE-2017-7375

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
libxml2 affected xmlsoft
Upstream advisory

CVE-2017-0663

Open SourcePoC exploitHIGH2017-06-06

A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code executio...

CVEs:CVE-2017-0663

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

RHSA-2017:1495

Open SourceEPSS <= 49%CRITICAL2017-06-19

Red Hat Security Advisory: chromium-browser security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Red Hat:rhel_extras:6 chromium-browser
chromium-browser-debuginfo affected Red Hat:rhel_extras:6 chromium-browser-debuginfo
Upstream advisory

openSUSE-SU-2017:1591-1

Open SourceEPSS <= 49%HIGH2017-06-18

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP2 chromium
Upstream advisory

openSUSE-SU-2017:1593-1

Open SourceEPSS <= 49%HIGH2017-06-18

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP2 chromium
Upstream advisory

CVE-2017-5088

GoogleEPSS <= 49%HIGH2017-06-16

Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 59.0.3071.117 for Android, allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.

CVEs:CVE-2017-5088

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5078

GoogleEPSS <= 49%CRITICAL2017-06-06

Insufficient validation of untrusted input in Blink's mailto: handling in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac allowed a remote attacker to perform command injection via a crafted HTML page, a similar issue to CVE-2004-0121. ...

CVEs:CVE-2017-5078

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5077

GoogleEPSS <= 49%HIGH2017-06-06

Insufficient validation of untrusted input in Skia in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2017-5077

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

DEBIAN-CVE-2017-9431

Open SourceEPSS <= 49%CRITICAL2017-06-05

DEBIAN-CVE-2017-9431

Affected products

ProductStatusVendorPackageEcosystem
grpc affected Debian:11 grpc
grpc affected Debian:12 grpc
grpc affected Debian:13 grpc
grpc affected Debian:14 grpc
Upstream advisory

CVE-2017-9431

Open SourceEPSS <= 49%CRITICAL2017-06-05

Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/error.c.

CVEs:CVE-2017-9431

Affected products

ProductStatusVendorPackageEcosystem
grpc affected grpc
Upstream advisory

MGASA-2017-0195

Open SourceEPSS <= 49%2017-06-29

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:5 golang
Upstream advisory

CVE-2017-8932

GoogleEPSS <= 49%MEDIUM2017-06-22

A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressiv...

CVEs:CVE-2017-8932

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
go affected golang
leap affected opensuse
suse_package_hub_for_suse_linux_enterprise affected novell
Upstream advisory

CVE-2017-5071

GoogleEPSS <= 49%MEDIUM2017-06-06

Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows and Mac, and 59.0.3071.92 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2017-5071

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-0637

Open SourceEPSS <= 49%HIGH2017-06-06

A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote c...

CVEs:CVE-2017-0637

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0641

Open SourceEPSS <= 49%HIGH2017-06-06

A remote denial of service vulnerability in libvpx in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Produc...

CVEs:CVE-2017-0641

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-5087

GoogleEPSS <= 49%CRITICAL2017-06-16

A use after free in Blink in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 59.0.3071.117 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page, aka an IndexedDB sandbox escape.

CVEs:CVE-2017-5087

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5079

GoogleEPSS <= 49%MEDIUM2017-06-06

Inappropriate implementation in Blink in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page.

CVEs:CVE-2017-5079

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2015-9014

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393750.

CVEs:CVE-2015-9014

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-5080

GoogleEPSS <= 49%CRITICAL2017-06-06

A use after free in credit card autofill in Google Chrome prior to 59.0.3071.86 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2017-5080

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2017-5076

GoogleEPSS <= 49%CRITICAL2017-06-06

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.

CVEs:CVE-2017-5076

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5089

GoogleEPSS <= 49%CRITICAL2017-06-16

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.104 for Mac allowed a remote attacker to perform domain spoofing via a crafted domain name.

CVEs:CVE-2017-5089

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5073

GoogleEPSS <= 49%CRITICAL2017-06-06

Use after free in print preview in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2017-5073

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5086

GoogleEPSS <= 49%CRITICAL2017-06-06

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Windows and Mac allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.

CVEs:CVE-2017-5086

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5072

GoogleEPSS <= 49%MEDIUM2017-06-06

Inappropriate implementation in Omnibox in Google Chrome prior to 59.0.3071.92 for Android allowed a remote attacker to perform domain spoofing with RTL characters via a crafted URL page.

CVEs:CVE-2017-5072

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2017-5075

GoogleEPSS <= 49%MEDIUM2017-06-06

Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page.

CVEs:CVE-2017-5075

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5083

GoogleEPSS <= 49%MEDIUM2017-06-06

Inappropriate implementation in Blink in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page.

CVEs:CVE-2017-5083

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2015-9008

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36384689.

CVEs:CVE-2015-9008

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9009

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393600.

CVEs:CVE-2015-9009

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9010

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393101.

CVEs:CVE-2015-9010

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9011

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36714882.

CVEs:CVE-2015-9011

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9013

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393251.

CVEs:CVE-2015-9013

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9953

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36714770.

CVEs:CVE-2014-9953

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9954

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36388559.

CVEs:CVE-2014-9954

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9955

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36384686.

CVEs:CVE-2014-9955

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9956

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36389611.

CVEs:CVE-2014-9956

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9957

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36387564.

CVEs:CVE-2014-9957

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9958

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36384774.

CVEs:CVE-2014-9958

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9959

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36383694.

CVEs:CVE-2014-9959

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9012

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36384691.

CVEs:CVE-2015-9012

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-5085

GoogleEPSS <= 49%MEDIUM2017-06-06

Inappropriate implementation in Bookmarks in Google Chrome prior to 59 for iOS allowed a remote attacker who convinced the user to perform certain operations to run JavaScript on chrome:// pages via a crafted bookmark.

CVEs:CVE-2017-5085

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2017-0638

Open SourceEPSS <= 49%HIGH2017-06-06

A remote code execution vulnerability in System UI component could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High because it is a remote arbitrary c...

CVEs:CVE-2017-0638

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-5074

GoogleEPSS <= 49%CRITICAL2017-06-06

A use after free in Chrome Apps in Google Chrome prior to 59.0.3071.86 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page, related to Bluetooth.

CVEs:CVE-2017-5074

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2014-7919

Open SourceEPSS <= 49%HIGH2017-06-08

b/libs/gui/ISurfaceComposer.cpp in Android allows attackers to trigger a denial of service (null pointer dereference and process crash).

CVEs:CVE-2014-7919

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-1207

GoogleEPSS <= 49%CRITICAL2017-06-06

Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file.

CVEs:CVE-2015-1207

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-7364

Open SourceEPSS <= 49%HIGH2017-06-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, in function __mdss_fb_copy_destscaler_data(), variable ds_data[i].scale may still point to a user-provided address (which could point to arbitrary kernel address), so on an...

CVEs:CVE-2017-7364

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9030

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, the Hypervisor API could be misused to bypass authentication.

CVEs:CVE-2015-9030

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-6247

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High due to the possibility of local arbitrary code executi...

CVEs:CVE-2017-6247

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-6248

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privilege...

CVEs:CVE-2017-6248

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-6249

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privilege...

CVEs:CVE-2017-6249

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0642

Open SourceEPSS <= 49%HIGH2017-06-06

A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Produ...

CVEs:CVE-2017-0642

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0636

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in the MediaTek command queue driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a pri...

CVEs:CVE-2017-0636

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0649

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in the MediaTek sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privile...

CVEs:CVE-2017-0649

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0640

Open SourceEPSS <= 49%HIGH2017-06-06

A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android...

CVEs:CVE-2017-0640

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0643

Open SourceEPSS <= 49%HIGH2017-06-06

A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android...

CVEs:CVE-2017-0643

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0644

Open SourceEPSS <= 49%HIGH2017-06-06

A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android...

CVEs:CVE-2017-0644

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9960

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the PlayReady API.

CVEs:CVE-2014-9960

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9023

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the PlayReady API.

CVEs:CVE-2015-9023

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9025

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a QTEE application.

CVEs:CVE-2015-9025

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9028

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a cryptographic routine.

CVEs:CVE-2015-9028

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10340

Open SourceEPSS <= 49%HIGH2017-06-13

In all Android releases from CAF using the Linux kernel, an integer underflow leading to buffer overflow vulnerability exists in a syscall handler.

CVEs:CVE-2016-10340

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10342

Open SourceEPSS <= 49%HIGH2017-06-13

In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a syscall handler.

CVEs:CVE-2016-10342

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9963

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in WideVine DRM.

CVEs:CVE-2014-9963

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-7759

Open SourceEPSS <= 49%HIGH2017-06-14

Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reading of local data through a violation of same-origin policy. Note: This attack only affects Firefox for Android...

CVEs:CVE-2017-7759

Affected products

ProductStatusVendorPackageEcosystem
android affected google
firefox affected mozilla
Upstream advisory

CVE-2014-9964

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, an integer overflow vulnerability exists in debug functionality.

CVEs:CVE-2014-9964

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9962

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of a DRM provisioning command.

CVEs:CVE-2014-9962

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9965

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of an SCM call.

CVEs:CVE-2014-9965

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9026

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.

CVEs:CVE-2015-9026

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9027

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.

CVEs:CVE-2015-9027

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5864

Open SourceEPSS <= 49%HIGH2017-06-06

In an audio driver function in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, some parameters are from userspace, and if they are set to a large value, integer overflow is possible followed by buffer overflow. In anothe...

CVEs:CVE-2016-5864

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9967

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.

CVEs:CVE-2014-9967

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9020

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in the unlocking of memory.

CVEs:CVE-2015-9020

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9033

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, a QTEE system call fails to validate a pointer.

CVEs:CVE-2015-9033

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10338

Open SourceEPSS <= 49%HIGH2017-06-13

In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing.

CVEs:CVE-2016-10338

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10341

Open SourceEPSS <= 49%HIGH2017-06-13

In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended.

CVEs:CVE-2016-10341

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9029

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, a vulnerability exists in the access control settings of modem memory.

CVEs:CVE-2015-9029

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9961

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, a vulnerability in eMMC write protection exists that can be used to bypass power-on write protection.

CVEs:CVE-2014-9961

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10339

Open SourceEPSS <= 49%HIGH2017-06-13

In all Android releases from CAF using the Linux kernel, HLOS can overwite secure memory or read contents of the keystore.

CVEs:CVE-2016-10339

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10332

Open SourceEPSS <= 49%MEDIUM2017-06-13

In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications.

CVEs:CVE-2016-10332

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10336

Open SourceEPSS <= 49%MEDIUM2017-06-13

In all Android releases from CAF using the Linux kernel, some regions of memory were not protected during boot.

CVEs:CVE-2016-10336

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10337

Open SourceEPSS <= 49%MEDIUM2017-06-13

In all Android releases from CAF using the Linux kernel, some validation of secure applications was not being performed.

CVEs:CVE-2016-10337

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-6421

Open SourceEPSS <= 49%CRITICAL2017-06-06

In the touch controller function in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a variable may be controlled by the user and can lead to a buffer overflow.

CVEs:CVE-2017-6421

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3830

Open SourceEPSS <= 49%MEDIUM2017-06-06

The stock Android browser address bar in all Android operating systems suffers from Address Bar Spoofing, which allows remote attackers to trick a victim by displaying a malicious page for legitimate domain names.

CVEs:CVE-2015-3830

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9021

Open SourceEPSS <= 49%MEDIUM2017-06-06

In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled.

CVEs:CVE-2015-9021

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9024

Open SourceEPSS <= 49%MEDIUM2017-06-06

In all Android releases from CAF using the Linux kernel, some interfaces were improperly exposed to QTEE applications.

CVEs:CVE-2015-9024

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8240

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, a kernel driver has an off-by-one buffer over-read vulnerability.

CVEs:CVE-2017-8240

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10333

Open SourceEPSS <= 49%MEDIUM2017-06-13

In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.

CVEs:CVE-2016-10333

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10334

Open SourceEPSS <= 49%MEDIUM2017-06-13

In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten.

CVEs:CVE-2016-10334

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10335

Open SourceEPSS <= 49%MEDIUM2017-06-13

In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.

CVEs:CVE-2016-10335

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2017-0647

Open SourceEPSS <= 49%HIGH2017-06-14

DEBIAN-CVE-2017-0647

Affected products

ProductStatusVendorPackageEcosystem
android-platform-system-core affected Debian:11 android-platform-system-core
Upstream advisory

CVE-2017-0647

Open SourceEPSS <= 49%HIGH2017-06-06

An information disclosure vulnerability in libziparchive could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. P...

CVEs:CVE-2017-0647

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-7369

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, an array index in an ALSA routine is not properly validating potentially leading to kernel stack corruption.

CVEs:CVE-2017-7369

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0639

Open SourceEPSS <= 49%HIGH2017-06-06

An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it is a general bypass for operating system protections that ...

CVEs:CVE-2017-0639

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0646

Open SourceEPSS <= 49%HIGH2017-06-06

An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate due to details specific to the vulnerability. Product: Android. V...

CVEs:CVE-2017-0646

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0645

Open SourceEPSS <= 49%HIGH2017-06-06

An elevation of privilege vulnerability in Bluetooth could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it is a local bypass of user interaction requirements. Product: And...

CVEs:CVE-2017-0645

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9031

Open SourceEPSS <= 49%MEDIUM2017-06-06

In all Android releases from CAF using the Linux kernel, a TZ memory address is exposed to HLOS by HDCP.

CVEs:CVE-2015-9031

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9032

Open SourceEPSS <= 49%MEDIUM2017-06-06

In all Android releases from CAF using the Linux kernel, a DRM key was exposed to QTEE applications.

CVEs:CVE-2015-9032

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9022

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, time-of-check Time-of-use (TOCTOU) Race Conditions exist in several TZ APIs.

CVEs:CVE-2015-9022

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9966

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists in Secure Display.

CVEs:CVE-2014-9966

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8241

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a WLAN function due to an incorrect message length.

CVEs:CVE-2017-8241

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5861

Open SourceEPSS <= 49%CRITICAL2017-06-06

In a display driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a variable controlled by userspace is used to calculate offsets and sizes for copy operations, which could result in heap overflow.

CVEs:CVE-2016-5861

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-7373

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, a double free vulnerability exists in a display driver.

CVEs:CVE-2017-7373

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8236

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in an IPA driver.

CVEs:CVE-2017-8236

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8237

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists while loading a firmware image.

CVEs:CVE-2017-8237

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8239

Open SourceEPSS <= 49%MEDIUM2017-06-06

In all Android releases from CAF using the Linux kernel, userspace-controlled parameters for flash initialization are not sanitized potentially leading to exposure of kernel memory.

CVEs:CVE-2017-8239

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-7365

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, a buffer overread can occur if a particular string is not NULL terminated.

CVEs:CVE-2017-7365

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-7367

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, an integer underflow vulnerability exists while processing the boot image.

CVEs:CVE-2017-7367

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-7371

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, a data pointer is potentially used after it has been freed when SLIMbus is turned off by Bluetooth.

CVEs:CVE-2017-7371

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8233

Open SourceEPSS <= 49%HIGH2017-06-06

In a camera driver function in all Android releases from CAF using the Linux kernel, a bounds check is missing when writing into an array potentially leading to an out-of-bounds heap write.

CVEs:CVE-2017-8233

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8234

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, an out of bounds access can potentially occur in a camera function.

CVEs:CVE-2017-8234

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8238

Open SourceEPSS <= 49%HIGH2017-06-13

In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a camera function.

CVEs:CVE-2017-8238

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-5082

GoogleEPSS <= 49%MEDIUM2017-06-06

Failure to take advantage of available mitigations in credit card autofill in Google Chrome prior to 59.0.3071.92 for Android allowed a local attacker to take screen shots of credit card information via a crafted HTML page.

CVEs:CVE-2017-5082

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2017-10709

Open SourceEPSS <= 49%HIGH2017-06-30

The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers to bypass a wrong-PIN lockout feature by pressing backspace after each PIN guess.

CVEs:CVE-2017-10709

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10297

Open SourceEPSS <= 49%HIGH2017-06-06

In TrustZone in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnerability could potentially exist.

CVEs:CVE-2016-10297

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-7370

Open SourceEPSS <= 49%CRITICAL2017-06-06

In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to a use-after-free condition.

CVEs:CVE-2017-7370

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-5081

GoogleEPSS <= 49%LOW2017-06-06

Lack of verification of an extension's locale folder in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed an attacker with local write access to modify extensions by modifying extension files.

CVEs:CVE-2017-5081

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-8242

Open SourceEPSS <= 49%MEDIUM2017-06-06

In all Android releases from CAF using the Linux kernel, a race condition exists in a QTEE driver potentially leading to an arbitrary memory write.

CVEs:CVE-2017-8242

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-7366

Open SourceEPSS <= 49%MEDIUM2017-06-06

In all Android releases from CAF using the Linux kernel, a KGSL ioctl was not validating all of its parameters.

CVEs:CVE-2017-7366

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8235

Open SourceEPSS <= 49%MEDIUM2017-06-06

In all Android releases from CAF using the Linux kernel, a memory structure in a camera driver is not properly protected.

CVEs:CVE-2017-8235

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-7372

Open SourceEPSS <= 49%CRITICAL2017-06-06

In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to buffer overflow or write to arbitrary pointer location.

CVEs:CVE-2017-7372

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-7368

Open SourceEPSS <= 49%HIGH2017-06-06

In all Android releases from CAF using the Linux kernel, a race condition potentially exists in the ioctl handler of a sound driver.

CVEs:CVE-2017-7368

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3840

Open SourceEPSS <= 49%MEDIUM2017-06-27

The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS and MMS messages without the associated "WRITE_SMS" permission.

CVEs:CVE-2015-3840

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9015

Open SourceEPSS <= 49%CRITICAL2017-06-06

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36714120.

CVEs:CVE-2015-9015

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-3748

Open SourceEPSS <= 49%HIGH2017-06-28

On Lenovo VIBE mobile phones, improper access controls on the nac_server component can be abused in conjunction with CVE-2017-3749 and CVE-2017-3750 to elevate privileges to the root user (commonly known as 'rooting' or "jail breaking" a device).

CVEs:CVE-2017-3748

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-5084

GoogleEPSS <= 49%LOW2017-06-12

Inappropriate implementation in image-burner in Google Chrome OS prior to 59.0.3071.92 allowed a local attacker to read local files via dbus-send commands to a BurnImage D-Bus endpoint.

CVEs:CVE-2017-5084

Affected products

ProductStatusVendorPackageEcosystem
chrome_os affected google
Upstream advisory

CVE-2017-3749

Open SourceEPSS <= 49%CRITICAL2017-06-29

On Lenovo VIBE mobile phones, the Idea Friend Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3750.

CVEs:CVE-2017-3749

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-3750

Open SourceEPSS <= 49%CRITICAL2017-06-29

On Lenovo VIBE mobile phones, the Lenovo Security Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3749.

CVEs:CVE-2017-3750

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.