Google Security Advisories · October 2017 — Google Security Advisories
90 advisories 88 CVEs 4 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2017-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 4 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2017-11826

GoogleExploitedCISA KEV listedHIGH2017-10-11

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code ...

CVEs:CVE-2017-11826

Affected products

ProductStatusVendorPackageEcosystem
office_compatibility_pack affected microsoft
office_online_server affected microsoft
office_web_apps_server affected microsoft
office_word_viewer affected microsoft
sharepoint_enterprise_server affected microsoft
sharepoint_server affected microsoft
word affected microsoft
Upstream advisory

CVE-2017-11826

Project ZeroExploitedCISA KEV listed2017-10-11

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.

CVEs:CVE-2017-11826

Upstream advisory

CVE-2017-11292

Project ZeroExploitedCISA KEV listed2017-10-16

Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.

CVEs:CVE-2017-11292

Upstream advisory

CVE-2017-11292

GoogleExploitedCISA KEV listedCRITICAL2017-10-16

Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead...

CVEs:CVE-2017-11292

Affected products

ProductStatusVendorPackageEcosystem
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
flash_player affected adobe
flash_player_desktop_runtime affected adobe
Upstream advisory

RHSA-2017:2997

Open SourcePoC exploitHIGH2017-10-20

Red Hat Security Advisory: chromium-browser security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Red Hat:rhel_extras:6 chromium-browser
chromium-browser-debuginfo affected Red Hat:rhel_extras:6 chromium-browser-debuginfo
Upstream advisory

CVE-2017-5124

GooglePoC exploitCRITICAL2017-10-18

Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page.

CVEs:CVE-2017-5124

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-5130

GooglePoC exploitCRITICAL2017-10-18

An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.

CVEs:CVE-2017-5130

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
libxml2 affected xmlsoft
Upstream advisory

CVE-2017-15396

GooglePoC exploitCRITICAL2017-10-26

A stack buffer overflow in NumberingSystem in International Components for Unicode (ICU) for C/C++ before 60.2, as used in V8 in Google Chrome prior to 62.0.3202.75 and other products, allowed a remote attacker to potentially exploit heap corruption vi...

CVEs:CVE-2017-15396

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
international_components_for_unicode affected icu-project
Upstream advisory

CVE-2017-15394

GooglePoC exploitCRITICAL2017-10-18

Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing in permission dialogs via IDN homographs in a crafted Chrome Extension.

CVEs:CVE-2017-15394

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-0807

Open SourcePoC exploitHIGH2017-10-03

An elevation of privilege vulnerability in the Android framework (ui framework). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35056974.

CVEs:CVE-2017-0807

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0806

Open SourcePoC exploitHIGH2017-10-03

An elevation of privilege vulnerability in the Android framework (gatekeeperresponse). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62998805.

CVEs:CVE-2017-0806

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0817

Open SourcePoC exploitHIGH2017-10-03

An information disclosure vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63522430.

CVEs:CVE-2017-0817

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0808

Open SourcePoC exploitHIGH2017-10-03

An information disclosure vulnerability in the Android framework (file system). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62301183.

CVEs:CVE-2017-0808

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0823

Open SourcePoC exploitHIGH2017-10-03

An information disclosure vulnerability in the Android system (rild). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37896655.

CVEs:CVE-2017-0823

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11051

Open SourcePoC exploitHIGH2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, information disclosure is possible in function __wlan_hdd_cfg80211_testmode since buffer hb_params is not initialized to zero.

CVEs:CVE-2017-11051

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0815

Open SourcePoC exploitHIGH2017-10-03

An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63526567.

CVEs:CVE-2017-0815

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0816

Open SourcePoC exploitHIGH2017-10-03

An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63662938.

CVEs:CVE-2017-0816

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0825

Open SourcePoC exploitHIGH2017-10-03

An information disclosure vulnerability in the Broadcom wifi driver. Product: Android. Versions: Android kernel. Android ID: A-37305633. References: B-V2017063002.

CVEs:CVE-2017-0825

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11053

Open SourcePoC exploitCRITICAL2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when qos map set IE of length less than 16 is received in association response or in qos map configure action frame, a buffer overflow can p...

CVEs:CVE-2017-11053

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11048

Open SourcePoC exploitCRITICAL2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a display driver function, a Use After Free condition can occur.

CVEs:CVE-2017-11048

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11050

Open SourcePoC exploitCRITICAL2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when the pktlogconf tool gives a pktlog buffer of size less than the minimal possible source data size in the host driver, a buffer overflow...

CVEs:CVE-2017-11050

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11059

Open SourcePoC exploitCRITICAL2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, setting the HMAC key by different threads during SHA operations may potentially lead to a buffer overflow.

CVEs:CVE-2017-11059

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9714

Open SourcePoC exploitHIGH2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, an out of bound memory access may happen in limCheckRxRSNIeMatch in case incorrect RSNIE is received from the client in assoc request.

CVEs:CVE-2017-9714

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9683

Open SourcePoC exploitCRITICAL2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing a meta image, an integer overflow can occur, if user-defined image offset and size values are too large.

CVEs:CVE-2017-9683

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11046

Open SourcePoC exploitCRITICAL2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when an audio driver ioctl handler is called, a kernel out-of-bounds write can potentially occur.

CVEs:CVE-2017-11046

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11056

Open SourcePoC exploitHIGH2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while doing sha and cipher operations, a userspace buffer is directly accessed in kernel space potentially leading to a page fault.

CVEs:CVE-2017-11056

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11057

Open SourcePoC exploitHIGH2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in compatibility mode, flash_data from 64-bit userspace may cause disclosure of kernel memory or a fault due to using a userspace-provided a...

CVEs:CVE-2017-11057

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11067

Open SourcePoC exploitHIGH2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the Athdiag procfs entry does not have a proper address sanity check which may potentially lead to the use of an out-of-range pointer offset.

CVEs:CVE-2017-11067

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9686

Open SourcePoC exploitCRITICAL2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, there is a possible double free/use after free in the SPS driver when debugfs logging is used.

CVEs:CVE-2017-9686

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9687

Open SourcePoC exploitCRITICAL2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, two concurrent threads/processes can write the value of "0" to the debugfs file that controls ipa ipc log which will lead to the double-free...

CVEs:CVE-2017-9687

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9706

Open SourcePoC exploitHIGH2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, an array out-of-bounds access can potentially occur in a display driver.

CVEs:CVE-2017-9706

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9697

Open SourcePoC exploitHIGH2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a race condition can allow access to already freed memory while reading command registration table entries in diag_dbgfs_read_table.

CVEs:CVE-2017-9697

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DLA-1148-1

Open SourceEPSS <= 49%2017-10-27

golang - security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Debian:7 golang
Upstream advisory

CVE-2017-15041

GoogleEPSS <= 49%CRITICAL2017-10-05

Go before 1.8.4 and 1.9.x before 1.9.1 allows "go get" remote command execution. Using custom domains, it is possible to arrange things so that example.com/pkg1 points to a Subversion repository but example.com/pkg1/pkg2 points to a Git repository. If ...

CVEs:CVE-2017-15041

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
developer_tools affected redhat
enterprise_linux_eus affected redhat
enterprise_linux_server affected redhat
enterprise_linux_server_aus affected redhat
enterprise_linux_tus affected redhat
go affected golang
Upstream advisory

DLA-1123-1

Open SourceEPSS <= 49%2017-10-06

golang - security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Debian:7 golang
Upstream advisory

AZL-79016

Open SourceEPSS <= 49%HIGH2017-10-05

CVE-2017-1000098 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

CVE-2017-1000098

GoogleEPSS <= 49%HIGH2017-10-04

The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ra...

CVEs:CVE-2017-1000098

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

CVE-2017-5133

GoogleEPSS <= 49%HIGH2017-10-18

Off-by-one read/write on the heap in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to corrupt memory and possibly leak information and potentially execute code via a crafted PDF file.

CVEs:CVE-2017-5133

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-5125

GoogleEPSS <= 49%CRITICAL2017-10-18

Heap buffer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2017-5125

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-15388

GoogleEPSS <= 49%HIGH2017-10-18

Iteration through non-finite points in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2017-15388

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-5127

GoogleEPSS <= 49%CRITICAL2017-10-18

Use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2017-5127

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-0810

Open SourceEPSS <= 49%HIGH2017-10-03

A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38207066.

CVEs:CVE-2017-0810

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0811

Open SourceEPSS <= 49%HIGH2017-10-03

A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37930177.

CVEs:CVE-2017-0811

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0809

Open SourceEPSS <= 49%HIGH2017-10-03

A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62673128.

CVEs:CVE-2017-0809

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-5132

GoogleEPSS <= 49%HIGH2017-10-18

Inappropriate implementation in V8 in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka incorrect WebAssembly stack manipulation.

CVEs:CVE-2017-5132

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-5128

GoogleEPSS <= 49%CRITICAL2017-10-18

Heap buffer overflow in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, related to WebGL.

CVEs:CVE-2017-5128

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-15386

GoogleEPSS <= 49%MEDIUM2017-10-18

Incorrect implementation in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2017-15386

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-5129

GoogleEPSS <= 49%CRITICAL2017-10-18

A use after free in WebAudio in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2017-5129

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-15393

GoogleEPSS <= 49%CRITICAL2017-10-18

Insufficient Policy Enforcement in Devtools remote debugging in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to obtain access to remote debugging functionality via a crafted HTML page, aka a Referer leak.

CVEs:CVE-2017-15393

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-5131

GoogleEPSS <= 49%CRITICAL2017-10-18

An integer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka an out-of-bounds write.

CVEs:CVE-2017-5131

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-15387

GoogleEPSS <= 49%CRITICAL2017-10-18

Insufficient enforcement of Content Security Policy in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to open javascript: URL windows when they should not be allowed to via a crafted HTML page.

CVEs:CVE-2017-15387

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-5126

GoogleEPSS <= 49%CRITICAL2017-10-18

A use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2017-5126

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-15389

GoogleEPSS <= 49%MEDIUM2017-10-18

An insufficient watchdog timer in navigation in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2017-15389

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-15391

GoogleEPSS <= 49%CRITICAL2017-10-18

Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to access Extension pages without authorisation via a crafted HTML page.

CVEs:CVE-2017-15391

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

AZL-79076

Open SourceEPSS <= 49%HIGH2017-10-05

CVE-2017-1000097 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

CVE-2017-1000097

GoogleEPSS <= 49%HIGH2017-10-04

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.

CVEs:CVE-2017-1000097

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

CVE-2017-0820

Open SourceEPSS <= 49%HIGH2017-10-03

A vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62187433.

CVEs:CVE-2017-0820

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15395

GoogleEPSS <= 49%CRITICAL2017-10-18

A use after free in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka an ImageCapture NULL pointer dereference.

CVEs:CVE-2017-15395

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-15390

GoogleEPSS <= 49%CRITICAL2017-10-18

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.

CVEs:CVE-2017-15390

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-0814

Open SourceEPSS <= 49%HIGH2017-10-03

An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62800140.

CVEs:CVE-2017-0814

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

AZL-79072

Open SourceEPSS <= 49%CRITICAL2017-10-05

CVE-2017-15042 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

CVE-2017-15042

GoogleEPSS <= 49%CRITICAL2017-10-05

An unintended cleartext issue exists in Go before 1.8.4 and 1.9.x before 1.9.1. RFC 4954 requires that, during SMTP, the PLAIN auth scheme must only be used on network connections secured with TLS. The original implementation of smtp.PlainAuth in Go 1....

CVEs:CVE-2017-15042

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

CVE-2015-1239

GoogleEPSS <= 49%CRITICAL2017-10-18

Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF.

CVEs:CVE-2015-1239

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
openjpeg affected uclouvain
pdfium affected google
Upstream advisory

CVE-2014-3164

Open SourceEPSS <= 49%CRITICAL2017-10-18

cmds/servicemanager/service_manager.c in Android before commit 7d42a3c31ba78a418f9bdde0e0ab951469f321b5 allows attackers to cause a denial of service (NULL pointer dereference, or out-of-bounds write) via vectors related to binder passed lengths.

CVEs:CVE-2014-3164

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0818

Open SourceEPSS <= 49%HIGH2017-10-03

A vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63581671.

CVEs:CVE-2017-0818

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0819

Open SourceEPSS <= 49%HIGH2017-10-03

A vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63045918.

CVEs:CVE-2017-0819

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0813

Open SourceEPSS <= 49%HIGH2017-10-03

A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36531046.

CVEs:CVE-2017-0813

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15392

GoogleEPSS <= 49%MEDIUM2017-10-18

Insufficient data validation in V8 in Google Chrome prior to 62.0.3202.62 allowed an attacker who can write to the Windows Registry to potentially exploit heap corruption via a crafted Windows Registry entry, related to PlatformIntegration.

CVEs:CVE-2017-15392

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2015-1206

GoogleEPSS <= 49%CRITICAL2017-10-06

Heap-based buffer overflow in Google Chrome before M40 allows remote attackers to cause a denial of service (unpaged memory write and process crash) via a crafted MP4 file.

CVEs:CVE-2015-1206

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2017-0822

Open SourceEPSS <= 49%CRITICAL2017-10-04

DEBIAN-CVE-2017-0822

Affected products

ProductStatusVendorPackageEcosystem
android-framework-23 affected Debian:11 android-framework-23
Upstream advisory

CVE-2017-0822

Open SourceEPSS <= 49%CRITICAL2017-10-03

An elevation of privilege vulnerability in the Android system (camera). Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63787722.

CVEs:CVE-2017-0822

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11052

Open SourceEPSS <= 49%HIGH2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted QCA_NL80211_VENDOR_SUBCMD_NDP cfg80211 vendor command a buffer over-read can occur.

CVEs:CVE-2017-11052

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11054

Open SourceEPSS <= 49%HIGH2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted cfg80211 vendor command, a buffer over-read can occur.

CVEs:CVE-2017-11054

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11055

Open SourceEPSS <= 49%HIGH2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted QCA_NL80211_VENDOR_SUBCMD_SET_WIFI_CONFIGURATION cfg80211 vendor command, a buffer over-read can occur.

CVEs:CVE-2017-11055

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11060

Open SourceEPSS <= 49%HIGH2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observed during processing of ACA_NL80211_VENDOR_SUBCMD_EXTSCAN_PNO_SET_PASSPOINT_LIST and QCA_NL80211_VENDOR_SUBCMD_EX...

CVEs:CVE-2017-11060

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11061

Open SourceEPSS <= 49%HIGH2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing cfg80211 vendor sub command QCA_NL80211_VENDOR_SUBCMD_ROAM, a buffer over-read can occur.

CVEs:CVE-2017-11061

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11062

Open SourceEPSS <= 49%HIGH2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, currently attributes are not validated in __wlan_hdd_cfg80211_do_acs which can potentially lead to a buffer overread.

CVEs:CVE-2017-11062

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11064

Open SourceEPSS <= 49%HIGH2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observed during processing of ACA_NL80211_VENDOR_SUBCMD_EXTSCAN_PNO_SET_PASSPOINT_LIST and QCA_NL80211_VENDOR_SUBCMD_EX...

CVEs:CVE-2017-11064

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9715

Open SourceEPSS <= 49%HIGH2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a vendor command, a buffer over-read can occur.

CVEs:CVE-2017-9715

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9717

Open SourceEPSS <= 49%HIGH2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while parsing Netlink attributes, a buffer overread can occur.

CVEs:CVE-2017-9717

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0812

Open SourceEPSS <= 49%HIGH2017-10-03

An elevation of privilege vulnerability in the Android media framework (audio hal). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62873231.

CVEs:CVE-2017-0812

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0824

Open SourceEPSS <= 49%CRITICAL2017-10-03

An elevation of privilege vulnerability in the Broadcom wifi driver. Product: Android. Versions: Android kernel. Android ID: A-37622847. References: B-V2017063001.

CVEs:CVE-2017-0824

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0828

Open SourceEPSS <= 49%CRITICAL2017-10-03

An elevation of privilege vulnerability in the Huawei bootloader. Product: Android. Versions: Android kernel. Android ID: A-34622855.

CVEs:CVE-2017-0828

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0829

Open SourceEPSS <= 49%CRITICAL2017-10-03

An elevation of privilege vulnerability in the Motorola bootloader. Product: Android. Versions: Android kernel. Android ID: A-62345044.

CVEs:CVE-2017-0829

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11063

Open SourceEPSS <= 49%HIGH2017-10-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, as a result of a race condition between two userspace processes that interact with the driver concurrently, a null pointer dereference can p...

CVEs:CVE-2017-11063

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-5090

GoogleEPSS <= 49%CRITICAL2017-10-27

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.115 for Mac allowed a remote attacker to perform domain spoofing via a crafted domain name containing a U+0620 character, aka Apple rdar problem 32458012.

CVEs:CVE-2017-5090

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2017-0827

Open SourceEPSS <= 49%HIGH2017-10-03

An elevation of privilege vulnerability in the MediaTek soc driver. Product: Android. Versions: Android kernel. Android ID: A-62539960. References: M-ALPS03353876, M-ALPS03353861, M-ALPS03353869, M-ALPS03353867, M-ALPS03353872.

CVEs:CVE-2017-0827

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0826

Open SourceEPSS <= 49%HIGH2017-10-03

An elevation of privilege vulnerability in the HTC bootloader. Product: Android. Versions: Android kernel. Android ID: A-34949781.

CVEs:CVE-2017-0826

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.