PatchSiren

Google CVE debriefs · Page 52

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Google CVE published 2017-02-17

CVE-2017-5011

CVE-2017-5011 is a medium-severity Google Chrome issue involving insufficiently sanitized DevTools URLs. According to the CVE description, a remote attacker could abuse this weakness after convincing a user to install a malicious extension, then use a crafted HTML page to read filesystem contents. The CVSS vector reflects network attackability but also required user interaction, which limits practical exp [truncated]

MEDIUM Google CVE published 2017-02-17

CVE-2017-5010

CVE-2017-5010 is a Google Chrome Blink issue that could allow a remote attacker to inject arbitrary scripts or HTML (UXSS) when a user visits a crafted HTML page. The supplied record places the impact in Chrome versions before 56.0.2924.76 on Linux, Windows, and Mac, and before 56.0.2924.87 on Android. Because exploitation requires user interaction and affects browser trust boundaries rather than availabi [truncated]

HIGH Google CVE published 2017-02-17

CVE-2017-5009

CVE-2017-5009 is a high-severity Google Chrome WebRTC memory-corruption issue. According to the CVE description, a crafted HTML page could trigger heap corruption through improper bounds checking in WebRTC, making this a network-reachable browser flaw with user interaction required. The supplied corpus points to vendor patches and downstream advisories, so remediation should focus on upgrading affected Ch [truncated]

MEDIUM Google CVE published 2017-02-17

CVE-2017-5008

CVE-2017-5008 is a Chrome/Blink browser flaw that could let a crafted HTML page trigger attacker-controlled JavaScript during a private script method invocation, enabling universal cross-site scripting (UXSS). The issue was publicly disclosed on 2017-02-17 and was addressed in Chrome updates before 56.0.2924.76 on Linux, Windows, and Mac, and before 56.0.2924.87 on Android.

MEDIUM Google CVE published 2017-02-17

CVE-2017-5007

CVE-2017-5007 is a browser security issue in Blink used by Google Chrome. According to the CVE description, Chrome incorrectly handled the sequence of events when closing a page, which could let a remote attacker inject arbitrary scripts or HTML and achieve UXSS through a crafted HTML page. NVD rates it as medium severity (CVSS 6.1) with network exposure, no privileges required, but user interaction needed.

MEDIUM Google CVE published 2017-02-17

CVE-2017-5006

CVE-2017-5006 is a Google Chrome Blink vulnerability that could let a remote attacker inject arbitrary HTML or script into a page context, creating a universal cross-site scripting (UXSS) risk. The issue was fixed in Chrome releases prior to the stated patched versions for desktop and Android. Organizations should treat it as a browser integrity problem that can expose authenticated sessions and trusted w [truncated]

HIGH Google CVE published 2017-02-08

CVE-2017-0450

CVE-2017-0450 is an Android elevation-of-privilege issue in Audioserver. According to the CVE description, a local malicious application could execute arbitrary code in the context of a privileged process. The issue is rated Moderate in the vendor description because it is mitigated by current platform configurations, but NVD assigns a High CVSS score (7.8).

HIGH Google CVE published 2017-02-08

CVE-2017-0449

CVE-2017-0449 is an Android elevation-of-privilege vulnerability in the Broadcom Wi‑Fi driver that could allow a local malicious application to execute code in kernel context. The Android bulletin characterizes the issue as Moderate because exploitation first requires compromising a privileged process and current platform configurations reduce impact. NVD rates it HIGH with a CVSS 3.0 vector of AV:L/AC:H/ [truncated]

MEDIUM Google CVE published 2017-02-08

CVE-2017-0448

CVE-2017-0448 is an Android information disclosure issue in the NVIDIA video driver. According to the supplied description, a local malicious application could access data outside its permitted scope, which makes the flaw relevant for devices where sensitive data exposure matters even without direct code execution. NVD rates the issue with CVSS 3.0 5.5 (Medium), but the impact can still be significant on [truncated]

HIGH Google CVE published 2017-02-08

CVE-2017-0447

CVE-2017-0447 is a high-severity elevation-of-privilege issue in the HTC touchscreen driver affecting Android kernel 3.18 and Android versions up to 7.1.1, according to NVD. The published impact is local: a malicious app could potentially execute code in the context of the kernel, but the CVSS vector also indicates high attack complexity and that user interaction is required. The NVD record references an [truncated]

HIGH Google CVE published 2017-02-08

CVE-2017-0446

CVE-2017-0446 is a high-severity Android elevation-of-privilege issue affecting the HTC touchscreen driver path. The published description says a local malicious application could execute arbitrary code in the kernel context, but exploitation is not a simple one-step local bug: it first requires compromising a privileged process. That combination makes the issue especially important on devices where the a [truncated]

HIGH Google CVE published 2017-02-08

CVE-2017-0445

CVE-2017-0445 is a High-severity Android kernel issue in the HTC touchscreen driver that could allow a local malicious application to execute arbitrary code in kernel context. The CVE description says the issue first requires compromising a privileged process. NVD lists affected Android versions up to 7.1.1 and Linux kernel 3.18, and the Android Security Bulletin provides the vendor patch reference.

HIGH Google CVE published 2017-02-08

CVE-2017-0444

CVE-2017-0444 is a high-severity elevation-of-privilege issue in the Realtek sound driver used by Android. According to the published description, a local malicious application could execute arbitrary code in kernel context. NVD associates the issue with Android versions up to 7.1.1 and Linux kernel 3.10, and the vendor advisory is linked from the Android security bulletin.

HIGH Google CVE published 2017-02-08

CVE-2017-0434

CVE-2017-0434 is a high-severity Android elevation-of-privilege issue affecting the Synaptics touchscreen driver. According to the CVE description, a local malicious application could execute arbitrary code within the context of the touchscreen chipset, with the rating reflecting that exploitation first requires compromising a privileged process. Google’s Android security bulletin lists a patch for the is [truncated]

HIGH Google CVE published 2017-02-08

CVE-2017-0433

CVE-2017-0433 is a high-severity elevation-of-privilege issue affecting Android-related builds and Linux kernel 3.10 systems that use the Synaptics touchscreen driver. According to the published description, a local malicious app could execute arbitrary code within the context of the touchscreen chipset, but the issue first requires compromising a privileged process. NVD ties the issue to Android versions [truncated]

HIGH Google CVE published 2017-02-08

CVE-2017-0429

CVE-2017-0429 is a local elevation-of-privilege issue in the NVIDIA GPU driver used on Android devices. According to the supplied NVD record and Android security bulletin reference, a malicious local application could execute arbitrary code in kernel context, which raises the impact from ordinary app compromise to possible full device compromise. The source corpus rates the issue as High by CVSS v3.0 (7.8 [truncated]

HIGH Google CVE published 2017-02-08

CVE-2017-0428

CVE-2017-0428 is a local elevation-of-privilege issue in the NVIDIA GPU driver as used on Android. According to NVD, a malicious app on the device could reach kernel context, with the potential for arbitrary code execution and permanent device compromise. The vulnerability was published on 2017-02-08 and is rated critical in the source description, while NVD assigns CVSS 3.0 7.8 (HIGH).

MEDIUM Google CVE published 2017-02-08

CVE-2017-0426

CVE-2017-0426 is an Android Filesystem information disclosure vulnerability that could let a local malicious application access data beyond its permissions. The issue is rated Moderate / Medium and affects Android 7.0, 7.1.0, and 7.1.1. Based on the published CVSS vector, successful abuse requires local access and user interaction, and the impact is confidentiality-only, with no integrity or availability [truncated]

MEDIUM Google CVE published 2017-02-08

CVE-2017-0425

CVE-2017-0425 is an Android information disclosure issue in Audioserver. According to the vendor and NVD records, a local malicious application could access data outside its permission levels, creating a confidentiality risk without requiring code execution. The CVE was published on 2017-02-08, and Android’s security bulletin for 2017-02-01 is the vendor reference associated with the fix.

MEDIUM Google CVE published 2017-02-08

CVE-2017-0424

CVE-2017-0424 is an information disclosure vulnerability in Android AOSP Messaging affecting Android 6.0, 6.0.1, 7.0, 7.1.0, and 7.1.1 per the supplied NVD CPE data. The issue can let a specially crafted file expose data outside intended permission boundaries, weakening a defense-in-depth or exploit-mitigation control in a privileged process. NVD rates the issue Medium (CVSS 5.5) with high confidentiality [truncated]

MEDIUM Google CVE published 2017-02-08

CVE-2017-0423

CVE-2017-0423 is a moderate Android Bluetooth elevation-of-privilege issue that can affect document access on impacted devices, but only when a nearby attacker first chains a separate Bluetooth stack vulnerability. NVD rates the issue as AV:A/AC:H with high confidentiality impact, so it is best treated as a targeted, adjacency-based risk rather than a broad remote compromise.

HIGH Google CVE published 2017-02-08

CVE-2017-0422

CVE-2017-0422 is a high-severity Android denial-of-service issue in Bionic DNS. According to the supplied CVE record, a remote attacker can use a specially crafted network packet to cause an affected device to hang or reboot. The issue is rated High because it is network-reachable and can disrupt availability without authentication or user interaction.

MEDIUM Google CVE published 2017-02-08

CVE-2017-0421

CVE-2017-0421 is an Android information disclosure issue in the Framework APIs. A local malicious application could use the flaw to bypass operating-system protections that normally isolate one app’s data from another app’s access. Google rated the issue as High in its Android security bulletin, while NVD lists a CVSS 3.0 base score of 5.5 (Medium) with confidentiality impact only. The practical concern i [truncated]

MEDIUM Google CVE published 2017-02-08

CVE-2017-0420

CVE-2017-0420 is an Android information disclosure issue in AOSP Mail. According to the CVE description, a local malicious application could bypass operating-system protections that isolate application data from other apps, leading to unauthorized access to data the app should not have. The issue was publicly published on 2017-02-08, with Android’s security bulletin dated 2017-02-01 as a vendor reference. [truncated]

HIGH Google CVE published 2017-02-08

CVE-2017-0419

CVE-2017-0419 is a high-severity Android elevation-of-privilege vulnerability in Audioserver. According to the published advisory and NVD record, a local malicious application could use the issue to execute arbitrary code within the context of a privileged process, gaining capabilities that are not normally available to third-party apps. The vulnerability was published on 2017-02-08 and affects multiple A [truncated]

HIGH Google CVE published 2017-02-08

CVE-2017-0418

CVE-2017-0418 is an Android elevation-of-privilege issue in Audioserver. According to the CVE record, a local malicious application could execute arbitrary code in the context of a privileged process, which is why the issue was rated High. The CVE was published on 2017-02-08, and NVD lists affected Android versions spanning 4.4.4 through 7.1.1. For defenders, the key takeaway is that this is a local attac [truncated]

HIGH Google CVE published 2017-02-08

CVE-2017-0417

CVE-2017-0417 is a high-severity Android elevation of privilege issue affecting Audioserver. A local malicious application could use the flaw to execute arbitrary code in the context of a privileged process, potentially gaining capabilities that normal third-party apps do not have. The issue was publicly disclosed in the CVE/NVD record on 2017-02-08, with the Android security bulletin referenced in the so [truncated]

HIGH Google CVE published 2017-02-08

CVE-2017-0416

CVE-2017-0416 is a high-severity Android elevation-of-privilege issue in audioserver. A local malicious app could execute arbitrary code in the context of a privileged process, with user interaction required and potential high impact to confidentiality, integrity, and availability. NVD maps the weakness to CWE-787 and rates the issue 7.8/High.

HIGH Google CVE published 2017-02-08

CVE-2017-0415

CVE-2017-0415 is a high-severity Android Mediaserver elevation-of-privilege issue. A local malicious application could trigger arbitrary code execution within a privileged process on affected Android versions, potentially gaining capabilities normally unavailable to third-party apps.

MEDIUM Google CVE published 2017-02-08

CVE-2017-0414

CVE-2017-0414 is an information disclosure issue in AOSP Messaging that could let a local malicious application bypass Android application-data isolation and access data it should not be able to read. Google rated the issue High in the Android security bulletin, while the NVD record lists a CVSS 3.0 score of 5.5 (Medium) with confidentiality impact only.