PatchSiren

Google CVE debriefs · Page 53

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Google CVE published 2017-02-08

CVE-2017-0413

CVE-2017-0413 is an information disclosure vulnerability in AOSP Messaging that could let a local malicious application bypass Android’s app-isolation protections and access data it should not be able to read. NVD rates the issue with CVSS 3.0 5.5 (Medium), but the vulnerability description also characterizes the impact as High because it can expose application data.

HIGH Google CVE published 2017-02-08

CVE-2017-0412

CVE-2017-0412 is a high-severity Android elevation-of-privilege issue in Framework APIs. According to the vendor and NVD record, a local malicious application could execute arbitrary code in the context of a privileged process on affected Android 7.0 and 7.1.1 devices; NVD also lists Android 7.1.0 in the affected CPE set. The issue is mapped to CWE-367 and carries a CVSS 3.0 score of 7.8 (AV:L/AC:L/PR:N/U [truncated]

HIGH Google CVE published 2017-02-08

CVE-2017-0411

CVE-2017-0411 is a high-severity Android elevation-of-privilege issue in Framework APIs. A local malicious app could use the flaw to execute arbitrary code in the context of a privileged process, increasing impact beyond normal third-party app permissions. The CVE was publicly published on 2017-02-08, and NVD ties it to Android 7.0, 7.1.0, and 7.1.1 with a CVSS 3.0 score of 7.8.

HIGH Google CVE published 2017-02-08

CVE-2017-0410

CVE-2017-0410 is a high-severity Android Framework vulnerability that can let a local malicious application execute arbitrary code inside a privileged process. The issue was publicly disclosed with the Android security bulletin dated 2017-02-08 and affects multiple Android release lines, including 5.0.2 through 7.1.1. For defenders, this is primarily a patch-and-coverage problem: if devices remain on affe [truncated]

HIGH Google CVE published 2017-02-08

CVE-2017-0409

CVE-2017-0409 is a high-severity Android libstagefright issue in which a specially crafted file can trigger arbitrary code execution in an unprivileged process. NVD records affected Android versions 6.0, 6.0.1, 7.0, 7.1.0, and 7.1.1, and the published CVSS 3.0 vector is 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Because exploitation depends on user interaction and a vulnerable content-processing path, the [truncated]

HIGH Google CVE published 2017-02-08

CVE-2017-0408

CVE-2017-0408 is a high-severity remote code execution issue described in Android's security bulletin for libgdx. According to the published advisory, a specially crafted file could allow arbitrary code execution in the context of an unprivileged process.

HIGH Google CVE published 2017-02-08

CVE-2017-0407

CVE-2017-0407 is a Mediaserver memory-corruption flaw in Android's libhevc component. According to the Android advisory, a specially crafted file could trigger corruption during media file and data processing, creating a path to remote code execution in the Mediaserver process. The CVE was published on 2017-02-08, with the vendor bulletin dated 2017-02-01.

HIGH Google CVE published 2017-02-08

CVE-2017-0406

CVE-2017-0406 describes a memory-corruption flaw in Android's Mediaserver processing path for libhevc. Google characterized it as a remote code execution issue, while NVD rates it 7.8 HIGH with a CVSS 3.0 vector indicating local access and user interaction are required.

HIGH Google CVE published 2017-02-08

CVE-2017-0405

CVE-2017-0405 describes a memory corruption issue in Android's Surfaceflinger component that can be triggered by a specially crafted file during media file and data processing. The impact can include remote code execution in the context of the Surfaceflinger process. NVD lists affected Android versions as 7.0, 7.1.0, and 7.1.1, with a CVSS v3.0 score of 7.8 (High), while the Android security bulletin refe [truncated]

CRITICAL Google CVE published 2017-02-08

CVE-2016-8418

CVE-2016-8418 is a critical Android kernel vulnerability described as a remote code execution issue in the Qualcomm crypto driver. The supplied NVD record indicates that Android versions up to 6.0.1 are affected and assigns a 9.8 CVSS score, making this a high-priority patch item for Android fleets.

CRITICAL Google CVE published 2017-01-30

CVE-2016-6604

CVE-2016-6604 is a critical NULL pointer dereference affecting the Samsung Exynos fimg2d driver. NVD rates it 9.8/CRITICAL and maps the vulnerable component to samsung:exynos_fimg2d. The issue is associated with Android L (5.0/5.1) and M (6.0) environments in the published description, with Samsung’s SMR-AUG-2016 advisory and related OSS-security references as the primary sources for remediation context.

CRITICAL Google CVE published 2017-01-27

CVE-2016-8411

CVE-2016-8411 is a critical Android memory-corruption issue in the QMI QOS TLV processing path. The vulnerable code is identified as qmi_qos_srvc.c, and NVD maps affected Android versions up to 7.1.1. Because the CVSS vector is network-reachable with no privileges or user interaction, this is a high-priority patching issue for any environment still using affected Android builds or vendor firmware derived [truncated]

MEDIUM Google CVE published 2017-01-19

CVE-2016-9650

CVE-2016-9650 is a Google Chrome Blink vulnerability that could let a remote attacker bypass a no-referrer policy by getting a victim to load a crafted HTML page. NVD assigns a medium-severity CVSS 3.0 score of 4.3, and the published record ties the issue to Chrome versions before 55.0.2883.75 on desktop platforms and before 55.0.2883.84 on Android. The practical risk is limited but relevant wherever brow [truncated]

MEDIUM Google CVE published 2017-01-19

CVE-2016-5226

CVE-2016-5226 describes a Chrome/Blink issue where a javascript: URL dragged and dropped into the browser’s URL bar could execute in the context of the current tab. The practical risk is a socially engineered XSS event against the person using the browser, not a remote wormable flaw. NVD rates it medium severity, with user interaction required and low impact to confidentiality and integrity.

MEDIUM Google CVE published 2017-01-19

CVE-2016-5225

CVE-2016-5225 is a Google Chrome Blink bug that could let a remote attacker bypass Content Security Policy (CSP) by serving a crafted HTML page with malformed form actions. The record shows network-based attack conditions with user interaction required, and the documented impact is limited to integrity.

MEDIUM Google CVE published 2017-01-19

CVE-2016-5224

CVE-2016-5224 is a medium-severity Google Chrome vulnerability involving a timing attack on denormalized floating point arithmetic in SVG filters in Blink. According to the CVE description, a remote attacker could use a crafted HTML page to help bypass the Same Origin Policy. Google’s remediation is referenced in the record for Chrome desktop and Android builds, and the issue is tied to browser versions b [truncated]

MEDIUM Google CVE published 2017-01-19

CVE-2016-5223

CVE-2016-5223 is a client-side memory-safety issue in Google Chrome's PDFium component. The CVE description says a crafted PDF could trigger an integer overflow, which in turn could lead to heap corruption or a denial of service. The record also indicates the issue was addressed in Chrome releases for Mac, Windows, Linux, and Android. Because the attack requires a user to open or process a malicious PDF, [truncated]

MEDIUM Google CVE published 2017-01-19

CVE-2016-5222

CVE-2016-5222 describes an issue in Google Chrome where incorrect handling of invalid URLs could let a remote attacker use a crafted HTML page to spoof the contents of the Omnibox (URL bar). The supplied record assigns CVSS 6.5 (Medium) and indicates user interaction is required. The primary security concern is user deception: a page can make the browser’s address bar appear to show something other than t [truncated]

MEDIUM Google CVE published 2017-01-19

CVE-2016-5221

CVE-2016-5221 is a Google Chrome vulnerability in ANGLE’s libGLESv2 component. According to the CVE description, a type confusion issue could let a remote attacker use a crafted HTML page to bypass buffer validation. The CVE record was published on 2017-01-19 and later modified by NVD on 2026-05-13. The supplied record classifies the issue as medium severity (CVSS 6.3) and indicates network attackability [truncated]

MEDIUM Google CVE published 2017-01-19

CVE-2016-5220

CVE-2016-5220 describes a Google Chrome PDFium flaw where navigation within PDFs was handled incorrectly, allowing a remote attacker to read local files through a crafted PDF. The issue is an information disclosure problem (CWE-200) with user interaction required, and NVD rates it CVSS 6.5 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).

MEDIUM Google CVE published 2017-01-19

CVE-2016-5219

CVE-2016-5219 is a Google Chrome V8 heap use-after-free that a remote attacker could potentially abuse with a crafted HTML page to cause heap corruption. NVD rates the issue CVSS 6.3 (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L), which means exploitation requires user interaction but can still affect confidentiality, integrity, and availability.

MEDIUM Google CVE published 2017-01-19

CVE-2016-5218

CVE-2016-5218 describes a Google Chrome issue where navigation within PDFs was handled incorrectly, allowing a remote attacker to temporarily spoof the contents of the Omnibox (URL bar) from a crafted HTML page containing PDF data. The issue was publicly recorded on 2017-01-19 and carries medium severity in the supplied data, with user interaction required and an integrity impact focused on what the brows [truncated]

MEDIUM Google CVE published 2017-01-19

CVE-2016-5217

CVE-2016-5217 describes an access-control flaw in Google Chrome's extensions API that could let a remote attacker reach privileged plugins and bypass site isolation using a crafted HTML page. The issue is rated medium severity (CVSS 6.5), but it matters because the impact is on browser isolation boundaries rather than a simple crash or nuisance bug. The public record ties the fix to Chrome releases 55.0.2 [truncated]

MEDIUM Google CVE published 2017-01-19

CVE-2016-5216

CVE-2016-5216 is a medium-severity Chrome/PDFium memory-safety issue. The CVE description says a use-after-free in PDFium could let a remote attacker trigger an out-of-bounds memory read by delivering a crafted PDF file. NVD maps the issue to CWE-416 and a network-reachable, user-interaction-dependent attack path.

MEDIUM Google CVE published 2017-01-19

CVE-2016-5215

CVE-2016-5215 is a browser memory-safety issue in Google Chrome's WebAudio component. According to the supplied NVD record, a crafted HTML page could trigger a use-after-free that led to an out-of-bounds memory read. The CVE is rated medium severity (CVSS 6.3) and is classified as CWE-416.

MEDIUM Google CVE published 2017-01-19

CVE-2016-5214

CVE-2016-5214 describes a Google Chrome for Windows issue where a crafted HTML page could cause a downloaded file to miss the Mark of the Web (MOTW). That can weaken downstream Windows security prompts and trust decisions for files acquired through the browser. The issue is rated medium severity in the supplied record and requires user interaction.

HIGH Google CVE published 2017-01-19

CVE-2016-5213

CVE-2016-5213 is a high-severity memory-corruption flaw in Google Chrome's V8 engine. NVD describes it as a use-after-free that could let a remote attacker potentially trigger heap corruption via a crafted HTML page. Because exploitation requires only that a victim load attacker-controlled web content, this is a browser patching priority for managed desktops and Android fleets.

MEDIUM Google CVE published 2017-01-19

CVE-2016-5212

CVE-2016-5212 is a Google Chrome information-disclosure issue in DevTools URL sanitization. A remote attacker could lure a user to a crafted HTML page and read local files from affected Chrome installs. The supplied description names fixed builds of 55.0.2883.75 for Mac, Windows, and Linux, and 55.0.2883.84 for Android. The NVD record classifies the issue as confidentiality-only, user-interaction required [truncated]

HIGH Google CVE published 2017-01-19

CVE-2016-5211

CVE-2016-5211 is a high-severity use-after-free in Chrome’s PDFium component. A remote attacker could potentially trigger heap corruption by persuading a user to open a crafted PDF file in affected Chrome builds. The supplied record ties the issue to Chrome prior to 55.0.2883.75 on Mac, Windows, and Linux, and prior to 55.0.2883.84 on Android.

HIGH Google CVE published 2017-01-19

CVE-2016-5210

CVE-2016-5210 is a high-severity Google Chrome vulnerability involving a heap buffer overflow during TIFF image parsing in PDFium. According to the CVE description, a crafted PDF file could trigger heap corruption remotely. The supplied NVD data rates the issue 8.8 (HIGH) with network attack vector, low attack complexity, no privileges required, and required user interaction.