PatchSiren

Google CVE debriefs · Page 54

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Google CVE published 2017-01-19

CVE-2016-5209

CVE-2016-5209 is a Google Chrome Blink issue caused by bad casting in bitmap manipulation. According to the CVE description, a remote attacker could potentially trigger heap corruption by getting a victim to open a crafted HTML page. NVD rates the issue 8.8 HIGH and maps it to CWE-787 (out-of-bounds write). The source corpus also points to Google’s stable-channel Chrome update and downstream distro adviso [truncated]

MEDIUM Google CVE published 2017-01-19

CVE-2016-5208

CVE-2016-5208 affects Google Chrome’s Blink engine and was fixed in Chrome 55.0.2883.75 for Linux and Windows, and 55.0.2883.84 for Android. The issue is described as possible corruption of the DOM tree during synchronous event handling. In practical terms, a remote attacker could use a crafted HTML page to inject arbitrary scripts or HTML, resulting in UXSS-style impact. NVD rates the issue CVSS 3.0 6.1 [truncated]

MEDIUM Google CVE published 2017-01-19

CVE-2016-5207

CVE-2016-5207 affects Google Chrome’s Blink engine. The CVE/NVD record says DOM tree corruption could occur during removal of a full-screen element, and a remote attacker could potentially exploit the issue via a crafted HTML page. The supplied record ties the issue to Chrome versions before 55.0.2883.75 on Mac, Windows, and Linux, and before 55.0.2883.84 on Android.

HIGH Google CVE published 2017-01-19

CVE-2016-5206

CVE-2016-5206 is a Chrome PDF plugin issue where redirect handling was incorrect, creating a path to bypass Same Origin Policy from a crafted HTML page. The supplied record classifies it as high severity (CVSS 8.8) and maps it to a browser integrity problem rather than a code-execution flaw.

MEDIUM Google CVE published 2017-01-19

CVE-2016-5205

CVE-2016-5205 is a Chrome/Blink client-side security issue that could let a remote attacker inject arbitrary scripts or HTML through a crafted HTML page. The NVD record classifies it as CWE-79 and gives it a medium CVSS 3.0 score of 6.1 with network attack vector and user interaction required. For defenders, the key concern is browser exposure on desktop fleets running affected Chrome versions, especially [truncated]

MEDIUM Google CVE published 2017-01-19

CVE-2016-5204

CVE-2016-5204 is a Chrome/Blink vulnerability involving leakage of an SVG shadow tree that can corrupt the DOM tree and let a remote attacker inject arbitrary scripts or HTML. NVD rates it medium severity, and the issue affects Chrome versions before the fixed 55.x releases noted in the CVE record.

HIGH Google CVE published 2017-01-19

CVE-2016-5203

CVE-2016-5203 is a high-severity Google Chrome issue in PDFium involving a use-after-free condition that could be reached with a crafted PDF file. The supplied CVE description says affected Chrome versions were fixed before 55.0.2883.75 on Mac, Windows, and Linux, and before 55.0.2883.84 on Android. Because the attack path is browser-delivered and requires user interaction, the main defensive concern is e [truncated]

MEDIUM Google CVE published 2017-01-19

CVE-2016-5201

CVE-2016-5201 is a Chrome information-disclosure issue in the extensions API that could let a remote attacker access privileged JavaScript code through a crafted HTML page. NVD classifies the weakness as CWE-200 and scores it 6.5/10 (medium). The CVE was published on 2017-01-19, and the NVD record was later modified on 2026-05-13; that later modification does not change the original vulnerability timing.

HIGH Google CVE published 2017-01-19

CVE-2016-5200

CVE-2016-5200 is a high-severity Google Chrome issue in V8 where type rules were incorrectly applied, allowing a remote attacker to potentially trigger heap corruption through a crafted HTML page. The CVSS 3.0 score is 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), which reflects network reachability, low attack complexity, and the need for user interaction. Google’s referenced stable-channel update and relat [truncated]

HIGH Google CVE published 2017-01-19

CVE-2016-5199

CVE-2016-5199 is a high-severity Chrome vulnerability tied to FFmpeg handling of crafted video content. According to the published description, an off-by-one error could cause a zero-size allocation and potentially lead to heap corruption, creating a remote attack path through malicious media. Google’s release advisory and the CVE record indicate this was addressed in specific Chrome updates across Mac, W [truncated]

HIGH Google CVE published 2017-01-19

CVE-2016-5197

CVE-2016-5197 affects Google Chrome for Android’s content view client. The issue is an insufficient validation of intent URLs: if an attacker had already compromised the renderer process and delivered a crafted HTML page, they could trigger arbitrary activity launches on the device. NVD rates the issue HIGH with a CVSS 3.0 score of 8.8, reflecting network reachability, low attack complexity, and high impa [truncated]

HIGH Google CVE published 2017-01-19

CVE-2016-5196

CVE-2016-5196 is a high-severity Chrome for Android issue where the content renderer client did not sufficiently enforce the Same Origin Policy for downloaded files. A remote attacker could use a crafted HTML page to access downloaded files and interact with sites where the user was already logged in, with user interaction required. The CVE was published by NVD on 2017-01-19.

HIGH Google CVE published 2017-01-18

CVE-2014-9910

CVE-2014-9910 is a High-severity elevation-of-privilege issue affecting Android’s Broadcom Wi‑Fi driver. According to the CVE record, a local malicious application could potentially execute arbitrary code in the kernel context, but the issue is rated High because exploitation first requires compromising a privileged process. NVD maps the issue to Android versions up to 7.1.0, and Google’s Android security [truncated]

HIGH Google CVE published 2017-01-18

CVE-2014-9909

CVE-2014-9909 describes an elevation of privilege issue in the Broadcom Wi‑Fi driver on Android. The record says a local malicious application could execute arbitrary code in kernel context, and it was rated High because it first required compromising a privileged process.

MEDIUM Google CVE published 2017-01-13

CVE-2017-0398

CVE-2017-0398 is a moderate-severity Android information disclosure issue in Audioserver. A local malicious app could access data beyond its permission level, exposing sensitive information on affected devices.

MEDIUM Google CVE published 2017-01-13

CVE-2016-8467

CVE-2016-8467 is an Android bootloader vulnerability that can let a local attacker execute arbitrary modem commands on the device. The impact is availability-focused: the issue is described as a local permanent denial of service that may require reflashing the entire operating system, and NVD lists Android versions through 7.1.0 as vulnerable.

HIGH Google CVE published 2017-01-12

CVE-2016-6492

CVE-2016-6492 is a high-severity local privilege escalation in the MediaTek camera_fdvt.c driver. According to the public record, a crafted application can trigger the MT6573FDVTIOC_T_SET_FDCONF_CMD IOCTL and abuse the MT6573FDVT_SetRegHW function to gain privileges on affected Android systems.

MEDIUM Google CVE published 2016-10-14

CVE-2005-4900

CVE-2005-4900 is a long-standing cryptographic weakness record for SHA-1 rather than a conventional software bug. The issue is that SHA-1 is not collision resistant, which can make certain spoofing attacks easier in contexts that rely on SHA-1 for integrity or identity, including the TLS 1.2 example cited in the CVE description. NVD classifies the weakness as CWE-326 and assigns a CVSS 3.0 score of 5.9 (M [truncated]