Advisories
GoogleExploitedCISA KEV listedCRITICAL2018-02-02
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitr...
CVEs:CVE-2018-4878
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
GoogleExploitedCISA KEV listedCRITICAL2018-02-02
CVEs:CVE-2018-4878
Project ZeroExploitedCISA KEV listed2018-02-02
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.
CVEs:CVE-2018-4878
GoogleWeaponized exploitCRITICAL2018-02-17
CVEs:CVE-2018-6396
GoogleWeaponized exploitCRITICAL2018-02-17
SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a layout=form_markers action, or the map parameter in a layout=default action.
CVEs:CVE-2018-6396
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_map_landkarten |
affected |
google_map_landkarten_project |
— |
— |
GoogleWeaponized exploitCRITICAL2018-02-05
CVEs:CVE-2018-6582
GoogleWeaponized exploitCRITICAL2018-02-05
SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.
CVEs:CVE-2018-6582
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| zh_googlemap |
affected |
zh_googlemap_project |
— |
— |
Open SourceWeaponized exploitHIGH2018-02-06
In the KeyStore service, there is a permissions bypass that allows access to protected resources. This could lead to local escalation of privilege with system execution privileges needed. User interaction is not needed for exploitation. Product: Androi...
CVEs:CVE-2017-13236
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleWeaponized exploitHIGH2018-02-06
CVEs:CVE-2017-13236
Open SourcePoC exploitMEDIUM2018-02-27
Red Hat Security Advisory: erlang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| erlang |
affected |
Red Hat:openstack:10::el7 |
erlang |
— |
| erlang-asn1 |
affected |
Red Hat:openstack:10::el7 |
erlang-asn1 |
— |
| erlang-compiler |
affected |
Red Hat:openstack:10::el7 |
erlang-compiler |
— |
| erlang-cosEvent |
affected |
Red Hat:openstack:10::el7 |
erlang-cosEvent |
— |
| erlang-cosEventDomain |
affected |
Red Hat:openstack:10::el7 |
erlang-cosEventDomain |
— |
| erlang-cosFileTransfer |
affected |
Red Hat:openstack:10::el7 |
erlang-cosFileTransfer |
— |
| erlang-cosNotification |
affected |
Red Hat:openstack:10::el7 |
erlang-cosNotification |
— |
| erlang-cosProperty |
affected |
Red Hat:openstack:10::el7 |
erlang-cosProperty |
— |
| erlang-cosTime |
affected |
Red Hat:openstack:10::el7 |
erlang-cosTime |
— |
| erlang-cosTransactions |
affected |
Red Hat:openstack:10::el7 |
erlang-cosTransactions |
— |
| erlang-crypto |
affected |
Red Hat:openstack:10::el7 |
erlang-crypto |
— |
| erlang-debuginfo |
affected |
Red Hat:openstack:10::el7 |
erlang-debuginfo |
— |
| erlang-diameter |
affected |
Red Hat:openstack:10::el7 |
erlang-diameter |
— |
| erlang-edoc |
affected |
Red Hat:openstack:10::el7 |
erlang-edoc |
— |
| erlang-eldap |
affected |
Red Hat:openstack:10::el7 |
erlang-eldap |
— |
| erlang-erl_docgen |
affected |
Red Hat:openstack:10::el7 |
erlang-erl_docgen |
— |
| erlang-erl_interface |
affected |
Red Hat:openstack:10::el7 |
erlang-erl_interface |
— |
| erlang-erts |
affected |
Red Hat:openstack:10::el7 |
erlang-erts |
— |
| erlang-eunit |
affected |
Red Hat:openstack:10::el7 |
erlang-eunit |
— |
| erlang-hipe |
affected |
Red Hat:openstack:10::el7 |
erlang-hipe |
— |
| erlang-ic |
affected |
Red Hat:openstack:10::el7 |
erlang-ic |
— |
| erlang-inets |
affected |
Red Hat:openstack:10::el7 |
erlang-inets |
— |
| erlang-kernel |
affected |
Red Hat:openstack:10::el7 |
erlang-kernel |
— |
| erlang-mnesia |
affected |
Red Hat:openstack:10::el7 |
erlang-mnesia |
— |
| erlang-odbc |
affected |
Red Hat:openstack:10::el7 |
erlang-odbc |
— |
| erlang-orber |
affected |
Red Hat:openstack:10::el7 |
erlang-orber |
— |
| erlang-ose |
affected |
Red Hat:openstack:10::el7 |
erlang-ose |
— |
| erlang-os_mon |
affected |
Red Hat:openstack:10::el7 |
erlang-os_mon |
— |
| erlang-otp_mibs |
affected |
Red Hat:openstack:10::el7 |
erlang-otp_mibs |
— |
| erlang-parsetools |
affected |
Red Hat:openstack:10::el7 |
erlang-parsetools |
— |
| erlang-percept |
affected |
Red Hat:openstack:10::el7 |
erlang-percept |
— |
| erlang-public_key |
affected |
Red Hat:openstack:10::el7 |
erlang-public_key |
— |
| erlang-runtime_tools |
affected |
Red Hat:openstack:10::el7 |
erlang-runtime_tools |
— |
| erlang-sasl |
affected |
Red Hat:openstack:10::el7 |
erlang-sasl |
— |
| erlang-snmp |
affected |
Red Hat:openstack:10::el7 |
erlang-snmp |
— |
| erlang-ssh |
affected |
Red Hat:openstack:10::el7 |
erlang-ssh |
— |
| erlang-ssl |
affected |
Red Hat:openstack:10::el7 |
erlang-ssl |
— |
| erlang-stdlib |
affected |
Red Hat:openstack:10::el7 |
erlang-stdlib |
— |
| erlang-syntax_tools |
affected |
Red Hat:openstack:10::el7 |
erlang-syntax_tools |
— |
| erlang-tools |
affected |
Red Hat:openstack:10::el7 |
erlang-tools |
— |
| erlang-xmerl |
affected |
Red Hat:openstack:10::el7 |
erlang-xmerl |
— |
Open SourcePoC exploitMEDIUM2018-02-13
Red Hat Security Advisory: erlang security and bug fix update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| erlang |
affected |
Red Hat:openstack:11::el7 |
erlang |
— |
| erlang-asn1 |
affected |
Red Hat:openstack:11::el7 |
erlang-asn1 |
— |
| erlang-compiler |
affected |
Red Hat:openstack:11::el7 |
erlang-compiler |
— |
| erlang-cosEvent |
affected |
Red Hat:openstack:11::el7 |
erlang-cosEvent |
— |
| erlang-cosEventDomain |
affected |
Red Hat:openstack:11::el7 |
erlang-cosEventDomain |
— |
| erlang-cosFileTransfer |
affected |
Red Hat:openstack:11::el7 |
erlang-cosFileTransfer |
— |
| erlang-cosNotification |
affected |
Red Hat:openstack:11::el7 |
erlang-cosNotification |
— |
| erlang-cosProperty |
affected |
Red Hat:openstack:11::el7 |
erlang-cosProperty |
— |
| erlang-cosTime |
affected |
Red Hat:openstack:11::el7 |
erlang-cosTime |
— |
| erlang-cosTransactions |
affected |
Red Hat:openstack:11::el7 |
erlang-cosTransactions |
— |
| erlang-crypto |
affected |
Red Hat:openstack:11::el7 |
erlang-crypto |
— |
| erlang-debuginfo |
affected |
Red Hat:openstack:11::el7 |
erlang-debuginfo |
— |
| erlang-diameter |
affected |
Red Hat:openstack:11::el7 |
erlang-diameter |
— |
| erlang-edoc |
affected |
Red Hat:openstack:11::el7 |
erlang-edoc |
— |
| erlang-eldap |
affected |
Red Hat:openstack:11::el7 |
erlang-eldap |
— |
| erlang-erl_docgen |
affected |
Red Hat:openstack:11::el7 |
erlang-erl_docgen |
— |
| erlang-erl_interface |
affected |
Red Hat:openstack:11::el7 |
erlang-erl_interface |
— |
| erlang-erts |
affected |
Red Hat:openstack:11::el7 |
erlang-erts |
— |
| erlang-eunit |
affected |
Red Hat:openstack:11::el7 |
erlang-eunit |
— |
| erlang-hipe |
affected |
Red Hat:openstack:11::el7 |
erlang-hipe |
— |
| erlang-ic |
affected |
Red Hat:openstack:11::el7 |
erlang-ic |
— |
| erlang-inets |
affected |
Red Hat:openstack:11::el7 |
erlang-inets |
— |
| erlang-kernel |
affected |
Red Hat:openstack:11::el7 |
erlang-kernel |
— |
| erlang-mnesia |
affected |
Red Hat:openstack:11::el7 |
erlang-mnesia |
— |
| erlang-odbc |
affected |
Red Hat:openstack:11::el7 |
erlang-odbc |
— |
| erlang-orber |
affected |
Red Hat:openstack:11::el7 |
erlang-orber |
— |
| erlang-ose |
affected |
Red Hat:openstack:11::el7 |
erlang-ose |
— |
| erlang-os_mon |
affected |
Red Hat:openstack:11::el7 |
erlang-os_mon |
— |
| erlang-otp_mibs |
affected |
Red Hat:openstack:11::el7 |
erlang-otp_mibs |
— |
| erlang-parsetools |
affected |
Red Hat:openstack:11::el7 |
erlang-parsetools |
— |
| erlang-percept |
affected |
Red Hat:openstack:11::el7 |
erlang-percept |
— |
| erlang-public_key |
affected |
Red Hat:openstack:11::el7 |
erlang-public_key |
— |
| erlang-runtime_tools |
affected |
Red Hat:openstack:11::el7 |
erlang-runtime_tools |
— |
| erlang-sasl |
affected |
Red Hat:openstack:11::el7 |
erlang-sasl |
— |
| erlang-snmp |
affected |
Red Hat:openstack:11::el7 |
erlang-snmp |
— |
| erlang-ssh |
affected |
Red Hat:openstack:11::el7 |
erlang-ssh |
— |
| erlang-ssl |
affected |
Red Hat:openstack:11::el7 |
erlang-ssl |
— |
| erlang-stdlib |
affected |
Red Hat:openstack:11::el7 |
erlang-stdlib |
— |
| erlang-syntax_tools |
affected |
Red Hat:openstack:11::el7 |
erlang-syntax_tools |
— |
| erlang-tools |
affected |
Red Hat:openstack:11::el7 |
erlang-tools |
— |
| erlang-xmerl |
affected |
Red Hat:openstack:11::el7 |
erlang-xmerl |
— |
Open SourcePoC exploitCRITICAL2018-02-26
Updated golang packages fix security vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Mageia:6 |
golang |
— |
GooglePoC exploitHIGH2018-02-07
CVEs:CVE-2018-6574
GooglePoC exploitCRITICAL2018-02-07
Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source code build, by leveraging the gcc or clang plugin feature, because -fplugin= and -plugin= arguments were not blocked.
CVEs:CVE-2018-6574
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_server_aus |
affected |
redhat |
— |
— |
| enterprise_linux_server_eus |
affected |
redhat |
— |
— |
| enterprise_linux_server_tus |
affected |
redhat |
— |
— |
| go |
affected |
golang |
— |
— |
Open SourcePoC exploitHIGH2018-02-07
Version update for docker, docker-runc, containerd, golang-github-docker-libnetwork
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| containerd |
affected |
SUSE:OpenStack Cloud 6 |
containerd |
— |
| containerd |
affected |
SUSE:Linux Enterprise Module for Containers 12 |
containerd |
— |
| docker |
affected |
SUSE:Linux Enterprise Module for Containers 12 |
docker |
— |
| docker |
affected |
SUSE:OpenStack Cloud 6 |
docker |
— |
| docker-runc |
affected |
SUSE:OpenStack Cloud 6 |
docker-runc |
— |
| docker-runc |
affected |
SUSE:Linux Enterprise Module for Containers 12 |
docker-runc |
— |
| golang-github-docker-libnetwork |
affected |
SUSE:OpenStack Cloud 6 |
golang-github-docker-libnetwork |
— |
| golang-github-docker-libnetwork |
affected |
SUSE:Linux Enterprise Module for Containers 12 |
golang-github-docker-libnetwork |
— |
GooglePoC exploitHIGH2018-02-06
CVEs:CVE-2017-13230
Open SourcePoC exploitHIGH2018-02-06
In hevc codec, there is an out-of-bounds write due to an incorrect bounds check with the i2_pic_width_in_luma_samples value. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed fo...
CVEs:CVE-2017-13230
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2018-02-06
In function ih264d_ref_idx_reordering of libavc, there is an out-of-bounds write due to modCount being defined as an unsigned character. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed...
CVEs:CVE-2017-13228
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2018-02-06
CVEs:CVE-2017-13228
Open SourcePoC exploitHIGH2018-02-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, when an access point sends a challenge text greater than 128 bytes, the host driver is unable to validate this potentially leading to authentication failure.
CVEs:CVE-2017-15817
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2018-02-06
CVEs:CVE-2017-15817
Open SourcePoC exploitHIGH2018-02-06
In audioserver, there is an out-of-bounds write due to a log statement using %s with an array that may not be NULL terminated. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not neede...
CVEs:CVE-2017-13232
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2018-02-06
CVEs:CVE-2017-13232
Open SourcePoC exploitHIGH2018-02-06
In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion. This could lead to a remote temporary denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: And...
CVEs:CVE-2017-13233
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2018-02-06
CVEs:CVE-2017-13233
Open SourcePoC exploitHIGH2018-02-06
In DLSParser of the sonivox library, there is possible resource exhaustion due to a memory leak. This could lead to remote temporary denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product:...
CVEs:CVE-2017-13234
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2018-02-06
CVEs:CVE-2017-13234
Open SourcePoC exploitHIGH2018-02-06
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in a power driver ioctl handler, an Untrusted Pointer Dereference may potentially occur.
CVEs:CVE-2017-17770
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2018-02-06
CVEs:CVE-2017-17770
Open SourcePoC exploitHIGH2018-02-06
In libmediadrm, there is an out-of-bounds write due to improper input validation. This could lead to local elevation of privileges with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versio...
CVEs:CVE-2017-13231
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2018-02-06
CVEs:CVE-2017-13231
Open SourcePoC exploitCRITICAL2018-02-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, due to lack of bounds checking on the variable "data_len" from the function WLANQCMBR_McProcessMsg, a buffer overflow may potentially occur in WLANFTM_McProcessMsg.
CVEs:CVE-2017-14884
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2018-02-06
CVEs:CVE-2017-14884
GooglePoC exploitHIGH2018-02-06
CVEs:CVE-2017-17764
Open SourcePoC exploitCRITICAL2018-02-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, the num_failure_info value from firmware is not properly validated in wma_rx_aggr_failure_event_handler() so that an integer overflow vulnerability in a buffer size calcula...
CVEs:CVE-2017-17764
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2018-02-06
CVEs:CVE-2017-17765
Open SourcePoC exploitCRITICAL2018-02-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, multiple values received from firmware are not properly validated in wma_get_ll_stats_ext_buf() and are used to allocate the sizes of buffers and may be vulnerable to integ...
CVEs:CVE-2017-17765
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitCRITICAL2018-02-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, in a KGSL IOCTL handler, a Use After Free Condition can potentially occur.
CVEs:CVE-2017-15820
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2018-02-06
CVEs:CVE-2017-15820
GooglePoC exploitHIGH2018-02-06
CVEs:CVE-2017-17767
Open SourcePoC exploitHIGH2018-02-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, the IL client may free a buffer OMX Video Encoder Component and then subsequently access the already freed buffer.
CVEs:CVE-2017-17767
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2018-02-06
CVEs:CVE-2017-13238
Open SourcePoC exploitMEDIUM2018-02-06
In XBLRamDump mode, there is a debug feature that can be used to dump memory contents, if an attacker has physical access to the device. This could lead to local information disclosure with no additional execution privileges needed. User interaction is...
CVEs:CVE-2017-13238
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2018-02-06
NVIDIA libnvmmlite_audio.so contains an elevation of privilege vulnerability when running in media server which may cause an out of bounds write and could lead to local code execution in a privileged process. This issue is rated as high. Product: Andro...
CVEs:CVE-2017-6279
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2018-02-06
CVEs:CVE-2017-6279
Open SourcePoC exploitHIGH2018-02-06
In the Pixel 2 bootloader, there is a missing permission check which bypasses carrier bootloader lock. This could lead to local elevation of privileges with user execution privileges needed. User interaction is not needed for exploitation. Product: And...
CVEs:CVE-2017-13247
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2018-02-06
CVEs:CVE-2017-13247
Open SourcePoC exploitCRITICAL2018-02-12
A elevation of privilege vulnerability in the Upstream kernel audio driver. Product: Android. Versions: Android kernel. ID: A-64315347.
CVEs:CVE-2017-13245
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2018-02-12
CVEs:CVE-2017-13245
GooglePoC exploitHIGH2018-02-06
CVEs:CVE-2015-9016
Open SourcePoC exploitCRITICAL2018-02-06
In blk_mq_tag_to_rq in blk-mq.c in the upstream kernel, there is a possible use after free due to a race condition when a request has been previously freed by blk_mq_complete_request. This could lead to local escalation of privilege. Product: Android. ...
CVEs:CVE-2015-9016
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitCRITICAL2018-02-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a GPU Driver which can potentially lead to a Use After Free condition.
CVEs:CVE-2017-15829
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2018-02-06
CVEs:CVE-2017-15829
Open SourceCoalition ESS 30-63%2018-02-15
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 12 SP2 |
chromium |
— |
Open SourceCoalition ESS 30-63%2018-02-15
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 12 SP2 |
chromium |
— |
GoogleCoalition ESS 30-63%CRITICAL2018-02-14
Type confusion could lead to a heap out-of-bounds write in V8 in Google Chrome prior to 64.0.3282.168 allowing a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVEs:CVE-2018-6056
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleCoalition ESS 30-63%HIGH2018-02-14
CVEs:CVE-2018-6056
Open SourceEPSS 49-79%2018-02-25
golang - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Debian:7 |
golang |
— |
GoogleEPSS 49-79%HIGH2018-02-16
The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import path (get/vcs.go only checks for "://" anywhere in the string), which allows remote attackers to execute arbitrary OS commands via a c...
CVEs:CVE-2018-7187
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| debian_linux |
affected |
debian |
— |
— |
| go |
affected |
golang |
— |
— |
GoogleEPSS 49-79%HIGH2018-02-16
CVEs:CVE-2018-7187
Open SourceCoalition ESS < 30%2018-02-04
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 12 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 12 SP2 |
chromium |
— |
| re2 |
affected |
SUSE:Package Hub 12 |
re2 |
— |
| re2 |
affected |
SUSE:Package Hub 12 SP2 |
re2 |
— |
Open SourceCoalition ESS < 30%2018-02-04
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 12 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 12 SP2 |
chromium |
— |
| re2 |
affected |
SUSE:Package Hub 12 |
re2 |
— |
| re2 |
affected |
SUSE:Package Hub 12 SP2 |
re2 |
— |
GoogleEPSS <= 49%CRITICAL2018-02-12
CVEs:CVE-2017-13229
Open SourceEPSS <= 49%HIGH2018-02-12
A remote code execution vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-68160703.
CVEs:CVE-2017-13229
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2018-02-09
Jerome Gamez Firebase Admin SDK for PHP Incorrect Access Control vulnerability
CVEs:CVE-2018-1000025
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| firebase-php |
affected |
kreait |
kreait/firebase-php |
— |
Open SourceEPSS <= 49%HIGH2018-02-09
Jerome Gamez Firebase Admin SDK for PHP version from 3.2.0 to 3.8.0 contains a Incorrect Access Control vulnerability in src/Firebase/Auth/IdTokenVerifier.php does not verify for token signature that can result in JWT with any email address and user ID...
CVEs:CVE-2018-1000025
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| firebase_admin_sdk_for_php |
affected |
firebase_admin_sdk_for_php_project |
— |
— |
GoogleEPSS <= 49%HIGH2018-02-07
Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker to execute a command with the same privileges as the cups daemon via a crafted PPD file, aka a printer zeroconfig CRLF issue.
CVEs:CVE-2017-15400
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome_os |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2018-02-07
CVEs:CVE-2017-15400
Open SourceEPSS <= 49%HIGH2018-02-09
Jenkins Android Lint Plugin 2.5 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request for...
CVEs:CVE-2018-1000055
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android_lint |
affected |
jenkins |
— |
— |
Open SourceEPSS <= 49%HIGH2018-02-09
XXE vulnerability in Jenkins Android Lint Plugin
CVEs:CVE-2018-1000055
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jvnet.hudson.plugins:android-lint |
affected |
Maven |
org.jvnet.hudson.plugins:android-lint |
— |
GoogleEPSS <= 49%HIGH2018-02-12
CVEs:CVE-2017-13243
Open SourceEPSS <= 49%HIGH2018-02-12
A information disclosure vulnerability in the Android system (ui). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. ID: A-38258991.
CVEs:CVE-2017-13243
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2018-02-12
A information disclosure vulnerability in the Android framework (crypto framework). Product: Android. Versions: 8.0, 8.1. ID: A-68694819.
CVEs:CVE-2017-13240
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2018-02-12
CVEs:CVE-2017-13240
Open SourceEPSS <= 49%HIGH2018-02-12
A information disclosure vulnerability in the Android media framework (libstagefright_soft_avcenc). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-69065651.
CVEs:CVE-2017-13241
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2018-02-12
CVEs:CVE-2017-13241
GoogleEPSS <= 49%HIGH2018-02-12
CVEs:CVE-2017-13242
Open SourceEPSS <= 49%HIGH2018-02-12
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-62672248.
CVEs:CVE-2017-13242
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2018-02-12
CVEs:CVE-2017-13246
Open SourceEPSS <= 49%HIGH2018-02-12
A information disclosure vulnerability in the Upstream kernel network driver. Product: Android. Versions: Android kernel. ID: A-36279469.
CVEs:CVE-2017-13246
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2018-02-12
A information disclosure vulnerability in the Android framework (ui framework). Product: Android. Versions: 8.0. ID: A-66244132.
CVEs:CVE-2017-13239
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2018-02-12
CVEs:CVE-2017-13239
GoogleEPSS <= 49%HIGH2018-02-07
Inappropriate implementation in ChromeVox in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker in a privileged network position to observe or tamper with certain cleartext HTTP requests by leveraging that position.
CVEs:CVE-2017-15397
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome_os |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2018-02-07
CVEs:CVE-2017-15397
GoogleEPSS <= 49%HIGH2018-02-23
CVEs:CVE-2017-15860
Open SourceEPSS <= 49%HIGH2018-02-23
In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing an encrypted authentication management frame, a stack buffer overflow may potentially occur.
CVEs:CVE-2017-15860
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2018-02-12
CVEs:CVE-2017-13235
Open SourceEPSS <= 49%MEDIUM2018-02-12
A other vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-68342866.
CVEs:CVE-2017-13235
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2018-02-15
In xt_qtaguid.c, there is a race condition due to insufficient locking. This could lead to local elevation of privileges with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Androi...
CVEs:CVE-2017-13273
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2018-02-15
CVEs:CVE-2017-13273
GoogleEPSS <= 49%HIGH2018-02-12
CVEs:CVE-2017-13244
Open SourceEPSS <= 49%CRITICAL2018-02-12
A elevation of privilege vulnerability in the Upstream kernel easel. Product: Android. Versions: Android kernel. ID: A-62678986.
CVEs:CVE-2017-13244
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2018-02-23
In all Qualcomm products with Android releases from CAF using the Linux kernel, in the function wma_roam_synch_event_handler, vdev_id is received from firmware and used to access an array without validation.
CVEs:CVE-2017-15861
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2018-02-23
CVEs:CVE-2017-15861
Open SourceEPSS <= 49%CRITICAL2018-02-23
In all Qualcomm products with Android releases from CAF using the Linux kernel, in wma_unified_link_radio_stats_event_handler(), the number of radio channels coming from firmware is not properly validated, potentially leading to an integer overflow vul...
CVEs:CVE-2017-15862
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2018-02-23
CVEs:CVE-2017-15862