Google Security Advisories · April 2018 — Google Security Advisories
210 advisories 106 CVEs 1 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2018-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

DSA-4182-1

Open SourceExploitedCISA KEV listed2018-04-28

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:9 chromium-browser
Upstream advisory

CVE-2018-6092

GoogleWeaponized exploitCRITICAL2018-04-18

An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVEs:CVE-2018-6092

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6084

GoogleWeaponized exploitHIGH2018-04-18

Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local attacker to execute arbitrary code via an executable file.

CVEs:CVE-2018-6084

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

RHSA-2018:0878

Open SourcePoC exploitHIGH2018-04-10

Red Hat Security Advisory: golang security, bug fix, and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Red Hat:enterprise_linux:7::server golang
golang-bin affected Red Hat:enterprise_linux:7::server golang-bin
golang-docs affected Red Hat:enterprise_linux:7::server golang-docs
golang-misc affected Red Hat:enterprise_linux:7::server golang-misc
golang-src affected Red Hat:enterprise_linux:7::server golang-src
golang-tests affected Red Hat:enterprise_linux:7::server golang-tests
Upstream advisory

CVE-2018-10237

GooglePoC exploitHIGH2018-04-26

Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray c...

CVEs:CVE-2018-10237

Affected products

ProductStatusVendorPackageEcosystem
banking_payments affected oracle
communications_ip_service_activator affected oracle
customer_management_and_segmentation_foundation affected oracle
database_server affected oracle
flexcube_investor_servicing affected oracle
flexcube_private_banking affected oracle
guava affected google
jboss_enterprise_application_platform affected redhat
openshift_container_platform affected redhat
openstack affected redhat
retail_integration_bus affected oracle
retail_xstore_point_of_service affected oracle
satellite affected redhat
satellite_capsule affected redhat
virtualization affected redhat
virtualization_host affected redhat
weblogic_server affected oracle
Upstream advisory

CVE-2018-10237

GooglePoC exploitMEDIUM2018-04-26

Denial of Service in Google Guava

CVEs:CVE-2018-10237

Affected products

ProductStatusVendorPackageEcosystem
com.googlecode.guava-osgi:guava-osgi affected Maven com.googlecode.guava-osgi:guava-osgi
com.google.guava:guava affected Maven com.google.guava:guava
com.google.guava:guava-jdk5 affected Maven com.google.guava:guava-jdk5
de.mhus.ports:vaadin-shared-deps affected Maven de.mhus.ports:vaadin-shared-deps
org.hudsonci.lib.guava:guava affected Maven org.hudsonci.lib.guava:guava
org.sonatype.sisu:sisu-guava affected Maven org.sonatype.sisu:sisu-guava
Upstream advisory

CVE-2017-13286

Open SourcePoC exploitHIGH2018-04-03

In writeToParcel and readFromParcel of OutputConfiguration.java, there is a permission bypass due to mismatched serialization. This could lead to a local escalation of privilege where the user can start an activity with system privileges, with no addit...

CVEs:CVE-2017-13286

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13305

Open SourcePoC exploitHIGH2018-04-03

A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974.

CVEs:CVE-2017-13305

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
ubuntu_linux affected canonical
Upstream advisory

CVE-2018-6085

GoogleCoalition ESS < 30%CRITICAL2018-04-18

Re-entry of a destructor in Networking Disk Cache in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

CVEs:CVE-2018-6085

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6087

GoogleCoalition ESS < 30%CRITICAL2018-04-18

A use-after-free in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVEs:CVE-2018-6087

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6086

GoogleCoalition ESS < 30%CRITICAL2018-04-18

A double-eviction in the Incognito mode cache that lead to a user-after-free in Networking Disk Cache in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

CVEs:CVE-2018-6086

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6090

GoogleCoalition ESS < 30%CRITICAL2018-04-18

An integer overflow that lead to a heap buffer-overflow in Skia in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVEs:CVE-2018-6090

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6101

GoogleCoalition ESS < 30%CRITICAL2018-04-18

A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page, if the user is running a remote DevTools debugging server.

CVEs:CVE-2018-6101

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6111

GoogleCoalition ESS < 30%HIGH2018-04-18

An object lifetime issue in the developer tools network handler in Google Chrome prior to 66.0.3359.117 allowed a local attacker to execute arbitrary code via a crafted HTML page.

CVEs:CVE-2018-6111

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6088

GoogleCoalition ESS < 30%CRITICAL2018-04-18

An iterator-invalidation bug in PDFium in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.

CVEs:CVE-2018-6088

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6091

GoogleCoalition ESS < 30%CRITICAL2018-04-18

Service Workers can intercept any request made by an <embed> or <object> tag in Fetch API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2018-6091

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6117

GoogleCoalition ESS < 30%HIGH2018-04-18

Confusing settings in Autofill in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2018-6117

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6106

GoogleCoalition ESS < 30%HIGH2018-04-18

An asynchronous generator may return an incorrect state in V8 in Google Chrome prior to 66.0.3359.117 allowing a remote attacker to potentially exploit object corruption via a crafted HTML page.

CVEs:CVE-2018-6106

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6094

GoogleCoalition ESS < 30%HIGH2018-04-18

Inline metadata in GarbageCollection in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2018-6094

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6095

GoogleCoalition ESS < 30%MEDIUM2018-04-18

Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to read local files via a crafted HTML page.

CVEs:CVE-2018-6095

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6089

GoogleCoalition ESS < 30%MEDIUM2018-04-18

A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.

CVEs:CVE-2018-6089

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6093

GoogleCoalition ESS < 30%MEDIUM2018-04-18

Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2018-6093

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6099

GoogleCoalition ESS < 30%MEDIUM2018-04-18

A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.

CVEs:CVE-2018-6099

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6112

GoogleCoalition ESS < 30%MEDIUM2018-04-18

Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2018-6112

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6103

GoogleCoalition ESS < 30%MEDIUM2018-04-18

A stagnant permission prompt in Prompts in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass permission policy via a crafted HTML page.

CVEs:CVE-2018-6103

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6096

GoogleCoalition ESS < 30%MEDIUM2018-04-18

A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obscure the full screen warning via a crafted HTML page.

CVEs:CVE-2018-6096

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6114

GoogleCoalition ESS < 30%CRITICAL2018-04-18

Incorrect enforcement of CSP for <object> tags in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVEs:CVE-2018-6114

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6097

GoogleCoalition ESS < 30%MEDIUM2018-04-18

Incorrect handling of asynchronous methods in Fullscreen in Google Chrome on macOS prior to 66.0.3359.117 allowed a remote attacker to enter full screen without showing a warning via a crafted HTML page.

CVEs:CVE-2018-6097

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6113

GoogleCoalition ESS < 30%MEDIUM2018-04-18

Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVEs:CVE-2018-6113

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6098

GoogleCoalition ESS < 30%MEDIUM2018-04-18

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2018-6098

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6108

GoogleCoalition ESS < 30%MEDIUM2018-04-18

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted HTML page.

CVEs:CVE-2018-6108

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6116

GoogleCoalition ESS < 30%MEDIUM2018-04-18

A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVEs:CVE-2018-6116

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6109

GoogleCoalition ESS < 30%MEDIUM2018-04-18

readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to access data on the user file system without explicit c...

CVEs:CVE-2018-6109

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6100

GoogleCoalition ESS < 30%MEDIUM2018-04-18

Incorrect handling of confusable characters in URL Formatter in Google Chrome on macOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2018-6100

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6104

GoogleCoalition ESS < 30%MEDIUM2018-04-18

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2018-6104

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6107

GoogleCoalition ESS < 30%MEDIUM2018-04-18

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2018-6107

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6105

GoogleCoalition ESS < 30%MEDIUM2018-04-18

Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2018-6105

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6110

GoogleCoalition ESS < 30%MEDIUM2018-04-18

Parsing documents as HTML in Downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to cause Chrome to execute scripts via a local non-HTML page.

CVEs:CVE-2018-6110

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6102

GoogleCoalition ESS < 30%MEDIUM2018-04-18

Missing confusable characters in Internationalization in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

CVEs:CVE-2018-6102

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6115

GoogleCoalition ESS < 30%MEDIUM2018-04-18

Inappropriate setting of the SEE_MASK_FLAG_NO_UI flag in file downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially bypass OS malware checks via a crafted HTML page.

CVEs:CVE-2018-6115

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-3563

Open SourceCoalition ESS < 30%CRITICAL2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, untrusted pointer dereference in apr_cb_func can lead to an arbitrary code execution.

CVEs:CVE-2018-3563

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3596

Open SourceCoalition ESS < 30%CRITICAL2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, legacy code vulnerable after migration has been removed.

CVEs:CVE-2018-3596

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3599

Open SourceCoalition ESS < 30%CRITICAL2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while notifying a DCI client, a Use After Free condition can occur.

CVEs:CVE-2018-3599

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3584

Open SourceCoalition ESS < 30%CRITICAL2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, a Use After Free condition can occur in the function rmnet_usb_ctrl_init().

CVEs:CVE-2018-3584

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3598

Open SourceCoalition ESS < 30%HIGH2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, insufficient validation of parameters from userspace in the camera driver can lead to inf...

CVEs:CVE-2018-3598

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5820

Open SourceCoalition ESS < 30%CRITICAL2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in the function wma_tbttoffset_update_event_handler(), a parameter received from firmware...

CVEs:CVE-2018-5820

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5822

Open SourceCoalition ESS < 30%HIGH2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, compromised WLAN FW can potentially cause a buffer overwrite.

CVEs:CVE-2018-5822

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3566

Open SourceCoalition ESS < 30%HIGH2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, a buffer overwrite may occur in ProcSetReqInternal() due to missing length check.

CVEs:CVE-2018-3566

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5821

Open SourceCoalition ESS < 30%HIGH2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in function wma_wow_wakeup_host_event(), wake_info->vdev_id is received from FW and is us...

CVEs:CVE-2018-5821

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5826

Open SourceCoalition ESS < 30%CRITICAL2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, due to a race condition, a Use After Free condition can occur in the WLAN driver.

CVEs:CVE-2018-5826

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5827

Open SourceCoalition ESS < 30%CRITICAL2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, a buffer overflow vulnerability exists in WLAN while processing an extscan hotlist event.

CVEs:CVE-2018-5827

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3567

Open SourceCoalition ESS < 30%CRITICAL2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, a buffer overflow vulnerability exists in WLAN while processing the HTT_T2H_MSG_TYPE_PEER...

CVEs:CVE-2018-3567

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3568

Open SourceCoalition ESS < 30%HIGH2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in __wlan_hdd_cfg80211_vendor_scan(), a buffer overwrite can potentially occur.

CVEs:CVE-2018-3568

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5828

Open SourceCoalition ESS < 30%HIGH2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in function wma_extscan_start_stop_event_handler(), vdev_id comes from the variable event...

CVEs:CVE-2018-5828

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5823

Open SourceCoalition ESS < 30%CRITICAL2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, improper buffer length validation in extscan hotlist event can lead to potential buffer o...

CVEs:CVE-2018-5823

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5824

Open SourceCoalition ESS < 30%CRITICAL2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while processing HTT_T2H_MSG_TYPE_RX_FLUSH or HTT_T2H_MSG_TYPE_RX_PN_IND messages, a buff...

CVEs:CVE-2018-5824

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5825

Open SourceCoalition ESS < 30%CRITICAL2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in the kernel IPA driver, a Use After Free condition can occur.

CVEs:CVE-2018-5825

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10230

Open SourceEPSS <= 49%HIGH2018-04-04

A remote code execution vulnerability in the Qualcomm crypto driver. Product: Android. Versions: Android kernel. Android ID: A-34389927. References: QC-CR#1091408.

CVEs:CVE-2016-10230

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13283

Open SourceEPSS <= 49%HIGH2018-04-03

In avrc_ctrl_pars_vendor_rsp of bluetooth avrcp_ctrl, there is a possible out of bounds write on the stack due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not n...

CVEs:CVE-2017-13283

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13281

Open SourceEPSS <= 49%HIGH2018-04-03

In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible stack buffer overflow due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2017-13281

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13282

Open SourceEPSS <= 49%HIGH2018-04-03

In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2017-13282

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13267

Open SourceEPSS <= 49%HIGH2018-04-03

In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2017-13267

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13284

Open SourceEPSS <= 49%HIGH2018-04-03

In config_set_string of config.cc, it is possible to pair a second BT keyboard without user approval due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is...

CVEs:CVE-2017-13284

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13292

Open SourceEPSS <= 49%HIGH2018-04-03

In wl_get_assoc_ies of wl_cfg80211.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Pr...

CVEs:CVE-2017-13292

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13285

Open SourceEPSS <= 49%HIGH2018-04-03

In SvoxSsmlParser and startElement of svox_ssml_parser.cpp, there is a possible out of bounds write due to an uninitialized buffer. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User...

CVEs:CVE-2017-13285

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10298

Open SourceEPSS <= 49%HIGH2018-04-04

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393252.

CVEs:CVE-2016-10298

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10299

Open SourceEPSS <= 49%HIGH2018-04-04

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-32577244.

CVEs:CVE-2016-10299

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10233

Open SourceEPSS <= 49%HIGH2018-04-04

An elevation of privilege vulnerability in the Qualcomm video driver. Product: Android. Versions: Android kernel. Android ID: A-34389926. References: QC-CR#897452.

CVEs:CVE-2016-10233

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13291

Open SourceEPSS <= 49%HIGH2018-04-03

In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible NULL pointer dereference due to missing bounds checks. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2017-13291

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13277

Open SourceEPSS <= 49%HIGH2018-04-03

In ihevcd_fmt_conv of ihevcd_fmt_conv.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Produc...

CVEs:CVE-2017-13277

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-1325

GoogleEPSS <= 49%MEDIUM2018-04-18

Cross-site Scripting in wicket-jquery-ui

CVEs:CVE-2018-1325

Affected products

ProductStatusVendorPackageEcosystem
com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent affected Maven com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent
Upstream advisory

CVE-2018-1325

GoogleEPSS <= 49%MEDIUM2018-04-18

In Apache wicket-jquery-ui <= 6.29.0, <= 7.10.1, <= 8.0.0-M9.1, JS code created in WYSIWYG editor will be executed on display.

CVEs:CVE-2018-1325

Affected products

ProductStatusVendorPackageEcosystem
wicket-jquery-ui affected wicket-jquery-ui_project
Upstream advisory

CVE-2016-10235

Open SourceEPSS <= 49%HIGH2018-04-04

A denial of service vulnerability in the Qualcomm WiFi driver. Product: Android. Versions: Android kernel. Android ID: A-34390620. References: QC-CR#1046409.

CVEs:CVE-2016-10235

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13280

Open SourceEPSS <= 49%HIGH2018-04-03

In the FrameSequence_gif::FrameSequence_gif function of libframesequence, there is a out of bounds read due to a missing bounds check. This could lead to a remote denial of service with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2017-13280

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13276

Open SourceEPSS <= 49%HIGH2018-04-03

In CProgramConfig_ReadHeightExt of tpdec_asc.cpp, there is a possible stack buffer overflow due to a missing bounds check. This could lead to a remote code execution with no additional execution privileges needed. User interaction is needed for exploit...

CVEs:CVE-2017-13276

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18147

Open SourceEPSS <= 49%CRITICAL2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in MMCP, a downlink message is not being properly validated.

CVEs:CVE-2017-18147

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10232

Open SourceEPSS <= 49%HIGH2018-04-04

An elevation of privilege vulnerability in the Qualcomm video driver. Product: Android. Versions: Android kernel. Android ID: A-34386696. References: QC-CR#1024872.

CVEs:CVE-2016-10232

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13279

Open SourceEPSS <= 49%HIGH2018-04-03

In M3UParser::parse of M3UParser.cpp, there is a memory resource exhaustion due to a large loop of pushing items into a vector. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for e...

CVEs:CVE-2017-13279

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13274

Open SourceEPSS <= 49%CRITICAL2018-04-03

In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security decisions with no additional execution privileges needed. User interaction is not needed for exploitation. ...

CVEs:CVE-2017-13274

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-0900

Open SourceEPSS <= 49%HIGH2018-04-20

The Device Administrator code in Android before 4.4.1_r1 might allow attackers to spoof device administrators and consequently bypass MDM restrictions by leveraging failure to update the mAdminMap data structure.

CVEs:CVE-2014-0900

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13278

Open SourceEPSS <= 49%HIGH2018-04-03

In MediaPlayerService::Client::notify of MediaPlayerService.cpp, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Produ...

CVEs:CVE-2017-13278

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13307

Open SourceEPSS <= 49%CRITICAL2018-04-03

A elevation of privilege vulnerability in the Upstream kernel pci sysfs. Product: Android. Versions: Android kernel. Android ID: A-69128924.

CVEs:CVE-2017-13307

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13301

Open SourceEPSS <= 49%HIGH2018-04-03

A denial of service vulnerability in the Android system (system ui). Product: Android. Versions: 8.0. Android ID: A-66498711.

CVEs:CVE-2017-13301

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13302

Open SourceEPSS <= 49%HIGH2018-04-03

A denial of service vulnerability in the Android system (system ui). Product: Android. Versions: 8.0. Android ID: A-69969749.

CVEs:CVE-2017-13302

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13299

Open SourceEPSS <= 49%HIGH2018-04-03

A other vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70897394.

CVEs:CVE-2017-13299

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13300

Open SourceEPSS <= 49%HIGH2018-04-03

A denial of service vulnerability in the Android media framework (libhevc). Product: Android. Versions: 6.0, 6.0.1. Android ID: A-71567394.

CVEs:CVE-2017-13300

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13295

Open SourceEPSS <= 49%HIGH2018-04-03

A denial of service vulnerability in the Android framework (package installer). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-62537081.

CVEs:CVE-2017-13295

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15822

Open SourceEPSS <= 49%CRITICAL2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while processing a 802.11 management frame, a buffer overflow may potentially occur.

CVEs:CVE-2017-15822

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13304

Open SourceEPSS <= 49%HIGH2018-04-03

A information disclosure vulnerability in the Upstream kernel mnh_sm driver. Product: Android. Versions: Android kernel. Android ID: A-70576999.

CVEs:CVE-2017-13304

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15837

Open SourceEPSS <= 49%MEDIUM2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, a policy for the packet pattern attribute NL80211_PKTPAT_OFFSET is not defined which can ...

CVEs:CVE-2017-15837

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15853

Open SourceEPSS <= 49%MEDIUM2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while processing PTT commands, ptt_sock_send_msg_to_app() is invoked without validating t...

CVEs:CVE-2017-15853

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13306

Open SourceEPSS <= 49%CRITICAL2018-04-03

A elevation of privilege vulnerability in the Upstream kernel mnh driver. Product: Android. Versions: Android kernel. Android ID: A-70295063.

CVEs:CVE-2017-13306

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13294

Open SourceEPSS <= 49%HIGH2018-04-03

A information disclosure vulnerability in the Android framework (aosp email application). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71814449.

CVEs:CVE-2017-13294

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13296

Open SourceEPSS <= 49%HIGH2018-04-03

A information disclosure vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70897454.

CVEs:CVE-2017-13296

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13297

Open SourceEPSS <= 49%HIGH2018-04-03

A information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71766721.

CVEs:CVE-2017-13297

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13298

Open SourceEPSS <= 49%HIGH2018-04-03

A information disclosure vulnerability in the Android media framework (libhavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-72117051.

CVEs:CVE-2017-13298

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13303

Open SourceEPSS <= 49%HIGH2018-04-03

A information disclosure vulnerability in the Broadcom bcmdhd driver. Product: Android. Versions: Android kernel. Android ID: A-71359108. References: B-V2018010501.

CVEs:CVE-2017-13303

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14890

Open SourceEPSS <= 49%HIGH2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in the processing of an SWBA event, the vdev_map value is not properly validated leading ...

CVEs:CVE-2017-14890

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14894

Open SourceEPSS <= 49%HIGH2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in wma_vdev_start_resp_handler(), vdev id is received from firmware as part of WMI_VDEV_S...

CVEs:CVE-2017-14894

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15836

Open SourceEPSS <= 49%CRITICAL2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, if the firmware sends a service ready event to the host with a large number in the num_hw...

CVEs:CVE-2017-15836

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13288

Open SourceEPSS <= 49%HIGH2018-04-03

In writeToParcel and readFromParcel of PeriodicAdvertisingReport.java, there is a permission bypass due to a 64/32bit int mismatch. This could lead to a local escalation of privilege where the user can start an activity with system privileges, with no ...

CVEs:CVE-2017-13288

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13289

Open SourceEPSS <= 49%HIGH2018-04-03

In writeToParcel and createFromParcel of RttManager.java, there is a permission bypass due to a write size mismatch. This could lead to a local escalation of privileges where the user can start an activity with system privileges, with no additional exe...

CVEs:CVE-2017-13289

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13293

Open SourceEPSS <= 49%HIGH2018-04-03

In the nfc_hci_cmd_received() function of core.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is ...

CVEs:CVE-2017-13293

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13287

Open SourceEPSS <= 49%HIGH2018-04-03

In createFromParcel of VerifyCredentialResponse.java, there is a possible invalid parcel read due to improper input validation. This could lead to local escalation of privilege if mPayload in writeToParcel were null, with no additional execution privil...

CVEs:CVE-2017-13287

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13290

Open SourceEPSS <= 49%MEDIUM2018-04-03

In sdp_server_handle_client_req of sdp_server.cc, there is an out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2017-13290

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11075

Open SourceEPSS <= 49%CRITICAL2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, if cmd_pkt and reg_pkt are called from different userspace threads, a use after free cond...

CVEs:CVE-2017-11075

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13275

Open SourceEPSS <= 49%MEDIUM2018-04-03

In getVSCoverage of CmapCoverage.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional privileges needed. User interaction is needed for exploitation. Product: A...

CVEs:CVE-2017-13275

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14880

Open SourceEPSS <= 49%HIGH2018-04-03

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while IPA WAN-driver is processing multiple requests from modem/user-space module, the gl...

CVEs:CVE-2017-14880

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.