Google Security Advisories · June 2018 — Google Security Advisories
121 advisories 59 CVEs 4 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2018-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 4 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

MGASA-2018-0268

Open SourceExploitedCISA KEV listedCRITICAL2018-06-04

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:6 chromium-browser-stable
Upstream advisory

CVE-2018-5002

GoogleExploitedCISA KEV listedHIGH2018-06-07

Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVEs:CVE-2018-5002

Affected products

ProductStatusVendorPackageEcosystem
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
flash_player affected adobe
flash_player_desktop_runtime affected adobe
Upstream advisory

CVE-2018-5002

Project ZeroExploitedCISA KEV listed2018-06-07

Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVEs:CVE-2018-5002

Upstream advisory

DSA-4237-1

Open SourceWeaponized exploit2018-06-30

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:9 chromium-browser
Upstream advisory

CVE-2018-9373

Open SourceActive exploitation (sightings)HIGH2018-06-05

In TdlsexRxFrameHandle of the MTK WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2018-9373

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9356

Open SourcePoC exploitHIGH2018-06-05

In bnep_data_ind of bnep_main.c, there is a possible remote code execution due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android ...

CVEs:CVE-2018-9356

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9355

Open SourcePoC exploitHIGH2018-06-05

In bta_dm_sdp_result of bta_dm_act.cc, there is a possible out of bounds stack write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation...

CVEs:CVE-2018-9355

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9360

Open SourcePoC exploitHIGH2018-06-05

In process_l2cap_cmd of l2c_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2018-9360

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9359

Open SourcePoC exploitHIGH2018-06-05

In process_l2cap_cmd of l2c_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2018-9359

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9361

Open SourcePoC exploitHIGH2018-06-05

In process_l2cap_cmd of l2c_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2018-9361

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9358

Open SourcePoC exploitHIGH2018-06-05

In gatts_process_attribute_req of gatt_sc.cc, there is a possible read of uninitialized data due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth process with no additional execution privileges needed. User i...

CVEs:CVE-2018-9358

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9362

Open SourcePoC exploitHIGH2018-06-05

In processMessagePart of InboundSmsHandler.java, there is a possible remote denial of service due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2018-9362

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3713

Open SourcePoC exploitMEDIUM2018-06-07

Path Traversal in angular-http-server

CVEs:CVE-2018-3713

Affected products

ProductStatusVendorPackageEcosystem
angular-http-server affected npm angular-http-server
Upstream advisory

CVE-2018-3713

Open SourcePoC exploitMEDIUM2018-06-06

Path Traversal in angular-http-server

CVEs:CVE-2018-3713

Affected products

ProductStatusVendorPackageEcosystem
angular-http-server affected npm angular-http-server
Upstream advisory

CVE-2018-3713

Open SourcePoC exploitHIGH2018-06-06

angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilename, which allows a malicious user to read content of any file with known path.

CVEs:CVE-2018-3713

Affected products

ProductStatusVendorPackageEcosystem
angular-http-server affected angular-http-server_project
Upstream advisory

CVE-2018-3738

Open SourcePoC exploitMEDIUM2018-06-07

protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files.

CVEs:CVE-2018-3738

Affected products

ProductStatusVendorPackageEcosystem
protobufjs affected protobufjs_project
Upstream advisory

CVE-2018-3738

Open SourcePoC exploitMEDIUM2018-06-07

Denial of Service in protobufjs

CVEs:CVE-2018-3738

Affected products

ProductStatusVendorPackageEcosystem
protobufjs affected npm protobufjs
Upstream advisory

CVE-2018-3738

Open SourcePoC exploitMEDIUM2018-06-07

Denial of Service in protobufjs

CVEs:CVE-2018-3738

Affected products

ProductStatusVendorPackageEcosystem
protobufjs affected npm protobufjs
Upstream advisory

CVE-2018-5829

Open SourcePoC exploitHIGH2018-06-05

In wlan_hdd_cfg80211_set_privacy_ibss() in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, a buffer over-read can potentially occur.

CVEs:CVE-2018-5829

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9347

Open SourcePoC exploitMEDIUM2018-06-05

In function SMF_ParseMetaEvent of file eas_smf.c there is incorrect input validation causing an infinite loop. This could lead to a remote temporary DoS with no additional execution privileges needed. User interaction is needed for exploitation. Produc...

CVEs:CVE-2018-9347

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9363

Open SourcePoC exploitHIGH2018-06-05

In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of bounds write with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel ...

CVEs:CVE-2018-9363

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
linux_kernel affected linux
ubuntu_linux affected canonical
Upstream advisory

CVE-2018-9341

Open SourcePoC exploitCRITICAL2018-06-05

In impeg2d_mc_fullx_fully of impeg2d_mc.c there is a possible out of bound write due to missing bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2018-9341

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9348

Open SourcePoC exploitHIGH2018-06-05

In SMF_ParseMetaEvent of eas_smf.c, there is a possible integer overflow. This could lead to remote denial of service due to resource exhaustion with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2018-9348

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18159

Open SourcePoC exploitHIGH2018-06-05

In Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, while processing a StrHwPlatform with length smaller than EFICHIPINFO_MAX_ID_LENGTH, an array out of bounds a...

CVEs:CVE-2017-18159

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5830

Open SourcePoC exploitCRITICAL2018-06-05

While processing the HTT_T2H_MSG_TYPE_MGMT_TX_COMPL_IND message, a buffer overflow can potentially occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05.

CVEs:CVE-2018-5830

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9364

Open SourcePoC exploitHIGH2018-06-05

In the LG LAF component, there is a special command that allowed modification of certain partitions. This could lead to bypass of secure boot. User interaction is not needed for exploitation.

CVEs:CVE-2018-9364

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9357

Open SourcePoC exploitHIGH2018-06-05

In BNEP_Write of bnep_api.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Product: An...

CVEs:CVE-2018-9357

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5835

Open SourcePoC exploitCRITICAL2018-06-05

If the seq_len is greater then CSR_MAX_RSC_LEN, a buffer overflow in __wlan_hdd_cfg80211_add_key() may occur when copying keyRSC in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patc...

CVEs:CVE-2018-5835

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5834

Open SourcePoC exploitHIGH2018-06-05

In __wlan_hdd_cfg80211_vendor_scan(), a buffer overwrite can potentially occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05.

CVEs:CVE-2018-5834

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-6290

Open SourcePoC exploitHIGH2018-06-05

In Android before the 2018-06-05 security patch level, NVIDIA TLK TrustZone contains a possible out of bounds write due to an integer overflow which could lead to local escalation of privilege with no additional execution privileges needed. User intera...

CVEs:CVE-2017-6290

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-6292

Open SourcePoC exploitHIGH2018-06-05

In Android before the 2018-06-05 security patch level, NVIDIA TLZ TrustZone contains a possible out of bounds write due to integer overflow which could lead to local escalation of privilege in the TrustZone with no additional execution privileges neede...

CVEs:CVE-2017-6292

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5854

Open SourcePoC exploitCRITICAL2018-06-05

A stack-based buffer overflow can occur in fastboot from all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.

CVEs:CVE-2018-5854

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5896

Open SourcePoC exploitCRITICAL2018-06-05

In Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, kernel panic may happen due to out-of-bound read, caused by not checking source buffer length against length ...

CVEs:CVE-2018-5896

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-6294

Open SourcePoC exploitHIGH2018-06-05

In Android before the 2018-06-05 security patch level, NVIDIA Tegra X1 TZ contains a possible out of bounds write due to missing bounds check which could lead to escalation of privilege from the kernel to the TZ. User interaction is not needed for expl...

CVEs:CVE-2017-6294

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9340

Open SourcePoC exploitCRITICAL2018-06-05

In ResStringPool::setTo of ResourceTypes.cpp, it's possible for an attacker to control the value of mStringPoolSize to be out of bounds, causing information disclosure.

CVEs:CVE-2018-9340

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9338

Open SourcePoC exploitHIGH2018-06-05

In ResStringPool::setTo of ResourceTypes.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2018-9338

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9371

Open SourcePoC exploitHIGH2018-06-05

In the Mediatek Preloader, there are out of bounds reads and writes due to an exposed interface that allows arbitrary peripheral memory mapping with insufficient blacklisting/whitelisting. This could lead to local elevation of privilege, given physical...

CVEs:CVE-2018-9371

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9339

Open SourcePoC exploitHIGH2018-06-05

In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne...

CVEs:CVE-2018-9339

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9366

Open SourcePoC exploitHIGH2018-06-05

In IMSA_Recv_Thread and VT_IMCB_Thread of ImsaClient.cpp and VideoTelephony.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User int...

CVEs:CVE-2018-9366

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9367

Open SourcePoC exploitHIGH2018-06-05

In FT_ACDK_CCT_V2_OP_ISP_SET_TUNING_PARAS of Meta_CCAP_Para.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...

CVEs:CVE-2018-9367

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9368

Open SourcePoC exploitHIGH2018-06-05

In mtkscoaudio debugfs there is a possible arbitrary kernel memory write due to missing bounds check and weakened SELinux policies. This could lead to local escalation of privilege with system  execution privileges needed. User interaction is not need...

CVEs:CVE-2018-9368

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9372

Open SourcePoC exploitHIGH2018-06-05

In cmd_flash_mmc_sparse_img of dl_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to a local escalation of privilege in the bootloader with no additional execution privileges needed. User interaction i...

CVEs:CVE-2018-9372

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9409

Open SourcePoC exploitHIGH2018-06-05

In HWCSession::SetColorModeById of hwc_session.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2018-9409

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13227

Open SourcePoC exploitMEDIUM2018-06-05

In the autofill service, the package name that is provided by the app process is trusted inappropriately.  This could lead to information disclosure with no additional execution privileges needed.  User interaction is not needed for exploitation.

CVEs:CVE-2017-13227

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9345

Open SourcePoC exploitMEDIUM2018-06-05

In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2018-9345

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9346

Open SourcePoC exploitMEDIUM2018-06-05

In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2018-9346

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9369

Open SourcePoC exploitHIGH2018-06-05

In bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2018-9369

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9344

Open SourcePoC exploitHIGH2018-06-05

In several functions of DescramblerImpl.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2018-9344

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-6149

GoogleCoalition ESS < 30%HIGH2018-06-13

Type confusion in JavaScript in Google Chrome prior to 67.0.3396.87 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

CVEs:CVE-2018-6149

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6148

GoogleCoalition ESS < 30%MEDIUM2018-06-07

Incorrect implementation in Content Security Policy in Google Chrome prior to 67.0.3396.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2018-6148

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-5857

Open SourceCoalition ESS < 30%CRITICAL2018-06-15

In the WCD CPE codec, a Use After Free condition can occur in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.

CVEs:CVE-2018-5857

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5863

Open SourceCoalition ESS < 30%CRITICAL2018-06-15

If userspace provides a too-large WPA RSN IE length in wlan_hdd_cfg80211_set_ie(), a buffer overflow occurs in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.

CVEs:CVE-2018-5863

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5860

Open SourceCoalition ESS < 30%MEDIUM2018-06-15

In the MDSS driver in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel, a data structure may be used without being initialized correctly.

CVEs:CVE-2018-5860

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

SUSE-SU-2018:1751-1

GoogleEPSS <= 49%CRITICAL2018-06-19

Security update for SUSE Manager Server 3.1

Affected products

ProductStatusVendorPackageEcosystem
cobbler affected SUSE:Manager Server 3.1 cobbler
google-gson affected SUSE:Manager Server 3.1 google-gson
patterns-suse-manager affected SUSE:Manager Server 3.1 patterns-suse-manager
prometheus-client-java affected SUSE:Manager Server 3.1 prometheus-client-java
py26-compat-salt affected SUSE:Manager Server 3.1 py26-compat-salt
salt-netapi-client affected SUSE:Manager Server 3.1 salt-netapi-client
spacewalk-backend affected SUSE:Manager Server 3.1 spacewalk-backend
spacewalk-branding affected SUSE:Manager Server 3.1 spacewalk-branding
spacewalk-certs-tools affected SUSE:Manager Server 3.1 spacewalk-certs-tools
spacewalk-java affected SUSE:Manager Server 3.1 spacewalk-java
spacewalk-utils affected SUSE:Manager Server 3.1 spacewalk-utils
spacewalk-web affected SUSE:Manager Server 3.1 spacewalk-web
susemanager affected SUSE:Manager Server 3.1 susemanager
susemanager-docs_en affected SUSE:Manager Server 3.1 susemanager-docs_en
susemanager-frontend-libs affected SUSE:Manager Server 3.1 susemanager-frontend-libs
susemanager-schema affected SUSE:Manager Server 3.1 susemanager-schema
susemanager-sls affected SUSE:Manager Server 3.1 susemanager-sls
susemanager-sync-data affected SUSE:Manager Server 3.1 susemanager-sync-data
susemanager-tftpsync affected SUSE:Manager Server 3.1 susemanager-tftpsync
Upstream advisory

CVE-2016-10677

GoogleEPSS <= 49%2018-06-04

Downloads Resources over HTTP in google-closure-tools-latest

CVEs:CVE-2016-10677

Affected products

ProductStatusVendorPackageEcosystem
google-closure-tools-latest affected npm google-closure-tools-latest
Upstream advisory

CVE-2016-10677

GoogleEPSS <= 49%HIGH2018-06-04

Downloads Resources over HTTP in google-closure-tools-latest

CVEs:CVE-2016-10677

Affected products

ProductStatusVendorPackageEcosystem
google-closure-tools-latest affected npm google-closure-tools-latest
Upstream advisory

CVE-2016-10677

GoogleEPSS <= 49%HIGH2018-06-04

google-closure-tools-latest is a Node.js module wrapper for downloading the latest version of the Google Closure tools google-closure-tools-latest downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to c...

CVEs:CVE-2016-10677

Affected products

ProductStatusVendorPackageEcosystem
google-closure-tools-latest affected google-closure-tools-latest_project
Upstream advisory

DEBIAN-CVE-2018-1002100

Open SourceEPSS <= 49%HIGH2018-06-02

DEBIAN-CVE-2018-1002100

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2018-1002100

Open SourceEPSS <= 49%HIGH2018-06-01

In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.

CVEs:CVE-2018-1002100

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2018-1000187

Open SourceEPSS <= 49%HIGH2018-06-05

A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDecorator.java that results in sensitive variables such as passwords being written to logs.

CVEs:CVE-2018-1000187

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected jenkins
Upstream advisory

CVE-2018-1000187

Open SourceEPSS <= 49%MEDIUM2018-06-05

Exposure of Sensitive Information in Jenkins Kubernetes Plugin

CVEs:CVE-2018-1000187

Affected products

ProductStatusVendorPackageEcosystem
org.csanchez.jenkins.plugins:kubernetes affected Maven org.csanchez.jenkins.plugins:kubernetes
Upstream advisory

CVE-2018-11537

Open SourceEPSS <= 49%CRITICAL2018-06-19

Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whitelist filter via a crafted domain.

CVEs:CVE-2018-11537

Affected products

ProductStatusVendorPackageEcosystem
angular-jwt affected auth0
Upstream advisory

CVE-2018-11537

Open SourceEPSS <= 49%MEDIUM2018-06-19

Auth0 angular-jwt misinterprets allowlist as regex

CVEs:CVE-2018-11537

Affected products

ProductStatusVendorPackageEcosystem
angular-jwt affected npm angular-jwt
Upstream advisory

CVE-2018-11537

Open SourceEPSS <= 49%MEDIUM2018-06-19

Auth0 angular-jwt misinterprets allowlist as regex

CVEs:CVE-2018-11537

Affected products

ProductStatusVendorPackageEcosystem
angular-jwt affected npm angular-jwt
Upstream advisory

CVE-2018-12716

GoogleEPSS <= 49%MEDIUM2018-06-25

The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from reading the scan_results JSON data, which allows remote attackers to determine the physical location of most web browsers by leveragi...

CVEs:CVE-2018-12716

Affected products

ProductStatusVendorPackageEcosystem
chromecast_firmware affected google
home_firmware affected google
Upstream advisory

CVE-2016-10641

Open SourceEPSS <= 49%2018-06-04

Downloads Resources over HTTP in node-bsdiff-android

CVEs:CVE-2016-10641

Affected products

ProductStatusVendorPackageEcosystem
node-bsdiff-android affected npm node-bsdiff-android
Upstream advisory

CVE-2016-10641

Open SourceEPSS <= 49%CRITICAL2018-06-04

node-bsdiff-android downloads resources over HTTP, which leaves it vulnerable to MITM attacks.

CVEs:CVE-2016-10641

Affected products

ProductStatusVendorPackageEcosystem
node-bsdiff-android affected node-bsdiff-android_project
Upstream advisory

CVE-2016-10641

Open SourceEPSS <= 49%HIGH2018-06-04

Downloads Resources over HTTP in node-bsdiff-android

CVEs:CVE-2016-10641

Affected products

ProductStatusVendorPackageEcosystem
node-bsdiff-android affected npm node-bsdiff-android
Upstream advisory

CVE-2018-10405

GoogleEPSS <= 49%CRITICAL2018-06-13

An issue was discovered in Google Santa and molcodesignchecker. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will b...

CVEs:CVE-2018-10405

Affected products

ProductStatusVendorPackageEcosystem
santa affected google
Upstream advisory

CVE-2017-18169

Open SourceEPSS <= 49%HIGH2018-06-15

User process can perform the kernel DOS in ashmem when doing cache maintenance operation in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.

CVEs:CVE-2017-18169

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-12440

GoogleEPSS <= 49%MEDIUM2018-06-15

BoringSSL through 2018-06-14 allows a memory-cache side-channel attack on DSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover a DSA key, the attacker needs access to either the local machine or a different virtual machine ...

CVEs:CVE-2018-12440

Affected products

ProductStatusVendorPackageEcosystem
boringssl affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.