Advisories
GoogleExploitedCISA KEV listedHIGH2018-12-06
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
CVEs:CVE-2018-15982
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
| flash_player |
affected |
adobe |
— |
— |
| flash_player_installer |
affected |
adobe |
— |
— |
GoogleExploitedCISA KEV listedCRITICAL2018-12-06
CVEs:CVE-2018-15982
Project ZeroExploitedCISA KEV listed2018-12-06
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
CVEs:CVE-2018-15982
Open SourceExploitedCISA KEV listedCRITICAL2018-12-15
Security update for Chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 12 SP2 |
chromium |
— |
Open SourceExploitedCISA KEV listedCRITICAL2018-12-11
DEBIAN-CVE-2018-17480
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceExploitedCISA KEV listed2018-12-07
chromium-browser - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser |
affected |
Debian:9 |
chromium-browser |
— |
GoogleExploitedCISA KEV listedHIGH2018-12-05
CVEs:CVE-2018-17480
GoogleExploitedCISA KEV listedCRITICAL2018-12-05
Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVEs:CVE-2018-17480
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleExploitedCISA KEV listedHIGH2018-12-20
CVEs:CVE-2018-8653
Project ZeroExploitedCISA KEV listed2018-12-20
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8643.
CVEs:CVE-2018-8653
GoogleExploitedCISA KEV listedCRITICAL2018-12-20
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet E...
CVEs:CVE-2018-8653
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| internet_explorer |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2018-12-12
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
CVEs:CVE-2018-8611
GoogleExploitedCISA KEV listedHIGH2018-12-12
CVEs:CVE-2018-8611
GoogleExploitedCISA KEV listedCRITICAL2018-12-12
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server...
CVEs:CVE-2018-8611
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| windows_10_1607 |
affected |
microsoft |
— |
— |
| windows_10_1703 |
affected |
microsoft |
— |
— |
| windows_10_1709 |
affected |
microsoft |
— |
— |
| windows_10_1803 |
affected |
microsoft |
— |
— |
| windows_10_1809 |
affected |
microsoft |
— |
— |
| windows_7 |
affected |
microsoft |
— |
— |
| windows_8.1 |
affected |
microsoft |
— |
— |
| windows_rt_8.1 |
affected |
microsoft |
— |
— |
| windows_server_2008 |
affected |
microsoft |
— |
— |
| windows_server_2012 |
affected |
microsoft |
— |
— |
| windows_server_2016 |
affected |
microsoft |
— |
— |
| windows_server_2019 |
affected |
microsoft |
— |
— |
Open SourceWeaponized exploitCRITICAL2018-12-05
DEBIAN-CVE-2018-1002105
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
Debian:11 |
kubernetes |
— |
| kubernetes |
affected |
Debian:12 |
kubernetes |
— |
| kubernetes |
affected |
Debian:13 |
kubernetes |
— |
| kubernetes |
affected |
Debian:14 |
kubernetes |
— |
Open SourceWeaponized exploitCRITICAL2018-12-05
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server t...
CVEs:CVE-2018-1002105
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
kubernetes |
— |
— |
| openshift_container_platform |
affected |
redhat |
— |
— |
| trident |
affected |
netapp |
— |
— |
Open SourceWeaponized exploitCRITICAL2018-12-05
Privilege Escalation in Kubernetes
CVEs:CVE-2018-1002105
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes/kubernetes |
affected |
github.com |
github.com/kubernetes/kubernetes |
— |
Open SourceWeaponized exploitCRITICAL2018-12-05
Privilege Escalation in Kubernetes
CVEs:CVE-2018-1002105
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes/kubernetes |
affected |
github.com |
github.com/kubernetes/kubernetes |
— |
Open SourceActive exploitation (sightings)CRITICAL2018-12-21
DEBIAN-CVE-2018-20346
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| sqlite3 |
affected |
Debian:11 |
sqlite3 |
— |
| sqlite3 |
affected |
Debian:12 |
sqlite3 |
— |
| sqlite3 |
affected |
Debian:13 |
sqlite3 |
— |
| sqlite3 |
affected |
Debian:14 |
sqlite3 |
— |
Open SourceActive exploitation (sightings)CRITICAL2018-12-11
DEBIAN-CVE-2018-18335
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)CRITICAL2018-12-05
Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2018-18335
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleActive exploitation (sightings)HIGH2018-12-05
CVEs:CVE-2018-18335
Open SourceActive exploitation (sightings)CRITICAL2018-12-11
DEBIAN-CVE-2018-18356
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| firefox-esr |
affected |
Debian:11 |
firefox-esr |
— |
| firefox-esr |
affected |
Debian:12 |
firefox-esr |
— |
| firefox-esr |
affected |
Debian:13 |
firefox-esr |
— |
| firefox-esr |
affected |
Debian:14 |
firefox-esr |
— |
| thunderbird |
affected |
Debian:11 |
thunderbird |
— |
| thunderbird |
affected |
Debian:12 |
thunderbird |
— |
| thunderbird |
affected |
Debian:13 |
thunderbird |
— |
| thunderbird |
affected |
Debian:14 |
thunderbird |
— |
GoogleActive exploitation (sightings)CRITICAL2018-12-05
An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2018-18356
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_server_aus |
affected |
redhat |
— |
— |
| enterprise_linux_server_eus |
affected |
redhat |
— |
— |
| enterprise_linux_server_tus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| leap |
affected |
opensuse |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleActive exploitation (sightings)HIGH2018-12-05
CVEs:CVE-2018-18356
Open SourceActive exploitation (sightings)CRITICAL2018-12-11
DEBIAN-CVE-2018-18342
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)CRITICAL2018-12-05
Execution of user supplied Javascript during object deserialization can update object length leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a craft...
CVEs:CVE-2018-18342
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleActive exploitation (sightings)HIGH2018-12-05
CVEs:CVE-2018-18342
Open SourceActive exploitation (sightings)MEDIUM2018-12-11
DEBIAN-CVE-2018-18351
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)MEDIUM2018-12-05
CVEs:CVE-2018-18351
GoogleActive exploitation (sightings)MEDIUM2018-12-05
Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass SameSite cookie policy via a crafted HTML page.
CVEs:CVE-2018-18351
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2018-12-11
DEBIAN-CVE-2018-18337
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)HIGH2018-12-05
CVEs:CVE-2018-18337
GoogleActive exploitation (sightings)CRITICAL2018-12-05
Incorrect handling of stylesheets leading to a use after free in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2018-18337
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| linux_desktop |
affected |
redhat |
— |
— |
| linux_server |
affected |
redhat |
— |
— |
| linux_workstation |
affected |
redhat |
— |
— |
Open SourceActive exploitation (sightings)HIGH2018-12-11
DEBIAN-CVE-2018-17481
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)HIGH2018-12-05
Incorrect object lifecycle handling in PDFium in Google Chrome prior to 71.0.3578.98 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVEs:CVE-2018-17481
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| linux_desktop |
affected |
redhat |
— |
— |
| linux_server |
affected |
redhat |
— |
— |
| linux_workstation |
affected |
redhat |
— |
— |
GoogleActive exploitation (sightings)HIGH2018-12-05
CVEs:CVE-2018-17481
Open SourceActive exploitation (sightings)HIGH2018-12-11
DEBIAN-CVE-2018-18336
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)HIGH2018-12-05
Incorrect object lifecycle in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVEs:CVE-2018-18336
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| linux_desktop |
affected |
redhat |
— |
— |
| linux_server |
affected |
redhat |
— |
— |
| linux_workstation |
affected |
redhat |
— |
— |
GoogleActive exploitation (sightings)HIGH2018-12-05
CVEs:CVE-2018-18336
Open SourceActive exploitation (sightings)MEDIUM2018-12-11
DEBIAN-CVE-2018-18344
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)MEDIUM2018-12-05
CVEs:CVE-2018-18344
GoogleActive exploitation (sightings)MEDIUM2018-12-05
Inappropriate allowance of the setDownloadBehavior devtools protocol feature in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote attacker with control of an installed extension to access files on the local file system via a crafted Ch...
CVEs:CVE-2018-18344
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2018-12-11
DEBIAN-CVE-2018-18341
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)CRITICAL2018-12-05
An integer overflow leading to a heap buffer overflow in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2018-18341
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| linux_desktop |
affected |
redhat |
— |
— |
| linux_server |
affected |
redhat |
— |
— |
| linux_workstation |
affected |
redhat |
— |
— |
GoogleActive exploitation (sightings)HIGH2018-12-05
CVEs:CVE-2018-18341
Open SourceActive exploitation (sightings)MEDIUM2018-12-11
DEBIAN-CVE-2018-18345
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)MEDIUM2018-12-05
CVEs:CVE-2018-18345
GoogleActive exploitation (sightings)MEDIUM2018-12-05
Incorrect handling of blob URLS in Site Isolation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker who had compromised the renderer process to bypass site isolation protections via a crafted HTML page.
CVEs:CVE-2018-18345
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
Open SourceActive exploitation (sightings)HIGH2018-12-11
DEBIAN-CVE-2018-18354
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)HIGH2018-12-11
DEBIAN-CVE-2018-18338
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)HIGH2018-12-11
DEBIAN-CVE-2018-18339
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)HIGH2018-12-05
Incorrect, thread-unsafe use of SkImage in Canvas in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2018-18338
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| linux_desktop |
affected |
redhat |
— |
— |
| linux_server |
affected |
redhat |
— |
— |
| linux_workstation |
affected |
redhat |
— |
— |
GoogleActive exploitation (sightings)HIGH2018-12-05
CVEs:CVE-2018-18338
GoogleActive exploitation (sightings)HIGH2018-12-05
Incorrect object lifecycle in WebAudio in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2018-18339
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| linux_desktop |
affected |
redhat |
— |
— |
| linux_server |
affected |
redhat |
— |
— |
| linux_workstation |
affected |
redhat |
— |
— |
GoogleActive exploitation (sightings)HIGH2018-12-05
CVEs:CVE-2018-18339
GoogleActive exploitation (sightings)HIGH2018-12-05
Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launch external programs via a crafted HTML page.
CVEs:CVE-2018-18354
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleActive exploitation (sightings)HIGH2018-12-05
CVEs:CVE-2018-18354
Open SourceActive exploitation (sightings)HIGH2018-12-11
DEBIAN-CVE-2018-18359
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)HIGH2018-12-05
Incorrect handling of Reflect.construct in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVEs:CVE-2018-18359
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| linux_desktop |
affected |
redhat |
— |
— |
| linux_server |
affected |
redhat |
— |
— |
| linux_workstation |
affected |
redhat |
— |
— |
GoogleActive exploitation (sightings)HIGH2018-12-05
CVEs:CVE-2018-18359
Open SourceActive exploitation (sightings)MEDIUM2018-12-11
DEBIAN-CVE-2018-18352
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)MEDIUM2018-12-05
CVEs:CVE-2018-18352
GoogleActive exploitation (sightings)MEDIUM2018-12-05
Service works could inappropriately gain access to cross origin audio in Media in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass same origin policy for audio content via a crafted HTML page.
CVEs:CVE-2018-18352
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
Open SourceActive exploitation (sightings)HIGH2018-12-11
DEBIAN-CVE-2018-18340
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)HIGH2018-12-11
DEBIAN-CVE-2018-18347
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)HIGH2018-12-05
Incorrect object lifecycle in MediaRecorder in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2018-18340
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| linux_desktop |
affected |
redhat |
— |
— |
| linux_server |
affected |
redhat |
— |
— |
| linux_workstation |
affected |
redhat |
— |
— |
GoogleActive exploitation (sightings)HIGH2018-12-05
CVEs:CVE-2018-18340
GoogleActive exploitation (sightings)HIGH2018-12-05
CVEs:CVE-2018-18347
GoogleActive exploitation (sightings)HIGH2018-12-05
Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to trick a user into executing javascript in an arbitrary origin via a crafted HTML page.
CVEs:CVE-2018-18347
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| linux_desktop |
affected |
redhat |
— |
— |
| linux_server |
affected |
redhat |
— |
— |
| linux_workstation |
affected |
redhat |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2018-12-11
DEBIAN-CVE-2018-18343
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)HIGH2018-12-05
CVEs:CVE-2018-18343
GoogleActive exploitation (sightings)CRITICAL2018-12-05
Incorrect handing of paths leading to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2018-18343
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| linux_desktop |
affected |
redhat |
— |
— |
| linux_server |
affected |
redhat |
— |
— |
| linux_workstation |
affected |
redhat |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2018-12-11
DEBIAN-CVE-2018-18350
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)CRITICAL2018-12-05
Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVEs:CVE-2018-18350
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2018-12-05
CVEs:CVE-2018-18350
Open SourceActive exploitation (sightings)MEDIUM2018-12-11
DEBIAN-CVE-2018-18353
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)MEDIUM2018-12-05
CVEs:CVE-2018-18353
GoogleActive exploitation (sightings)MEDIUM2018-12-05
Failure to dismiss http auth dialogs on navigation in Network Authentication in Google Chrome on Android prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of an auto dialog via a crafted HTML page.
CVEs:CVE-2018-18353
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2018-12-11
DEBIAN-CVE-2018-18346
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)MEDIUM2018-12-05
CVEs:CVE-2018-18346
GoogleActive exploitation (sightings)MEDIUM2018-12-05
Incorrect handling of alert box display in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to present confusing browser UI via a crafted HTML page.
CVEs:CVE-2018-18346
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| linux_desktop |
affected |
redhat |
— |
— |
| linux_server |
affected |
redhat |
— |
— |
| linux_workstation |
affected |
redhat |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2018-12-11
DEBIAN-CVE-2018-18357
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
Open SourceActive exploitation (sightings)MEDIUM2018-12-11
DEBIAN-CVE-2018-18355
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)MEDIUM2018-12-05
CVEs:CVE-2018-18355
GoogleActive exploitation (sightings)MEDIUM2018-12-05
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
CVEs:CVE-2018-18355
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2018-12-05
CVEs:CVE-2018-18357
GoogleActive exploitation (sightings)MEDIUM2018-12-05
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
CVEs:CVE-2018-18357
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2018-12-11
DEBIAN-CVE-2018-18348
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)MEDIUM2018-12-05
CVEs:CVE-2018-18348
GoogleActive exploitation (sightings)MEDIUM2018-12-05
Incorrect handling of bidirectional domain names with RTL characters in Omnibox in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
CVEs:CVE-2018-18348
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2018-12-11
DEBIAN-CVE-2018-18349
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)MEDIUM2018-12-05
CVEs:CVE-2018-18349
GoogleActive exploitation (sightings)CRITICAL2018-12-05
Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 71.0.3578.80 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrom...
CVEs:CVE-2018-18349
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2018-12-17
rendertron XSS vulnerability
CVEs:CVE-2017-18352
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| rendertron |
affected |
npm |
rendertron |
— |
GoogleActive exploitation (sightings)CRITICAL2018-12-17
Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs.
CVEs:CVE-2017-18352
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| rendertron |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2018-12-17
rendertron XSS vulnerability
CVEs:CVE-2017-18352
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| rendertron |
affected |
npm |
rendertron |
— |
Open SourceActive exploitation (sightings)CRITICAL2018-12-11
DEBIAN-CVE-2018-18358
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)MEDIUM2018-12-05
CVEs:CVE-2018-18358
GoogleActive exploitation (sightings)CRITICAL2018-12-05
Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.
CVEs:CVE-2018-18358
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
Open SourcePoC exploitCRITICAL2018-12-28
Security update for containerd, docker and go
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| containerd |
affected |
SUSE:Linux Enterprise Module for Containers 15 |
containerd |
— |
| docker |
affected |
SUSE:Linux Enterprise Module for Containers 15 |
docker |
— |
| docker-runc |
affected |
SUSE:Linux Enterprise Module for Containers 15 |
docker-runc |
— |
| golang-github-docker-libnetwork |
affected |
SUSE:Linux Enterprise Module for Containers 15 |
golang-github-docker-libnetwork |
— |
Open SourcePoC exploitHIGH2018-12-14
CVE-2018-16875 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
GooglePoC exploitHIGH2018-12-14
CVEs:CVE-2018-16875
GooglePoC exploitHIGH2018-12-14
The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers ac...
CVEs:CVE-2018-16875
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GooglePoC exploitHIGH2018-12-17
rendertron LFI vulnerability
CVEs:CVE-2017-18354
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| rendertron |
affected |
npm |
rendertron |
— |
GooglePoC exploitHIGH2018-12-17
rendertron LFI vulnerability
CVEs:CVE-2017-18354
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| rendertron |
affected |
npm |
rendertron |
— |
GooglePoC exploitHIGH2018-12-17
Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusion (LFI) bug where arbitrary files can be read by a remote attacker.
CVEs:CVE-2017-18354
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| rendertron |
affected |
google |
— |
— |
GooglePoC exploitHIGH2018-12-17
rendertron can remotely shut down Chrome instance
CVEs:CVE-2017-18353
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| rendertron |
affected |
npm |
rendertron |
— |
GooglePoC exploitHIGH2018-12-17
rendertron can remotely shut down Chrome instance
CVEs:CVE-2017-18353
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| rendertron |
affected |
npm |
rendertron |
— |
GooglePoC exploitHIGH2018-12-17
Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all users. Visiting this route with a GET request allows any unauthorized remote attacker to disable the core service of the applicat...
CVEs:CVE-2017-18353
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| rendertron |
affected |
google |
— |
— |
GooglePoC exploitHIGH2018-12-17
Rendertron discloses absolute paths of files
CVEs:CVE-2017-18355
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| rendertron |
affected |
npm |
rendertron |
— |
GooglePoC exploitHIGH2018-12-17
Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the "_where" attribute of package.json files.
CVEs:CVE-2017-18355
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| rendertron |
affected |
google |
— |
— |
GooglePoC exploitHIGH2018-12-17
Rendertron discloses absolute paths of files
CVEs:CVE-2017-18355
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| rendertron |
affected |
npm |
rendertron |
— |
GooglePoC exploitHIGH2018-12-04
CVEs:CVE-2018-9568
Open SourcePoC exploitHIGH2018-12-04
In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android....
CVEs:CVE-2018-9568
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_server_aus |
affected |
redhat |
— |
— |
| enterprise_linux_server_eus |
affected |
redhat |
— |
— |
| enterprise_linux_server_tus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleEPSS 49-79%HIGH2018-12-14
CVEs:CVE-2018-16873
GoogleEPSS 49-79%HIGH2018-12-14
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go package, or a package that imports it directly or indirectly. Specifically, i...
CVEs:CVE-2018-16873
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| go |
affected |
golang |
— |
— |
| leap |
affected |
opensuse |
— |
— |
| linux_enterprise_server |
affected |
suse |
— |
— |
Open SourceEPSS 49-79%CRITICAL2018-12-29
Security update for go
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
SUSE:Package Hub 15 |
go |
— |
| go1.10 |
affected |
SUSE:Package Hub 15 |
go1.10 |
— |
| golang-packaging |
affected |
SUSE:Package Hub 15 |
golang-packaging |
— |
Open SourceCoalition ESS < 30%HIGH2018-12-04
In ParsePayloadHeader of payload_metadata.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2018-9556
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2018-12-04
CVEs:CVE-2018-9556
Open SourceCoalition ESS < 30%HIGH2018-12-04
In CAacDecoder_Init of aacdecoder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product:...
CVEs:CVE-2018-9550
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-12-04
CVEs:CVE-2018-9550
Open SourceCoalition ESS < 30%HIGH2018-12-04
In readBytes of xltdecwbxml.c, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product:...
CVEs:CVE-2018-9565
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-12-04
CVEs:CVE-2018-9565
Open SourceCoalition ESS < 30%HIGH2018-12-07
In impd_init_drc_decode_post_config of impd_drc_gain_decoder.c there is a possible out-of-bound write due to incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for...
CVEs:CVE-2018-9569
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-12-07
CVEs:CVE-2018-9569
GoogleCoalition ESS < 30%HIGH2018-12-07
CVEs:CVE-2018-9571
Open SourceCoalition ESS < 30%HIGH2018-12-07
In impd_parse_loud_eq_instructions of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for...
CVEs:CVE-2018-9571
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2018-12-07
In impd_drc_parse_coeff of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitati...
CVEs:CVE-2018-9572
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-12-07
CVEs:CVE-2018-9572
GoogleCoalition ESS < 30%HIGH2018-12-04
CVEs:CVE-2018-9549
Open SourceCoalition ESS < 30%HIGH2018-12-04
In lppTransposer of lpp_tran.cpp there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android...
CVEs:CVE-2018-9549
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-12-04
CVEs:CVE-2018-9551
Open SourceCoalition ESS < 30%HIGH2018-12-04
In CAacDecoder_Init of aacdecoder.cpp, there is a possible out-of-bound write due to a missing bounds check. This could lead to remote code execution in the media server with no additional execution privileges needed. User interaction is needed for exp...
CVEs:CVE-2018-9551
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-12-04
CVEs:CVE-2018-9553
Open SourceCoalition ESS < 30%HIGH2018-12-04
In MasteringMetadata::Parse of mkvparser.cc there is a possible double free due to an insecure default value. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product:...
CVEs:CVE-2018-9553
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-12-04
CVEs:CVE-2018-9562
Open SourceCoalition ESS < 30%HIGH2018-12-04
In bta_ag_do_disc of bta_ag_sdp.cc, there is a possible out-of-bound read due to an incorrect parameter size. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2018-9562
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-12-07
CVEs:CVE-2018-9570
Open SourceCoalition ESS < 30%HIGH2018-12-07
In impd_parse_drc_ext_v1 of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitat...
CVEs:CVE-2018-9570
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2018-12-07
In impd_parse_filt_block of impd_drc_dynamic_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploita...
CVEs:CVE-2018-9573
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-12-07
CVEs:CVE-2018-9573
GoogleCoalition ESS < 30%HIGH2018-12-07
CVEs:CVE-2018-9574
Open SourceCoalition ESS < 30%HIGH2018-12-07
In impd_parse_split_drc_characteristic of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed...
CVEs:CVE-2018-9574
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-12-07
CVEs:CVE-2018-9575
Open SourceCoalition ESS < 30%HIGH2018-12-07
In impd_parse_dwnmix_instructions of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for ...
CVEs:CVE-2018-9575
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2018-12-07
In impd_parse_parametric_drc_instructions of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is nee...
CVEs:CVE-2018-9576
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-12-07
CVEs:CVE-2018-9576
Open SourceCoalition ESS < 30%HIGH2018-12-07
In impd_parametric_drc_parse_gain_set_params of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is ...
CVEs:CVE-2018-9577
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-12-07
CVEs:CVE-2018-9577
GoogleCoalition ESS < 30%CRITICAL2018-12-07
CVEs:CVE-2018-9578
Open SourceCoalition ESS < 30%CRITICAL2018-12-07
In ixheaacd_adts_crc_start_reg of ixheaacd_adts_crc_check.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is no...
CVEs:CVE-2018-9578
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2018-12-04
In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2018-9555
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-12-04
CVEs:CVE-2018-9555
GoogleCoalition ESS < 30%MEDIUM2018-12-04
CVEs:CVE-2018-9552
Open SourceCoalition ESS < 30%HIGH2018-12-04
In ihevcd_sao_shift_ctb of ihevcd_sao.c there is a possible out of bounds write due to missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product:...
CVEs:CVE-2018-9552
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2018-12-04
CVEs:CVE-2018-9566
Open SourceCoalition ESS < 30%MEDIUM2018-12-04
In process_service_search_rsp of sdp_discovery.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure when connecting to a malicious Bluetooth device with no additional execution privil...
CVEs:CVE-2018-9566
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-12-04
CVEs:CVE-2018-9557
Open SourceCoalition ESS < 30%HIGH2018-12-04
In really_install_package of install.cpp, there is a possible free of arbitrary memory due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2018-9557
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2018-12-04
In rw_t2t_handle_tlv_detect of rw_t2t_ndef.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC kernel with no additional execution privileges needed. User interaction is...
CVEs:CVE-2018-9558
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-12-04
CVEs:CVE-2018-9558
GoogleCoalition ESS < 30%HIGH2018-12-04
CVEs:CVE-2018-9538
Open SourceCoalition ESS < 30%HIGH2018-12-04
In V4L2SliceVideoDecodeAccelerator::Dequeue of v4l2_slice_video_decode_accelerator.cc, there is a possible out of bounds read of a function pointer due to an incorrect bounds check. This could lead to local escalation of privilege with no additional ex...
CVEs:CVE-2018-9538
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-12-04
CVEs:CVE-2018-9547
Open SourceCoalition ESS < 30%HIGH2018-12-04
In unflatten of GraphicBuffer.cpp, there is a possible bad fd close due to improper input validation. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not needed f...
CVEs:CVE-2018-9547
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-12-04
CVEs:CVE-2018-9559
Open SourceCoalition ESS < 30%HIGH2018-12-04
In persist_set_key and other functions of cryptfs.cpp, there is a possible out-of-bounds write due to an uncaught error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...
CVEs:CVE-2018-9559
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2018-12-04
In dumpExtractors of IMediaExtractor.cp, there is a possible disclosure of recently accessed media files due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is no...
CVEs:CVE-2018-9554
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2018-12-04
CVEs:CVE-2018-9554
Open SourceCoalition ESS < 30%HIGH2018-12-04
In HID_DevAddRecord of hidd_api.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege in the Bluetooth service with User execution privileges needed. User interaction is not needed f...
CVEs:CVE-2018-9560
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-12-04
CVEs:CVE-2018-9560
Open SourceCoalition ESS < 30%MEDIUM2018-12-04
In multiple functions of ContentProvider.java, there is a possible permission bypass due to a missing URI validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2018-9548
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2018-12-04
CVEs:CVE-2018-9548
Open SourceCoalition ESS < 30%HIGH2018-12-04
On Pixel devices there is a bug causing verified boot to show the same certificate fingerprint despite using different signing keys. This may lead to local escalation of privilege if people are relying on those fingerprints to determine what version of...
CVEs:CVE-2018-9567
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-12-04
CVEs:CVE-2018-9567
GoogleEPSS <= 49%CRITICAL2018-12-14
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the import path of a malicious Go package which contains curly braces (both '{' and '}' characters). Specifically, it is only vul...
CVEs:CVE-2018-16874
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| go |
affected |
golang |
— |
— |
| leap |
affected |
opensuse |
— |
— |
| linux_enterprise_server |
affected |
suse |
— |
— |
GoogleEPSS <= 49%HIGH2018-12-14
CVEs:CVE-2018-16874
Open SourceEPSS <= 49%CRITICAL2018-12-05
In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up volume mounts on Windows nodes, which could lead to command line argument injection.
CVEs:CVE-2018-1002101
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
kubernetes |
— |
— |
Open SourceEPSS <= 49%MEDIUM2018-12-05
Kubernetes Arbitrary Command Injection
CVEs:CVE-2018-1002101
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
GoogleEPSS <= 49%CRITICAL2018-12-05
In Minikube versions 0.3.0-0.29.0, minikube exposes the Kubernetes Dashboard listening on the VM IP at port 30000. In VM environments where the IP is easy to predict, the attacker can use DNS rebinding to indirectly make requests to the Kubernetes Dash...
CVEs:CVE-2018-1002103
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| minikube |
affected |
kubernetes |
— |
— |
Open SourceEPSS <= 49%HIGH2018-12-05
Minikube RCE via DNS Rebinding
CVEs:CVE-2018-1002103
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| minikube |
affected |
k8s.io |
k8s.io/minikube |
— |
Open SourceEPSS <= 49%HIGH2018-12-17
Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which allows attackers to cause a denial of service ("physical address not valid" panic) via a crafted application.
CVEs:CVE-2018-20168
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| gvisor |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2018-12-17
CVEs:CVE-2018-20168
Open SourceEPSS <= 49%CRITICAL2018-12-04
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, A use after free condition can occur in the SPS driver which can lead to error in kernel.
CVEs:CVE-2018-11960
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2018-12-04
CVEs:CVE-2018-11960
GoogleEPSS <= 49%HIGH2018-12-04
CVEs:CVE-2018-11961
Open SourceEPSS <= 49%HIGH2018-12-04
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possibility of accessing out of bound vector index When updating some GNSS configurations.
CVEs:CVE-2018-11961
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2018-12-04
CVEs:CVE-2018-11963
Open SourceEPSS <= 49%HIGH2018-12-04
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Buffer overread may occur due to non-null terminated strings while processing vsprintf in camera jpeg driver.
CVEs:CVE-2018-11963
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2018-12-04
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, if there is an unlikely memory alloc failure for the secure pool in boot, it can result in wrong pointer access causing kernel panic.
CVEs:CVE-2018-11987
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2018-12-04
CVEs:CVE-2018-11987
GoogleEPSS <= 49%HIGH2018-12-20
CVEs:CVE-2018-11985
Open SourceEPSS <= 49%CRITICAL2018-12-20
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, When allocating heap using user supplied size, Possible heap overflow vulnerability due to integer overflow in roundup to native pointer.
CVEs:CVE-2018-11985
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%CRITICAL2018-12-20
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, There is no synchronization between msm_vb2 buffer operations which can lead to use after free.
CVEs:CVE-2017-9704
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2018-12-20
CVEs:CVE-2017-9704
GoogleEPSS <= 49%HIGH2018-12-20
CVEs:CVE-2018-11983
Open SourceEPSS <= 49%HIGH2018-12-20
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Error in kernel observed while accessing freed mask pointers after reallocating memory for mask table.
CVEs:CVE-2018-11983
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2018-12-20
CVEs:CVE-2018-11984
Open SourceEPSS <= 49%CRITICAL2018-12-20
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, A use after free condition and an out-of-bounds access can occur in the DIAG driver.
CVEs:CVE-2018-11984
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2018-12-20
CVEs:CVE-2018-11986
Open SourceEPSS <= 49%CRITICAL2018-12-20
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possible buffer overflow in TX and RX FIFOs of microcontroller in camera subsystem used to exchange commands and messages between Micro FW and CP...
CVEs:CVE-2018-11986
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2018-12-20
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Un-trusted pointer de-reference issue by accessing a variable which is already freed.
CVEs:CVE-2018-11988
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2018-12-20
CVEs:CVE-2018-11988
Open SourceEPSS <= 49%HIGH2018-12-20
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Exposing the hashed content in /etc/passwd may lead to security issue.
CVEs:CVE-2018-11964
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2018-12-20
CVEs:CVE-2018-11964
Open SourceEPSS <= 49%HIGH2018-12-20
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Anyone can execute proptrigger.sh which will lead to change in properties.
CVEs:CVE-2018-11965
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2018-12-20
CVEs:CVE-2018-11965