Google Security Advisories · February 2019 — Google Security Advisories
102 advisories 69 CVEs 16 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2019-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 16 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2019-7286

Project ZeroExploitedCISA KEV listed2019-02-08

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges.

CVEs:CVE-2019-7286

Upstream advisory

CVE-2019-7286

GoogleExploitedCISA KEV listedCRITICAL2019-02-08

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges.

CVEs:CVE-2019-7286

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2019-0676

Project ZeroExploitedCISA KEV listed2019-02-13

An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'.

CVEs:CVE-2019-0676

Upstream advisory

CVE-2019-0676

GoogleExploitedCISA KEV listedHIGH2019-02-13

An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclo...

CVEs:CVE-2019-0676

Affected products

ProductStatusVendorPackageEcosystem
internet_explorer affected microsoft
Upstream advisory

CVE-2019-7287

Project ZeroExploitedCISA KEV listed2019-02-08

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2019-7287

Upstream advisory

CVE-2019-7287

GoogleExploitedCISA KEV listedHIGH2019-02-08

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2019-7287

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

SUSE-SU-2019:0495-1

Open SourceExploitedVulnCheck KEV listedCRITICAL2019-02-26

Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork, runc

Affected products

ProductStatusVendorPackageEcosystem
containerd affected SUSE:Linux Enterprise Module for Containers 15 containerd
docker affected SUSE:Linux Enterprise Module for Containers 15 docker
docker-runc affected SUSE:Linux Enterprise Module for Containers 15 docker-runc
golang-github-docker-libnetwork affected SUSE:Linux Enterprise Module for Containers 15 golang-github-docker-libnetwork
Upstream advisory

CVE-2019-5736

Open SourceExploitedVulnCheck KEV listedHIGH2019-02-08

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of...

CVEs:CVE-2019-5736

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
container_development_kit affected redhat
dc\/os affected d2iq
docker affected docker
enterprise_linux affected redhat
enterprise_linux_server affected redhat
fedora affected fedoraproject
hci_management_node affected netapp
kubernetes_engine affected google
kubernetes_engine affected d2iq
leap affected opensuse
lxc affected linuxcontainers
mesos affected apache
onesphere affected hp
openshift affected redhat
runc affected linuxfoundation
service_management_automation affected microfocus
solidfire affected netapp
ubuntu_linux affected canonical
Upstream advisory

DEBIAN-CVE-2019-5782

Open SourceExploitedVulnCheck KEV listedCRITICAL2019-02-19

DEBIAN-CVE-2019-5782

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

openSUSE-SU-2019:0216-1

Open SourceExploitedVulnCheck KEV listedCRITICAL2019-02-19

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 chromium
Upstream advisory

openSUSE-SU-2019:0206-1

Open SourceExploitedVulnCheck KEV listedCRITICAL2019-02-18

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP2 chromium
Upstream advisory

DSA-4395-1

Open SourceExploitedVulnCheck KEV listed2019-02-18

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:9 chromium
Upstream advisory

CVE-2019-1999

Open SourceWeaponized exploitHIGH2019-02-05

In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2019-1999

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
ubuntu_linux affected canonical
Upstream advisory

CVE-2019-2000

Open SourceWeaponized exploitHIGH2019-02-05

In several functions of binder.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: An...

CVEs:CVE-2019-2000

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MGASA-2019-0066

Open SourcePoC exploitCRITICAL2019-02-13

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:6 golang
Upstream advisory

SUSE-SU-2019:0286-1

Open SourcePoC exploitCRITICAL2019-02-07

Security update for docker

Affected products

ProductStatusVendorPackageEcosystem
containerd affected SUSE:Linux Enterprise Module for Containers 15 containerd
docker affected SUSE:Linux Enterprise Module for Containers 15 docker
docker-runc affected SUSE:Linux Enterprise Module for Containers 15 docker-runc
golang-github-docker-libnetwork affected SUSE:Linux Enterprise Module for Containers 15 golang-github-docker-libnetwork
Upstream advisory

DSA-4380-1

Open SourcePoC exploit2019-02-01

golang-1.8 - security update

Affected products

ProductStatusVendorPackageEcosystem
golang-1.8 affected Debian:9 golang-1.8
Upstream advisory

RHSA-2019:0212

Open SourcePoC exploitMEDIUM2019-02-07

Red Hat Security Advisory: CloudForms 4.7 security, bug fix and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
ansible-runner affected Red Hat:cloudforms_managementengine:5.10::el7 ansible-runner
ansible-tower affected Red Hat:cloudforms_managementengine:5.10::el7 ansible-tower
ansible-tower-server affected Red Hat:cloudforms_managementengine:5.10::el7 ansible-tower-server
ansible-tower-setup affected Red Hat:cloudforms_managementengine:5.10::el7 ansible-tower-setup
ansible-tower-ui affected Red Hat:cloudforms_managementengine:5.10::el7 ansible-tower-ui
ansible-tower-venv-ansible affected Red Hat:cloudforms_managementengine:5.10::el7 ansible-tower-venv-ansible
ansible-tower-venv-tower affected Red Hat:cloudforms_managementengine:5.10::el7 ansible-tower-venv-tower
bubblewrap affected Red Hat:cloudforms_managementengine:5.10::el7 bubblewrap
bubblewrap-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 bubblewrap-debuginfo
cfme affected Red Hat:cloudforms_managementengine:5.10::el7 cfme
cfme-amazon-smartstate affected Red Hat:cloudforms_managementengine:5.10::el7 cfme-amazon-smartstate
cfme-appliance affected Red Hat:cloudforms_managementengine:5.10::el7 cfme-appliance
cfme-appliance-common affected Red Hat:cloudforms_managementengine:5.10::el7 cfme-appliance-common
cfme-appliance-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 cfme-appliance-debuginfo
cfme-appliance-tools affected Red Hat:cloudforms_managementengine:5.10::el7 cfme-appliance-tools
cfme-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 cfme-debuginfo
cfme-gemset affected Red Hat:cloudforms_managementengine:5.10::el7 cfme-gemset
cfme-gemset-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 cfme-gemset-debuginfo
dbus-api-service affected Red Hat:cloudforms_managementengine:5.10::el7 dbus-api-service
dumb-init affected Red Hat:cloudforms_managementengine:5.10::el7 dumb-init
dumb-init-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 dumb-init-debuginfo
erlang affected Red Hat:cloudforms_managementengine:5.10::el7 erlang
erlang-asn1 affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-asn1
erlang-common_test affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-common_test
erlang-compiler affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-compiler
erlang-cosEvent affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-cosEvent
erlang-cosEventDomain affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-cosEventDomain
erlang-cosFileTransfer affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-cosFileTransfer
erlang-cosNotification affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-cosNotification
erlang-cosProperty affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-cosProperty
erlang-cosTime affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-cosTime
erlang-cosTransactions affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-cosTransactions
erlang-crypto affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-crypto
erlang-debugger affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-debugger
erlang-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-debuginfo
erlang-dialyzer affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-dialyzer
erlang-diameter affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-diameter
erlang-doc affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-doc
erlang-edoc affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-edoc
erlang-eldap affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-eldap
erlang-erl_docgen affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-erl_docgen
erlang-erl_interface affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-erl_interface
erlang-erts affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-erts
erlang-et affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-et
erlang-eunit affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-eunit
erlang-gs affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-gs
erlang-hipe affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-hipe
erlang-ic affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-ic
erlang-inets affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-inets
erlang-jinterface affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-jinterface
erlang-kernel affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-kernel
erlang-megaco affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-megaco
erlang-mnesia affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-mnesia
erlang-observer affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-observer
erlang-odbc affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-odbc
erlang-orber affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-orber
erlang-os_mon affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-os_mon
erlang-otp_mibs affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-otp_mibs
erlang-parsetools affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-parsetools
erlang-percept affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-percept
erlang-public_key affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-public_key
erlang-reltool affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-reltool
erlang-runtime_tools affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-runtime_tools
erlang-sasl affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-sasl
erlang-snmp affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-snmp
erlang-ssh affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-ssh
erlang-ssl affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-ssl
erlang-stdlib affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-stdlib
erlang-syntax_tools affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-syntax_tools
erlang-tools affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-tools
erlang-typer affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-typer
erlang-wx affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-wx
erlang-xmerl affected Red Hat:cloudforms_managementengine:5.10::el7 erlang-xmerl
google-compute-engine affected Red Hat:cloudforms_managementengine:5.10::el7 google-compute-engine
google-config affected Red Hat:cloudforms_managementengine:5.10::el7 google-config
httpd-configmap-generator affected Red Hat:cloudforms_managementengine:5.10::el7 httpd-configmap-generator
nginx affected Red Hat:cloudforms_managementengine:5.10::el7 nginx
nginx-all-modules affected Red Hat:cloudforms_managementengine:5.10::el7 nginx-all-modules
nginx-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 nginx-debuginfo
nginx-filesystem affected Red Hat:cloudforms_managementengine:5.10::el7 nginx-filesystem
nginx-mod-http-geoip affected Red Hat:cloudforms_managementengine:5.10::el7 nginx-mod-http-geoip
nginx-mod-http-image-filter affected Red Hat:cloudforms_managementengine:5.10::el7 nginx-mod-http-image-filter
nginx-mod-http-perl affected Red Hat:cloudforms_managementengine:5.10::el7 nginx-mod-http-perl
nginx-mod-http-xslt-filter affected Red Hat:cloudforms_managementengine:5.10::el7 nginx-mod-http-xslt-filter
nginx-mod-mail affected Red Hat:cloudforms_managementengine:5.10::el7 nginx-mod-mail
nginx-mod-stream affected Red Hat:cloudforms_managementengine:5.10::el7 nginx-mod-stream
ovirt-ansible-cluster-upgrade affected Red Hat:cloudforms_managementengine:5.10::el7 ovirt-ansible-cluster-upgrade
ovirt-ansible-disaster-recovery affected Red Hat:cloudforms_managementengine:5.10::el7 ovirt-ansible-disaster-recovery
ovirt-ansible-engine-setup affected Red Hat:cloudforms_managementengine:5.10::el7 ovirt-ansible-engine-setup
ovirt-ansible-image-template affected Red Hat:cloudforms_managementengine:5.10::el7 ovirt-ansible-image-template
ovirt-ansible-infra affected Red Hat:cloudforms_managementengine:5.10::el7 ovirt-ansible-infra
ovirt-ansible-manageiq affected Red Hat:cloudforms_managementengine:5.10::el7 ovirt-ansible-manageiq
ovirt-ansible-repositories affected Red Hat:cloudforms_managementengine:5.10::el7 ovirt-ansible-repositories
ovirt-ansible-roles affected Red Hat:cloudforms_managementengine:5.10::el7 ovirt-ansible-roles
ovirt-ansible-shutdown-env affected Red Hat:cloudforms_managementengine:5.10::el7 ovirt-ansible-shutdown-env
ovirt-ansible-v2v-conversion-host affected Red Hat:cloudforms_managementengine:5.10::el7 ovirt-ansible-v2v-conversion-host
ovirt-ansible-vm-infra affected Red Hat:cloudforms_managementengine:5.10::el7 ovirt-ansible-vm-infra
postgresql96 affected Red Hat:cloudforms_managementengine:5.10::el7 postgresql96
postgresql96-contrib affected Red Hat:cloudforms_managementengine:5.10::el7 postgresql96-contrib
postgresql96-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 postgresql96-debuginfo
postgresql96-devel affected Red Hat:cloudforms_managementengine:5.10::el7 postgresql96-devel
postgresql96-docs affected Red Hat:cloudforms_managementengine:5.10::el7 postgresql96-docs
postgresql96-libs affected Red Hat:cloudforms_managementengine:5.10::el7 postgresql96-libs
postgresql96-plperl affected Red Hat:cloudforms_managementengine:5.10::el7 postgresql96-plperl
postgresql96-plpython affected Red Hat:cloudforms_managementengine:5.10::el7 postgresql96-plpython
postgresql96-pltcl affected Red Hat:cloudforms_managementengine:5.10::el7 postgresql96-pltcl
postgresql96-server affected Red Hat:cloudforms_managementengine:5.10::el7 postgresql96-server
postgresql96-test affected Red Hat:cloudforms_managementengine:5.10::el7 postgresql96-test
prince affected Red Hat:cloudforms_managementengine:5.10::el7 prince
pyOpenSSL affected Red Hat:cloudforms_managementengine:5.10::el7 pyOpenSSL
pyOpenSSL-doc affected Red Hat:cloudforms_managementengine:5.10::el7 pyOpenSSL-doc
python2-bambou affected Red Hat:cloudforms_managementengine:5.10::el7 python2-bambou
python2-crypto affected Red Hat:cloudforms_managementengine:5.10::el7 python2-crypto
python2-daemon affected Red Hat:cloudforms_managementengine:5.10::el7 python2-daemon
python2-future affected Red Hat:cloudforms_managementengine:5.10::el7 python2-future
python2-lockfile affected Red Hat:cloudforms_managementengine:5.10::el7 python2-lockfile
python2-pbr affected Red Hat:cloudforms_managementengine:5.10::el7 python2-pbr
python2-pexpect affected Red Hat:cloudforms_managementengine:5.10::el7 python2-pexpect
python2-psutil affected Red Hat:cloudforms_managementengine:5.10::el7 python2-psutil
python2-ptyprocess affected Red Hat:cloudforms_managementengine:5.10::el7 python2-ptyprocess
python2-pylxca affected Red Hat:cloudforms_managementengine:5.10::el7 python2-pylxca
python2-pyOpenSSL affected Red Hat:cloudforms_managementengine:5.10::el7 python2-pyOpenSSL
python2-requests affected Red Hat:cloudforms_managementengine:5.10::el7 python2-requests
python2-requests-toolbelt affected Red Hat:cloudforms_managementengine:5.10::el7 python2-requests-toolbelt
python2-tabulate affected Red Hat:cloudforms_managementengine:5.10::el7 python2-tabulate
python2-urllib3 affected Red Hat:cloudforms_managementengine:5.10::el7 python2-urllib3
python2-vspk affected Red Hat:cloudforms_managementengine:5.10::el7 python2-vspk
python-bambou affected Red Hat:cloudforms_managementengine:5.10::el7 python-bambou
python-colorama affected Red Hat:cloudforms_managementengine:5.10::el7 python-colorama
python-crypto affected Red Hat:cloudforms_managementengine:5.10::el7 python-crypto
python-crypto-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 python-crypto-debuginfo
python-daemon affected Red Hat:cloudforms_managementengine:5.10::el7 python-daemon
python-funcsigs affected Red Hat:cloudforms_managementengine:5.10::el7 python-funcsigs
python-funcsigs-doc affected Red Hat:cloudforms_managementengine:5.10::el7 python-funcsigs-doc
python-future affected Red Hat:cloudforms_managementengine:5.10::el7 python-future
python-lockfile affected Red Hat:cloudforms_managementengine:5.10::el7 python-lockfile
python-meld3 affected Red Hat:cloudforms_managementengine:5.10::el7 python-meld3
python-meld3-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 python-meld3-debuginfo
python-mock affected Red Hat:cloudforms_managementengine:5.10::el7 python-mock
python-pbr affected Red Hat:cloudforms_managementengine:5.10::el7 python-pbr
python-pexpect affected Red Hat:cloudforms_managementengine:5.10::el7 python-pexpect
python-psutil affected Red Hat:cloudforms_managementengine:5.10::el7 python-psutil
python-psutil-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 python-psutil-debuginfo
python-ptyprocess affected Red Hat:cloudforms_managementengine:5.10::el7 python-ptyprocess
python-pylxca affected Red Hat:cloudforms_managementengine:5.10::el7 python-pylxca
python-pysocks affected Red Hat:cloudforms_managementengine:5.10::el7 python-pysocks
python-qpid-proton affected Red Hat:cloudforms_managementengine:5.10::el7 python-qpid-proton
python-qpid-proton-docs affected Red Hat:cloudforms_managementengine:5.10::el7 python-qpid-proton-docs
python-requests affected Red Hat:cloudforms_managementengine:5.10::el7 python-requests
python-requests-toolbelt affected Red Hat:cloudforms_managementengine:5.10::el7 python-requests-toolbelt
python-tabulate affected Red Hat:cloudforms_managementengine:5.10::el7 python-tabulate
python-urllib3 affected Red Hat:cloudforms_managementengine:5.10::el7 python-urllib3
python-vspk affected Red Hat:cloudforms_managementengine:5.10::el7 python-vspk
qpid-proton affected Red Hat:cloudforms_managementengine:5.10::el7 qpid-proton
qpid-proton-c affected Red Hat:cloudforms_managementengine:5.10::el7 qpid-proton-c
qpid-proton-c-devel affected Red Hat:cloudforms_managementengine:5.10::el7 qpid-proton-c-devel
qpid-proton-c-docs affected Red Hat:cloudforms_managementengine:5.10::el7 qpid-proton-c-docs
qpid-proton-cpp affected Red Hat:cloudforms_managementengine:5.10::el7 qpid-proton-cpp
qpid-proton-cpp-devel affected Red Hat:cloudforms_managementengine:5.10::el7 qpid-proton-cpp-devel
qpid-proton-cpp-docs affected Red Hat:cloudforms_managementengine:5.10::el7 qpid-proton-cpp-docs
qpid-proton-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 qpid-proton-debuginfo
rabbitmq-server affected Red Hat:cloudforms_managementengine:5.10::el7 rabbitmq-server
rh-postgresql95-postgresql-pglogical affected Red Hat:cloudforms_managementengine:5.10::el7 rh-postgresql95-postgresql-pglogical
rh-postgresql95-postgresql-pglogical-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 rh-postgresql95-postgresql-pglogical-debuginfo
rh-postgresql95-repmgr affected Red Hat:cloudforms_managementengine:5.10::el7 rh-postgresql95-repmgr
rh-postgresql95-repmgr-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 rh-postgresql95-repmgr-debuginfo
ruby affected Red Hat:cloudforms_managementengine:5.10::el7 ruby
ruby-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 ruby-debuginfo
ruby-devel affected Red Hat:cloudforms_managementengine:5.10::el7 ruby-devel
ruby-doc affected Red Hat:cloudforms_managementengine:5.10::el7 ruby-doc
rubygem-bcrypt affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-bcrypt
rubygem-bcrypt-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-bcrypt-debuginfo
rubygem-bcrypt-doc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-bcrypt-doc
rubygem-bigdecimal affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-bigdecimal
rubygem-did_you_mean affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-did_you_mean
rubygem-ffi affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-ffi
rubygem-ffi-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-ffi-debuginfo
rubygem-ffi-doc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-ffi-doc
rubygem-hamlit affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-hamlit
rubygem-hamlit-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-hamlit-debuginfo
rubygem-hamlit-doc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-hamlit-doc
rubygem-http_parser.rb affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-http_parser.rb
rubygem-http_parser.rb-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-http_parser.rb-debuginfo
rubygem-http_parser.rb-doc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-http_parser.rb-doc
rubygem-io-console affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-io-console
rubygem-json affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-json
rubygem-json-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-json-debuginfo
rubygem-json-doc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-json-doc
rubygem-linux_block_device affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-linux_block_device
rubygem-linux_block_device-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-linux_block_device-debuginfo
rubygem-linux_block_device-doc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-linux_block_device-doc
rubygem-memory_buffer affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-memory_buffer
rubygem-memory_buffer-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-memory_buffer-debuginfo
rubygem-memory_buffer-doc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-memory_buffer-doc
rubygem-minitest affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-minitest
rubygem-net-telnet affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-net-telnet
rubygem-nio4r affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-nio4r
rubygem-nio4r-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-nio4r-debuginfo
rubygem-nio4r-doc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-nio4r-doc
rubygem-nokogiri affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-nokogiri
rubygem-nokogiri-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-nokogiri-debuginfo
rubygem-nokogiri-doc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-nokogiri-doc
rubygem-openssl affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-openssl
rubygem-ovirt-engine-sdk4 affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-ovirt-engine-sdk4
rubygem-ovirt-engine-sdk4-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-ovirt-engine-sdk4-debuginfo
rubygem-ovirt-engine-sdk4-doc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-ovirt-engine-sdk4-doc
rubygem-pg affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-pg
rubygem-pg-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-pg-debuginfo
rubygem-pg-doc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-pg-doc
rubygem-power_assert affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-power_assert
rubygem-psych affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-psych
rubygem-puma affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-puma
rubygem-puma-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-puma-debuginfo
rubygem-puma-doc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-puma-doc
rubygem-qpid_proton affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-qpid_proton
rubygem-qpid_proton-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-qpid_proton-debuginfo
rubygem-qpid_proton-doc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-qpid_proton-doc
rubygem-rake affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-rake
rubygem-rdoc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-rdoc
rubygem-redhat_access_cfme affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-redhat_access_cfme
rubygem-redhat_access_cfme-doc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-redhat_access_cfme-doc
rubygem-redhat_access_lib affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-redhat_access_lib
rubygem-rugged affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-rugged
rubygem-rugged-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-rugged-debuginfo
rubygem-rugged-doc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-rugged-doc
rubygems affected Red Hat:cloudforms_managementengine:5.10::el7 rubygems
rubygems-devel affected Red Hat:cloudforms_managementengine:5.10::el7 rubygems-devel
rubygem-sqlite3 affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-sqlite3
rubygem-sqlite3-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-sqlite3-debuginfo
rubygem-sqlite3-doc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-sqlite3-doc
rubygem-test-unit affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-test-unit
rubygem-unf_ext affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-unf_ext
rubygem-unf_ext-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-unf_ext-debuginfo
rubygem-unf_ext-doc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-unf_ext-doc
rubygem-websocket-driver affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-websocket-driver
rubygem-websocket-driver-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-websocket-driver-debuginfo
rubygem-websocket-driver-doc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-websocket-driver-doc
rubygem-xmlrpc affected Red Hat:cloudforms_managementengine:5.10::el7 rubygem-xmlrpc
ruby-irb affected Red Hat:cloudforms_managementengine:5.10::el7 ruby-irb
ruby-libs affected Red Hat:cloudforms_managementengine:5.10::el7 ruby-libs
smem affected Red Hat:cloudforms_managementengine:5.10::el7 smem
supervisor affected Red Hat:cloudforms_managementengine:5.10::el7 supervisor
wmi affected Red Hat:cloudforms_managementengine:5.10::el7 wmi
wmi-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 wmi-debuginfo
wxBase3 affected Red Hat:cloudforms_managementengine:5.10::el7 wxBase3
wxGTK3 affected Red Hat:cloudforms_managementengine:5.10::el7 wxGTK3
wxGTK3-debuginfo affected Red Hat:cloudforms_managementengine:5.10::el7 wxGTK3-debuginfo
wxGTK3-devel affected Red Hat:cloudforms_managementengine:5.10::el7 wxGTK3-devel
wxGTK3-docs affected Red Hat:cloudforms_managementengine:5.10::el7 wxGTK3-docs
wxGTK3-gl affected Red Hat:cloudforms_managementengine:5.10::el7 wxGTK3-gl
wxGTK3-media affected Red Hat:cloudforms_managementengine:5.10::el7 wxGTK3-media
wxGTK3-xmldocs affected Red Hat:cloudforms_managementengine:5.10::el7 wxGTK3-xmldocs
Upstream advisory

CVE-2019-5784

GooglePoC exploitMEDIUM2019-02-18

Incorrect handling of deferred code in V8 in Google Chrome prior to 72.0.3626.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5784

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2019-5763

Open SourceCoalition ESS 30-63%HIGH2019-02-19

DEBIAN-CVE-2019-5763

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DSA-4379-1

Open SourceEPSS 49-79%2019-02-01

golang-1.7 - security update

Affected products

ProductStatusVendorPackageEcosystem
golang-1.7 affected Debian:9 golang-1.7
Upstream advisory

DLA-1664-1

Open SourceCoalition ESS < 30%2019-02-06

golang - security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Debian:8 golang
Upstream advisory

DEBIAN-CVE-2019-5770

Open SourceCoalition ESS < 30%HIGH2019-02-19

DEBIAN-CVE-2019-5770

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5756

Open SourceCoalition ESS < 30%CRITICAL2019-02-19

DEBIAN-CVE-2019-5756

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5762

Open SourceCoalition ESS < 30%CRITICAL2019-02-19

DEBIAN-CVE-2019-5762

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5779

Open SourceCoalition ESS < 30%MEDIUM2019-02-19

DEBIAN-CVE-2019-5779

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-1991

Open SourceCoalition ESS < 30%HIGH2019-02-05

In btif_dm_data_copy of btif_core.cc, there is a possible out of bounds write due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Andro...

CVEs:CVE-2019-1991

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-1988

Open SourceCoalition ESS < 30%HIGH2019-02-05

In sample6 of SkSwizzler.cpp, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution in system_server with no additional execution privileges needed. User interaction is needed for exploitatio...

CVEs:CVE-2019-1988

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2019-5755

Open SourceCoalition ESS < 30%HIGH2019-02-19

DEBIAN-CVE-2019-5755

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5773

Open SourceCoalition ESS < 30%MEDIUM2019-02-19

DEBIAN-CVE-2019-5773

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5757

Open SourceCoalition ESS < 30%HIGH2019-02-19

DEBIAN-CVE-2019-5757

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5772

Open SourceCoalition ESS < 30%HIGH2019-02-19

DEBIAN-CVE-2019-5772

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5758

Open SourceCoalition ESS < 30%HIGH2019-02-19

DEBIAN-CVE-2019-5758

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5766

Open SourceCoalition ESS < 30%MEDIUM2019-02-19

DEBIAN-CVE-2019-5766

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5769

Open SourceCoalition ESS < 30%HIGH2019-02-19

DEBIAN-CVE-2019-5769

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5774

Open SourceCoalition ESS < 30%CRITICAL2019-02-19

DEBIAN-CVE-2019-5774

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-1986

Open SourceCoalition ESS < 30%HIGH2019-02-05

In SkSwizzler::onSetSampleX of SkSwizzler.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege in system_server with no additional execution privileges needed. User interaction is...

CVEs:CVE-2019-1986

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2019-5781

Open SourceCoalition ESS < 30%MEDIUM2019-02-19

DEBIAN-CVE-2019-5781

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5775

Open SourceCoalition ESS < 30%MEDIUM2019-02-19

DEBIAN-CVE-2019-5775

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5776

Open SourceCoalition ESS < 30%MEDIUM2019-02-19

DEBIAN-CVE-2019-5776

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5777

Open SourceCoalition ESS < 30%MEDIUM2019-02-19

DEBIAN-CVE-2019-5777

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5759

Open SourceCoalition ESS < 30%CRITICAL2019-02-19

DEBIAN-CVE-2019-5759

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5760

Open SourceCoalition ESS < 30%HIGH2019-02-19

DEBIAN-CVE-2019-5760

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5764

Open SourceCoalition ESS < 30%HIGH2019-02-19

DEBIAN-CVE-2019-5764

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-5785

GoogleCoalition ESS < 30%MEDIUM2019-02-13

Incorrect convexity calculations in Skia in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

CVEs:CVE-2019-5785

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-1992

Open SourceCoalition ESS < 30%HIGH2019-02-05

In bta_hl_sdp_query_results of bta_hl_main.cc, there is a possible use-after-free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: An...

CVEs:CVE-2019-1992

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2019-5767

Open SourceCoalition ESS < 30%MEDIUM2019-02-19

DEBIAN-CVE-2019-5767

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-1987

Open SourceCoalition ESS < 30%HIGH2019-02-05

In onSetSampleX of SkSwizzler.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: And...

CVEs:CVE-2019-1987

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2019-5768

Open SourceCoalition ESS < 30%MEDIUM2019-02-19

DEBIAN-CVE-2019-5768

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5783

Open SourceCoalition ESS < 30%HIGH2019-02-19

DEBIAN-CVE-2019-5783

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-5783

GoogleCoalition ESS < 30%HIGH2019-02-19

Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform a Dangling Markup Injection attack via a crafted HTML page.

CVEs:CVE-2019-5783

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2019-5778

Open SourceCoalition ESS < 30%MEDIUM2019-02-19

DEBIAN-CVE-2019-5778

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-1994

Open SourceCoalition ESS < 30%HIGH2019-02-05

In refresh of DevelopmentTiles.java, there is the possibility of leaving development settings accessible due to an insecure default value. This could lead to unwanted access to development settings, with no additional execution privileges needed. User ...

CVEs:CVE-2019-1994

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-1997

Open SourceCoalition ESS < 30%HIGH2019-02-05

In random_get_bytes of random.c, there is a possible degradation of randomness due to an insecure default value. This could lead to local information disclosure via an insecure wireless connection with no additional execution privileges needed. User in...

CVEs:CVE-2019-1997

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-6267

Open SourceCoalition ESS < 30%HIGH2019-02-05

NVIDIA Tegra OpenMax driver (libnvomx) contains a vulnerability in which the software does not validate or incorrectly validates input that can affect the control flow or data flow of a program, which may lead to denial of service or escalation of priv...

CVEs:CVE-2018-6267

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-6268

Open SourceCoalition ESS < 30%HIGH2019-02-05

NVIDIA Tegra library contains a vulnerability in libnvmmlite_video.so, where referencing memory after it has been freed may lead to denial of service or possible escalation of privileges. Android ID: A-80433161.

CVEs:CVE-2018-6268

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-6271

Open SourceCoalition ESS < 30%HIGH2019-02-05

NVIDIA Tegra OpenMax driver (libnvomx) contains a vulnerability in which the software delivers extra data with the buffer and does not properly validated the extra data, which may lead to denial of service or escalation of privileges. Android ID: A-801...

CVEs:CVE-2018-6271

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2019-5754

Open SourceCoalition ESS < 30%MEDIUM2019-02-19

DEBIAN-CVE-2019-5754

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2019-5765

Open SourceCoalition ESS < 30%MEDIUM2019-02-19

DEBIAN-CVE-2019-5765

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-1996

Open SourceCoalition ESS < 30%MEDIUM2019-02-05

In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not ne...

CVEs:CVE-2019-1996

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2019-5780

Open SourceCoalition ESS < 30%HIGH2019-02-19

DEBIAN-CVE-2019-5780

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-1993

Open SourceCoalition ESS < 30%HIGH2019-02-05

In register_app of btif_hd.cc, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: ...

CVEs:CVE-2019-1993

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2001

Open SourceCoalition ESS < 30%MEDIUM2019-02-05

The permissions on /proc/iomem were world-readable. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID:...

CVEs:CVE-2019-2001

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-1995

Open SourceCoalition ESS < 30%MEDIUM2019-02-05

In ComposeActivityEmail of ComposeActivityEmail.java, there is a possible way to silently attach files to an email due to a confused deputy. This could lead to local information disclosure, sending files accessible to AOSP Mail to a remote email recipi...

CVEs:CVE-2019-1995

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-1998

Open SourceCoalition ESS < 30%HIGH2019-02-05

In event_handler of keymaster_app.c, there is possible resource exhaustion due to a table being lost on reboot. This could lead to local denial of service that is not fixed by a factory reset, with no additional execution privileges needed. User intera...

CVEs:CVE-2019-1998

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-69r7-cw26-px6h

GoogleEPSS <= 49%HIGH2019-02-18

Downloads Resources over HTTP in google-closure-tools-latest

Affected products

ProductStatusVendorPackageEcosystem
google-closure-tools-latest affected npm google-closure-tools-latest
Upstream advisory

GHSA-69r7-cw26-px6h

GoogleEPSS <= 49%HIGH2019-02-18

Downloads Resources over HTTP in google-closure-tools-latest

Affected products

ProductStatusVendorPackageEcosystem
google-closure-tools-latest affected npm google-closure-tools-latest
Upstream advisory

GHSA-97gv-3p2c-xw7j

Open SourceEPSS <= 49%CRITICAL2019-02-18

Denial of Service and Content Injection in i18n-node-angular

Affected products

ProductStatusVendorPackageEcosystem
i18n-node-angular affected npm i18n-node-angular
Upstream advisory

GHSA-97gv-3p2c-xw7j

Open SourceEPSS <= 49%CRITICAL2019-02-18

Denial of Service and Content Injection in i18n-node-angular

Affected products

ProductStatusVendorPackageEcosystem
i18n-node-angular affected npm i18n-node-angular
Upstream advisory

CVE-2018-13893

Open SourceEPSS <= 49%HIGH2019-02-11

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Out of bound mask range access caused by using possible old value of msg mask table count while copying masks to userspace.

CVEs:CVE-2018-13893

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-12010

Open SourceEPSS <= 49%CRITICAL2019-02-11

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Absence of length sanity check may lead to possible stack overflow resulting in memory corruption in trustzone region.

CVEs:CVE-2018-12010

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-12006

Open SourceEPSS <= 49%MEDIUM2019-02-11

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Users with no extra privileges can potentially access leaked data due to uninitialized padding present in display function.

CVEs:CVE-2018-12006

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-12011

Open SourceEPSS <= 49%MEDIUM2019-02-11

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Uninitialized data for socket address leads to information exposure.

CVEs:CVE-2018-12011

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DSA-4395-2

Open SourceAll remaining2019-02-26

chromium - regression update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:9 chromium
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.