Google Security Advisories · April 2019 — Google Security Advisories
141 advisories 76 CVEs 6 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2019-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 6 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2019-0803

Project ZeroExploitedCISA KEV listed2019-04-09

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0859.

CVEs:CVE-2019-0803

Upstream advisory

CVE-2019-0803

GoogleExploitedCISA KEV listedCRITICAL2019-04-09

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0859.

CVEs:CVE-2019-0803

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1703 affected microsoft
windows_10_1709 affected microsoft
windows_10_1803 affected microsoft
windows_10_1809 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_1709 affected microsoft
windows_server_1803 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
Upstream advisory

CVE-2019-0859

GoogleExploitedCISA KEV listedCRITICAL2019-04-09

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0803.

CVEs:CVE-2019-0859

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1703 affected microsoft
windows_10_1709 affected microsoft
windows_10_1803 affected microsoft
windows_10_1809 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_1709 affected microsoft
windows_server_1803 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
Upstream advisory

CVE-2019-0859

Project ZeroExploitedCISA KEV listed2019-04-09

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0803.

CVEs:CVE-2019-0859

Upstream advisory

CVE-2019-11244

Open SourceActive exploitation (sightings)MEDIUM2019-04-22

Kubernetes Unsafe Cacheing

CVEs:CVE-2019-11244

Affected products

ProductStatusVendorPackageEcosystem
client-go affected k8s.io k8s.io/client-go
Upstream advisory

CVE-2019-11244

Open SourceActive exploitation (sightings)MEDIUM2019-04-22

In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different...

CVEs:CVE-2019-11244

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
openshift_container_platform affected redhat
trident affected netapp
Upstream advisory

CVE-2019-11244

Open SourceActive exploitation (sightings)MEDIUM2019-04-22

Kubernetes Unsafe Cacheing

CVEs:CVE-2019-11244

Affected products

ProductStatusVendorPackageEcosystem
client-go affected k8s.io k8s.io/client-go
Upstream advisory

CVE-2019-1002101

Open SourcePoC exploitMEDIUM2019-04-01

The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside the container, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar b...

CVEs:CVE-2019-1002101

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
openshift_container_platform affected redhat
Upstream advisory

DEBIAN-CVE-2019-1002100

Open SourcePoC exploitCRITICAL2019-04-01

DEBIAN-CVE-2019-1002100

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2019-1002100

Open SourcePoC exploitCRITICAL2019-04-01

In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type...

CVEs:CVE-2019-1002100

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
openshift_container_platform affected redhat
Upstream advisory

DEBIAN-CVE-2019-9946

Open SourcePoC exploitHIGH2019-04-02

DEBIAN-CVE-2019-9946

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2019-9946

Open SourcePoC exploitHIGH2019-04-02

Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables ...

CVEs:CVE-2019-9946

Affected products

ProductStatusVendorPackageEcosystem
cloud_insights affected netapp
kubernetes affected kubernetes
portmap affected cncf
Upstream advisory

CVE-2019-5822

GooglePoC exploitHIGH2019-04-24

Inappropriate implementation in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

CVEs:CVE-2019-5822

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2019-11243

Open SourcePoC exploitHIGH2019-04-22

Kubernetes did not effectively clear service account credentials

CVEs:CVE-2019-11243

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2019-11243

Open SourcePoC exploitHIGH2019-04-22

In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions, rest.Anonym...

CVEs:CVE-2019-11243

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
trident affected netapp
Upstream advisory

DLA-1749-1

Open SourceCoalition ESS < 30%2019-04-03

golang - security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Debian:8 golang
Upstream advisory

CVE-2019-5817

GoogleCoalition ESS < 30%CRITICAL2019-04-24

Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5817

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2019-5808

GoogleCoalition ESS < 30%CRITICAL2019-04-24

Use after free in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5808

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2019-5816

GoogleCoalition ESS < 30%HIGH2019-04-24

Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote attacker to potentially persist an exploited process via a crafted HTML page.

CVEs:CVE-2019-5816

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2019-5818

GoogleCoalition ESS < 30%HIGH2019-04-24

Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.

CVEs:CVE-2019-5818

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2019-5809

GoogleCoalition ESS < 30%CRITICAL2019-04-24

Use after free in file chooser in Google Chrome prior to 74.0.3729.108 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page.

CVEs:CVE-2019-5809

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2019-5805

GoogleCoalition ESS < 30%CRITICAL2019-04-24

Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2019-5805

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2019-5820

GoogleCoalition ESS < 30%CRITICAL2019-04-24

Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2019-5820

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2019-5821

GoogleCoalition ESS < 30%CRITICAL2019-04-24

Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2019-5821

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2019-5807

GoogleCoalition ESS < 30%HIGH2019-04-24

Object lifetime issue in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5807

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2019-5812

GoogleCoalition ESS < 30%MEDIUM2019-04-24

Inadequate security UI in iOS UI in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVEs:CVE-2019-5812

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2019-5813

GoogleCoalition ESS < 30%CRITICAL2019-04-24

Use after free in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5813

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2019-5806

GoogleCoalition ESS < 30%CRITICAL2019-04-24

Integer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5806

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2019-5811

GoogleCoalition ESS < 30%HIGH2019-04-24

Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

CVEs:CVE-2019-5811

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2019-2027

Open SourceCoalition ESS < 30%HIGH2019-04-02

In floor0_inverse1 of floor0.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: And...

CVEs:CVE-2019-2027

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2028

Open SourceCoalition ESS < 30%HIGH2019-04-02

In numerous hand-crafted functions in libmpeg2, NEON registers are not preserved. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-...

CVEs:CVE-2019-2028

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-5810

GoogleCoalition ESS < 30%HIGH2019-04-24

Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2019-5810

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2019-5823

GoogleCoalition ESS < 30%CRITICAL2019-04-24

Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2019-5823

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2019-5814

GoogleCoalition ESS < 30%CRITICAL2019-04-24

Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2019-5814

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2019-2030

Open SourceCoalition ESS < 30%CRITICAL2019-04-02

In removeInterfaceAddress of NetworkController.cpp, there is a possible use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions...

CVEs:CVE-2019-2030

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2037

Open SourceCoalition ESS < 30%HIGH2019-04-02

In l2cu_send_peer_config_rej of l2c_utils.cc, there is a possible out-of-bound read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2019-2037

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-frxx-2m33-6wcr

Open SourceCoalition ESS < 30%CRITICAL2019-04-24

Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-frxx-2m33-6wcr

Open SourceCoalition ESS < 30%CRITICAL2019-04-24

Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2019-208

Open SourceCoalition ESS < 30%CRITICAL2019-04-23

PYSEC-2019-208

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2019-226

Open SourceCoalition ESS < 30%CRITICAL2019-04-23

PYSEC-2019-226

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2019-233

Open SourceCoalition ESS < 30%CRITICAL2019-04-23

PYSEC-2019-233

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2018-8825

Open SourceCoalition ESS < 30%CRITICAL2019-04-23

Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow

CVEs:CVE-2018-8825

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2018-8825

Open SourceCoalition ESS < 30%HIGH2019-04-23

PYSEC-2019-233

CVEs:CVE-2018-8825

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2018-8825

Open SourceCoalition ESS < 30%CRITICAL2019-04-23

Google TensorFlow 1.7 and below is affected by: Buffer Overflow. The impact is: execute arbitrary code (local).

CVEs:CVE-2018-8825

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2019-2029

Open SourceCoalition ESS < 30%HIGH2019-04-02

In btm_proc_smp_cback of tm_ble.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. V...

CVEs:CVE-2019-2029

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-mw6v-crh8-8533

Open SourceCoalition ESS < 30%CRITICAL2019-04-30

Integer Overflow or Wraparound in Google TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mw6v-crh8-8533

Open SourceCoalition ESS < 30%CRITICAL2019-04-30

Integer Overflow or Wraparound in Google TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2019-205

Open SourceCoalition ESS < 30%CRITICAL2019-04-24

PYSEC-2019-205

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2019-223

Open SourceCoalition ESS < 30%CRITICAL2019-04-24

PYSEC-2019-223

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2019-230

Open SourceCoalition ESS < 30%CRITICAL2019-04-24

PYSEC-2019-230

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2018-7575

Open SourceCoalition ESS < 30%CRITICAL2019-04-24

PYSEC-2019-230

CVEs:CVE-2018-7575

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2018-7575

Open SourceCoalition ESS < 30%CRITICAL2019-04-24

Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent.

CVEs:CVE-2018-7575

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2018-7575

Open SourceCoalition ESS < 30%CRITICAL2019-04-24

Integer Overflow or Wraparound in Google TensorFlow

CVEs:CVE-2018-7575

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qx2v-j445-g354

Open SourceCoalition ESS < 30%HIGH2019-04-30

Improper Input Validation in Google TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qx2v-j445-g354

Open SourceCoalition ESS < 30%HIGH2019-04-30

Improper Input Validation in Google TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2019-207

Open SourceCoalition ESS < 30%HIGH2019-04-24

PYSEC-2019-207

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2019-225

Open SourceCoalition ESS < 30%HIGH2019-04-24

PYSEC-2019-225

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2019-232

Open SourceCoalition ESS < 30%HIGH2019-04-24

PYSEC-2019-232

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2018-7577

Open SourceCoalition ESS < 30%HIGH2019-04-24

Improper Input Validation in Google TensorFlow

CVEs:CVE-2018-7577

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2018-7577

Open SourceCoalition ESS < 30%HIGH2019-04-24

Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google TensorFlow before 1.7.1, could result in a crash or read from other parts of process memory.

CVEs:CVE-2018-7577

Affected products

ProductStatusVendorPackageEcosystem
snappy affected google
tensorflow affected google
Upstream advisory

CVE-2018-7577

Open SourceCoalition ESS < 30%HIGH2019-04-24

PYSEC-2019-232

CVEs:CVE-2018-7577

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2019-2034

Open SourceCoalition ESS < 30%HIGH2019-04-02

In rw_i93_sm_read_ndef of rw_i93.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the NFC process with no additional execution privileges needed. User interaction is needed for ...

CVEs:CVE-2019-2034

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-mfg7-x5m7-6p8w

Open SourceCoalition ESS < 30%HIGH2019-04-30

NULL Pointer Dereference in Google TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mfg7-x5m7-6p8w

Open SourceCoalition ESS < 30%HIGH2019-04-30

NULL Pointer Dereference in Google TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2019-210

Open SourceCoalition ESS < 30%HIGH2019-04-24

PYSEC-2019-210

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2019-228

Open SourceCoalition ESS < 30%HIGH2019-04-24

PYSEC-2019-228

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2019-235

Open SourceCoalition ESS < 30%HIGH2019-04-24

PYSEC-2019-235

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2019-9635

Open SourceCoalition ESS < 30%HIGH2019-04-24

NULL pointer dereference in Google TensorFlow before 1.12.2 could cause a denial of service via an invalid GIF file.

CVEs:CVE-2019-9635

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2019-9635

Open SourceCoalition ESS < 30%HIGH2019-04-24

PYSEC-2019-235

CVEs:CVE-2019-9635

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2019-9635

Open SourceCoalition ESS < 30%HIGH2019-04-24

NULL Pointer Dereference in Google TensorFlow

CVEs:CVE-2019-9635

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-jfq2-rj7f-9gvf

Open SourceCoalition ESS < 30%HIGH2019-04-24

Null pointer dereference in TensorFlow leads to exploitation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-jfq2-rj7f-9gvf

Open SourceCoalition ESS < 30%HIGH2019-04-24

Null pointer dereference in TensorFlow leads to exploitation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2019-206

Open SourceCoalition ESS < 30%2019-04-23

PYSEC-2019-206

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2019-224

Open SourceCoalition ESS < 30%2019-04-23

PYSEC-2019-224

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2019-231

Open SourceCoalition ESS < 30%2019-04-23

PYSEC-2019-231

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2018-7576

Open SourceCoalition ESS < 30%HIGH2019-04-23

PYSEC-2019-231

CVEs:CVE-2018-7576

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2018-7576

Open SourceCoalition ESS < 30%MEDIUM2019-04-23

Google TensorFlow 1.6.x and earlier is affected by: Null Pointer Dereference. The type of exploitation is: context-dependent.

CVEs:CVE-2018-7576

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2018-7576

Open SourceCoalition ESS < 30%HIGH2019-04-23

Null pointer dereference in TensorFlow leads to exploitation

CVEs:CVE-2018-7576

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2019-2035

Open SourceCoalition ESS < 30%HIGH2019-04-02

In rw_i93_sm_update_ndef of rw_i93.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. P...

CVEs:CVE-2019-2035

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2038

Open SourceCoalition ESS < 30%MEDIUM2019-04-02

In rw_i93_process_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. P...

CVEs:CVE-2019-2038

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-5819

GoogleCoalition ESS < 30%HIGH2019-04-24

Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allowed a local attacker to execute arbitrary code via a crafted string copied to clipboard.

CVEs:CVE-2019-5819

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2019-2041

Open SourceCoalition ESS < 30%HIGH2019-04-02

In the configuration of NFC modules on certain devices, there is a possible failure to distinguish individual devices due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. Use...

CVEs:CVE-2019-2041

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2031

Open SourceCoalition ESS < 30%HIGH2019-04-02

In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2019-2031

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2033

Open SourceCoalition ESS < 30%HIGH2019-04-02

In create_hdr of dnssd_clientstub.c, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Andro...

CVEs:CVE-2019-2033

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2039

Open SourceCoalition ESS < 30%MEDIUM2019-04-02

In rw_i93_sm_detect_ndef of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Pro...

CVEs:CVE-2019-2039

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2032

Open SourceCoalition ESS < 30%HIGH2019-04-02

In SetScanResponseData of ble_advertiser_hci_interface.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne...

CVEs:CVE-2019-2032

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2040

Open SourceCoalition ESS < 30%MEDIUM2019-04-02

In rw_i93_process_ext_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitatio...

CVEs:CVE-2019-2040

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2026

Open SourceCoalition ESS < 30%HIGH2019-04-02

In updateAssistMenuItems of Editor.java, there is a possible escape from the Setup Wizard due to a missing permission check. This could lead to local escalation of privilege and FRP bypass with no additional execution privileges needed. User interactio...

CVEs:CVE-2019-2026

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-7574

GoogleCoalition ESS < 30%2019-04-24

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-7576, CVE-2018-21233. Reason: this candidate was intended for one issue, but the description and references inadvertently combined multiple issues. Notes: All CVE users should cons...

CVEs:CVE-2018-7574

Upstream advisory

DEBIAN-CVE-2017-18367

Open SourceEPSS <= 49%HIGH2019-04-24

DEBIAN-CVE-2017-18367

Affected products

ProductStatusVendorPackageEcosystem
golang-github-seccomp-libseccomp-golang affected Debian:14 golang-github-seccomp-libseccomp-golang
golang-github-seccomp-libseccomp-golang affected Debian:13 golang-github-seccomp-libseccomp-golang
golang-github-seccomp-libseccomp-golang affected Debian:11 golang-github-seccomp-libseccomp-golang
golang-github-seccomp-libseccomp-golang affected Debian:12 golang-github-seccomp-libseccomp-golang
Upstream advisory

CVE-2017-18367

Open SourceEPSS <= 49%MEDIUM2019-04-24

Improper Input Validation in libseccomp-golang

CVEs:CVE-2017-18367

Affected products

ProductStatusVendorPackageEcosystem
seccomp/libseccomp-golang affected github.com github.com/seccomp/libseccomp-golang
Upstream advisory

CVE-2017-18367

Open SourceEPSS <= 49%HIGH2019-04-24

Improper Input Validation in libseccomp-golang

CVEs:CVE-2017-18367

Affected products

ProductStatusVendorPackageEcosystem
seccomp/libseccomp-golang affected github.com github.com/seccomp/libseccomp-golang
Upstream advisory

CVE-2017-18367

Open SourceEPSS <= 49%HIGH2019-04-24

libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A process running under a restrictive seccomp filter that specified multiple syscall arguments could bypass intended access restrictions ...

CVEs:CVE-2017-18367

Affected products

ProductStatusVendorPackageEcosystem
libseccomp-golang affected libseccomp-golang_project
Upstream advisory

GHSA-q492-f7gr-27rp

Open SourceEPSS <= 49%CRITICAL2019-04-30

Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-q492-f7gr-27rp

Open SourceEPSS <= 49%CRITICAL2019-04-30

Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2019-204

Open SourceEPSS <= 49%CRITICAL2019-04-24

PYSEC-2019-204

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2019-222

Open SourceEPSS <= 49%CRITICAL2019-04-24

PYSEC-2019-222

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2019-229

Open SourceEPSS <= 49%CRITICAL2019-04-24

PYSEC-2019-229

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2018-10055

Open SourceEPSS <= 49%HIGH2019-04-24

PYSEC-2019-229

CVEs:CVE-2018-10055

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2018-10055

Open SourceEPSS <= 49%CRITICAL2019-04-24

Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow

CVEs:CVE-2018-10055

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2018-10055

Open SourceEPSS <= 49%CRITICAL2019-04-24

Invalid memory access and/or a heap buffer overflow in the TensorFlow XLA compiler in Google TensorFlow before 1.7.1 could cause a crash or read from other parts of process memory via a crafted configuration file.

CVEs:CVE-2018-10055

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.