Advisories
Project ZeroExploitedCISA KEV listed2019-04-09
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0859.
CVEs:CVE-2019-0803
GoogleExploitedCISA KEV listedHIGH2019-04-09
CVEs:CVE-2019-0803
GoogleExploitedCISA KEV listedCRITICAL2019-04-09
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0859.
CVEs:CVE-2019-0803
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| windows_10_1507 |
affected |
microsoft |
— |
— |
| windows_10_1607 |
affected |
microsoft |
— |
— |
| windows_10_1703 |
affected |
microsoft |
— |
— |
| windows_10_1709 |
affected |
microsoft |
— |
— |
| windows_10_1803 |
affected |
microsoft |
— |
— |
| windows_10_1809 |
affected |
microsoft |
— |
— |
| windows_7 |
affected |
microsoft |
— |
— |
| windows_8.1 |
affected |
microsoft |
— |
— |
| windows_rt_8.1 |
affected |
microsoft |
— |
— |
| windows_server_1709 |
affected |
microsoft |
— |
— |
| windows_server_1803 |
affected |
microsoft |
— |
— |
| windows_server_2008 |
affected |
microsoft |
— |
— |
| windows_server_2012 |
affected |
microsoft |
— |
— |
| windows_server_2016 |
affected |
microsoft |
— |
— |
| windows_server_2019 |
affected |
microsoft |
— |
— |
GoogleExploitedCISA KEV listedHIGH2019-04-09
CVEs:CVE-2019-0859
GoogleExploitedCISA KEV listedCRITICAL2019-04-09
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0803.
CVEs:CVE-2019-0859
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| windows_10_1507 |
affected |
microsoft |
— |
— |
| windows_10_1607 |
affected |
microsoft |
— |
— |
| windows_10_1703 |
affected |
microsoft |
— |
— |
| windows_10_1709 |
affected |
microsoft |
— |
— |
| windows_10_1803 |
affected |
microsoft |
— |
— |
| windows_10_1809 |
affected |
microsoft |
— |
— |
| windows_7 |
affected |
microsoft |
— |
— |
| windows_8.1 |
affected |
microsoft |
— |
— |
| windows_rt_8.1 |
affected |
microsoft |
— |
— |
| windows_server_1709 |
affected |
microsoft |
— |
— |
| windows_server_1803 |
affected |
microsoft |
— |
— |
| windows_server_2008 |
affected |
microsoft |
— |
— |
| windows_server_2012 |
affected |
microsoft |
— |
— |
| windows_server_2016 |
affected |
microsoft |
— |
— |
| windows_server_2019 |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2019-04-09
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0803.
CVEs:CVE-2019-0859
Open SourceActive exploitation (sightings)MEDIUM2019-04-22
Kubernetes Unsafe Cacheing
CVEs:CVE-2019-11244
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| client-go |
affected |
k8s.io |
k8s.io/client-go |
— |
Open SourceActive exploitation (sightings)MEDIUM2019-04-22
In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different...
CVEs:CVE-2019-11244
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
kubernetes |
— |
— |
| openshift_container_platform |
affected |
redhat |
— |
— |
| trident |
affected |
netapp |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2019-04-22
Kubernetes Unsafe Cacheing
CVEs:CVE-2019-11244
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| client-go |
affected |
k8s.io |
k8s.io/client-go |
— |
Open SourcePoC exploitMEDIUM2019-04-01
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside the container, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar b...
CVEs:CVE-2019-1002101
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
kubernetes |
— |
— |
| openshift_container_platform |
affected |
redhat |
— |
— |
Open SourcePoC exploitMEDIUM2019-04-01
Symlink Attack in kubectl cp
CVEs:CVE-2019-1002101
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitMEDIUM2019-04-01
Symlink Attack in kubectl cp
CVEs:CVE-2019-1002101
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitCRITICAL2019-04-01
DEBIAN-CVE-2019-1002100
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
Debian:11 |
kubernetes |
— |
| kubernetes |
affected |
Debian:12 |
kubernetes |
— |
| kubernetes |
affected |
Debian:13 |
kubernetes |
— |
| kubernetes |
affected |
Debian:14 |
kubernetes |
— |
Open SourcePoC exploitMEDIUM2019-04-01
Kubernetes DoS Vulnerability
CVEs:CVE-2019-1002100
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitCRITICAL2019-04-01
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type...
CVEs:CVE-2019-1002100
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
kubernetes |
— |
— |
| openshift_container_platform |
affected |
redhat |
— |
— |
Open SourcePoC exploitHIGH2019-04-02
DEBIAN-CVE-2019-9946
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
Debian:11 |
kubernetes |
— |
| kubernetes |
affected |
Debian:12 |
kubernetes |
— |
| kubernetes |
affected |
Debian:13 |
kubernetes |
— |
| kubernetes |
affected |
Debian:14 |
kubernetes |
— |
Open SourcePoC exploitHIGH2019-04-02
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables ...
CVEs:CVE-2019-9946
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cloud_insights |
affected |
netapp |
— |
— |
| kubernetes |
affected |
kubernetes |
— |
— |
| portmap |
affected |
cncf |
— |
— |
GooglePoC exploitHIGH2019-04-02
CVEs:CVE-2019-9946
GooglePoC exploitHIGH2019-04-24
Inappropriate implementation in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
CVEs:CVE-2019-5822
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GooglePoC exploitHIGH2019-04-24
CVEs:CVE-2019-5822
Open SourcePoC exploitHIGH2019-04-22
Kubernetes did not effectively clear service account credentials
CVEs:CVE-2019-11243
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitHIGH2019-04-22
In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions, rest.Anonym...
CVEs:CVE-2019-11243
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
kubernetes |
— |
— |
| trident |
affected |
netapp |
— |
— |
Open SourceCoalition ESS < 30%2019-04-03
golang - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Debian:8 |
golang |
— |
GoogleCoalition ESS < 30%HIGH2019-04-24
CVEs:CVE-2019-5817
GoogleCoalition ESS < 30%CRITICAL2019-04-24
Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-5817
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2019-04-24
Use after free in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-5808
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-04-24
CVEs:CVE-2019-5808
GoogleCoalition ESS < 30%HIGH2019-04-24
Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote attacker to potentially persist an exploited process via a crafted HTML page.
CVEs:CVE-2019-5816
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-04-24
CVEs:CVE-2019-5816
GoogleCoalition ESS < 30%HIGH2019-04-24
Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.
CVEs:CVE-2019-5818
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-04-24
CVEs:CVE-2019-5818
GoogleCoalition ESS < 30%CRITICAL2019-04-24
Use after free in file chooser in Google Chrome prior to 74.0.3729.108 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page.
CVEs:CVE-2019-5809
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-04-24
CVEs:CVE-2019-5809
GoogleCoalition ESS < 30%MEDIUM2019-04-24
CVEs:CVE-2019-5805
GoogleCoalition ESS < 30%CRITICAL2019-04-24
Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVEs:CVE-2019-5805
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-04-24
CVEs:CVE-2019-5820
GoogleCoalition ESS < 30%CRITICAL2019-04-24
Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVEs:CVE-2019-5820
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2019-04-24
Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVEs:CVE-2019-5821
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-04-24
CVEs:CVE-2019-5821
GoogleCoalition ESS < 30%HIGH2019-04-24
CVEs:CVE-2019-5807
GoogleCoalition ESS < 30%HIGH2019-04-24
Object lifetime issue in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-5807
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-04-24
Inadequate security UI in iOS UI in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
CVEs:CVE-2019-5812
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-04-24
CVEs:CVE-2019-5812
GoogleCoalition ESS < 30%CRITICAL2019-04-24
Use after free in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-5813
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-04-24
CVEs:CVE-2019-5813
GoogleCoalition ESS < 30%HIGH2019-04-24
CVEs:CVE-2019-5806
GoogleCoalition ESS < 30%CRITICAL2019-04-24
Integer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-5806
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-04-24
CVEs:CVE-2019-5811
GoogleCoalition ESS < 30%HIGH2019-04-24
Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
CVEs:CVE-2019-5811
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-02
In floor0_inverse1 of floor0.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: And...
CVEs:CVE-2019-2027
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-04-02
CVEs:CVE-2019-2027
Open SourceCoalition ESS < 30%HIGH2019-04-02
In numerous hand-crafted functions in libmpeg2, NEON registers are not preserved. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-...
CVEs:CVE-2019-2028
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-04-02
CVEs:CVE-2019-2028
GoogleCoalition ESS < 30%HIGH2019-04-24
Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVEs:CVE-2019-5810
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-04-24
CVEs:CVE-2019-5810
GoogleCoalition ESS < 30%MEDIUM2019-04-24
CVEs:CVE-2019-5823
GoogleCoalition ESS < 30%CRITICAL2019-04-24
Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVEs:CVE-2019-5823
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2019-04-24
Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2019-5814
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-04-24
CVEs:CVE-2019-5814
GoogleCoalition ESS < 30%CRITICAL2019-04-02
CVEs:CVE-2019-2030
Open SourceCoalition ESS < 30%CRITICAL2019-04-02
In removeInterfaceAddress of NetworkController.cpp, there is a possible use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions...
CVEs:CVE-2019-2030
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-02
In l2cu_send_peer_config_rej of l2c_utils.cc, there is a possible out-of-bound read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2019-2037
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-04-02
CVEs:CVE-2019-2037
Open SourceCoalition ESS < 30%CRITICAL2019-04-24
Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-04-24
Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-04-23
PYSEC-2019-208
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-04-23
PYSEC-2019-226
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-04-23
PYSEC-2019-233
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-04-23
Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow
CVEs:CVE-2018-8825
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-23
PYSEC-2019-233
CVEs:CVE-2018-8825
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-04-23
Google TensorFlow 1.7 and below is affected by: Buffer Overflow. The impact is: execute arbitrary code (local).
CVEs:CVE-2018-8825
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-04-02
CVEs:CVE-2019-2029
Open SourceCoalition ESS < 30%HIGH2019-04-02
In btm_proc_smp_cback of tm_ble.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. V...
CVEs:CVE-2019-2029
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-04-30
Integer Overflow or Wraparound in Google TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-04-30
Integer Overflow or Wraparound in Google TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-04-24
PYSEC-2019-205
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-04-24
PYSEC-2019-223
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-04-24
PYSEC-2019-230
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-04-24
PYSEC-2019-230
CVEs:CVE-2018-7575
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-04-24
Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent.
CVEs:CVE-2018-7575
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-04-24
Integer Overflow or Wraparound in Google TensorFlow
CVEs:CVE-2018-7575
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-30
Improper Input Validation in Google TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-30
Improper Input Validation in Google TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-24
PYSEC-2019-207
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-24
PYSEC-2019-225
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-24
PYSEC-2019-232
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-24
Improper Input Validation in Google TensorFlow
CVEs:CVE-2018-7577
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-24
Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google TensorFlow before 1.7.1, could result in a crash or read from other parts of process memory.
CVEs:CVE-2018-7577
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| snappy |
affected |
google |
— |
— |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-24
PYSEC-2019-232
CVEs:CVE-2018-7577
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
GoogleCoalition ESS < 30%HIGH2019-04-02
CVEs:CVE-2019-2034
Open SourceCoalition ESS < 30%HIGH2019-04-02
In rw_i93_sm_read_ndef of rw_i93.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the NFC process with no additional execution privileges needed. User interaction is needed for ...
CVEs:CVE-2019-2034
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-30
NULL Pointer Dereference in Google TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-30
NULL Pointer Dereference in Google TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-24
PYSEC-2019-210
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-24
PYSEC-2019-228
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-24
PYSEC-2019-235
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-24
NULL pointer dereference in Google TensorFlow before 1.12.2 could cause a denial of service via an invalid GIF file.
CVEs:CVE-2019-9635
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-24
PYSEC-2019-235
CVEs:CVE-2019-9635
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-24
NULL Pointer Dereference in Google TensorFlow
CVEs:CVE-2019-9635
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-24
Null pointer dereference in TensorFlow leads to exploitation
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-24
Null pointer dereference in TensorFlow leads to exploitation
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%2019-04-23
PYSEC-2019-206
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%2019-04-23
PYSEC-2019-224
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%2019-04-23
PYSEC-2019-231
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-23
PYSEC-2019-231
CVEs:CVE-2018-7576
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2019-04-23
Google TensorFlow 1.6.x and earlier is affected by: Null Pointer Dereference. The type of exploitation is: context-dependent.
CVEs:CVE-2018-7576
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-23
Null pointer dereference in TensorFlow leads to exploitation
CVEs:CVE-2018-7576
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
GoogleCoalition ESS < 30%HIGH2019-04-02
CVEs:CVE-2019-2035
Open SourceCoalition ESS < 30%HIGH2019-04-02
In rw_i93_sm_update_ndef of rw_i93.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. P...
CVEs:CVE-2019-2035
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2019-04-02
In rw_i93_process_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. P...
CVEs:CVE-2019-2038
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-04-02
CVEs:CVE-2019-2038
GoogleCoalition ESS < 30%HIGH2019-04-24
CVEs:CVE-2019-5819
GoogleCoalition ESS < 30%HIGH2019-04-24
Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allowed a local attacker to execute arbitrary code via a crafted string copied to clipboard.
CVEs:CVE-2019-5819
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-02
In the configuration of NFC modules on certain devices, there is a possible failure to distinguish individual devices due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. Use...
CVEs:CVE-2019-2041
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-04-02
CVEs:CVE-2019-2041
GoogleCoalition ESS < 30%HIGH2019-04-02
CVEs:CVE-2019-2031
Open SourceCoalition ESS < 30%HIGH2019-04-02
In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2019-2031
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-02
In create_hdr of dnssd_clientstub.c, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Andro...
CVEs:CVE-2019-2033
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-04-02
CVEs:CVE-2019-2033
Open SourceCoalition ESS < 30%MEDIUM2019-04-02
In rw_i93_sm_detect_ndef of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Pro...
CVEs:CVE-2019-2039
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-04-02
CVEs:CVE-2019-2039
GoogleCoalition ESS < 30%HIGH2019-04-02
CVEs:CVE-2019-2032
Open SourceCoalition ESS < 30%HIGH2019-04-02
In SetScanResponseData of ble_advertiser_hci_interface.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne...
CVEs:CVE-2019-2032
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2019-04-02
CVEs:CVE-2019-2040
Open SourceCoalition ESS < 30%MEDIUM2019-04-02
In rw_i93_process_ext_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitatio...
CVEs:CVE-2019-2040
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2019-04-02
In updateAssistMenuItems of Editor.java, there is a possible escape from the Setup Wizard due to a missing permission check. This could lead to local escalation of privilege and FRP bypass with no additional execution privileges needed. User interactio...
CVEs:CVE-2019-2026
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-04-02
CVEs:CVE-2019-2026
GoogleCoalition ESS < 30%2019-04-24
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-7576, CVE-2018-21233. Reason: this candidate was intended for one issue, but the description and references inadvertently combined multiple issues. Notes: All CVE users should cons...
CVEs:CVE-2018-7574
Open SourceCoalition ESS < 30%HIGH2019-04-24
Rejected CVE ID
CVEs:CVE-2018-7574
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceEPSS <= 49%HIGH2019-04-24
DEBIAN-CVE-2017-18367
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-seccomp-libseccomp-golang |
affected |
Debian:14 |
golang-github-seccomp-libseccomp-golang |
— |
| golang-github-seccomp-libseccomp-golang |
affected |
Debian:13 |
golang-github-seccomp-libseccomp-golang |
— |
| golang-github-seccomp-libseccomp-golang |
affected |
Debian:11 |
golang-github-seccomp-libseccomp-golang |
— |
| golang-github-seccomp-libseccomp-golang |
affected |
Debian:12 |
golang-github-seccomp-libseccomp-golang |
— |
Open SourceEPSS <= 49%MEDIUM2019-04-24
Improper Input Validation in libseccomp-golang
CVEs:CVE-2017-18367
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| seccomp/libseccomp-golang |
affected |
github.com |
github.com/seccomp/libseccomp-golang |
— |
Open SourceEPSS <= 49%HIGH2019-04-24
Improper Input Validation in libseccomp-golang
CVEs:CVE-2017-18367
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| seccomp/libseccomp-golang |
affected |
github.com |
github.com/seccomp/libseccomp-golang |
— |
Open SourceEPSS <= 49%HIGH2019-04-24
libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A process running under a restrictive seccomp filter that specified multiple syscall arguments could bypass intended access restrictions ...
CVEs:CVE-2017-18367
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| libseccomp-golang |
affected |
libseccomp-golang_project |
— |
— |
Open SourceEPSS <= 49%CRITICAL2019-04-30
Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceEPSS <= 49%CRITICAL2019-04-30
Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceEPSS <= 49%CRITICAL2019-04-24
PYSEC-2019-204
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceEPSS <= 49%CRITICAL2019-04-24
PYSEC-2019-222
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceEPSS <= 49%CRITICAL2019-04-24
PYSEC-2019-229
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceEPSS <= 49%HIGH2019-04-24
PYSEC-2019-229
CVEs:CVE-2018-10055
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceEPSS <= 49%CRITICAL2019-04-24
Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow
CVEs:CVE-2018-10055
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceEPSS <= 49%CRITICAL2019-04-24
Invalid memory access and/or a heap buffer overflow in the TensorFlow XLA compiler in Google TensorFlow before 1.7.1 could cause a crash or read from other parts of process memory via a crafted configuration file.
CVEs:CVE-2018-10055
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |