Advisories
GoogleExploitedCISA KEV listedCRITICAL2019-05-14
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android pr...
CVEs:CVE-2019-3568
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| whatsapp |
affected |
whatsapp |
— |
— |
| whatsapp_business |
affected |
whatsapp |
— |
— |
GoogleExploitedCISA KEV listedCRITICAL2019-05-14
CVEs:CVE-2019-3568
Project ZeroExploitedCISA KEV listed2019-05-14
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.
CVEs:CVE-2019-3568
Open SourceExploitedVulnCheck KEV listedCRITICAL2019-05-27
Security update for containerd, docker, docker-runc, go, go1.11, go1.12, golang-github-docker-libnetwork
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| containerd |
affected |
openSUSE:Leap 15.1 |
containerd |
— |
| docker |
affected |
openSUSE:Leap 15.1 |
docker |
— |
| docker-runc |
affected |
openSUSE:Leap 15.1 |
docker-runc |
— |
| go |
affected |
openSUSE:Leap 15.1 |
go |
— |
| go1.11 |
affected |
openSUSE:Leap 15.1 |
go1.11 |
— |
| go1.12 |
affected |
openSUSE:Leap 15.1 |
go1.12 |
— |
| golang-github-docker-libnetwork |
affected |
openSUSE:Leap 15.1 |
golang-github-docker-libnetwork |
— |
Open SourceExploitedVulnCheck KEV listedCRITICAL2019-05-14
Security update for containerd, docker, docker-runc, go, go1.11, go1.12, golang-github-docker-libnetwork
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| containerd |
affected |
SUSE:Linux Enterprise Module for Containers 15 |
containerd |
— |
| docker |
affected |
SUSE:Linux Enterprise Module for Containers 15 |
docker |
— |
| docker-runc |
affected |
SUSE:Linux Enterprise Module for Containers 15 |
docker-runc |
— |
| golang-github-docker-libnetwork |
affected |
SUSE:Linux Enterprise Module for Containers 15 |
golang-github-docker-libnetwork |
— |
Open SourceWeaponized exploitCRITICAL2019-05-23
DEBIAN-CVE-2019-5789
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceWeaponized exploitCRITICAL2019-05-23
DEBIAN-CVE-2019-5788
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceWeaponized exploitHIGH2019-05-23
DEBIAN-CVE-2019-5796
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourcePoC exploitCRITICAL2019-05-16
Security update for containerd, docker, docker-runc, go, go1.11, go1.12, golang-github-docker-libnetwork
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| containerd |
affected |
SUSE:Linux Enterprise Module for Containers 12 |
— |
— |
| containerd |
affected |
SUSE:Linux Enterprise Module for Containers 12 |
containerd |
— |
| docker |
affected |
SUSE:Linux Enterprise Module for Containers 12 |
docker |
— |
| docker-runc |
affected |
SUSE:Linux Enterprise Module for Containers 12 |
docker-runc |
— |
| golang-github-docker-libnetwork |
affected |
SUSE:Linux Enterprise Module for Containers 12 |
golang-github-docker-libnetwork |
— |
Open SourcePoC exploitCRITICAL2019-05-22
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 |
chromium |
— |
Open SourcePoC exploitCRITICAL2019-05-04
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
openSUSE:Leap 15.0 |
chromium |
— |
Google CloudPoC exploit2019-05-14
Date published: 2019-05-14 (Medium)
Google CloudPoC exploit2019-05-14
GCP-COMPUTE-20190514 (Medium)
Open SourceCoalition ESS 30-63%CRITICAL2019-05-23
DEBIAN-CVE-2019-5790
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2019-05-09
DEBIAN-CVE-2019-11840
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-go.crypto |
affected |
Debian:11 |
golang-go.crypto |
— |
| golang-go.crypto |
affected |
Debian:12 |
golang-go.crypto |
— |
| golang-go.crypto |
affected |
Debian:13 |
golang-go.crypto |
— |
| golang-go.crypto |
affected |
Debian:14 |
golang-go.crypto |
— |
Open SourceCoalition ESS < 30%MEDIUM2019-05-09
golang.org/x/crypto/salsa20/salsa uses insufficiently random values
CVEs:CVE-2019-11840
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/crypto |
affected |
golang.org |
golang.org/x/crypto |
— |
GoogleCoalition ESS < 30%MEDIUM2019-05-09
An issue was discovered in the supplementary Go cryptography library, golang.org/x/crypto, before v0.0.0-20190320223903-b7391e95e576. A flaw was found in the amd64 implementation of the golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/salsa ...
CVEs:CVE-2019-11840
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| crypto |
affected |
golang |
— |
— |
| crypto |
affected |
golang |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| x/crypto |
affected |
golang |
— |
— |
| x/crypto |
affected |
golang.org |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2019-05-23
DEBIAN-CVE-2019-5798
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| firefox-esr |
affected |
Debian:11 |
firefox-esr |
— |
| firefox-esr |
affected |
Debian:12 |
firefox-esr |
— |
| firefox-esr |
affected |
Debian:13 |
firefox-esr |
— |
| firefox-esr |
affected |
Debian:14 |
firefox-esr |
— |
| thunderbird |
affected |
Debian:11 |
thunderbird |
— |
| thunderbird |
affected |
Debian:12 |
thunderbird |
— |
| thunderbird |
affected |
Debian:13 |
thunderbird |
— |
| thunderbird |
affected |
Debian:14 |
thunderbird |
— |
GoogleCoalition ESS < 30%CRITICAL2019-05-13
CVEs:CVE-2019-11888
GoogleCoalition ESS < 30%CRITICAL2019-05-13
Go through 1.12.5 on Windows mishandles process creation with a nil environment in conjunction with a non-nil token, which allows attackers to obtain sensitive information or gain privileges.
CVEs:CVE-2019-11888
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2019-05-22
DEBIAN-CVE-2019-11841
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-go.crypto |
affected |
Debian:11 |
golang-go.crypto |
— |
| golang-go.crypto |
affected |
Debian:12 |
golang-go.crypto |
— |
| golang-go.crypto |
affected |
Debian:13 |
golang-go.crypto |
— |
| golang-go.crypto |
affected |
Debian:14 |
golang-go.crypto |
— |
GoogleCoalition ESS < 30%MEDIUM2019-05-22
A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography libraries 2019-03-25. According to the OpenPGP Message Format specification in RFC 4880 chapter 7, a cleartext signed message can contain o...
CVEs:CVE-2019-11841
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| crypto |
affected |
golang |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2019-05-22
Golang/x/crypto message forgery vulnerability
CVEs:CVE-2019-11841
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/crypto |
affected |
golang.org |
golang.org/x/crypto |
— |
GoogleCoalition ESS < 30%HIGH2019-05-27
CVEs:CVE-2019-5827
GoogleCoalition ESS < 30%CRITICAL2019-05-27
Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-5827
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-05-27
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
openSUSE:Leap 15.0 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.1 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2019-05-23
DEBIAN-CVE-2019-5787
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2019-05-23
DEBIAN-CVE-2019-5791
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2019-05-23
DEBIAN-CVE-2019-5799
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2019-05-02
Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-5824
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-05-02
CVEs:CVE-2019-5824
GoogleCoalition ESS < 30%CRITICAL2019-05-07
CVEs:CVE-2019-2045
Open SourceCoalition ESS < 30%HIGH2019-05-07
In JSCallTyper of typer.cc, there is an out of bounds write due to an incorrect bounds check. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2019-2045
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2019-05-07
CVEs:CVE-2019-2047
Open SourceCoalition ESS < 30%HIGH2019-05-07
In UpdateLoadElement of ic.cc, there is a possible out-of-bounds write due to type confusion. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2019-2047
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2019-05-07
CVEs:CVE-2019-2046
Open SourceCoalition ESS < 30%HIGH2019-05-07
In CalculateInstanceSizeForDerivedClass of objects.cc, there is possible memory corruption due to an integer overflow. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is...
CVEs:CVE-2019-2046
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-05-23
DEBIAN-CVE-2019-5792
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-05-23
DEBIAN-CVE-2019-5795
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2019-05-07
In MakeMP>G4VideoCodecSpecificData of APacketSource.cpp, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote code execution in the media server with no additional execution privileges needed. User interac...
CVEs:CVE-2019-2044
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-05-07
CVEs:CVE-2019-2044
Open SourceCoalition ESS < 30%MEDIUM2019-05-23
DEBIAN-CVE-2019-5794
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-05-23
DEBIAN-CVE-2019-5800
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2019-05-23
DEBIAN-CVE-2019-5803
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2019-05-07
In heap of spaces.h, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure when processing a proxy auto config file with no additional execution privileges needed. User interaction is ...
CVEs:CVE-2019-2051
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-05-07
CVEs:CVE-2019-2051
Open SourceCoalition ESS < 30%HIGH2019-05-07
In VisitPointers of heap.cc, there is a possible out-of-bounds read due to type confusion. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Androi...
CVEs:CVE-2019-2052
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-05-07
CVEs:CVE-2019-2052
Open SourceCoalition ESS < 30%CRITICAL2019-05-23
DEBIAN-CVE-2019-5793
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2019-05-23
DEBIAN-CVE-2019-5802
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2019-05-07
In the seccomp implementation prior to kernel version 4.8, there is a possible seccomp bypass due to seccomp policies that allow the use of ptrace. This could lead to local escalation of privilege with no additional execution privileges needed. User in...
CVEs:CVE-2019-2054
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-05-07
CVEs:CVE-2019-2054
Open SourceCoalition ESS < 30%CRITICAL2019-05-07
NVIDIA Tegra TLK Widevine Trust Application contains a vulnerability in which missing the input parameter checking of video metadata count may lead to Arbitrary Code Execution, Denial of Service or Escalation of Privileges. Android ID: A-72315075. Seve...
CVEs:CVE-2018-6243
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-05-07
CVEs:CVE-2018-6243
Open SourceCoalition ESS < 30%HIGH2019-05-07
In SmsDefaultDialog.onStart of SmsDefaultDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead to local escalation of privilege, granting privileges to a local app without the user's informed consent, with n...
CVEs:CVE-2019-2043
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-05-07
CVEs:CVE-2019-2043
GoogleCoalition ESS < 30%2019-05-07
CVEs:CVE-2019-2053
Open SourceCoalition ESS < 30%MEDIUM2019-05-07
In wnm_parse_neighbor_report_elem of wnm_sta.c, there is a possible out-of-bounds read due to missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2019-2053
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-05-07
CVEs:CVE-2019-2049
Open SourceCoalition ESS < 30%HIGH2019-05-07
In SendMediaUpdate and SendFolderUpdate of avrcp_service.cc, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege in the Bluetooth service with no additional execution privileges needed. User i...
CVEs:CVE-2019-2049
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2019-05-07
In tearDownClientInterface of WificondControl.java, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2019-2050
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2019-05-07
CVEs:CVE-2019-2050
GoogleEPSS <= 49%CRITICAL2019-05-30
An unhandled exception vulnerability exists during Google Sign-In with Google API C++ Client before 2019-04-10. It potentially causes an outage of third-party services that were not designed to recover from exceptions. On the client, ID token handling ...
CVEs:CVE-2018-20840
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| api_c\+\+_client |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2019-05-30
CVEs:CVE-2018-20840
Open SourceAll remainingHIGH2019-05-31
Path Traversal in angular-http-server
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular-http-server |
affected |
npm |
angular-http-server |
— |
Open SourceAll remainingHIGH2019-05-31
Path Traversal in angular-http-server
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular-http-server |
affected |
npm |
angular-http-server |
— |