Google Security Advisories · April 2020 — Google Security Advisories
266 advisories 262 CVEs 10 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2020-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 10 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

openSUSE-SU-2020:0554-1

Open SourceExploitedCISA KEV listed2020-04-26

Security update for kubernetes

Affected products

ProductStatusVendorPackageEcosystem
cri-o affected openSUSE:Leap 15.1 cri-o
cri-tools affected openSUSE:Leap 15.1 cri-tools
go1.14 affected openSUSE:Leap 15.1 go1.14
kubernetes affected openSUSE:Leap 15.1 kubernetes
Upstream advisory

CVE-2020-12271

GoogleExploitedCISA KEV listedCRITICAL2020-04-27

A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration (HTTPS) service or the User Port...

CVEs:CVE-2020-12271

Affected products

ProductStatusVendorPackageEcosystem
sfos affected sophos
Upstream advisory

CVE-2020-12271

Project ZeroExploitedCISA KEV listed2020-04-27

A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration (HTTPS) service or the User Portal exposed on the WAN zone. A successful attack may have caused remote code execution that exfiltrated usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Di

CVEs:CVE-2020-12271

Upstream advisory

CVE-2020-6820

Project ZeroExploitedCISA KEV listed2020-04-06

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

CVEs:CVE-2020-6820

Upstream advisory

CVE-2020-6820

GoogleExploitedCISA KEV listedCRITICAL2020-04-06

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < ...

CVEs:CVE-2020-6820

Affected products

ProductStatusVendorPackageEcosystem
firefox affected mozilla
thunderbird affected mozilla
Upstream advisory

CVE-2020-1027

GoogleExploitedCISA KEV listedCRITICAL2020-04-15

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1000, CVE-2020-1003.

CVEs:CVE-2020-1027

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1709 affected microsoft
windows_10_1803 affected microsoft
windows_10_1809 affected microsoft
windows_10_1903 affected microsoft
windows_10_1909 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_1803 affected microsoft
windows_server_1903 affected microsoft
windows_server_1909 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
Upstream advisory

CVE-2020-1027

Project ZeroExploitedCISA KEV listed2020-04-15

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1000, CVE-2020-1003.

CVEs:CVE-2020-1027

Upstream advisory

CVE-2020-6819

GoogleExploitedCISA KEV listedCRITICAL2020-04-06

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefo...

CVEs:CVE-2020-6819

Affected products

ProductStatusVendorPackageEcosystem
firefox affected mozilla
thunderbird affected mozilla
Upstream advisory

CVE-2020-6819

Project ZeroExploitedCISA KEV listed2020-04-06

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

CVEs:CVE-2020-6819

Upstream advisory

DSA-4654-1

Open SourceExploitedCISA KEV listed2020-04-07

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:10 chromium
Upstream advisory

CVE-2020-35864

GoogleActive exploitation (sightings)HIGH2020-04-11

An issue was discovered in the flatbuffers crate through 2020-04-11 for Rust. read_scalar (and read_scalar_at) can transmute values without unsafe blocks.

CVEs:CVE-2020-35864

Affected products

ProductStatusVendorPackageEcosystem
flatbuffers affected google
Upstream advisory

RHSA-2020:1454

Open SourcePoC exploitHIGH2020-04-14

Red Hat Security Advisory: Satellite 6.7 release.

Affected products

ProductStatusVendorPackageEcosystem
ansiblerole-foreman_scap_client affected Red Hat:satellite:6.7::el7 ansiblerole-foreman_scap_client
ansiblerole-foreman_scap_client affected Red Hat:satellite_capsule:6.7::el7 ansiblerole-foreman_scap_client
ansiblerole-insights-client affected Red Hat:satellite_capsule:6.7::el7 ansiblerole-insights-client
ansiblerole-insights-client affected Red Hat:satellite:6.7::el7 ansiblerole-insights-client
ansiblerole-satellite-receptor-installer affected Red Hat:satellite:6.7::el7 ansiblerole-satellite-receptor-installer
ansiblerole-satellite-receptor-installer affected Red Hat:satellite_capsule:6.7::el7 ansiblerole-satellite-receptor-installer
ansible-runner affected Red Hat:satellite_capsule:6.7::el7 ansible-runner
ansible-runner affected Red Hat:satellite:6.7::el7 ansible-runner
candlepin affected Red Hat:satellite:6.7::el7 candlepin
candlepin-selinux affected Red Hat:satellite:6.7::el7 candlepin-selinux
createrepo_c affected Red Hat:satellite:6.7::el7 createrepo_c
createrepo_c affected Red Hat:satellite_capsule:6.7::el7 createrepo_c
createrepo_c-debuginfo affected Red Hat:satellite:6.7::el7 createrepo_c-debuginfo
createrepo_c-debuginfo affected Red Hat:satellite_capsule:6.7::el7 createrepo_c-debuginfo
createrepo_c-libs affected Red Hat:satellite_capsule:6.7::el7 createrepo_c-libs
createrepo_c-libs affected Red Hat:satellite:6.7::el7 createrepo_c-libs
foreman affected Red Hat:satellite_capsule:6.7::el7 foreman
foreman affected Red Hat:satellite:6.7::el7 foreman
foreman-bootloaders-redhat affected Red Hat:satellite_capsule:6.7::el7 foreman-bootloaders-redhat
foreman-bootloaders-redhat affected Red Hat:satellite:6.7::el7 foreman-bootloaders-redhat
foreman-bootloaders-redhat-tftpboot affected Red Hat:satellite_capsule:6.7::el7 foreman-bootloaders-redhat-tftpboot
foreman-bootloaders-redhat-tftpboot affected Red Hat:satellite:6.7::el7 foreman-bootloaders-redhat-tftpboot
foreman-cli affected Red Hat:satellite:6.7::el7 foreman-cli
foreman-cli affected Red Hat:satellite_capsule:6.7::el7 foreman-cli
foreman-debug affected Red Hat:satellite_capsule:6.7::el7 foreman-debug
foreman-debug affected Red Hat:satellite:6.7::el7 foreman-debug
foreman-discovery-image affected Red Hat:satellite_capsule:6.7::el7 foreman-discovery-image
foreman-discovery-image affected Red Hat:satellite:6.7::el7 foreman-discovery-image
foreman-ec2 affected Red Hat:satellite:6.7::el7 foreman-ec2
foreman-ec2 affected Red Hat:satellite_capsule:6.7::el7 foreman-ec2
foreman-gce affected Red Hat:satellite_capsule:6.7::el7 foreman-gce
foreman-gce affected Red Hat:satellite:6.7::el7 foreman-gce
foreman-installer affected Red Hat:satellite_capsule:6.7::el7 foreman-installer
foreman-installer affected Red Hat:satellite:6.7::el7 foreman-installer
foreman-installer-katello affected Red Hat:satellite:6.7::el7 foreman-installer-katello
foreman-installer-katello affected Red Hat:satellite_capsule:6.7::el7 foreman-installer-katello
foreman-journald affected Red Hat:satellite:6.7::el7 foreman-journald
foreman-journald affected Red Hat:satellite_capsule:6.7::el7 foreman-journald
foreman-libvirt affected Red Hat:satellite:6.7::el7 foreman-libvirt
foreman-libvirt affected Red Hat:satellite_capsule:6.7::el7 foreman-libvirt
foreman-openstack affected Red Hat:satellite_capsule:6.7::el7 foreman-openstack
foreman-openstack affected Red Hat:satellite:6.7::el7 foreman-openstack
foreman-ovirt affected Red Hat:satellite_capsule:6.7::el7 foreman-ovirt
foreman-ovirt affected Red Hat:satellite:6.7::el7 foreman-ovirt
foreman-postgresql affected Red Hat:satellite_capsule:6.7::el7 foreman-postgresql
foreman-postgresql affected Red Hat:satellite:6.7::el7 foreman-postgresql
foreman-proxy affected Red Hat:satellite:6.7::el7 foreman-proxy
foreman-proxy affected Red Hat:satellite_capsule:6.7::el7 foreman-proxy
foreman-proxy-content affected Red Hat:satellite_capsule:6.7::el7 foreman-proxy-content
foreman-proxy-content affected Red Hat:satellite:6.7::el7 foreman-proxy-content
foreman-proxy-journald affected Red Hat:satellite:6.7::el7 foreman-proxy-journald
foreman-proxy-journald affected Red Hat:satellite_capsule:6.7::el7 foreman-proxy-journald
foreman-rackspace affected Red Hat:satellite_capsule:6.7::el7 foreman-rackspace
foreman-rackspace affected Red Hat:satellite:6.7::el7 foreman-rackspace
foreman-selinux affected Red Hat:satellite:6.7::el7 foreman-selinux
foreman-selinux affected Red Hat:satellite_capsule:6.7::el7 foreman-selinux
foreman-telemetry affected Red Hat:satellite_capsule:6.7::el7 foreman-telemetry
foreman-telemetry affected Red Hat:satellite:6.7::el7 foreman-telemetry
foreman-vmware affected Red Hat:satellite:6.7::el7 foreman-vmware
foreman-vmware affected Red Hat:satellite_capsule:6.7::el7 foreman-vmware
future affected Red Hat:satellite:6.7::el7 future
future affected Red Hat:satellite_capsule:6.7::el7 future
gofer affected Red Hat:satellite_capsule:6.7::el7 gofer
gofer affected Red Hat:satellite:6.7::el7 gofer
hfsplus-tools affected Red Hat:satellite:6.7::el7 hfsplus-tools
hfsplus-tools affected Red Hat:satellite_capsule:6.7::el7 hfsplus-tools
hfsplus-tools-debuginfo affected Red Hat:satellite_capsule:6.7::el7 hfsplus-tools-debuginfo
hfsplus-tools-debuginfo affected Red Hat:satellite:6.7::el7 hfsplus-tools-debuginfo
katello affected Red Hat:satellite_capsule:6.7::el7 katello
katello affected Red Hat:satellite:6.7::el7 katello
katello-certs-tools affected Red Hat:satellite_capsule:6.7::el7 katello-certs-tools
katello-certs-tools affected Red Hat:satellite:6.7::el7 katello-certs-tools
katello-client-bootstrap affected Red Hat:satellite_capsule:6.7::el7 katello-client-bootstrap
katello-client-bootstrap affected Red Hat:satellite:6.7::el7 katello-client-bootstrap
katello-common affected Red Hat:satellite:6.7::el7 katello-common
katello-common affected Red Hat:satellite_capsule:6.7::el7 katello-common
katello-debug affected Red Hat:satellite:6.7::el7 katello-debug
katello-debug affected Red Hat:satellite_capsule:6.7::el7 katello-debug
katello-selinux affected Red Hat:satellite:6.7::el7 katello-selinux
katello-selinux affected Red Hat:satellite_capsule:6.7::el7 katello-selinux
katello-service affected Red Hat:satellite:6.7::el7 katello-service
katello-service affected Red Hat:satellite_capsule:6.7::el7 katello-service
keycloak-httpd-client-install affected Red Hat:satellite:6.7::el7 keycloak-httpd-client-install
kobo affected Red Hat:satellite_capsule:6.7::el7 kobo
kobo affected Red Hat:satellite:6.7::el7 kobo
libmodulemd affected Red Hat:satellite:6.7::el7 libmodulemd
libmodulemd affected Red Hat:satellite_capsule:6.7::el7 libmodulemd
libmodulemd-debuginfo affected Red Hat:satellite_capsule:6.7::el7 libmodulemd-debuginfo
libmodulemd-debuginfo affected Red Hat:satellite:6.7::el7 libmodulemd-debuginfo
libsolv affected Red Hat:satellite:6.7::el7 libsolv
libsolv affected Red Hat:satellite_capsule:6.7::el7 libsolv
libsolv-debuginfo affected Red Hat:satellite_capsule:6.7::el7 libsolv-debuginfo
libsolv-debuginfo affected Red Hat:satellite:6.7::el7 libsolv-debuginfo
libwebsockets affected Red Hat:satellite:6.7::el7 libwebsockets
libwebsockets affected Red Hat:satellite_capsule:6.7::el7 libwebsockets
libwebsockets-debuginfo affected Red Hat:satellite:6.7::el7 libwebsockets-debuginfo
libwebsockets-debuginfo affected Red Hat:satellite_capsule:6.7::el7 libwebsockets-debuginfo
livecd-tools affected Red Hat:satellite:6.7::el7 livecd-tools
livecd-tools affected Red Hat:satellite_capsule:6.7::el7 livecd-tools
mod_passenger affected Red Hat:satellite:6.7::el7 mod_passenger
mod_xsendfile affected Red Hat:satellite_capsule:6.7::el7 mod_xsendfile
mod_xsendfile affected Red Hat:satellite:6.7::el7 mod_xsendfile
mod_xsendfile-debuginfo affected Red Hat:satellite:6.7::el7 mod_xsendfile-debuginfo
mod_xsendfile-debuginfo affected Red Hat:satellite_capsule:6.7::el7 mod_xsendfile-debuginfo
ostree affected Red Hat:satellite_capsule:6.7::el7 ostree
ostree affected Red Hat:satellite:6.7::el7 ostree
ostree-debuginfo affected Red Hat:satellite_capsule:6.7::el7 ostree-debuginfo
ostree-debuginfo affected Red Hat:satellite:6.7::el7 ostree-debuginfo
pcp-mmvstatsd affected Red Hat:satellite:6.7::el7 pcp-mmvstatsd
pulp affected Red Hat:satellite:6.7::el7 pulp
pulp affected Red Hat:satellite_capsule:6.7::el7 pulp
pulp-admin-client affected Red Hat:satellite:6.7::el7 pulp-admin-client
pulp-admin-client affected Red Hat:satellite_capsule:6.7::el7 pulp-admin-client
pulp-docker affected Red Hat:satellite:6.7::el7 pulp-docker
pulp-docker affected Red Hat:satellite_capsule:6.7::el7 pulp-docker
pulp-docker-admin-extensions affected Red Hat:satellite_capsule:6.7::el7 pulp-docker-admin-extensions
pulp-docker-admin-extensions affected Red Hat:satellite:6.7::el7 pulp-docker-admin-extensions
pulp-docker-plugins affected Red Hat:satellite_capsule:6.7::el7 pulp-docker-plugins
pulp-docker-plugins affected Red Hat:satellite:6.7::el7 pulp-docker-plugins
pulp-katello affected Red Hat:satellite:6.7::el7 pulp-katello
pulp-katello affected Red Hat:satellite_capsule:6.7::el7 pulp-katello
pulp-maintenance affected Red Hat:satellite:6.7::el7 pulp-maintenance
pulp-maintenance affected Red Hat:satellite_capsule:6.7::el7 pulp-maintenance
pulp-nodes-child affected Red Hat:satellite:6.7::el7 pulp-nodes-child
pulp-nodes-child affected Red Hat:satellite_capsule:6.7::el7 pulp-nodes-child
pulp-nodes-common affected Red Hat:satellite_capsule:6.7::el7 pulp-nodes-common
pulp-nodes-common affected Red Hat:satellite:6.7::el7 pulp-nodes-common
pulp-nodes-parent affected Red Hat:satellite:6.7::el7 pulp-nodes-parent
pulp-nodes-parent affected Red Hat:satellite_capsule:6.7::el7 pulp-nodes-parent
pulp-ostree affected Red Hat:satellite_capsule:6.7::el7 pulp-ostree
pulp-ostree affected Red Hat:satellite:6.7::el7 pulp-ostree
pulp-ostree-admin-extensions affected Red Hat:satellite:6.7::el7 pulp-ostree-admin-extensions
pulp-ostree-admin-extensions affected Red Hat:satellite_capsule:6.7::el7 pulp-ostree-admin-extensions
pulp-ostree-plugins affected Red Hat:satellite:6.7::el7 pulp-ostree-plugins
pulp-ostree-plugins affected Red Hat:satellite_capsule:6.7::el7 pulp-ostree-plugins
pulp-puppet affected Red Hat:satellite_capsule:6.7::el7 pulp-puppet
pulp-puppet affected Red Hat:satellite:6.7::el7 pulp-puppet
pulp-puppet-admin-extensions affected Red Hat:satellite:6.7::el7 pulp-puppet-admin-extensions
pulp-puppet-admin-extensions affected Red Hat:satellite_capsule:6.7::el7 pulp-puppet-admin-extensions
pulp-puppet-plugins affected Red Hat:satellite_capsule:6.7::el7 pulp-puppet-plugins
pulp-puppet-plugins affected Red Hat:satellite:6.7::el7 pulp-puppet-plugins
pulp-puppet-tools affected Red Hat:satellite_capsule:6.7::el7 pulp-puppet-tools
pulp-puppet-tools affected Red Hat:satellite:6.7::el7 pulp-puppet-tools
pulp-rpm affected Red Hat:satellite_capsule:6.7::el7 pulp-rpm
pulp-rpm affected Red Hat:satellite:6.7::el7 pulp-rpm
pulp-rpm-admin-extensions affected Red Hat:satellite:6.7::el7 pulp-rpm-admin-extensions
pulp-rpm-admin-extensions affected Red Hat:satellite_capsule:6.7::el7 pulp-rpm-admin-extensions
pulp-rpm-plugins affected Red Hat:satellite:6.7::el7 pulp-rpm-plugins
pulp-rpm-plugins affected Red Hat:satellite_capsule:6.7::el7 pulp-rpm-plugins
pulp-selinux affected Red Hat:satellite_capsule:6.7::el7 pulp-selinux
pulp-selinux affected Red Hat:satellite:6.7::el7 pulp-selinux
pulp-server affected Red Hat:satellite:6.7::el7 pulp-server
pulp-server affected Red Hat:satellite_capsule:6.7::el7 pulp-server
puppet-agent affected Red Hat:satellite:6.7::el7 puppet-agent
puppet-agent affected Red Hat:satellite_capsule:6.7::el7 puppet-agent
puppet-agent-oauth affected Red Hat:satellite_capsule:6.7::el7 puppet-agent-oauth
puppet-agent-oauth affected Red Hat:satellite:6.7::el7 puppet-agent-oauth
puppet-foreman_scap_client affected Red Hat:satellite_capsule:6.7::el7 puppet-foreman_scap_client
puppet-foreman_scap_client affected Red Hat:satellite:6.7::el7 puppet-foreman_scap_client
puppetlabs-stdlib affected Red Hat:satellite:6.7::el7 puppetlabs-stdlib
puppetlabs-stdlib affected Red Hat:satellite_capsule:6.7::el7 puppetlabs-stdlib
puppetserver affected Red Hat:satellite:6.7::el7 puppetserver
puppetserver affected Red Hat:satellite_capsule:6.7::el7 puppetserver
pycairo affected Red Hat:satellite:6.7::el7 pycairo
pycairo affected Red Hat:satellite_capsule:6.7::el7 pycairo
pycairo-debuginfo affected Red Hat:satellite:6.7::el7 pycairo-debuginfo
pycairo-debuginfo affected Red Hat:satellite_capsule:6.7::el7 pycairo-debuginfo
pygobject3 affected Red Hat:satellite_capsule:6.7::el7 pygobject3
pygobject3 affected Red Hat:satellite:6.7::el7 pygobject3
pygobject3-debuginfo affected Red Hat:satellite:6.7::el7 pygobject3-debuginfo
pygobject3-debuginfo affected Red Hat:satellite_capsule:6.7::el7 pygobject3-debuginfo
python2-amqp affected Red Hat:satellite_capsule:6.7::el7 python2-amqp
python2-amqp affected Red Hat:satellite:6.7::el7 python2-amqp
python2-ansible-runner affected Red Hat:satellite_capsule:6.7::el7 python2-ansible-runner
python2-ansible-runner affected Red Hat:satellite:6.7::el7 python2-ansible-runner
python2-anyjson affected Red Hat:satellite_capsule:6.7::el7 python2-anyjson
python2-anyjson affected Red Hat:satellite:6.7::el7 python2-anyjson
python2-billiard affected Red Hat:satellite_capsule:6.7::el7 python2-billiard
python2-billiard affected Red Hat:satellite:6.7::el7 python2-billiard
python2-celery affected Red Hat:satellite_capsule:6.7::el7 python2-celery
python2-celery affected Red Hat:satellite:6.7::el7 python2-celery
python2-click affected Red Hat:satellite:6.7::el7 python2-click
python2-click affected Red Hat:satellite_capsule:6.7::el7 python2-click
python2-crane affected Red Hat:satellite:6.7::el7 python2-crane
python2-crane affected Red Hat:satellite_capsule:6.7::el7 python2-crane
python2-daemon affected Red Hat:satellite_capsule:6.7::el7 python2-daemon
python2-daemon affected Red Hat:satellite:6.7::el7 python2-daemon
python2-django affected Red Hat:satellite:6.7::el7 python2-django
python2-django affected Red Hat:satellite_capsule:6.7::el7 python2-django
python2-flask affected Red Hat:satellite_capsule:6.7::el7 python2-flask
python2-flask affected Red Hat:satellite:6.7::el7 python2-flask
python2-future affected Red Hat:satellite_capsule:6.7::el7 python2-future
python2-future affected Red Hat:satellite:6.7::el7 python2-future
python2-gobject affected Red Hat:satellite_capsule:6.7::el7 python2-gobject
python2-gobject affected Red Hat:satellite:6.7::el7 python2-gobject
python2-gobject-base affected Red Hat:satellite:6.7::el7 python2-gobject-base
python2-gobject-base affected Red Hat:satellite_capsule:6.7::el7 python2-gobject-base
python2-isodate affected Red Hat:satellite_capsule:6.7::el7 python2-isodate
python2-isodate affected Red Hat:satellite:6.7::el7 python2-isodate
python2-itsdangerous affected Red Hat:satellite:6.7::el7 python2-itsdangerous
python2-itsdangerous affected Red Hat:satellite_capsule:6.7::el7 python2-itsdangerous
python2-jinja2 affected Red Hat:satellite_capsule:6.7::el7 python2-jinja2
python2-jinja2 affected Red Hat:satellite:6.7::el7 python2-jinja2
python2-jmespath affected Red Hat:satellite_capsule:6.7::el7 python2-jmespath
python2-jmespath affected Red Hat:satellite:6.7::el7 python2-jmespath
python2-keycloak-httpd-client-install affected Red Hat:satellite:6.7::el7 python2-keycloak-httpd-client-install
python2-kombu affected Red Hat:satellite:6.7::el7 python2-kombu
python2-kombu affected Red Hat:satellite_capsule:6.7::el7 python2-kombu
python2-lockfile affected Red Hat:satellite_capsule:6.7::el7 python2-lockfile
python2-lockfile affected Red Hat:satellite:6.7::el7 python2-lockfile
python2-markupsafe affected Red Hat:satellite:6.7::el7 python2-markupsafe
python2-markupsafe affected Red Hat:satellite_capsule:6.7::el7 python2-markupsafe
python2-okaara affected Red Hat:satellite_capsule:6.7::el7 python2-okaara
python2-okaara affected Red Hat:satellite:6.7::el7 python2-okaara
python2-pexpect affected Red Hat:satellite:6.7::el7 python2-pexpect
python2-pexpect affected Red Hat:satellite_capsule:6.7::el7 python2-pexpect
python2-ptyprocess affected Red Hat:satellite:6.7::el7 python2-ptyprocess
python2-ptyprocess affected Red Hat:satellite_capsule:6.7::el7 python2-ptyprocess
python2-pycurl affected Red Hat:satellite:6.7::el7 python2-pycurl
python2-pycurl affected Red Hat:satellite_capsule:6.7::el7 python2-pycurl
python2-solv affected Red Hat:satellite_capsule:6.7::el7 python2-solv
python2-solv affected Red Hat:satellite:6.7::el7 python2-solv
python2-twisted affected Red Hat:satellite_capsule:6.7::el7 python2-twisted
python2-twisted affected Red Hat:satellite:6.7::el7 python2-twisted
python2-vine affected Red Hat:satellite:6.7::el7 python2-vine
python2-vine affected Red Hat:satellite_capsule:6.7::el7 python2-vine
python2-werkzeug affected Red Hat:satellite:6.7::el7 python2-werkzeug
python2-werkzeug affected Red Hat:satellite_capsule:6.7::el7 python2-werkzeug
python3-aiohttp affected Red Hat:satellite:6.7::el7 python3-aiohttp
python3-async-timeout affected Red Hat:satellite:6.7::el7 python3-async-timeout
python3-attrs affected Red Hat:satellite:6.7::el7 python3-attrs
python3-cchardet affected Red Hat:satellite:6.7::el7 python3-cchardet
python3-chardet affected Red Hat:satellite:6.7::el7 python3-chardet
python3-dateutil affected Red Hat:satellite:6.7::el7 python3-dateutil
python3-idna affected Red Hat:satellite:6.7::el7 python3-idna
python3-idna-ssl affected Red Hat:satellite:6.7::el7 python3-idna-ssl
python3-multidict affected Red Hat:satellite:6.7::el7 python3-multidict
python3-prometheus-client affected Red Hat:satellite:6.7::el7 python3-prometheus-client
python3-receptor-satellite affected Red Hat:satellite:6.7::el7 python3-receptor-satellite
python3-six affected Red Hat:satellite:6.7::el7 python3-six
python3-typing-extensions affected Red Hat:satellite:6.7::el7 python3-typing-extensions
python3-yarl affected Red Hat:satellite:6.7::el7 python3-yarl
python-aiohttp affected Red Hat:satellite:6.7::el7 python-aiohttp
python-aiohttp-debuginfo affected Red Hat:satellite:6.7::el7 python-aiohttp-debuginfo
python-amqp affected Red Hat:satellite_capsule:6.7::el7 python-amqp
python-amqp affected Red Hat:satellite:6.7::el7 python-amqp
python-anyjson affected Red Hat:satellite:6.7::el7 python-anyjson
python-anyjson affected Red Hat:satellite_capsule:6.7::el7 python-anyjson
python-async-timeout affected Red Hat:satellite:6.7::el7 python-async-timeout
python-attrs affected Red Hat:satellite:6.7::el7 python-attrs
python-billiard affected Red Hat:satellite:6.7::el7 python-billiard
python-billiard affected Red Hat:satellite_capsule:6.7::el7 python-billiard
python-billiard-debuginfo affected Red Hat:satellite:6.7::el7 python-billiard-debuginfo
python-billiard-debuginfo affected Red Hat:satellite_capsule:6.7::el7 python-billiard-debuginfo
python-blinker affected Red Hat:satellite:6.7::el7 python-blinker
python-blinker affected Red Hat:satellite_capsule:6.7::el7 python-blinker
python-bson affected Red Hat:satellite_capsule:6.7::el7 python-bson
python-bson affected Red Hat:satellite:6.7::el7 python-bson
python-cchardet affected Red Hat:satellite:6.7::el7 python-cchardet
python-cchardet-debuginfo affected Red Hat:satellite:6.7::el7 python-cchardet-debuginfo
python-celery affected Red Hat:satellite:6.7::el7 python-celery
python-celery affected Red Hat:satellite_capsule:6.7::el7 python-celery
python-chardet affected Red Hat:satellite:6.7::el7 python-chardet
python-click affected Red Hat:satellite_capsule:6.7::el7 python-click
python-click affected Red Hat:satellite:6.7::el7 python-click
python-crane affected Red Hat:satellite_capsule:6.7::el7 python-crane
python-crane affected Red Hat:satellite:6.7::el7 python-crane
python-daemon affected Red Hat:satellite:6.7::el7 python-daemon
python-daemon affected Red Hat:satellite_capsule:6.7::el7 python-daemon
python-dateutil affected Red Hat:satellite:6.7::el7 python-dateutil
python-django affected Red Hat:satellite:6.7::el7 python-django
python-django affected Red Hat:satellite_capsule:6.7::el7 python-django
python-flask affected Red Hat:satellite_capsule:6.7::el7 python-flask
python-flask affected Red Hat:satellite:6.7::el7 python-flask
python-gnupg affected Red Hat:satellite_capsule:6.7::el7 python-gnupg
python-gnupg affected Red Hat:satellite:6.7::el7 python-gnupg
python-gofer affected Red Hat:satellite_capsule:6.7::el7 python-gofer
python-gofer affected Red Hat:satellite:6.7::el7 python-gofer
python-gofer-qpid affected Red Hat:satellite_capsule:6.7::el7 python-gofer-qpid
python-gofer-qpid affected Red Hat:satellite:6.7::el7 python-gofer-qpid
python-idna affected Red Hat:satellite:6.7::el7 python-idna
python-idna-ssl affected Red Hat:satellite:6.7::el7 python-idna-ssl
python-imgcreate affected Red Hat:satellite:6.7::el7 python-imgcreate
python-imgcreate affected Red Hat:satellite_capsule:6.7::el7 python-imgcreate
python-isodate affected Red Hat:satellite:6.7::el7 python-isodate
python-isodate affected Red Hat:satellite_capsule:6.7::el7 python-isodate
python-itsdangerous affected Red Hat:satellite_capsule:6.7::el7 python-itsdangerous
python-itsdangerous affected Red Hat:satellite:6.7::el7 python-itsdangerous
python-jinja2 affected Red Hat:satellite:6.7::el7 python-jinja2
python-jinja2 affected Red Hat:satellite_capsule:6.7::el7 python-jinja2
python-jmespath affected Red Hat:satellite:6.7::el7 python-jmespath
python-jmespath affected Red Hat:satellite_capsule:6.7::el7 python-jmespath
python-kid affected Red Hat:satellite_capsule:6.7::el7 python-kid
python-kid affected Red Hat:satellite:6.7::el7 python-kid
python-kombu affected Red Hat:satellite_capsule:6.7::el7 python-kombu
python-kombu affected Red Hat:satellite:6.7::el7 python-kombu
python-lockfile affected Red Hat:satellite_capsule:6.7::el7 python-lockfile
python-lockfile affected Red Hat:satellite:6.7::el7 python-lockfile
python-markupsafe affected Red Hat:satellite_capsule:6.7::el7 python-markupsafe
python-markupsafe affected Red Hat:satellite:6.7::el7 python-markupsafe
python-markupsafe-debuginfo affected Red Hat:satellite:6.7::el7 python-markupsafe-debuginfo
python-markupsafe-debuginfo affected Red Hat:satellite_capsule:6.7::el7 python-markupsafe-debuginfo
python-mongoengine affected Red Hat:satellite:6.7::el7 python-mongoengine
python-mongoengine affected Red Hat:satellite_capsule:6.7::el7 python-mongoengine
python-multidict affected Red Hat:satellite:6.7::el7 python-multidict
python-multidict-debuginfo affected Red Hat:satellite:6.7::el7 python-multidict-debuginfo
python-nectar affected Red Hat:satellite_capsule:6.7::el7 python-nectar
python-nectar affected Red Hat:satellite:6.7::el7 python-nectar
python-oauth2 affected Red Hat:satellite_capsule:6.7::el7 python-oauth2
python-oauth2 affected Red Hat:satellite:6.7::el7 python-oauth2
python-okaara affected Red Hat:satellite_capsule:6.7::el7 python-okaara
python-okaara affected Red Hat:satellite:6.7::el7 python-okaara
python-pexpect affected Red Hat:satellite:6.7::el7 python-pexpect
python-pexpect affected Red Hat:satellite_capsule:6.7::el7 python-pexpect
python-prometheus-client affected Red Hat:satellite:6.7::el7 python-prometheus-client
python-psutil affected Red Hat:satellite_capsule:6.7::el7 python-psutil
python-psutil affected Red Hat:satellite:6.7::el7 python-psutil
python-psutil-debuginfo affected Red Hat:satellite:6.7::el7 python-psutil-debuginfo
python-psutil-debuginfo affected Red Hat:satellite_capsule:6.7::el7 python-psutil-debuginfo
python-ptyprocess affected Red Hat:satellite:6.7::el7 python-ptyprocess
python-ptyprocess affected Red Hat:satellite_capsule:6.7::el7 python-ptyprocess
python-pulp-agent-lib affected Red Hat:satellite_capsule:6.7::el7 python-pulp-agent-lib
python-pulp-agent-lib affected Red Hat:satellite:6.7::el7 python-pulp-agent-lib
python-pulp-bindings affected Red Hat:satellite:6.7::el7 python-pulp-bindings
python-pulp-bindings affected Red Hat:satellite_capsule:6.7::el7 python-pulp-bindings
python-pulp-client-lib affected Red Hat:satellite_capsule:6.7::el7 python-pulp-client-lib
python-pulp-client-lib affected Red Hat:satellite:6.7::el7 python-pulp-client-lib
python-pulp-common affected Red Hat:satellite_capsule:6.7::el7 python-pulp-common
python-pulp-common affected Red Hat:satellite:6.7::el7 python-pulp-common
python-pulp-docker-common affected Red Hat:satellite:6.7::el7 python-pulp-docker-common
python-pulp-docker-common affected Red Hat:satellite_capsule:6.7::el7 python-pulp-docker-common
python-pulp-integrity affected Red Hat:satellite_capsule:6.7::el7 python-pulp-integrity
python-pulp-integrity affected Red Hat:satellite:6.7::el7 python-pulp-integrity
python-pulp-oid_validation affected Red Hat:satellite:6.7::el7 python-pulp-oid_validation
python-pulp-oid_validation affected Red Hat:satellite_capsule:6.7::el7 python-pulp-oid_validation
python-pulp-ostree-common affected Red Hat:satellite:6.7::el7 python-pulp-ostree-common
python-pulp-ostree-common affected Red Hat:satellite_capsule:6.7::el7 python-pulp-ostree-common
python-pulp-puppet-common affected Red Hat:satellite_capsule:6.7::el7 python-pulp-puppet-common
python-pulp-puppet-common affected Red Hat:satellite:6.7::el7 python-pulp-puppet-common
python-pulp-repoauth affected Red Hat:satellite:6.7::el7 python-pulp-repoauth
python-pulp-repoauth affected Red Hat:satellite_capsule:6.7::el7 python-pulp-repoauth
python-pulp-rpm-common affected Red Hat:satellite:6.7::el7 python-pulp-rpm-common
python-pulp-rpm-common affected Red Hat:satellite_capsule:6.7::el7 python-pulp-rpm-common
python-pulp-streamer affected Red Hat:satellite_capsule:6.7::el7 python-pulp-streamer
python-pulp-streamer affected Red Hat:satellite:6.7::el7 python-pulp-streamer
python-pycurl affected Red Hat:satellite:6.7::el7 python-pycurl
python-pycurl affected Red Hat:satellite_capsule:6.7::el7 python-pycurl
python-pycurl-debuginfo affected Red Hat:satellite_capsule:6.7::el7 python-pycurl-debuginfo
python-pycurl-debuginfo affected Red Hat:satellite:6.7::el7 python-pycurl-debuginfo
python-pymongo affected Red Hat:satellite_capsule:6.7::el7 python-pymongo
python-pymongo affected Red Hat:satellite:6.7::el7 python-pymongo
python-pymongo-debuginfo affected Red Hat:satellite_capsule:6.7::el7 python-pymongo-debuginfo
python-pymongo-debuginfo affected Red Hat:satellite:6.7::el7 python-pymongo-debuginfo
python-pymongo-gridfs affected Red Hat:satellite:6.7::el7 python-pymongo-gridfs
python-pymongo-gridfs affected Red Hat:satellite_capsule:6.7::el7 python-pymongo-gridfs
python-qpid affected Red Hat:satellite:6.7::el7 python-qpid
python-qpid affected Red Hat:satellite_capsule:6.7::el7 python-qpid
python-qpid-proton affected Red Hat:satellite:6.7::el7 python-qpid-proton
python-qpid-proton affected Red Hat:satellite_capsule:6.7::el7 python-qpid-proton
python-qpid-qmf affected Red Hat:satellite:6.7::el7 python-qpid-qmf
python-qpid-qmf affected Red Hat:satellite_capsule:6.7::el7 python-qpid-qmf
python-receptor-satellite affected Red Hat:satellite:6.7::el7 python-receptor-satellite
python-saslwrapper affected Red Hat:satellite_capsule:6.7::el7 python-saslwrapper
python-saslwrapper affected Red Hat:satellite:6.7::el7 python-saslwrapper
python-semantic_version affected Red Hat:satellite_capsule:6.7::el7 python-semantic_version
python-semantic_version affected Red Hat:satellite:6.7::el7 python-semantic_version
python-simplejson affected Red Hat:satellite:6.7::el7 python-simplejson
python-simplejson affected Red Hat:satellite_capsule:6.7::el7 python-simplejson
python-simplejson-debuginfo affected Red Hat:satellite_capsule:6.7::el7 python-simplejson-debuginfo
python-simplejson-debuginfo affected Red Hat:satellite:6.7::el7 python-simplejson-debuginfo
python-six affected Red Hat:satellite:6.7::el7 python-six
python-twisted affected Red Hat:satellite_capsule:6.7::el7 python-twisted
python-twisted affected Red Hat:satellite:6.7::el7 python-twisted
python-twisted-debuginfo affected Red Hat:satellite:6.7::el7 python-twisted-debuginfo
python-twisted-debuginfo affected Red Hat:satellite_capsule:6.7::el7 python-twisted-debuginfo
python-typing-extensions affected Red Hat:satellite:6.7::el7 python-typing-extensions
python-vine affected Red Hat:satellite:6.7::el7 python-vine
python-vine affected Red Hat:satellite_capsule:6.7::el7 python-vine
python-werkzeug affected Red Hat:satellite:6.7::el7 python-werkzeug
python-werkzeug affected Red Hat:satellite_capsule:6.7::el7 python-werkzeug
python-yarl affected Red Hat:satellite:6.7::el7 python-yarl
python-yarl-debuginfo affected Red Hat:satellite:6.7::el7 python-yarl-debuginfo
python-zope-interface affected Red Hat:satellite:6.7::el7 python-zope-interface
python-zope-interface affected Red Hat:satellite_capsule:6.7::el7 python-zope-interface
python-zope-interface-debuginfo affected Red Hat:satellite_capsule:6.7::el7 python-zope-interface-debuginfo
python-zope-interface-debuginfo affected Red Hat:satellite:6.7::el7 python-zope-interface-debuginfo
qpid-cpp affected Red Hat:satellite_capsule:6.7::el7 qpid-cpp
qpid-cpp affected Red Hat:satellite:6.7::el7 qpid-cpp
qpid-cpp-client affected Red Hat:satellite_capsule:6.7::el7 qpid-cpp-client
qpid-cpp-client affected Red Hat:satellite:6.7::el7 qpid-cpp-client
qpid-cpp-client-devel affected Red Hat:satellite_capsule:6.7::el7 qpid-cpp-client-devel
qpid-cpp-client-devel affected Red Hat:satellite:6.7::el7 qpid-cpp-client-devel
qpid-cpp-debuginfo affected Red Hat:satellite_capsule:6.7::el7 qpid-cpp-debuginfo
qpid-cpp-debuginfo affected Red Hat:satellite:6.7::el7 qpid-cpp-debuginfo
qpid-cpp-server affected Red Hat:satellite_capsule:6.7::el7 qpid-cpp-server
qpid-cpp-server affected Red Hat:satellite:6.7::el7 qpid-cpp-server
qpid-cpp-server-linearstore affected Red Hat:satellite:6.7::el7 qpid-cpp-server-linearstore
qpid-cpp-server-linearstore affected Red Hat:satellite_capsule:6.7::el7 qpid-cpp-server-linearstore
qpid-dispatch affected Red Hat:satellite_capsule:6.7::el7 qpid-dispatch
qpid-dispatch affected Red Hat:satellite:6.7::el7 qpid-dispatch
qpid-dispatch-debuginfo affected Red Hat:satellite:6.7::el7 qpid-dispatch-debuginfo
qpid-dispatch-debuginfo affected Red Hat:satellite_capsule:6.7::el7 qpid-dispatch-debuginfo
qpid-dispatch-router affected Red Hat:satellite_capsule:6.7::el7 qpid-dispatch-router
qpid-dispatch-router affected Red Hat:satellite:6.7::el7 qpid-dispatch-router
qpid-dispatch-tools affected Red Hat:satellite:6.7::el7 qpid-dispatch-tools
qpid-dispatch-tools affected Red Hat:satellite_capsule:6.7::el7 qpid-dispatch-tools
qpid-proton affected Red Hat:satellite:6.7::el7 qpid-proton
qpid-proton affected Red Hat:satellite_capsule:6.7::el7 qpid-proton
qpid-proton-c affected Red Hat:satellite_capsule:6.7::el7 qpid-proton-c
qpid-proton-c affected Red Hat:satellite:6.7::el7 qpid-proton-c
qpid-proton-debuginfo affected Red Hat:satellite_capsule:6.7::el7 qpid-proton-debuginfo
qpid-proton-debuginfo affected Red Hat:satellite:6.7::el7 qpid-proton-debuginfo
qpid-qmf affected Red Hat:satellite:6.7::el7 qpid-qmf
qpid-qmf affected Red Hat:satellite_capsule:6.7::el7 qpid-qmf
qpid-tools affected Red Hat:satellite:6.7::el7 qpid-tools
qpid-tools affected Red Hat:satellite_capsule:6.7::el7 qpid-tools
receptor affected Red Hat:satellite:6.7::el7 receptor
redhat-access-insights-puppet affected Red Hat:satellite_capsule:6.7::el7 redhat-access-insights-puppet
redhat-access-insights-puppet affected Red Hat:satellite:6.7::el7 redhat-access-insights-puppet
repoview affected Red Hat:satellite_capsule:6.7::el7 repoview
repoview affected Red Hat:satellite:6.7::el7 repoview
rhel8-kickstart-setup affected Red Hat:satellite:6.7::el7 rhel8-kickstart-setup
rubygem-ansi affected Red Hat:satellite:6.7::el7 rubygem-ansi
rubygem-ansi affected Red Hat:satellite_capsule:6.7::el7 rubygem-ansi
rubygem-bundler_ext affected Red Hat:satellite_capsule:6.7::el7 rubygem-bundler_ext
rubygem-bundler_ext affected Red Hat:satellite:6.7::el7 rubygem-bundler_ext
rubygem-clamp affected Red Hat:satellite:6.7::el7 rubygem-clamp
rubygem-clamp affected Red Hat:satellite_capsule:6.7::el7 rubygem-clamp
rubygem-concurrent-ruby affected Red Hat:satellite:6.7::el7 rubygem-concurrent-ruby
rubygem-concurrent-ruby affected Red Hat:satellite_capsule:6.7::el7 rubygem-concurrent-ruby
rubygem-facter affected Red Hat:satellite:6.7::el7 rubygem-facter
rubygem-faraday affected Red Hat:satellite_capsule:6.7::el7 rubygem-faraday
rubygem-faraday affected Red Hat:satellite:6.7::el7 rubygem-faraday
rubygem-faraday_middleware affected Red Hat:satellite:6.7::el7 rubygem-faraday_middleware
rubygem-faraday_middleware affected Red Hat:satellite_capsule:6.7::el7 rubygem-faraday_middleware
rubygem-fast_gettext affected Red Hat:satellite_capsule:6.7::el7 rubygem-fast_gettext
rubygem-fast_gettext affected Red Hat:satellite:6.7::el7 rubygem-fast_gettext
rubygem-ffi affected Red Hat:satellite:6.7::el7 rubygem-ffi
rubygem-ffi affected Red Hat:satellite_capsule:6.7::el7 rubygem-ffi
rubygem-ffi-debuginfo affected Red Hat:satellite:6.7::el7 rubygem-ffi-debuginfo
rubygem-ffi-debuginfo affected Red Hat:satellite_capsule:6.7::el7 rubygem-ffi-debuginfo
rubygem-foreman_scap_client affected Red Hat:satellite:6.7::el7 rubygem-foreman_scap_client
rubygem-gssapi affected Red Hat:satellite:6.7::el7 rubygem-gssapi
rubygem-gssapi affected Red Hat:satellite_capsule:6.7::el7 rubygem-gssapi
rubygem-hashie affected Red Hat:satellite_capsule:6.7::el7 rubygem-hashie
rubygem-hashie affected Red Hat:satellite:6.7::el7 rubygem-hashie
rubygem-highline affected Red Hat:satellite_capsule:6.7::el7 rubygem-highline
rubygem-highline affected Red Hat:satellite:6.7::el7 rubygem-highline
rubygem-infoblox affected Red Hat:satellite:6.7::el7 rubygem-infoblox
rubygem-infoblox affected Red Hat:satellite_capsule:6.7::el7 rubygem-infoblox
rubygem-journald-logger affected Red Hat:satellite:6.7::el7 rubygem-journald-logger
rubygem-journald-logger affected Red Hat:satellite_capsule:6.7::el7 rubygem-journald-logger
rubygem-journald-native affected Red Hat:satellite_capsule:6.7::el7 rubygem-journald-native
rubygem-journald-native affected Red Hat:satellite:6.7::el7 rubygem-journald-native
rubygem-journald-native-debuginfo affected Red Hat:satellite:6.7::el7 rubygem-journald-native-debuginfo
rubygem-journald-native-debuginfo affected Red Hat:satellite_capsule:6.7::el7 rubygem-journald-native-debuginfo
rubygem-jwt affected Red Hat:satellite_capsule:6.7::el7 rubygem-jwt
rubygem-jwt affected Red Hat:satellite:6.7::el7 rubygem-jwt
rubygem-kafo affected Red Hat:satellite:6.7::el7 rubygem-kafo
rubygem-kafo affected Red Hat:satellite_capsule:6.7::el7 rubygem-kafo
rubygem-kafo_parsers affected Red Hat:satellite:6.7::el7 rubygem-kafo_parsers
rubygem-kafo_parsers affected Red Hat:satellite_capsule:6.7::el7 rubygem-kafo_parsers
rubygem-kafo_wizards affected Red Hat:satellite_capsule:6.7::el7 rubygem-kafo_wizards
rubygem-kafo_wizards affected Red Hat:satellite:6.7::el7 rubygem-kafo_wizards
rubygem-little-plugger affected Red Hat:satellite:6.7::el7 rubygem-little-plugger
rubygem-little-plugger affected Red Hat:satellite_capsule:6.7::el7 rubygem-little-plugger
rubygem-logging affected Red Hat:satellite_capsule:6.7::el7 rubygem-logging
rubygem-logging affected Red Hat:satellite:6.7::el7 rubygem-logging
rubygem-logging-journald affected Red Hat:satellite_capsule:6.7::el7 rubygem-logging-journald
rubygem-logging-journald affected Red Hat:satellite:6.7::el7 rubygem-logging-journald
rubygem-mime-types affected Red Hat:satellite:6.7::el7 rubygem-mime-types
rubygem-mime-types affected Red Hat:satellite_capsule:6.7::el7 rubygem-mime-types
rubygem-multi_json affected Red Hat:satellite:6.7::el7 rubygem-multi_json
rubygem-multi_json affected Red Hat:satellite_capsule:6.7::el7 rubygem-multi_json
rubygem-multipart-post affected Red Hat:satellite_capsule:6.7::el7 rubygem-multipart-post
rubygem-multipart-post affected Red Hat:satellite:6.7::el7 rubygem-multipart-post
rubygem-netrc affected Red Hat:satellite_capsule:6.7::el7 rubygem-netrc
rubygem-netrc affected Red Hat:satellite:6.7::el7 rubygem-netrc
rubygem-net-ssh affected Red Hat:satellite_capsule:6.7::el7 rubygem-net-ssh
rubygem-net-ssh affected Red Hat:satellite:6.7::el7 rubygem-net-ssh
rubygem-newt affected Red Hat:satellite:6.7::el7 rubygem-newt
rubygem-newt affected Red Hat:satellite_capsule:6.7::el7 rubygem-newt
rubygem-newt-debuginfo affected Red Hat:satellite:6.7::el7 rubygem-newt-debuginfo
rubygem-newt-debuginfo affected Red Hat:satellite_capsule:6.7::el7 rubygem-newt-debuginfo
rubygem-oauth affected Red Hat:satellite:6.7::el7 rubygem-oauth
rubygem-oauth affected Red Hat:satellite_capsule:6.7::el7 rubygem-oauth
rubygem-openscap affected Red Hat:satellite_capsule:6.7::el7 rubygem-openscap
rubygem-openscap affected Red Hat:satellite:6.7::el7 rubygem-openscap
rubygem-passenger affected Red Hat:satellite:6.7::el7 rubygem-passenger
rubygem-passenger-debuginfo affected Red Hat:satellite:6.7::el7 rubygem-passenger-debuginfo
rubygem-passenger-native affected Red Hat:satellite:6.7::el7 rubygem-passenger-native
rubygem-passenger-native-libs affected Red Hat:satellite:6.7::el7 rubygem-passenger-native-libs
rubygem-powerbar affected Red Hat:satellite:6.7::el7 rubygem-powerbar
rubygem-powerbar affected Red Hat:satellite_capsule:6.7::el7 rubygem-powerbar
rubygem-rack affected Red Hat:satellite:6.7::el7 rubygem-rack
rubygem-rack affected Red Hat:satellite_capsule:6.7::el7 rubygem-rack
rubygem-rack-protection affected Red Hat:satellite:6.7::el7 rubygem-rack-protection
rubygem-rack-protection affected Red Hat:satellite_capsule:6.7::el7 rubygem-rack-protection
rubygem-rake affected Red Hat:satellite:6.7::el7 rubygem-rake
rubygem-rake affected Red Hat:satellite_capsule:6.7::el7 rubygem-rake
rubygem-rb-inotify affected Red Hat:satellite:6.7::el7 rubygem-rb-inotify
rubygem-rb-inotify affected Red Hat:satellite_capsule:6.7::el7 rubygem-rb-inotify
rubygem-rest-client affected Red Hat:satellite_capsule:6.7::el7 rubygem-rest-client
rubygem-rest-client affected Red Hat:satellite:6.7::el7 rubygem-rest-client
rubygem-rkerberos affected Red Hat:satellite:6.7::el7 rubygem-rkerberos
rubygem-rkerberos affected Red Hat:satellite_capsule:6.7::el7 rubygem-rkerberos
rubygem-rkerberos-debuginfo affected Red Hat:satellite_capsule:6.7::el7 rubygem-rkerberos-debuginfo
rubygem-rkerberos-debuginfo affected Red Hat:satellite:6.7::el7 rubygem-rkerberos-debuginfo
rubygem-rsec affected Red Hat:satellite:6.7::el7 rubygem-rsec
rubygem-rsec affected Red Hat:satellite_capsule:6.7::el7 rubygem-rsec
rubygem-rubyipmi affected Red Hat:satellite_capsule:6.7::el7 rubygem-rubyipmi
rubygem-rubyipmi affected Red Hat:satellite:6.7::el7 rubygem-rubyipmi
rubygem-sinatra affected Red Hat:satellite_capsule:6.7::el7 rubygem-sinatra
rubygem-sinatra affected Red Hat:satellite:6.7::el7 rubygem-sinatra
rubygem-smart_proxy_ansible affected Red Hat:satellite_capsule:6.7::el7 rubygem-smart_proxy_ansible
rubygem-smart_proxy_ansible affected Red Hat:satellite:6.7::el7 rubygem-smart_proxy_ansible
rubygem-smart_proxy_dhcp_infoblox affected Red Hat:satellite_capsule:6.7::el7 rubygem-smart_proxy_dhcp_infoblox
rubygem-smart_proxy_dhcp_infoblox affected Red Hat:satellite:6.7::el7 rubygem-smart_proxy_dhcp_infoblox
rubygem-smart_proxy_dhcp_remote_isc affected Red Hat:satellite_capsule:6.7::el7 rubygem-smart_proxy_dhcp_remote_isc
rubygem-smart_proxy_dhcp_remote_isc affected Red Hat:satellite:6.7::el7 rubygem-smart_proxy_dhcp_remote_isc
rubygem-smart_proxy_discovery affected Red Hat:satellite:6.7::el7 rubygem-smart_proxy_discovery
rubygem-smart_proxy_discovery affected Red Hat:satellite_capsule:6.7::el7 rubygem-smart_proxy_discovery
rubygem-smart_proxy_discovery_image affected Red Hat:satellite_capsule:6.7::el7 rubygem-smart_proxy_discovery_image
rubygem-smart_proxy_discovery_image affected Red Hat:satellite:6.7::el7 rubygem-smart_proxy_discovery_image
rubygem-smart_proxy_dns_infoblox affected Red Hat:satellite:6.7::el7 rubygem-smart_proxy_dns_infoblox
rubygem-smart_proxy_dns_infoblox affected Red Hat:satellite_capsule:6.7::el7 rubygem-smart_proxy_dns_infoblox
rubygem-smart_proxy_dynflow affected Red Hat:satellite_capsule:6.7::el7 rubygem-smart_proxy_dynflow
rubygem-smart_proxy_dynflow affected Red Hat:satellite:6.7::el7 rubygem-smart_proxy_dynflow
rubygem-smart_proxy_openscap affected Red Hat:satellite_capsule:6.7::el7 rubygem-smart_proxy_openscap
rubygem-smart_proxy_openscap affected Red Hat:satellite:6.7::el7 rubygem-smart_proxy_openscap
rubygem-smart_proxy_pulp affected Red Hat:satellite:6.7::el7 rubygem-smart_proxy_pulp
rubygem-smart_proxy_pulp affected Red Hat:satellite_capsule:6.7::el7 rubygem-smart_proxy_pulp
rubygem-smart_proxy_remote_execution_ssh affected Red Hat:satellite:6.7::el7 rubygem-smart_proxy_remote_execution_ssh
rubygem-smart_proxy_remote_execution_ssh affected Red Hat:satellite_capsule:6.7::el7 rubygem-smart_proxy_remote_execution_ssh
rubygem-tilt affected Red Hat:satellite:6.7::el7 rubygem-tilt
rubygem-tilt affected Red Hat:satellite_capsule:6.7::el7 rubygem-tilt
saslwrapper affected Red Hat:satellite_capsule:6.7::el7 saslwrapper
saslwrapper affected Red Hat:satellite:6.7::el7 saslwrapper
saslwrapper-debuginfo affected Red Hat:satellite:6.7::el7 saslwrapper-debuginfo
saslwrapper-debuginfo affected Red Hat:satellite_capsule:6.7::el7 saslwrapper-debuginfo
satellite affected Red Hat:satellite:6.7::el7 satellite
satellite affected Red Hat:satellite_capsule:6.7::el7 satellite
satellite-capsule affected Red Hat:satellite:6.7::el7 satellite-capsule
satellite-capsule affected Red Hat:satellite_capsule:6.7::el7 satellite-capsule
satellite-cli affected Red Hat:satellite_capsule:6.7::el7 satellite-cli
satellite-cli affected Red Hat:satellite:6.7::el7 satellite-cli
satellite-common affected Red Hat:satellite:6.7::el7 satellite-common
satellite-common affected Red Hat:satellite_capsule:6.7::el7 satellite-common
satellite-debug-tools affected Red Hat:satellite:6.7::el7 satellite-debug-tools
satellite-debug-tools affected Red Hat:satellite_capsule:6.7::el7 satellite-debug-tools
satellite-installer affected Red Hat:satellite:6.7::el7 satellite-installer
satellite-installer affected Red Hat:satellite_capsule:6.7::el7 satellite-installer
tfm affected Red Hat:satellite_capsule:6.7::el7 tfm
tfm affected Red Hat:satellite:6.7::el7 tfm
tfm-ror52 affected Red Hat:satellite_capsule:6.7::el7 tfm-ror52
tfm-ror52 affected Red Hat:satellite:6.7::el7 tfm-ror52
tfm-ror52-rubygem-actioncable affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-actioncable
tfm-ror52-rubygem-actionmailer affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-actionmailer
tfm-ror52-rubygem-actionpack affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-actionpack
tfm-ror52-rubygem-actionview affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-actionview
tfm-ror52-rubygem-activejob affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-activejob
tfm-ror52-rubygem-activemodel affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-activemodel
tfm-ror52-rubygem-activerecord affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-activerecord
tfm-ror52-rubygem-activestorage affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-activestorage
tfm-ror52-rubygem-activesupport affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-activesupport
tfm-ror52-rubygem-arel affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-arel
tfm-ror52-rubygem-builder affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-builder
tfm-ror52-rubygem-coffee-rails affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-coffee-rails
tfm-ror52-rubygem-coffee-script affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-coffee-script
tfm-ror52-rubygem-coffee-script-source affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-coffee-script-source
tfm-ror52-rubygem-concurrent-ruby affected Red Hat:satellite_capsule:6.7::el7 tfm-ror52-rubygem-concurrent-ruby
tfm-ror52-rubygem-concurrent-ruby affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-concurrent-ruby
tfm-ror52-rubygem-crass affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-crass
tfm-ror52-rubygem-erubi affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-erubi
tfm-ror52-rubygem-execjs affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-execjs
tfm-ror52-rubygem-globalid affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-globalid
tfm-ror52-rubygem-i18n affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-i18n
tfm-ror52-rubygem-loofah affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-loofah
tfm-ror52-rubygem-mail affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-mail
tfm-ror52-rubygem-marcel affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-marcel
tfm-ror52-rubygem-method_source affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-method_source
tfm-ror52-rubygem-mimemagic affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-mimemagic
tfm-ror52-rubygem-mime-types affected Red Hat:satellite_capsule:6.7::el7 tfm-ror52-rubygem-mime-types
tfm-ror52-rubygem-mime-types affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-mime-types
tfm-ror52-rubygem-mime-types-data affected Red Hat:satellite_capsule:6.7::el7 tfm-ror52-rubygem-mime-types-data
tfm-ror52-rubygem-mime-types-data affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-mime-types-data
tfm-ror52-rubygem-mini_mime affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-mini_mime
tfm-ror52-rubygem-mini_portile2 affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-mini_portile2
tfm-ror52-rubygem-multi_json affected Red Hat:satellite_capsule:6.7::el7 tfm-ror52-rubygem-multi_json
tfm-ror52-rubygem-multi_json affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-multi_json
tfm-ror52-rubygem-mustermann affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-mustermann
tfm-ror52-rubygem-mustermann affected Red Hat:satellite_capsule:6.7::el7 tfm-ror52-rubygem-mustermann
tfm-ror52-rubygem-nio4r affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-nio4r
tfm-ror52-rubygem-nio4r-debuginfo affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-nio4r-debuginfo
tfm-ror52-rubygem-nokogiri affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-nokogiri
tfm-ror52-rubygem-nokogiri-debuginfo affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-nokogiri-debuginfo
tfm-ror52-rubygem-rack affected Red Hat:satellite_capsule:6.7::el7 tfm-ror52-rubygem-rack
tfm-ror52-rubygem-rack affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-rack
tfm-ror52-rubygem-rack-protection affected Red Hat:satellite_capsule:6.7::el7 tfm-ror52-rubygem-rack-protection
tfm-ror52-rubygem-rack-protection affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-rack-protection
tfm-ror52-rubygem-rack-test affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-rack-test
tfm-ror52-rubygem-rails affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-rails
tfm-ror52-rubygem-rails-dom-testing affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-rails-dom-testing
tfm-ror52-rubygem-rails-html-sanitizer affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-rails-html-sanitizer
tfm-ror52-rubygem-railties affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-railties
tfm-ror52-rubygem-sinatra affected Red Hat:satellite_capsule:6.7::el7 tfm-ror52-rubygem-sinatra
tfm-ror52-rubygem-sinatra affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-sinatra
tfm-ror52-rubygem-sprockets affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-sprockets
tfm-ror52-rubygem-sprockets-rails affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-sprockets-rails
tfm-ror52-rubygem-sqlite3 affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-sqlite3
tfm-ror52-rubygem-sqlite3 affected Red Hat:satellite_capsule:6.7::el7 tfm-ror52-rubygem-sqlite3
tfm-ror52-rubygem-sqlite3-debuginfo affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-sqlite3-debuginfo
tfm-ror52-rubygem-sqlite3-debuginfo affected Red Hat:satellite_capsule:6.7::el7 tfm-ror52-rubygem-sqlite3-debuginfo
tfm-ror52-rubygem-thor affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-thor
tfm-ror52-rubygem-thread_safe affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-thread_safe
tfm-ror52-rubygem-tilt affected Red Hat:satellite_capsule:6.7::el7 tfm-ror52-rubygem-tilt
tfm-ror52-rubygem-tilt affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-tilt
tfm-ror52-rubygem-turbolinks affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-turbolinks
tfm-ror52-rubygem-tzinfo affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-tzinfo
tfm-ror52-rubygem-websocket-driver affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-websocket-driver
tfm-ror52-rubygem-websocket-driver-debuginfo affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-websocket-driver-debuginfo
tfm-ror52-rubygem-websocket-extensions affected Red Hat:satellite:6.7::el7 tfm-ror52-rubygem-websocket-extensions
tfm-ror52-runtime affected Red Hat:satellite_capsule:6.7::el7 tfm-ror52-runtime
tfm-ror52-runtime affected Red Hat:satellite:6.7::el7 tfm-ror52-runtime
tfm-rubygem-activerecord-import affected Red Hat:satellite:6.7::el7 tfm-rubygem-activerecord-import
tfm-rubygem-activerecord-session_store affected Red Hat:satellite:6.7::el7 tfm-rubygem-activerecord-session_store
tfm-rubygem-addressable affected Red Hat:satellite:6.7::el7 tfm-rubygem-addressable
tfm-rubygem-algebrick affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-algebrick
tfm-rubygem-algebrick affected Red Hat:satellite:6.7::el7 tfm-rubygem-algebrick
tfm-rubygem-ancestry affected Red Hat:satellite:6.7::el7 tfm-rubygem-ancestry
tfm-rubygem-anemone affected Red Hat:satellite:6.7::el7 tfm-rubygem-anemone
tfm-rubygem-angular-rails-templates affected Red Hat:satellite:6.7::el7 tfm-rubygem-angular-rails-templates
tfm-rubygem-apipie-bindings affected Red Hat:satellite:6.7::el7 tfm-rubygem-apipie-bindings
tfm-rubygem-apipie-params affected Red Hat:satellite:6.7::el7 tfm-rubygem-apipie-params
tfm-rubygem-apipie-params affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-apipie-params
tfm-rubygem-apipie-rails affected Red Hat:satellite:6.7::el7 tfm-rubygem-apipie-rails
tfm-rubygem-audited affected Red Hat:satellite:6.7::el7 tfm-rubygem-audited
tfm-rubygem-awesome_print affected Red Hat:satellite:6.7::el7 tfm-rubygem-awesome_print
tfm-rubygem-azure_mgmt_compute affected Red Hat:satellite:6.7::el7 tfm-rubygem-azure_mgmt_compute
tfm-rubygem-azure_mgmt_network affected Red Hat:satellite:6.7::el7 tfm-rubygem-azure_mgmt_network
tfm-rubygem-azure_mgmt_resources affected Red Hat:satellite:6.7::el7 tfm-rubygem-azure_mgmt_resources
tfm-rubygem-azure_mgmt_storage affected Red Hat:satellite:6.7::el7 tfm-rubygem-azure_mgmt_storage
tfm-rubygem-bcrypt affected Red Hat:satellite:6.7::el7 tfm-rubygem-bcrypt
tfm-rubygem-bcrypt-debuginfo affected Red Hat:satellite:6.7::el7 tfm-rubygem-bcrypt-debuginfo
tfm-rubygem-bundler_ext affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-bundler_ext
tfm-rubygem-bundler_ext affected Red Hat:satellite:6.7::el7 tfm-rubygem-bundler_ext
tfm-rubygem-clamp affected Red Hat:satellite:6.7::el7 tfm-rubygem-clamp
tfm-rubygem-concurrent-ruby-edge affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-concurrent-ruby-edge
tfm-rubygem-concurrent-ruby-edge affected Red Hat:satellite:6.7::el7 tfm-rubygem-concurrent-ruby-edge
tfm-rubygem-css_parser affected Red Hat:satellite:6.7::el7 tfm-rubygem-css_parser
tfm-rubygem-daemons affected Red Hat:satellite:6.7::el7 tfm-rubygem-daemons
tfm-rubygem-deacon affected Red Hat:satellite:6.7::el7 tfm-rubygem-deacon
tfm-rubygem-declarative affected Red Hat:satellite:6.7::el7 tfm-rubygem-declarative
tfm-rubygem-declarative-option affected Red Hat:satellite:6.7::el7 tfm-rubygem-declarative-option
tfm-rubygem-deep_cloneable affected Red Hat:satellite:6.7::el7 tfm-rubygem-deep_cloneable
tfm-rubygem-deface affected Red Hat:satellite:6.7::el7 tfm-rubygem-deface
tfm-rubygem-diffy affected Red Hat:satellite:6.7::el7 tfm-rubygem-diffy
tfm-rubygem-domain_name affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-domain_name
tfm-rubygem-domain_name affected Red Hat:satellite:6.7::el7 tfm-rubygem-domain_name
tfm-rubygem-dynflow affected Red Hat:satellite:6.7::el7 tfm-rubygem-dynflow
tfm-rubygem-dynflow affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-dynflow
tfm-rubygem-ethon affected Red Hat:satellite:6.7::el7 tfm-rubygem-ethon
tfm-rubygem-excon affected Red Hat:satellite:6.7::el7 tfm-rubygem-excon
tfm-rubygem-facter affected Red Hat:satellite:6.7::el7 tfm-rubygem-facter
tfm-rubygem-faraday affected Red Hat:satellite:6.7::el7 tfm-rubygem-faraday
tfm-rubygem-faraday-cookie_jar affected Red Hat:satellite:6.7::el7 tfm-rubygem-faraday-cookie_jar
tfm-rubygem-fast_gettext affected Red Hat:satellite:6.7::el7 tfm-rubygem-fast_gettext
tfm-rubygem-ffi affected Red Hat:satellite:6.7::el7 tfm-rubygem-ffi
tfm-rubygem-ffi affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-ffi
tfm-rubygem-ffi-debuginfo affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-ffi-debuginfo
tfm-rubygem-ffi-debuginfo affected Red Hat:satellite:6.7::el7 tfm-rubygem-ffi-debuginfo
tfm-rubygem-fog-aws affected Red Hat:satellite:6.7::el7 tfm-rubygem-fog-aws
tfm-rubygem-fog-core affected Red Hat:satellite:6.7::el7 tfm-rubygem-fog-core
tfm-rubygem-fog-google affected Red Hat:satellite:6.7::el7 tfm-rubygem-fog-google
tfm-rubygem-fog-json affected Red Hat:satellite:6.7::el7 tfm-rubygem-fog-json
tfm-rubygem-fog-kubevirt affected Red Hat:satellite:6.7::el7 tfm-rubygem-fog-kubevirt
tfm-rubygem-fog-libvirt affected Red Hat:satellite:6.7::el7 tfm-rubygem-fog-libvirt
tfm-rubygem-fog-openstack affected Red Hat:satellite:6.7::el7 tfm-rubygem-fog-openstack
tfm-rubygem-fog-ovirt affected Red Hat:satellite:6.7::el7 tfm-rubygem-fog-ovirt
tfm-rubygem-fog-rackspace affected Red Hat:satellite:6.7::el7 tfm-rubygem-fog-rackspace
tfm-rubygem-fog-vsphere affected Red Hat:satellite:6.7::el7 tfm-rubygem-fog-vsphere
tfm-rubygem-fog-xml affected Red Hat:satellite:6.7::el7 tfm-rubygem-fog-xml
tfm-rubygem-foreman_ansible affected Red Hat:satellite:6.7::el7 tfm-rubygem-foreman_ansible
tfm-rubygem-foreman_ansible_core affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-foreman_ansible_core
tfm-rubygem-foreman_ansible_core affected Red Hat:satellite:6.7::el7 tfm-rubygem-foreman_ansible_core
tfm-rubygem-foreman_azure_rm affected Red Hat:satellite:6.7::el7 tfm-rubygem-foreman_azure_rm
tfm-rubygem-foreman_bootdisk affected Red Hat:satellite:6.7::el7 tfm-rubygem-foreman_bootdisk
tfm-rubygem-foreman_discovery affected Red Hat:satellite:6.7::el7 tfm-rubygem-foreman_discovery
tfm-rubygem-foreman_hooks affected Red Hat:satellite:6.7::el7 tfm-rubygem-foreman_hooks
tfm-rubygem-foreman_inventory_upload affected Red Hat:satellite:6.7::el7 tfm-rubygem-foreman_inventory_upload
tfm-rubygem-foreman_kubevirt affected Red Hat:satellite:6.7::el7 tfm-rubygem-foreman_kubevirt
tfm-rubygem-foreman_openscap affected Red Hat:satellite:6.7::el7 tfm-rubygem-foreman_openscap
tfm-rubygem-foreman_remote_execution affected Red Hat:satellite:6.7::el7 tfm-rubygem-foreman_remote_execution
tfm-rubygem-foreman_remote_execution-cockpit affected Red Hat:satellite:6.7::el7 tfm-rubygem-foreman_remote_execution-cockpit
tfm-rubygem-foreman_remote_execution_core affected Red Hat:satellite:6.7::el7 tfm-rubygem-foreman_remote_execution_core
tfm-rubygem-foreman_remote_execution_core affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-foreman_remote_execution_core
tfm-rubygem-foreman_rh_cloud affected Red Hat:satellite:6.7::el7 tfm-rubygem-foreman_rh_cloud
tfm-rubygem-foreman-tasks affected Red Hat:satellite:6.7::el7 tfm-rubygem-foreman-tasks
tfm-rubygem-foreman-tasks-core affected Red Hat:satellite:6.7::el7 tfm-rubygem-foreman-tasks-core
tfm-rubygem-foreman-tasks-core affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-foreman-tasks-core
tfm-rubygem-foreman_templates affected Red Hat:satellite:6.7::el7 tfm-rubygem-foreman_templates
tfm-rubygem-foreman_theme_satellite affected Red Hat:satellite:6.7::el7 tfm-rubygem-foreman_theme_satellite
tfm-rubygem-foreman_virt_who_configure affected Red Hat:satellite:6.7::el7 tfm-rubygem-foreman_virt_who_configure
tfm-rubygem-formatador affected Red Hat:satellite:6.7::el7 tfm-rubygem-formatador
tfm-rubygem-friendly_id affected Red Hat:satellite:6.7::el7 tfm-rubygem-friendly_id
tfm-rubygem-get_process_mem affected Red Hat:satellite:6.7::el7 tfm-rubygem-get_process_mem
tfm-rubygem-gettext affected Red Hat:satellite:6.7::el7 tfm-rubygem-gettext
tfm-rubygem-gettext_i18n_rails affected Red Hat:satellite:6.7::el7 tfm-rubygem-gettext_i18n_rails
tfm-rubygem-git affected Red Hat:satellite:6.7::el7 tfm-rubygem-git
tfm-rubygem-google-api-client affected Red Hat:satellite:6.7::el7 tfm-rubygem-google-api-client
tfm-rubygem-googleauth affected Red Hat:satellite:6.7::el7 tfm-rubygem-googleauth
tfm-rubygem-graphql affected Red Hat:satellite:6.7::el7 tfm-rubygem-graphql
tfm-rubygem-graphql-batch affected Red Hat:satellite:6.7::el7 tfm-rubygem-graphql-batch
tfm-rubygem-gssapi affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-gssapi
tfm-rubygem-gssapi affected Red Hat:satellite:6.7::el7 tfm-rubygem-gssapi
tfm-rubygem-hammer_cli affected Red Hat:satellite:6.7::el7 tfm-rubygem-hammer_cli
tfm-rubygem-hammer_cli_foreman affected Red Hat:satellite:6.7::el7 tfm-rubygem-hammer_cli_foreman
tfm-rubygem-hammer_cli_foreman_admin affected Red Hat:satellite:6.7::el7 tfm-rubygem-hammer_cli_foreman_admin
tfm-rubygem-hammer_cli_foreman_ansible affected Red Hat:satellite:6.7::el7 tfm-rubygem-hammer_cli_foreman_ansible
tfm-rubygem-hammer_cli_foreman_azure_rm affected Red Hat:satellite:6.7::el7 tfm-rubygem-hammer_cli_foreman_azure_rm
tfm-rubygem-hammer_cli_foreman_bootdisk affected Red Hat:satellite:6.7::el7 tfm-rubygem-hammer_cli_foreman_bootdisk
tfm-rubygem-hammer_cli_foreman_discovery affected Red Hat:satellite:6.7::el7 tfm-rubygem-hammer_cli_foreman_discovery
tfm-rubygem-hammer_cli_foreman_docker affected Red Hat:satellite:6.7::el7 tfm-rubygem-hammer_cli_foreman_docker
tfm-rubygem-hammer_cli_foreman_kubevirt affected Red Hat:satellite:6.7::el7 tfm-rubygem-hammer_cli_foreman_kubevirt
tfm-rubygem-hammer_cli_foreman_openscap affected Red Hat:satellite:6.7::el7 tfm-rubygem-hammer_cli_foreman_openscap
tfm-rubygem-hammer_cli_foreman_remote_execution affected Red Hat:satellite:6.7::el7 tfm-rubygem-hammer_cli_foreman_remote_execution
tfm-rubygem-hammer_cli_foreman_tasks affected Red Hat:satellite:6.7::el7 tfm-rubygem-hammer_cli_foreman_tasks
tfm-rubygem-hammer_cli_foreman_templates affected Red Hat:satellite:6.7::el7 tfm-rubygem-hammer_cli_foreman_templates
tfm-rubygem-hammer_cli_foreman_virt_who_configure affected Red Hat:satellite:6.7::el7 tfm-rubygem-hammer_cli_foreman_virt_who_configure
tfm-rubygem-hammer_cli_katello affected Red Hat:satellite:6.7::el7 tfm-rubygem-hammer_cli_katello
tfm-rubygem-hashie affected Red Hat:satellite:6.7::el7 tfm-rubygem-hashie
tfm-rubygem-highline affected Red Hat:satellite:6.7::el7 tfm-rubygem-highline
tfm-rubygem-http affected Red Hat:satellite:6.7::el7 tfm-rubygem-http
tfm-rubygem-httpclient affected Red Hat:satellite:6.7::el7 tfm-rubygem-httpclient
tfm-rubygem-http-cookie affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-http-cookie
tfm-rubygem-http-cookie affected Red Hat:satellite:6.7::el7 tfm-rubygem-http-cookie
tfm-rubygem-http-form_data affected Red Hat:satellite:6.7::el7 tfm-rubygem-http-form_data
tfm-rubygem-http_parser.rb affected Red Hat:satellite:6.7::el7 tfm-rubygem-http_parser.rb
tfm-rubygem-http_parser.rb-debuginfo affected Red Hat:satellite:6.7::el7 tfm-rubygem-http_parser.rb-debuginfo
tfm-rubygem-ipaddress affected Red Hat:satellite:6.7::el7 tfm-rubygem-ipaddress
tfm-rubygem-jgrep affected Red Hat:satellite:6.7::el7 tfm-rubygem-jgrep
tfm-rubygem-journald-logger affected Red Hat:satellite:6.7::el7 tfm-rubygem-journald-logger
tfm-rubygem-journald-native affected Red Hat:satellite:6.7::el7 tfm-rubygem-journald-native
tfm-rubygem-journald-native-debuginfo affected Red Hat:satellite:6.7::el7 tfm-rubygem-journald-native-debuginfo
tfm-rubygem-jwt affected Red Hat:satellite:6.7::el7 tfm-rubygem-jwt
tfm-rubygem-katello affected Red Hat:satellite:6.7::el7 tfm-rubygem-katello
tfm-rubygem-kubeclient affected Red Hat:satellite:6.7::el7 tfm-rubygem-kubeclient
tfm-rubygem-ldap_fluff affected Red Hat:satellite:6.7::el7 tfm-rubygem-ldap_fluff
tfm-rubygem-little-plugger affected Red Hat:satellite:6.7::el7 tfm-rubygem-little-plugger
tfm-rubygem-locale affected Red Hat:satellite:6.7::el7 tfm-rubygem-locale
tfm-rubygem-logging affected Red Hat:satellite:6.7::el7 tfm-rubygem-logging
tfm-rubygem-logging-journald affected Red Hat:satellite:6.7::el7 tfm-rubygem-logging-journald
tfm-rubygem-memoist affected Red Hat:satellite:6.7::el7 tfm-rubygem-memoist
tfm-rubygem-ms_rest affected Red Hat:satellite:6.7::el7 tfm-rubygem-ms_rest
tfm-rubygem-ms_rest_azure affected Red Hat:satellite:6.7::el7 tfm-rubygem-ms_rest_azure
tfm-rubygem-multipart-post affected Red Hat:satellite:6.7::el7 tfm-rubygem-multipart-post
tfm-rubygem-net-ldap affected Red Hat:satellite:6.7::el7 tfm-rubygem-net-ldap
tfm-rubygem-net-ping affected Red Hat:satellite:6.7::el7 tfm-rubygem-net-ping
tfm-rubygem-netrc affected Red Hat:satellite:6.7::el7 tfm-rubygem-netrc
tfm-rubygem-netrc affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-netrc
tfm-rubygem-net-scp affected Red Hat:satellite:6.7::el7 tfm-rubygem-net-scp
tfm-rubygem-net-ssh affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-net-ssh
tfm-rubygem-net-ssh affected Red Hat:satellite:6.7::el7 tfm-rubygem-net-ssh
tfm-rubygem-net-ssh-krb affected Red Hat:satellite:6.7::el7 tfm-rubygem-net-ssh-krb
tfm-rubygem-net-ssh-krb affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-net-ssh-krb
tfm-rubygem-oauth affected Red Hat:satellite:6.7::el7 tfm-rubygem-oauth
tfm-rubygem-optimist affected Red Hat:satellite:6.7::el7 tfm-rubygem-optimist
tfm-rubygem-os affected Red Hat:satellite:6.7::el7 tfm-rubygem-os
tfm-rubygem-ovirt-engine-sdk affected Red Hat:satellite:6.7::el7 tfm-rubygem-ovirt-engine-sdk
tfm-rubygem-ovirt-engine-sdk-debuginfo affected Red Hat:satellite:6.7::el7 tfm-rubygem-ovirt-engine-sdk-debuginfo
tfm-rubygem-ovirt_provision_plugin affected Red Hat:satellite:6.7::el7 tfm-rubygem-ovirt_provision_plugin
tfm-rubygem-parse-cron affected Red Hat:satellite:6.7::el7 tfm-rubygem-parse-cron
tfm-rubygem-passenger affected Red Hat:satellite:6.7::el7 tfm-rubygem-passenger
tfm-rubygem-passenger-debuginfo affected Red Hat:satellite:6.7::el7 tfm-rubygem-passenger-debuginfo
tfm-rubygem-passenger-native affected Red Hat:satellite:6.7::el7 tfm-rubygem-passenger-native
tfm-rubygem-passenger-native-libs affected Red Hat:satellite:6.7::el7 tfm-rubygem-passenger-native-libs
tfm-rubygem-pg affected Red Hat:satellite:6.7::el7 tfm-rubygem-pg
tfm-rubygem-pg-debuginfo affected Red Hat:satellite:6.7::el7 tfm-rubygem-pg-debuginfo
tfm-rubygem-polyglot affected Red Hat:satellite:6.7::el7 tfm-rubygem-polyglot
tfm-rubygem-powerbar affected Red Hat:satellite:6.7::el7 tfm-rubygem-powerbar
tfm-rubygem-prometheus-client affected Red Hat:satellite:6.7::el7 tfm-rubygem-prometheus-client
tfm-rubygem-promise.rb affected Red Hat:satellite:6.7::el7 tfm-rubygem-promise.rb
tfm-rubygem-public_suffix affected Red Hat:satellite:6.7::el7 tfm-rubygem-public_suffix
tfm-rubygem-pulp_2to3_migration_client affected Red Hat:satellite:6.7::el7 tfm-rubygem-pulp_2to3_migration_client
tfm-rubygem-pulp_ansible_client affected Red Hat:satellite:6.7::el7 tfm-rubygem-pulp_ansible_client
tfm-rubygem-pulpcore_client affected Red Hat:satellite:6.7::el7 tfm-rubygem-pulpcore_client
tfm-rubygem-pulp_docker_client affected Red Hat:satellite:6.7::el7 tfm-rubygem-pulp_docker_client
tfm-rubygem-pulp_file_client affected Red Hat:satellite:6.7::el7 tfm-rubygem-pulp_file_client
tfm-rubygem-pulp_rpm_client affected Red Hat:satellite:6.7::el7 tfm-rubygem-pulp_rpm_client
tfm-rubygem-qpid_messaging affected Red Hat:satellite:6.7::el7 tfm-rubygem-qpid_messaging
tfm-rubygem-qpid_messaging-debuginfo affected Red Hat:satellite:6.7::el7 tfm-rubygem-qpid_messaging-debuginfo
tfm-rubygem-quantile affected Red Hat:satellite:6.7::el7 tfm-rubygem-quantile
tfm-rubygem-rabl affected Red Hat:satellite:6.7::el7 tfm-rubygem-rabl
tfm-rubygem-rack-cors affected Red Hat:satellite:6.7::el7 tfm-rubygem-rack-cors
tfm-rubygem-rack-jsonp affected Red Hat:satellite:6.7::el7 tfm-rubygem-rack-jsonp
tfm-rubygem-rails-i18n affected Red Hat:satellite:6.7::el7 tfm-rubygem-rails-i18n
tfm-rubygem-rainbow affected Red Hat:satellite:6.7::el7 tfm-rubygem-rainbow
tfm-rubygem-rbovirt affected Red Hat:satellite:6.7::el7 tfm-rubygem-rbovirt
tfm-rubygem-rbvmomi affected Red Hat:satellite:6.7::el7 tfm-rubygem-rbvmomi
tfm-rubygem-record_tag_helper affected Red Hat:satellite:6.7::el7 tfm-rubygem-record_tag_helper
tfm-rubygem-recursive-open-struct affected Red Hat:satellite:6.7::el7 tfm-rubygem-recursive-open-struct
tfm-rubygem-redhat_access affected Red Hat:satellite:6.7::el7 tfm-rubygem-redhat_access
tfm-rubygem-redhat_access_lib affected Red Hat:satellite:6.7::el7 tfm-rubygem-redhat_access_lib
tfm-rubygem-representable affected Red Hat:satellite:6.7::el7 tfm-rubygem-representable
tfm-rubygem-responders affected Red Hat:satellite:6.7::el7 tfm-rubygem-responders
tfm-rubygem-rest-client affected Red Hat:satellite:6.7::el7 tfm-rubygem-rest-client
tfm-rubygem-rest-client affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-rest-client
tfm-rubygem-retriable affected Red Hat:satellite:6.7::el7 tfm-rubygem-retriable
tfm-rubygem-roadie affected Red Hat:satellite:6.7::el7 tfm-rubygem-roadie
tfm-rubygem-roadie-rails affected Red Hat:satellite:6.7::el7 tfm-rubygem-roadie-rails
tfm-rubygem-robotex affected Red Hat:satellite:6.7::el7 tfm-rubygem-robotex
tfm-rubygem-ruby2ruby affected Red Hat:satellite:6.7::el7 tfm-rubygem-ruby2ruby
tfm-rubygem-ruby-libvirt affected Red Hat:satellite:6.7::el7 tfm-rubygem-ruby-libvirt
tfm-rubygem-ruby-libvirt-debuginfo affected Red Hat:satellite:6.7::el7 tfm-rubygem-ruby-libvirt-debuginfo
tfm-rubygem-ruby_parser affected Red Hat:satellite:6.7::el7 tfm-rubygem-ruby_parser
tfm-rubygem-runcible affected Red Hat:satellite:6.7::el7 tfm-rubygem-runcible
tfm-rubygem-safemode affected Red Hat:satellite:6.7::el7 tfm-rubygem-safemode
tfm-rubygem-scoped_search affected Red Hat:satellite:6.7::el7 tfm-rubygem-scoped_search
tfm-rubygem-secure_headers affected Red Hat:satellite:6.7::el7 tfm-rubygem-secure_headers
tfm-rubygem-sequel affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-sequel
tfm-rubygem-sequel affected Red Hat:satellite:6.7::el7 tfm-rubygem-sequel
tfm-rubygem-sexp_processor affected Red Hat:satellite:6.7::el7 tfm-rubygem-sexp_processor
tfm-rubygem-signet affected Red Hat:satellite:6.7::el7 tfm-rubygem-signet
tfm-rubygem-smart_proxy_dynflow_core affected Red Hat:satellite:6.7::el7 tfm-rubygem-smart_proxy_dynflow_core
tfm-rubygem-smart_proxy_dynflow_core affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-smart_proxy_dynflow_core
tfm-rubygem-sshkey affected Red Hat:satellite:6.7::el7 tfm-rubygem-sshkey
tfm-rubygem-statsd-instrument affected Red Hat:satellite:6.7::el7 tfm-rubygem-statsd-instrument
tfm-rubygem-statsd-instrument affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-statsd-instrument
tfm-rubygem-text affected Red Hat:satellite:6.7::el7 tfm-rubygem-text
tfm-rubygem-timeliness affected Red Hat:satellite:6.7::el7 tfm-rubygem-timeliness
tfm-rubygem-typhoeus affected Red Hat:satellite:6.7::el7 tfm-rubygem-typhoeus
tfm-rubygem-uber affected Red Hat:satellite:6.7::el7 tfm-rubygem-uber
tfm-rubygem-unf affected Red Hat:satellite:6.7::el7 tfm-rubygem-unf
tfm-rubygem-unf affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-unf
tfm-rubygem-unf_ext affected Red Hat:satellite:6.7::el7 tfm-rubygem-unf_ext
tfm-rubygem-unf_ext affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-unf_ext
tfm-rubygem-unf_ext-debuginfo affected Red Hat:satellite:6.7::el7 tfm-rubygem-unf_ext-debuginfo
tfm-rubygem-unf_ext-debuginfo affected Red Hat:satellite_capsule:6.7::el7 tfm-rubygem-unf_ext-debuginfo
tfm-rubygem-unicode affected Red Hat:satellite:6.7::el7 tfm-rubygem-unicode
tfm-rubygem-unicode-debuginfo affected Red Hat:satellite:6.7::el7 tfm-rubygem-unicode-debuginfo
tfm-rubygem-unicode-display_width affected Red Hat:satellite:6.7::el7 tfm-rubygem-unicode-display_width
tfm-rubygem-validates_lengths_from_database affected Red Hat:satellite:6.7::el7 tfm-rubygem-validates_lengths_from_database
tfm-rubygem-webpack-rails affected Red Hat:satellite:6.7::el7 tfm-rubygem-webpack-rails
tfm-rubygem-will_paginate affected Red Hat:satellite:6.7::el7 tfm-rubygem-will_paginate
tfm-rubygem-x-editable-rails affected Red Hat:satellite:6.7::el7 tfm-rubygem-x-editable-rails
tfm-runtime affected Red Hat:satellite_capsule:6.7::el7 tfm-runtime
tfm-runtime affected Red Hat:satellite:6.7::el7 tfm-runtime
Upstream advisory

DEBIAN-CVE-2019-11254

Open SourcePoC exploitMEDIUM2020-04-01

DEBIAN-CVE-2019-11254

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2019-11254

Open SourcePoC exploitMEDIUM2020-04-01

The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.

CVEs:CVE-2019-11254

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2020-0082

Open SourcePoC exploitHIGH2020-04-07

In ExternalVibration of ExternalVibration.java, there is a possible activation of an arbitrary intent due to unsafe deserialization. This could lead to local escalation of privilege to system_server with no additional execution privileges needed. User ...

CVEs:CVE-2020-0082

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0068

Open SourcePoC exploitHIGH2020-04-07

In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2020-0068

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MGASA-2020-0149

Open SourceCoalition ESS 30-63%CRITICAL2020-04-01

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:7 chromium-browser-stable
Upstream advisory

MGASA-2020-0185

Open SourceCoalition ESS 30-63%CRITICAL2020-04-26

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:7 chromium-browser-stable
Upstream advisory

CVE-2020-6458

GoogleCoalition ESS 30-63%HIGH2020-04-22

Out of bounds read and write in PDFium in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2020-6458

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

MGASA-2020-0173

Open SourceCoalition ESS < 30%CRITICAL2020-04-15

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:7 golang
Upstream advisory

openSUSE-SU-2020:0540-1

Open SourceCoalition ESS < 30%CRITICAL2020-04-18

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

MGASA-2020-0174

Open SourceCoalition ESS < 30%CRITICAL2020-04-16

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:7 chromium-browser-stable
Upstream advisory

openSUSE-SU-2020:0519-1

Open SourceCoalition ESS < 30%CRITICAL2020-04-15

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

DEBIAN-CVE-2020-6455

Open SourceCoalition ESS < 30%HIGH2020-04-13

DEBIAN-CVE-2020-6455

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6455

GoogleCoalition ESS < 30%HIGH2020-04-08

Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6455

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6442

Open SourceCoalition ESS < 30%MEDIUM2020-04-13

DEBIAN-CVE-2020-6442

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6442

GoogleCoalition ESS < 30%MEDIUM2020-04-08

Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2020-6442

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6445

Open SourceCoalition ESS < 30%CRITICAL2020-04-13

DEBIAN-CVE-2020-6445

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6445

GoogleCoalition ESS < 30%CRITICAL2020-04-08

Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVEs:CVE-2020-6445

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6430

Open SourceCoalition ESS < 30%HIGH2020-04-13

DEBIAN-CVE-2020-6430

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6430

GoogleCoalition ESS < 30%HIGH2020-04-08

Type Confusion in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6430

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6447

Open SourceCoalition ESS < 30%HIGH2020-04-13

DEBIAN-CVE-2020-6447

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6447

GoogleCoalition ESS < 30%HIGH2020-04-08

Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6447

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6452

Open SourceCoalition ESS < 30%CRITICAL2020-04-13

DEBIAN-CVE-2020-6452

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

openSUSE-SU-2020:0512-1

Open SourceCoalition ESS < 30%CRITICAL2020-04-12

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP3 chromium
Upstream advisory

CVE-2020-6452

GoogleCoalition ESS < 30%CRITICAL2020-04-01

Heap buffer overflow in media in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6452

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6443

Open SourceCoalition ESS < 30%CRITICAL2020-04-13

DEBIAN-CVE-2020-6443

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6443

GoogleCoalition ESS < 30%CRITICAL2020-04-08

Insufficient data validation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to execute arbitrary code via a crafted HTML page.

CVEs:CVE-2020-6443

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6439

Open SourceCoalition ESS < 30%CRITICAL2020-04-13

DEBIAN-CVE-2020-6439

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6439

GoogleCoalition ESS < 30%CRITICAL2020-04-08

Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page.

CVEs:CVE-2020-6439

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2020-11767

Open SourceCoalition ESS < 30%MEDIUM2020-04-15

Istio through 1.5.1 and Envoy through 1.14.1 have a data-leak issue. If there is a TCP connection (negotiated with SNI over HTTPS) to *.example.com, a request for a domain concurrently configured explicitly (e.g., abc.example.com) is sent to the server...

CVEs:CVE-2020-11767

Affected products

ProductStatusVendorPackageEcosystem
envoy affected envoyproxy
istio affected istio
Upstream advisory

DEBIAN-CVE-2020-6441

Open SourceCoalition ESS < 30%CRITICAL2020-04-13

DEBIAN-CVE-2020-6441

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6441

GoogleCoalition ESS < 30%CRITICAL2020-04-08

Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page.

CVEs:CVE-2020-6441

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6437

Open SourceCoalition ESS < 30%MEDIUM2020-04-13

DEBIAN-CVE-2020-6437

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6437

GoogleCoalition ESS < 30%MEDIUM2020-04-08

Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted application.

CVEs:CVE-2020-6437

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6448

Open SourceCoalition ESS < 30%CRITICAL2020-04-13

DEBIAN-CVE-2020-6448

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6448

GoogleCoalition ESS < 30%CRITICAL2020-04-08

Use after free in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6448

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6432

Open SourceCoalition ESS < 30%CRITICAL2020-04-13

DEBIAN-CVE-2020-6432

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6432

GoogleCoalition ESS < 30%CRITICAL2020-04-08

Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2020-6432

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6423

Open SourceCoalition ESS < 30%CRITICAL2020-04-13

DEBIAN-CVE-2020-6423

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6423

GoogleCoalition ESS < 30%CRITICAL2020-04-08

Use after free in audio in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6423

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6434

Open SourceCoalition ESS < 30%CRITICAL2020-04-13

DEBIAN-CVE-2020-6434

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6434

GoogleCoalition ESS < 30%CRITICAL2020-04-08

Use after free in devtools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6434

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6446

Open SourceCoalition ESS < 30%CRITICAL2020-04-13

DEBIAN-CVE-2020-6446

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6433

Open SourceCoalition ESS < 30%CRITICAL2020-04-13

DEBIAN-CVE-2020-6433

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6435

Open SourceCoalition ESS < 30%CRITICAL2020-04-13

DEBIAN-CVE-2020-6435

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6433

GoogleCoalition ESS < 30%CRITICAL2020-04-08

Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2020-6433

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2020-6435

GoogleCoalition ESS < 30%CRITICAL2020-04-08

Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2020-6435

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2020-6446

GoogleCoalition ESS < 30%CRITICAL2020-04-08

Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVEs:CVE-2020-6446

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6436

Open SourceCoalition ESS < 30%CRITICAL2020-04-13

DEBIAN-CVE-2020-6436

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6436

GoogleCoalition ESS < 30%CRITICAL2020-04-08

Use after free in window management in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6436

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6431

Open SourceCoalition ESS < 30%CRITICAL2020-04-13

DEBIAN-CVE-2020-6431

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6431

GoogleCoalition ESS < 30%CRITICAL2020-04-08

Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted HTML page.

CVEs:CVE-2020-6431

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6450

Open SourceCoalition ESS < 30%CRITICAL2020-04-13

DEBIAN-CVE-2020-6450

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6450

GoogleCoalition ESS < 30%CRITICAL2020-04-01

Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6450

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6451

Open SourceCoalition ESS < 30%CRITICAL2020-04-13

DEBIAN-CVE-2020-6451

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6451

GoogleCoalition ESS < 30%CRITICAL2020-04-01

Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6451

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6454

Open SourceCoalition ESS < 30%CRITICAL2020-04-13

DEBIAN-CVE-2020-6454

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6454

GoogleCoalition ESS < 30%CRITICAL2020-04-08

Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

CVEs:CVE-2020-6454

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6456

Open SourceCoalition ESS < 30%MEDIUM2020-04-13

DEBIAN-CVE-2020-6456

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6456

GoogleCoalition ESS < 30%MEDIUM2020-04-08

Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allowed a local attacker to bypass site isolation via crafted clipboard contents.

CVEs:CVE-2020-6456

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6444

Open SourceCoalition ESS < 30%MEDIUM2020-04-13

DEBIAN-CVE-2020-6444

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6444

GoogleCoalition ESS < 30%MEDIUM2020-04-08

Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6444

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2020-6462

GoogleCoalition ESS < 30%CRITICAL2020-04-28

Use after free in task scheduling in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-6462

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2020-0070

Open SourceCoalition ESS < 30%HIGH2020-04-07

In rw_t2t_update_lock_attributes of rw_t2t_ndef.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2020-0070

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0071

Open SourceCoalition ESS < 30%HIGH2020-04-07

In rw_t2t_extract_default_locks_info of rw_t2t_ndef.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not nee...

CVEs:CVE-2020-0071

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0072

Open SourceCoalition ESS < 30%HIGH2020-04-07

In rw_t2t_handle_tlv_detect_rsp of rw_t2t_ndef.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2020-0072

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0073

Open SourceCoalition ESS < 30%HIGH2020-04-07

In rw_t2t_handle_tlv_detect_rsp of rw_t2t_ndef.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2020-0073

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2020-6438

Open SourceCoalition ESS < 30%CRITICAL2020-04-13

DEBIAN-CVE-2020-6438

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6438

GoogleCoalition ESS < 30%CRITICAL2020-04-08

Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension.

CVEs:CVE-2020-6438

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

openSUSE-SU-2020:0566-1

Open SourceCoalition ESS < 30%CRITICAL2020-04-30

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2020:0541-1

Open SourceCoalition ESS < 30%CRITICAL2020-04-20

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

CVE-2020-6457

GoogleCoalition ESS < 30%CRITICAL2020-04-16

Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-6457

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2020-6440

Open SourceCoalition ESS < 30%HIGH2020-04-13

DEBIAN-CVE-2020-6440

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6440

GoogleCoalition ESS < 30%HIGH2020-04-08

Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.

CVEs:CVE-2020-6440

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2020-6461

GoogleCoalition ESS < 30%CRITICAL2020-04-28

Use after free in storage in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-6461

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2020-6459

GoogleCoalition ESS < 30%CRITICAL2020-04-22

Use after free in payments in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6459

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2020-6460

GoogleCoalition ESS < 30%MEDIUM2020-04-22

Insufficient data validation in URL formatting in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to perform domain spoofing via a crafted domain name.

CVEs:CVE-2020-6460

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2019-20791

GoogleCoalition ESS < 30%CRITICAL2020-04-28

OpenThread before 2019-12-13 has a stack-based buffer overflow in MeshCoP::Commissioner::GeneratePskc.

CVEs:CVE-2019-20791

Affected products

ProductStatusVendorPackageEcosystem
openthread affected google
Upstream advisory

CVE-2020-11600

Open SourceCoalition ESS < 30%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with Q(10.0) software. There is arbitrary code execution in the Fingerprint Trustlet via a memory overwrite. The Samsung IDs are SVE-2019-16587, SVE-2019-16588, SVE-2019-16589 (April 2020).

CVEs:CVE-2020-11600

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-11603

Open SourceCoalition ESS < 30%CRITICAL2020-04-08

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (incorporating TEEGRIS) software. Type confusion in the MLDAP Trustlet allows arbitrary code execution. The Samsung ID is SVE-2020-16599 (April 2020).

CVEs:CVE-2020-11603

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-7922

Open SourceCoalition ESS < 30%MEDIUM2020-04-09

X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kubernetes cluster improper access to MongoDB instances. Customers who do not use X.509 authentication, and those who do not use the Ope...

CVEs:CVE-2020-7922

Affected products

ProductStatusVendorPackageEcosystem
mongodb_enterprise_kubernetes_operator affected mongodb
Upstream advisory

CVE-2019-15789

Open SourceCoalition ESS < 30%HIGH2020-04-08

Privilege escalation vulnerability in MicroK8s allows a low privilege user with local access to obtain root access to the host by provisioning a privileged container. Fixed in MicroK8s 1.15.3.

CVEs:CVE-2019-15789

Affected products

ProductStatusVendorPackageEcosystem
microk8s affected canonical
Upstream advisory

CVE-2020-0080

Open SourceCoalition ESS < 30%HIGH2020-04-07

In onOpActiveChanged and related methods of AppOpsControllerImpl.java, there is a possible way to display an app overlaying other apps without the notification icon that it's overlaying. This could lead to local escalation of privilege with User execut...

CVEs:CVE-2020-0080

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0067

Open SourceCoalition ESS < 30%MEDIUM2020-04-07

In f2fs_xattr_generic_list of xattr.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not required for exploitation.Prod...

CVEs:CVE-2020-0067

Affected products

ProductStatusVendorPackageEcosystem
android affected google
ubuntu_linux affected canonical
Upstream advisory

CVE-2020-11604

Open SourceCoalition ESS < 30%CRITICAL2020-04-08

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (incorporating TEEGRIS) software. There is an Out-of-bounds read in the MLDAP Trustlet. The Samsung ID is SVE-2019-16565 (April 2020).

CVEs:CVE-2020-11604

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20772

Open SourceCoalition ESS < 30%CRITICAL2020-04-17

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. The Account subsystem allows authorization bypass. The LG ID is LVE-SMP-190007 (August 2019).

CVEs:CVE-2019-20772

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20780

Open SourceCoalition ESS < 30%CRITICAL2020-04-17

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Certain security settings, related to whether packages are verified and accepted only from known sources, are mishandled. The LG ID is LVE-SMP-190002 (Ap...

CVEs:CVE-2019-20780

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20778

Open SourceCoalition ESS < 30%CRITICAL2020-04-17

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. The Backup subsystem does not properly restrict operations or validate their input. The LG ID is LVE-SMP-190004 (June 2019).

CVEs:CVE-2019-20778

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20777

Open SourceCoalition ESS < 30%CRITICAL2020-04-17

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. WapService mishandles OTA Provisioning on V40 and G7 devices. The LG ID is LVE-SMP-190006 (July 2019).

CVEs:CVE-2019-20777

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20782

Open SourceCoalition ESS < 30%CRITICAL2020-04-17

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. LG Advanced Flash (LAF) has a buffer overflow. The LG ID is LVE-SMP-190001 (March 2019).

CVEs:CVE-2019-20782

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-11873

Open SourceCoalition ESS < 30%CRITICAL2020-04-17

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A stack-based buffer overflow in the logging tool could allow an attacker to gain privileges. The LG ID is LVE-SMP-200005 (April 2020).

CVEs:CVE-2020-11873

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-11605

Open SourceCoalition ESS < 30%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is sensitive information exposure from dumpstate in NFC logs. The Samsung ID is SVE-2019-16359 (April 2020).

CVEs:CVE-2020-11605

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20783

Open SourceCoalition ESS < 30%CRITICAL2020-04-17

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 (North America CDMA) software. The LTE protocol implementation allows a bypass of AKA (Authentication and Key Agreement). The LG ID is LVE-SMP-180014 (February 2019).

CVEs:CVE-2019-20783

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-11607

Open SourceCoalition ESS < 30%MEDIUM2020-04-08

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Notification exposure occurs in Lockdown mode because of the Edge Lighting application. The Samsung ID is SVE-2020-16680 (April 2020).

CVEs:CVE-2020-11607

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-11874

Open SourceCoalition ESS < 30%HIGH2020-04-17

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. Attackers can bypass Factory Reset Protection (FRP). The LG ID is LVE-SMP-200004 (March 2020).

CVEs:CVE-2020-11874

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20771

Open SourceCoalition ESS < 30%HIGH2020-04-17

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. WapService allows unconfirmed configuration changes via a modified OMACP message. The LG ID is LVE-SMP-190006 (August 2019).

CVEs:CVE-2019-20771

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-8895

GoogleCoalition ESS < 30%HIGH2020-04-21

Untrusted Search Path vulnerability in the windows installer of Google Earth Pro versions prior to 7.3.3 allows an attacker to insert malicious local files to execute unauthenticated remote code on the targeted system.

CVEs:CVE-2020-8895

Affected products

ProductStatusVendorPackageEcosystem
earth affected google
Upstream advisory

CVE-2020-11875

Open SourceCoalition ESS < 30%HIGH2020-04-17

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10.0 (MTK chipsets) software. The MTK kernel does not properly implement exception handling, allowing an attacker to gain privileges. The LG ID is LVE-SMP-200001 (February ...

CVEs:CVE-2020-11875

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0081

Open SourceCoalition ESS < 30%HIGH2020-04-07

In finalize of AssetManager.java, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2020-0081

Affected products

ProductStatusVendorPackageEcosystem
android affected google
fedora affected fedoraproject
Upstream advisory

CVE-2020-11606

Open SourceCoalition ESS < 30%LOW2020-04-08

An issue was discovered on Samsung mobile devices with Q(10.0) software. Information about application preview (in the Secure Folder) leaks on a locked device. The Samsung ID is SVE-2019-16463 (April 2020).

CVEs:CVE-2020-11606

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0076

Open SourceCoalition ESS < 30%HIGH2020-04-07

In get_auth_result of the FPC IRIS TrustZone app, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2020-0076

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0078

Open SourceCoalition ESS < 30%HIGH2020-04-07

In releaseSecureStops of DrmPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2020-0078

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0079

Open SourceCoalition ESS < 30%HIGH2020-04-07

In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to stale pointer. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: ...

CVEs:CVE-2020-0079

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-11602

Open SourceCoalition ESS < 30%LOW2020-04-08

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Google Assistant leaks clipboard contents on a locked device. The Samsung ID is SVE-2019-16558 (April 2020).

CVEs:CVE-2020-11602

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20770

Open SourceCoalition ESS < 30%CRITICAL2020-04-17

An issue was discovered on LG mobile devices with Android OS 9.0 software. The HAL service has a buffer overflow that leads to arbitrary code execution. The LG ID is LVE-SMP-190013 (September 2019).

CVEs:CVE-2019-20770

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-11601

Open SourceCoalition ESS < 30%MEDIUM2020-04-08

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. There is unauthorized access to applications in the Secure Folder via floating icons. The Samsung ID is SVE-2019-16195 (April 2020).

CVEs:CVE-2020-11601

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2056

Open SourceCoalition ESS < 30%MEDIUM2020-04-07

There is a possible disclosure of RAM using a shared crypto key due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andr...

CVEs:CVE-2019-2056

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20773

Open SourceCoalition ESS < 30%HIGH2020-04-17

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. Unprivileged applications can execute shell commands via the connectivity service. The LG ID is LVE-SMP-190008 (August 2019).

CVEs:CVE-2019-20773

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0075

Open SourceCoalition ESS < 30%MEDIUM2020-04-07

In set_shared_key of the FPC IRIS TrustZone app, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2020-0075

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0077

Open SourceCoalition ESS < 30%MEDIUM2020-04-07

In authorize_enroll of the FPC IRIS TrustZone app, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2020-0077

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20785

Open SourceCoalition ESS < 30%MEDIUM2020-04-17

An issue was discovered on LG mobile devices with Android OS 8.0 and 8.1 software for the DTAG carrier. RILD in the radio layer uses an uninitialized variable. The LG ID is LVE-SMP-180013 (January 2019).

CVEs:CVE-2019-20785

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20774

Open SourceCoalition ESS < 30%MEDIUM2020-04-17

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. A system service allows local retrieval of the user's password. The LG ID is LVE-SMP-190009 (August 2019).

CVEs:CVE-2019-20774

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20784

Open SourceCoalition ESS < 30%MEDIUM2020-04-17

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 (MTK chipsets) software. Interaction of GPS with 911 emergency calls is mishandled. The LG ID is LVE-SMP-180012 (January 2019).

CVEs:CVE-2019-20784

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20779

Open SourceCoalition ESS < 30%HIGH2020-04-17

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. A TrustZone trusted application can crash via crafted input. The LG ID is LVE-SMP-190003 (May 2019).

CVEs:CVE-2019-20779

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20776

Open SourceCoalition ESS < 30%HIGH2020-04-17

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. A TZ trusted application can crash via crafted input. The LG ID is LVE-SMP-190005 (July 2019).

CVEs:CVE-2019-20776

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20775

Open SourceCoalition ESS < 30%HIGH2020-04-17

An issue was discovered on LG mobile devices with Android OS 9.0 (Qualcomm SDM450, SDM845, SM6150, and SM8150 chipsets) software. Weak encryption leads to local information disclosure. The LG ID is LVE-SMP-190010 (August 2019).

CVEs:CVE-2019-20775

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8546

Open SourceEPSS <= 49%HIGH2020-04-10

An issue was discovered on Samsung mobile devices with software through 2015-11-12, affecting the Galaxy S6/S6 Edge, Galaxy S6 Edge+, and Galaxy Note5 with the Shannon333 chipset. There is a stack-based buffer overflow in the baseband process that is e...

CVEs:CVE-2015-8546

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11038

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with software through 2016-04-05 (incorporating the Samsung Professional Audio SDK). The Jack audio service doesn't implement access control for shared memory, leading to arbitrary code execution or pri...

CVEs:CVE-2016-11038

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21050

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.X) (Exynos chipsets) software. There is a Buffer overflow in the esecomm Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2018-12852 (October 2018).

CVEs:CVE-2018-21050

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21051

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Exynos chipsets) software. There is an invalid free in the fingerprint Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2018-12853 (October 2018).

CVEs:CVE-2018-21051

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21055

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with N(7.0) (Qualcomm models using MSM8996 chipsets) software. A device can be rooted with a custom image to execute arbitrary scripts in the INIT context. The Samsung ID is SVE-2018-11940 (September 20...

CVEs:CVE-2018-21055

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21052

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.X) (Exynos chipsets) software. There is incorrect usage of shared memory in the vaultkeeper Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2018-12855 (October 2...

CVEs:CVE-2018-21052

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21072

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) (Exynos chipsets) software. A kernel driver allows out-of-bounds Read/Write operations and possibly arbitrary code execution. The Samsung ID is SVE-2018-11358 (May 2018).

CVEs:CVE-2018-21072

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21089

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) (MT6755/MT6757 Mediatek models) software. Bootloader has an integer overflow that leads to arbitrary code execution via the download offset control. The Samsung ID is SVE-2017-10732 (January...

CVEs:CVE-2018-21089

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21044

Open SourceEPSS <= 49%CRITICAL2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.0) software. The sem Trustlet has a buffer overflow that leads to arbitrary TEE code execution. The Samsung IDs are SVE-2018-13230, SVE-2018-13231, SVE-2018-13232, SVE-2018-13233 (De...

CVEs:CVE-2018-21044

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18652

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. SVoice allows arbitrary code execution by changing dynamic libraries. The Samsung ID is SVE-2017-9299 (September 2017).

CVEs:CVE-2017-18652

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21075

Open SourceEPSS <= 49%CRITICAL2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. The Call+ application can load classes from an unintended path, leading to Code Execution. The Samsung ID is SVE-2017-10886 (April 2018).

CVEs:CVE-2018-21075

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21042

Open SourceEPSS <= 49%CRITICAL2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Dual Messenger allows installation of an arbitrary APK with resultant privileged code execution. The Samsung ID is SVE-2018-13299 (December 2018).

CVEs:CVE-2018-21042

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-5524

Open SourceEPSS <= 49%CRITICAL2020-04-10

An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-05-13. There is a buffer overflow in datablock_write because the amount of received data is not validated. The Samsung ID is SVE-2015-4018 (December 2015).

CVEs:CVE-2015-5524

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21049

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.X) (Exynos chipsets) software. There is an arbitrary memory write in a Trustlet because a secure driver allows access to sensitive APIs. The Samsung ID is SVE-2018-12881 (November 20...

CVEs:CVE-2018-21049

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21063

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.x) (Exynos chipsets) software. Keymaster has an architectural problem because tlApi in TEE is not properly protected. The Samsung ID is SVE-2018-11792 (August 2018).

CVEs:CVE-2018-21063

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21057

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) O(8.x, and P(9.0) (Exynos chipsets) software. There is a stack-based buffer overflow in the Shannon Baseband. The Samsung ID is SVE-2018-12757 (September 2018).

CVEs:CVE-2018-21057

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21066

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with M(6.0) (Exynos or MediaTek chipsets) software. There is a buffer overflow in a Trustlet that can cause memory corruption. The Samsung ID is SVE-2018-11599 (July 2018).

CVEs:CVE-2018-21066

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21090

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with software through 2017-11-03 (S.LSI modem chipsets). The Exynos modem chipset has a baseband buffer overflow. The Samsung ID is SVE-2017-10745 (January 2018).

CVEs:CVE-2018-21090

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11039

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) (AP + CP MDM9x35, or Qualcomm Onechip) software. There is a NULL pointer dereference issue in the IPC socket code. The Samsung ID is SVE-2016-5980 (July 2016).

CVEs:CVE-2016-11039

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21038

Open SourceEPSS <= 49%CRITICAL2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) software. The Secure Folder app's startup logic allows authentication bypass. The Samsung ID is SVE-2018-11628 (December 2018).

CVEs:CVE-2018-21038

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9547

Open SourceEPSS <= 49%HIGH2020-04-10

An issue was discovered on Samsung mobile devices with JBP(4.3) and KK(4.4.2) software. Because the READ_LOGS permission is mishandled, sensitive information is disclosed in a world-readable copy of the log file if the error message is "Unhandled excep...

CVEs:CVE-2015-9547

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21064

Open SourceEPSS <= 49%CRITICAL2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is an array overflow in a driver's input booster. The Samsung ID is SVE-2017-11816 (August 2018).

CVEs:CVE-2018-21064

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21065

Open SourceEPSS <= 49%CRITICAL2020-04-08

An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.x) software. There is an integer underflow in eCryptFS because of a missing size check. The Samsung ID is SVE-2017-11855 (August 2018).

CVEs:CVE-2018-21065

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18683

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. SVoice allows Hare Hunting during application installation. The Samsung ID is SVE-2016-6942 (February 2017).

CVEs:CVE-2017-18683

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18684

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. SVoice allows provider seizure via an application that uses a custom provider. The Samsung ID is SVE-2016-6942 (February 2017).

CVEs:CVE-2017-18684

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18696

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (Exynos7420, Exynos8890, or MSM8996 chipsets) software. RKP allows memory corruption. The Samsung ID is SVE-2016-7897 (January 2017).

CVEs:CVE-2017-18696

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21054

Open SourceEPSS <= 49%CRITICAL2020-04-08

An issue was discovered on Samsung mobile devices with M(6.0), N(7.x) and O(8.x) except exynos9610/9820 in all Platforms, M(6.0) except MSM8909 SC77xx/9830 exynos3470/5420, N(7.0) except MSM8939, N(7.1) except MSM8996 SDM6xx/M6737T software. There is a...

CVEs:CVE-2018-21054

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21087

Open SourceEPSS <= 49%CRITICAL2020-04-08

An issue was discovered on Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software. There is a vnswap heap-based buffer overflow via the store function, with resultant privilege escalation. The Samsung ID is SVE-2017-10599 (January 2018).

CVEs:CVE-2018-21087

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18644

Open SourceEPSS <= 49%CRITICAL2020-04-08

An issue was discovered on Samsung mobile devices with L(5.1), M(6.x), and N(7.x) software. There is a muic_set_reg_sel heap-based buffer overflow during the reading of MUIC register values. The Samsung ID is SVE-2017-10011 (December 2017).

CVEs:CVE-2017-18644

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18645

Open SourceEPSS <= 49%CRITICAL2020-04-08

An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) (Qualcomm chipsets) software. There is a panel_lpm sysfs stack-based buffer overflow. The Samsung ID is SVE-2017-9414 (December 2017).

CVEs:CVE-2017-18645

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18655

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is a stack-based buffer overflow with resultant memory corruption in a trustlet. The Samsung IDs are SVE-2017-8889, SVE-2017-8891, and SVE-2017-8892 (August 2017).

CVEs:CVE-2017-18655

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18660

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is a buffer overflow in tlc_server. The Samsung ID is SVE-2017-8888 (July 2017).

CVEs:CVE-2017-18660

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18661

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is a buffer overflow in process_cipher_tdea. The Samsung ID is SVE-2017-8973 (July 2017).

CVEs:CVE-2017-18661

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18690

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) (Exynos54xx, Exynos7420, Exynos8890, or Exynos8895 chipsets) software. There is a buffer overflow in the sensor hub. The Samsung ID is SVE-2016-7484 (January...

CVEs:CVE-2017-18690

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18691

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (Exynos8890 chipsets) software. There are multiple Buffer Overflows in TSP sysfs cmd_store. The Samsung ID is SVE-2016-7500 (January 2017).

CVEs:CVE-2017-18691

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18693

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. There is a buffer overflow in the fps sysfs entry. The Samsung ID is SVE-2016-7510 (January 2017).

CVEs:CVE-2017-18693

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11025

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with software through 2016-09-13 (Exynos AP chipsets). There is a memcpy heap-based buffer overflow in the OTP service. The Samsung ID is SVE-2016-7114 (December 2016).

CVEs:CVE-2016-11025

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11028

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with software through 2016-09-13 (Exynos AP chipsets). There is a stack-based buffer overflow in the OTP TrustZone trustlet. The Samsung IDs are SVE-2016-7173 and SVE-2016-7174 (December 2016).

CVEs:CVE-2016-11028

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11033

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) software. There is a heap-based buffer overflow in tlc_server. The Samsung IDs are SVE-2016-7220 and SVE-2016-7225 (November 2016).

CVEs:CVE-2016-11033

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11036

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2016-6008 (August 2016).

CVEs:CVE-2016-11036

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21041

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with O(8.x) software. Access to Gallery in the Secure Folder can occur without authentication. The Samsung ID is SVE-2018-13057 (December 2018).

CVEs:CVE-2018-21041

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21088

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can cause a reboot because InputMethodManagerService has an unprotected system service. The Samsung ID is SVE-2017-9995 (January 2018).

CVEs:CVE-2018-21088

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21091

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. Telecom has a System Crash via abnormal exception handling. The Samsung ID is SVE-2017-10906 (January 2018).

CVEs:CVE-2018-21091

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18674

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with N(7.0) software. The time service (aka Timaservice) allows a kernel panic. The Samsung ID is SVE-2017-8593 (May 2017).

CVEs:CVE-2017-18674

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18679

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) software. SLocation can cause a system crash via a call to an API that is not implemented. The Samsung ID is SVE-2017-8285 (April 2017).

CVEs:CVE-2017-18679

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18682

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. Because of incorrect exception handling and an unprotected intent, AudioService can cause a system crash, The Samsung IDs are SVE-2017-8114, SVE-20...

CVEs:CVE-2017-18682

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18685

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. The InputMethod application can cause a system crash via a malformed serializable object in an Intent. The Samsung ID is SVE-2016-7123 (February 2017).

CVEs:CVE-2017-18685

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11026

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. BootReceiver allows attackers to trigger a system crash because of incorrect exception handling. The Samsung ID is SVE-2016-7118 (December 2016).

CVEs:CVE-2016-11026

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11031

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. AntService allows a system_server crash and reboot. The Samsung ID is SVE-2016-7044 (November 2016).

CVEs:CVE-2016-11031

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18650

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with N(7.x) software. There is a WifiStateMachine IllegalArgumentException and reboot if a malformed wpa_supplicant.conf is read. The Samsung ID is SVE-2017-9828 (October 2017).

CVEs:CVE-2017-18650

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18651

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. There is an Integer Overflow in process_M_SetTokenTUIPasswd during handling of a trusted application, leading to memory corruption. The Samsung IDs are SVE-2017-9008 and...

CVEs:CVE-2017-18651

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18663

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with N(7.x) software. Because of missing Intent exception handling, system_server can have a NullPointerException with a crash of a system process. The Samsung IDs are SVE-2017-9122, SVE-2017-9123, SVE-...

CVEs:CVE-2017-18663

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18664

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. There is a NULL pointer exception in PersonManager, causing memory corruption. The Samsung ID is SVE-2017-8286 (June 2017).

CVEs:CVE-2017-18664

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18670

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. android.intent.action.SIOP_LEVEL_CHANGED allows a serializable intent reboot. The Samsung ID is SVE-2017-8363 (May 2017).

CVEs:CVE-2017-18670

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18671

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with L(5.0/5.1), M(6.0), and N(7.x) software. Intents related to Wi-Fi have incorrect exception handling, leading to a crash of system processes. The Samsung ID is SVE-2017-8389 (May 2017).

CVEs:CVE-2017-18671

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18675

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) (Exynos7420 or Exynox8890 chipsets) software. The Camera application can leak uninitialized memory via ion. The Samsung ID is SVE-2016-6989 (April 2017).

CVEs:CVE-2017-18675

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18678

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. An attacker can crash system processes via a Serializable object because of missing exception handling. The Samsung IDs are SVE-2017-8109, SVE-2017...

CVEs:CVE-2017-18678

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21059

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is Clipboard content visibility in the locked state via the emergency contact picker. The Samsung ID is SVE-2018-11806 (September 2018).

CVEs:CVE-2018-21059

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21060

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is a Keyboard learned words leak in the locked state via the emergency contact picker. The Samsung IDs are SVE-2018-11989, SVE-2018-11990 (September 2018).

CVEs:CVE-2018-21060

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21069

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) (MediaTek chipsets) software. There is information disclosure (of kernel stack memory) in a MediaTek driver. The Samsung ID is SVE-2018-11852 (July 2018).

CVEs:CVE-2018-21069

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21079

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), N(7.x), and O(8.0) software. There is a kernel pointer leak in the USB gadget driver. The Samsung ID is SVE-2017-10993 (March 2018).

CVEs:CVE-2018-21079

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21083

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) (Exynos or Qualcomm chipsets) software. There is information disclosure (of a kernel address) via trustonic_tee. The Samsung ID is SVE-2017-11175 (February 2018).

CVEs:CVE-2018-21083

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18643

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. There is information disclosure of the kbase_context address of a GPU memory node. The Samsung ID is SVE-2017-8907 (December 2017).

CVEs:CVE-2017-18643

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18662

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. Data outside of the rkp log buffer boundary is read, causing an information leak. The Samsung ID is SVE-2017-9109 (July 2017).

CVEs:CVE-2017-18662

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18688

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with L(5.1), M(6.0), and N(7.0) software. There is an information disclosure (of memory locations outside a buffer) via /dev/dsm_ctrl_dev. The Samsung ID is SVE-2016-7340 (January 2017).

CVEs:CVE-2017-18688

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21039

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with N(7.0) software. With the Location permission for the compass feature in Quick Tools (aka QuickTools), an attacker can bypass the lockscreen. The Samsung ID is SVE-2018-12053 (December 2018).

CVEs:CVE-2018-21039

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18658

Open SourceEPSS <= 49%MEDIUM2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) software. The multiwindow_facade API allows attackers to cause a NullPointerException and system halt via an attempted screen touch of a non-existing display. The Samsung ID is SVE-2017-9383...

CVEs:CVE-2017-18658

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18659

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. Attackers can crash system processes via a broadcast to AdaptiveDisplayColorService. The Samsung ID is SVE-2017-8290 (July 2017).

CVEs:CVE-2017-18659

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11042

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. There is a SIM Lock bypass. The Samsung ID is SVE-2016-5381 (June 2016).

CVEs:CVE-2016-11042

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18648

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with KK(4.4.x), L(5.x), M(6.x), and N(7.x) software. Arbitrary file read/write operations can occur in the locked state via a crafted MTP command. The Samsung ID is SVE-2017-10086 (November 2017).

CVEs:CVE-2017-18648

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11049

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with software through 2016-01-16 (Shannon333/308/310 chipsets). The IMEI may be retrieved and modified because of an error in managing key information. The Samsung ID is SVE-2016-5435 (March 2016).

CVEs:CVE-2016-11049

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11029

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with L(5.0/5.1), M(6.0), and N(7.0) software. Attackers can read the password of the Mobile Hotspot in the log because of an unprotected intent. The Samsung ID is SVE-2016-7301 (December 2016).

CVEs:CVE-2016-11029

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21081

Open SourceEPSS <= 49%CRITICAL2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) software. In Dual Messenger, the second app can use the runtime permissions of the first app without a user's consent. The Samsung ID is SVE-2017-11018 (March 2018).

CVEs:CVE-2018-21081

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18676

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with N(7.0) (Qualcomm chipsets) software. There is an RKP kernel protection bypass (in which unwanted memory mappings may occur) because of a lack of MSR trapping. The Samsung ID is SVE-2016-7901 (April...

CVEs:CVE-2017-18676

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21047

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with O(8.x) software. There is a Factory Reset Protection (FRP) bypass via the voice assistant because Internet access begins before the Setup Wizard finishes. The Samsung ID is SVE-2018-12894 (November...

CVEs:CVE-2018-21047

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21078

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) software. The Contacts application allows attackers to originate video calls because SS (Supplementary Service) and USSD (Unstructured Supplementary Service Data) codes a...

CVEs:CVE-2018-21078

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11034

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. The decode function in Qjpeg in Qt 5.7 allows attackers to trigger a system crash via a malformed image. The Samsung ID is SVE-2016-6560 (October 2016).

CVEs:CVE-2016-11034

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11046

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with JBP(4.3), KK(4.4), and L(5.0/5.1) software. Because of a misused whitelist, attackers can reach the radio layer (aka RIL or RILD) to place calls or send SMS messages. The Samsung ID is SVE-2016-573...

CVEs:CVE-2016-11046

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9546

Open SourceEPSS <= 49%HIGH2020-04-10

An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTTP is used for an Inputmethod, rather than HTTPS. A man-in-the-middle attacker can modify the client-server data stream to insert dir...

CVEs:CVE-2015-9546

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21067

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with M(6.0) software. There is an information disclosure in a Trustlet because an address is logged. The Samsung ID is SVE-2018-11600 (July 2018).

CVEs:CVE-2018-21067

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18656

Open SourceEPSS <= 49%MEDIUM2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is a buffer over-read in a trustlet. The Samsung ID is SVE-2017-8890 (August 2017).

CVEs:CVE-2017-18656

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18686

Open SourceEPSS <= 49%MEDIUM2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) software. Contact information can leak to a log file because of the broadcasting of an unprotected intent. The Samsung ID is SVE-2016-7180 (February 2017).

CVEs:CVE-2017-18686

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18687

Open SourceEPSS <= 49%MEDIUM2020-04-07

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. An attacker can obtain the full pathnames of sdcard files by reading the system protected log upon reception of a certain intent. The Samsung ID is...

CVEs:CVE-2017-18687

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18694

Open SourceEPSS <= 49%MEDIUM2020-04-07

An issue was discovered on Samsung mobile devices with software through 2016-10-25 (Exynos5 chipsets). Attackers can read kernel addresses in the log because an incorrect format specifier is used. The Samsung ID is SVE-2016-7551 (January 2017).

CVEs:CVE-2017-18694

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18666

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. Applications can send arbitrary premium SMS messages. The Samsung ID is SVE-2017-8701 (June 2017).

CVEs:CVE-2017-18666

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18668

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) software. Attackers can prevent users from making outbound calls and sending outbound text messages. The Samsung ID is SVE-2017-8706 (June 2017).

CVEs:CVE-2017-18668

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18669

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with N(7.x) software. Persona has an unprotected API that allows launch of any activity with system privileges. The Samsung ID is SVE-2017-9000 (June 2017).

CVEs:CVE-2017-18669

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18677

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. Because of an unprotected Intent, an attacker can reset the configuration of certain applications. The Samsung ID is SVE-2016-7142 (April 2017).

CVEs:CVE-2017-18677

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18695

Open SourceEPSS <= 49%MEDIUM2020-04-07

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. Attackers (who control a certain subdomain) can discover a user's credentials, during an email account login, via an EAS autodiscover packet. The S...

CVEs:CVE-2017-18695

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21085

Open SourceEPSS <= 49%CRITICAL2020-04-08

An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is a race condition with a resultant use-after-free in vnswap_deinit_backing_storage. The Samsung ID is SVE-2017-11176 (February 2018).

CVEs:CVE-2018-21085

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21086

Open SourceEPSS <= 49%CRITICAL2020-04-08

An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is a race condition with a resultant double free in vnswap_init_backing_storage. The Samsung ID is SVE-2017-11177 (February 2018).

CVEs:CVE-2018-21086

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21071

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with M(6.0) software. Because of an unprotected intent, an attacker can read arbitrary files and emails, and take over an email account. The Samsung ID is SVE-2018-11633 (May 2018).

CVEs:CVE-2018-21071

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21040

Open SourceEPSS <= 49%CRITICAL2020-04-08

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 9810 chipsets) software. There is a race condition with a resultant use-after-free in the g2d driver. The Samsung ID is SVE-2018-12959 (December 2018).

CVEs:CVE-2018-21040

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21084

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with L(5.1), M(6.0), and N(7.x) software. There is a race condition with a resultant read-after-free issue in get_kek. The Samsung ID is SVE-2017-11174 (February 2018).

CVEs:CVE-2018-21084

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18647

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with M(6,x) and N(7.0) software. The TA Scrypto v1.0 implementation in Secure Driver has a race condition with a resultant buffer overflow. The Samsung IDs are SVE-2017-8973, SVE-2017-8974, and SVE-2017...

CVEs:CVE-2017-18647

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18692

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (MSM8939, MSM8996, MSM8998, Exynos7580, Exynos8890, or Exynos8895 chipsets) software. There is a race condition, with a resultant buffer overflow, in the sec_ts touchscreen sysfs ...

CVEs:CVE-2017-18692

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11030

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) (with Hrm sensor support) software. The sysfs of the MAX86902 sensor driver does not prevent concurrent access, leading to a race condition and resultant heap-based ...

CVEs:CVE-2016-11030

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18657

Open SourceEPSS <= 49%MEDIUM2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is an arbitrary write in a trustlet. The Samsung ID is SVE-2017-8893 (August 2017).

CVEs:CVE-2017-18657

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11032

Open SourceEPSS <= 49%MEDIUM2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) software. An attacker can disable all Sound functionality by broadcasting an unprotected intent. The Samsung IDs are SVE-2016-7179 and SVE-2016-7182 (November 2016).

CVEs:CVE-2016-11032

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18667

Open SourceEPSS <= 49%MEDIUM2020-04-07

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. Attackers can prevent users from learning that SMS storage space has been exhausted. The Samsung ID is SVE-2017-8702 (June 2017).

CVEs:CVE-2017-18667

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11045

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with L(5.0/5.1) software. The Gallery library allow memory corruption via a malformed image. The Samsung ID is SVE-2016-5317 (May 2016).

CVEs:CVE-2016-11045

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11052

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with L(5.0/5.1) software. je_free in libQjpeg.so in Qjpeg in Qt 5.5 allows memory corruption via a malformed JPEG file. The Samsung ID is SVE-2015-5110 (January 2016).

CVEs:CVE-2016-11052

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18649

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can boot a device with root privileges because the bootloader for the Qualcomm MSM8998 chipset lacks an integrity check of the system image, aka the "SamFAIL" issue. Th...

CVEs:CVE-2017-18649

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21058

Open SourceEPSS <= 49%CRITICAL2020-04-08

An issue was discovered on Samsung mobile devices with N(7.0), O(8.0) (exynos7420 or Exynos 8890/8996 chipsets) software. Cache attacks can occur against the Keymaster AES-GCM implementation because T-Tables are used; the Cryptography Extension (CE) is...

CVEs:CVE-2018-21058

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18653

Open SourceEPSS <= 49%MEDIUM2020-04-07

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. The Email application allows attackers to send emails on behalf of any user via a broadcasted intent. The Samsung ID is SVE-2017-9357 (September 20...

CVEs:CVE-2017-18653

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18654

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0, 7.1) software. An unauthenticated attacker can register a new security certificate. The Samsung ID is SVE-2017-9659 (September 2017).

CVEs:CVE-2017-18654

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18689

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (Exynos5433, Exynos7420, or Exynos7870 chipsets) software. An attacker can bypass a ko (aka Kernel Module) signature by modifying the count of kernel modules. The Samsung ID is SV...

CVEs:CVE-2017-18689

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18665

Open SourceEPSS <= 49%CRITICAL2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) software. There is a NULL pointer exception in WifiService via adb-cmd, causing memory corruption. The Samsung ID is SVE-2017-8287 (June 2017).

CVEs:CVE-2017-18665

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11043

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) software. The S/MIME implementation in EAS uses DES (where 3DES is intended). The Samsung ID is SVE-2016-5871 (June 2016).

CVEs:CVE-2016-11043

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21092

Open SourceEPSS <= 49%MEDIUM2020-04-08

An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. A crafted AT command may be sent by the DeviceTest application via an NFC tag. The Samsung ID is SVE-2017-10885 (January 2018).

CVEs:CVE-2018-21092

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21068

Open SourceEPSS <= 49%MEDIUM2020-04-08

An issue was discovered on Samsung mobile devices with O(8.0) software. Execution of an application in a locked Secure Folder can occur without a password via a split screen. The Samsung ID is SVE-2018-11669 (July 2018).

CVEs:CVE-2018-21068

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21062

Open SourceEPSS <= 49%MEDIUM2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. When biometric authentication is disabled, an attacker can view Streams content (e.g., a Gallery slideshow) of a locked Secure Folder via a connection to an external dev...

CVEs:CVE-2018-21062

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21053

Open SourceEPSS <= 49%MEDIUM2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is Clipboard access in the lockscreen state via a physical keyboard. The Samsung ID is SVE-2018-12684 (October 2018).

CVEs:CVE-2018-21053

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21056

Open SourceEPSS <= 49%MEDIUM2020-04-08

An issue was discovered on Samsung mobile devices with O(8.x) software. The Smartwatch displays Secure Folder Notification content. The Samsung ID is SVE-2018-12458 (September 2018).

CVEs:CVE-2018-21056

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21048

Open SourceEPSS <= 49%MEDIUM2020-04-08

An issue was discovered on Samsung mobile devices with O(8.x) software. There is a Notification leak on a locked device in Standalone Dex mode. The Samsung ID is SVE-2018-12925 (November 2018).

CVEs:CVE-2018-21048

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21045

Open SourceEPSS <= 49%MEDIUM2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is Clipboard access in the lockscreen state via a copy-and-paste action. The Samsung ID is SVE-2018-13381 (December 2018).

CVEs:CVE-2018-21045

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21073

Open SourceEPSS <= 49%LOW2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.0) (Galaxy S9+, Galaxy S9, Galaxy S8+, Galaxy S8, Note 8). There is access to Clipboard content in the locked state via the Edge panel. The Samsung ID is SVE-2017-10748 (May 2018).

CVEs:CVE-2018-21073

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21077

Open SourceEPSS <= 49%LOW2020-04-08

An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.x) software. There is a Clipboard content disclosure in the locked state because the keyboard may be used during an emergency call. The Samsung ID is SVE-2017-11107 (April 2...

CVEs:CVE-2018-21077

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11027

Open SourceEPSS <= 49%LOW2020-04-07

An issue was discovered on Samsung mobile devices with M(6.0) software. In the Shade Locked state, a physically proximate attacker can read notifications on the lock screen. The Samsung ID is SVE-2016-7132 (December 2016).

CVEs:CVE-2016-11027

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11041

Open SourceEPSS <= 49%MEDIUM2020-04-07

An issue was discovered on Samsung mobile devices with KK(4.4) software. Attackers can bypass the lockscreen by sending an AT command over USB. The Samsung ID is SVE-2015-5301 (June 2016).

CVEs:CVE-2016-11041

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18680

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (tablets) software. The lockscreen interface allows Add User actions, leading to an unintended ability to access user data in external storage. The Samsung ID is SVE-2016-7797...

CVEs:CVE-2017-18680

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21082

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) software. Dex Station allows App Pinning bypass and lock-screen bypass via the "Use screen lock type to unpin" option. The Samsung ID is SVE-2017-11106 (February 2018).

CVEs:CVE-2018-21082

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11047

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with JBP(4.2) and KK(4.4) (Marvell chipsets) software. The ACIPC-MSOCKET driver allows local privilege escalation via a stack-based buffer overflow. The Samsung ID is SVE-2016-5393 (April 2016).

CVEs:CVE-2016-11047

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21061

Open SourceEPSS <= 49%MEDIUM2020-04-08

An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) software. A fake charger can execute critical functions in the locked state. The Samsung ID is SVE-2016-6341 (August 2018).

CVEs:CVE-2018-21061

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21076

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) (Exynos8890/8895 chipsets) software. There is information disclosure (a KASLR offset) in the Secure Driver via a modified trustlet. The Samsung ID is SVE-2017-10987 (April 2018).

CVEs:CVE-2018-21076

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21046

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with O(8.x) software. There is clipboard Data Exposure via the Emergency Dialer upon connecting a USB device. The Samsung ID is SVE-2018-12911 (November 2018).

CVEs:CVE-2018-21046

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11040

Open SourceEPSS <= 49%MEDIUM2020-04-07

An issue was discovered on Samsung mobile devices with L(5.0/5.1) (with USB OTG MyFile2014_L_ESS support) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2015-5068 (June 2016).

CVEs:CVE-2016-11040

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11048

Open SourceEPSS <= 49%MEDIUM2020-04-07

An issue was discovered on Samsung mobile devices with L(5.0/5.1) (Spreadtrum or Marvell chipsets) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2016-5421 (March 2016).

CVEs:CVE-2016-11048

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11053

Open SourceEPSS <= 49%MEDIUM2020-04-07

An issue was discovered on Samsung mobile devices with software through 2015-11-11 (supporting FRP/RL). There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2015-5131 (January 2016).

CVEs:CVE-2016-11053

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21070

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x), O(8.0) devices (MSM8998 or SDM845 chipsets) software. An attacker can bypass Secure Boot and obtain root access because of a missing Bootloader integrity check. The Samsung ID is SVE-2018-1...

CVEs:CVE-2018-21070

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18673

Open SourceEPSS <= 49%LOW2020-04-07

An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can disable the Location service on a locked device, making it impossible for the rightful owner to find a stolen device. The Samsung ID is SVE-2017-8524 (May 2017).

CVEs:CVE-2017-18673

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21074

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with M(6.x) (Exynos or Qualcomm chipsets) software. There is information disclosure from a Trustlet via the debug log. The Samsung ID is SVE-2017-10638 (April 2018).

CVEs:CVE-2018-21074

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21043

Open SourceEPSS <= 49%HIGH2020-04-08

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 9810 chipsets) software. There is information disclosure about a kernel pointer in the g2d_drv driver because of logging. The Samsung ID is SVE-2018-13035 (December 2018).

CVEs:CVE-2018-21043

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18646

Open SourceEPSS <= 49%MEDIUM2020-04-08

An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. An attacker can bypass the password requirement for tablet user switching by folding the magnetic cover. The Samsung ID is SVE-2017-10602 (December 2017).

CVEs:CVE-2017-18646

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11035

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with software through 2016-05-27 (Exynos AP chipsets). A local graphics user can cause a Kernel Crash via the fb0(DECON) frame buffer interface. The Samsung ID is SVE-2016-7011 (October 2016).

CVEs:CVE-2016-11035

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18672

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with L(5.0/5.1), M(6.0), and N(7.x) software. Because of incorrect exception handling for Intents, a local attacker can force a reboot within framework.jar. The Samsung ID is SVE-2017-8390 (May 2017).

CVEs:CVE-2017-18672

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-21080

Open SourceEPSS <= 49%MEDIUM2020-04-08

An issue was discovered on Samsung mobile devices with N(7.x) software. A physically proximate attacker wielding a magnet can activate NFC to bypass the lockscreen. The Samsung ID is SVE-2017-10897 (March 2018).

CVEs:CVE-2018-21080

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-11044

Open SourceEPSS <= 49%HIGH2020-04-07

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (with Fingerprint support) software. The check of an application's signature can be bypassed during installation. The Samsung ID is SVE-2016-5923 (June 2016).

CVEs:CVE-2016-11044

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ALEA-2020:1711

GoogleAll remainingHIGH2020-04-28

new module: maven:3.6

Affected products

ProductStatusVendorPackageEcosystem
aopalliance affected AlmaLinux:8 aopalliance
apache-commons-cli affected AlmaLinux:8 apache-commons-cli
apache-commons-codec affected AlmaLinux:8 apache-commons-codec
apache-commons-io affected AlmaLinux:8 apache-commons-io
apache-commons-lang3 affected AlmaLinux:8 apache-commons-lang3
atinject affected AlmaLinux:8 atinject
cdi-api affected AlmaLinux:8 cdi-api
geronimo-annotation affected AlmaLinux:8 geronimo-annotation
google-guice affected AlmaLinux:8 google-guice
guava affected AlmaLinux:8 guava
httpcomponents-core affected AlmaLinux:8 httpcomponents-core
jansi affected AlmaLinux:8 jansi
jcl-over-slf4j affected AlmaLinux:8 jcl-over-slf4j
jsoup affected AlmaLinux:8 jsoup
jsr-305 affected AlmaLinux:8 jsr-305
maven-resolver affected AlmaLinux:8 maven-resolver
maven-shared-utils affected AlmaLinux:8 maven-shared-utils
maven-wagon affected AlmaLinux:8 maven-wagon
plexus-cipher affected AlmaLinux:8 plexus-cipher
plexus-classworlds affected AlmaLinux:8 plexus-classworlds
plexus-containers-component-annotations affected AlmaLinux:8 plexus-containers-component-annotations
plexus-interpolation affected AlmaLinux:8 plexus-interpolation
plexus-sec-dispatcher affected AlmaLinux:8 plexus-sec-dispatcher
plexus-utils affected AlmaLinux:8 plexus-utils
sisu affected AlmaLinux:8 sisu
slf4j affected AlmaLinux:8 slf4j
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.