Advisories
Open SourceExploitedCISA KEV listedHIGH2020-07-21
Security update for SUSE Manager Client Tools
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| dracut-saltboot |
affected |
SUSE:Manager Client Tools 15 |
dracut-saltboot |
— |
| golang-github-prometheus-prometheus |
affected |
SUSE:Manager Client Tools 15 |
golang-github-prometheus-prometheus |
— |
| grafana |
affected |
SUSE:Manager Client Tools 15 |
grafana |
— |
| koan |
affected |
SUSE:Manager Client Tools 15 |
koan |
— |
| mgr-cfg |
affected |
SUSE:Manager Client Tools 15 |
mgr-cfg |
— |
| mgr-custom-info |
affected |
SUSE:Manager Client Tools 15 |
mgr-custom-info |
— |
| mgr-daemon |
affected |
SUSE:Manager Client Tools 15 |
mgr-daemon |
— |
| mgr-osad |
affected |
SUSE:Manager Client Tools 15 |
mgr-osad |
— |
| mgr-push |
affected |
SUSE:Manager Client Tools 15 |
mgr-push |
— |
| mgr-virtualization |
affected |
SUSE:Manager Client Tools 15 |
mgr-virtualization |
— |
| rhnlib |
affected |
SUSE:Manager Client Tools 15 |
rhnlib |
— |
| spacecmd |
affected |
SUSE:Manager Client Tools 15 |
spacecmd |
— |
| spacewalk-client-tools |
affected |
SUSE:Manager Client Tools 15 |
spacewalk-client-tools |
— |
| spacewalk-koan |
affected |
SUSE:Manager Client Tools 15 |
spacewalk-koan |
— |
| spacewalk-oscap |
affected |
SUSE:Manager Client Tools 15 |
spacewalk-oscap |
— |
| spacewalk-remote-utils |
affected |
SUSE:Manager Client Tools 15 |
spacewalk-remote-utils |
— |
| supportutils-plugin-susemanager-client |
affected |
SUSE:Manager Client Tools 15 |
supportutils-plugin-susemanager-client |
— |
| suseRegisterInfo |
affected |
SUSE:Manager Client Tools 15 |
suseRegisterInfo |
— |
| uyuni-base |
affected |
SUSE:Manager Client Tools 15 |
uyuni-base |
— |
| uyuni-common-libs |
affected |
SUSE:Manager Client Tools 15 |
uyuni-common-libs |
— |
| zypp-plugin-spacewalk |
affected |
SUSE:Manager Client Tools 15 |
zypp-plugin-spacewalk |
— |
Open SourceExploitedCISA KEV listedHIGH2020-07-21
Security update for SUSE Manager Client Tools
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cobbler |
affected |
SUSE:OpenStack Cloud 8 |
cobbler |
— |
| cobbler |
affected |
SUSE:HPE Helion OpenStack 8 |
cobbler |
— |
| cobbler |
affected |
SUSE:OpenStack Cloud 9 |
cobbler |
— |
| cobbler |
affected |
SUSE:Manager Client Tools 12 |
cobbler |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise Server 12 SP5 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:OpenStack Cloud 9 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:OpenStack Cloud Crowbar 8 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:OpenStack Cloud Crowbar 9 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise Server for SAP Applications 12 SP5 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Manager Client Tools 12 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise Server for SAP Applications 12 SP4 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise Server 12 SP3-LTSS |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise Server 12 SP3-BCL |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise Server 12 SP4-LTSS |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:HPE Helion OpenStack 8 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:OpenStack Cloud 8 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-prometheus |
affected |
SUSE:Manager Client Tools 12 |
golang-github-prometheus-prometheus |
— |
| grafana |
affected |
SUSE:Manager Client Tools 12 |
grafana |
— |
| mgr-cfg |
affected |
SUSE:Manager Client Tools 12 |
mgr-cfg |
— |
| mgr-custom-info |
affected |
SUSE:Manager Client Tools 12 |
mgr-custom-info |
— |
| mgr-daemon |
affected |
SUSE:Manager Client Tools 12 |
mgr-daemon |
— |
| mgr-osad |
affected |
SUSE:Manager Client Tools 12 |
mgr-osad |
— |
| mgr-push |
affected |
SUSE:Manager Client Tools 12 |
mgr-push |
— |
| mgr-virtualization |
affected |
SUSE:Manager Client Tools 12 |
mgr-virtualization |
— |
| rhnlib |
affected |
SUSE:Manager Client Tools 12 |
rhnlib |
— |
| spacecmd |
affected |
SUSE:Manager Client Tools 12 |
spacecmd |
— |
| spacewalk-client-tools |
affected |
SUSE:Manager Client Tools 12 |
spacewalk-client-tools |
— |
| spacewalk-koan |
affected |
SUSE:Manager Client Tools 12 |
spacewalk-koan |
— |
| spacewalk-oscap |
affected |
SUSE:Manager Client Tools 12 |
spacewalk-oscap |
— |
| spacewalk-remote-utils |
affected |
SUSE:Manager Client Tools 12 |
spacewalk-remote-utils |
— |
| supportutils-plugin-susemanager-client |
affected |
SUSE:Manager Client Tools 12 |
supportutils-plugin-susemanager-client |
— |
| suseRegisterInfo |
affected |
SUSE:Manager Client Tools 12 |
suseRegisterInfo |
— |
| uyuni-base |
affected |
SUSE:Manager Client Tools 12 |
uyuni-base |
— |
| uyuni-common-libs |
affected |
SUSE:Manager Client Tools 12 |
uyuni-common-libs |
— |
| zypp-plugin-spacewalk |
affected |
SUSE:Manager Client Tools 12 |
zypp-plugin-spacewalk |
— |
Open SourceWeaponized exploitCRITICAL2020-07-22
DEBIAN-CVE-2020-6507
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceWeaponized exploit2020-07-01
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:10 |
chromium |
— |
Open SourceWeaponized exploitCRITICAL2020-07-26
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP1 |
chromium |
— |
Open SourceWeaponized exploitCRITICAL2020-07-23
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP2 |
chromium |
— |
Open SourceWeaponized exploitMEDIUM2020-07-22
DEBIAN-CVE-2020-6519
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceWeaponized exploitCRITICAL2020-07-20
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
openSUSE:Leap 15.1 |
chromium |
— |
GoogleWeaponized exploit2020-07-20
CVEs:CVE-2020-6519
GoogleWeaponized exploitMEDIUM2020-07-20
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVEs:CVE-2020-6519
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
Open SourceWeaponized exploitCRITICAL2020-07-20
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
openSUSE:Leap 15.2 |
chromium |
— |
Open SourceWeaponized exploitMEDIUM2020-07-22
DEBIAN-CVE-2020-6514
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| firefox-esr |
affected |
Debian:11 |
firefox-esr |
— |
| firefox-esr |
affected |
Debian:12 |
firefox-esr |
— |
| firefox-esr |
affected |
Debian:13 |
firefox-esr |
— |
| firefox-esr |
affected |
Debian:14 |
firefox-esr |
— |
| thunderbird |
affected |
Debian:11 |
thunderbird |
— |
| thunderbird |
affected |
Debian:12 |
thunderbird |
— |
| thunderbird |
affected |
Debian:13 |
thunderbird |
— |
| thunderbird |
affected |
Debian:14 |
thunderbird |
— |
GoogleWeaponized exploitMEDIUM2020-07-20
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
CVEs:CVE-2020-6514
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| leap |
affected |
opensuse |
— |
— |
| safari |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
| watchos |
affected |
apple |
— |
— |
GoogleWeaponized exploit2020-07-20
CVEs:CVE-2020-6514
GoogleWeaponized exploitHIGH2020-07-07
CVEs:CVE-2020-0230
Open SourceWeaponized exploitCRITICAL2020-07-07
There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid ID: A-156337262
CVEs:CVE-2020-0230
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleWeaponized exploitCRITICAL2020-07-01
ASB-A-156337262
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourcePoC exploitCRITICAL2020-07-22
DEBIAN-CVE-2020-8559
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
Debian:11 |
kubernetes |
— |
| kubernetes |
affected |
Debian:12 |
kubernetes |
— |
| kubernetes |
affected |
Debian:13 |
kubernetes |
— |
| kubernetes |
affected |
Debian:14 |
kubernetes |
— |
Open SourcePoC exploitMEDIUM2020-07-22
Privilege Escalation in Kubernetes
CVEs:CVE-2020-8559
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| apimachinery |
affected |
k8s.io |
k8s.io/apimachinery |
— |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitCRITICAL2020-07-22
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise t...
CVEs:CVE-2020-8559
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
kubernetes |
— |
— |
Open SourcePoC exploitMEDIUM2020-07-22
Privilege Escalation in Kubernetes
CVEs:CVE-2020-8559
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| apimachinery |
affected |
k8s.io |
k8s.io/apimachinery |
— |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitMEDIUM2020-07-22
DEBIAN-CVE-2020-6516
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GooglePoC exploitMEDIUM2020-07-20
Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2020-6516
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GooglePoC exploit2020-07-20
CVEs:CVE-2020-6516
Open SourcePoC exploitCRITICAL2020-07-22
DEBIAN-CVE-2020-6506
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourcePoC exploitHIGH2020-07-27
DEBIAN-CVE-2020-8558
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
Debian:11 |
kubernetes |
— |
| kubernetes |
affected |
Debian:12 |
kubernetes |
— |
| kubernetes |
affected |
Debian:13 |
kubernetes |
— |
| kubernetes |
affected |
Debian:14 |
kubernetes |
— |
Open SourcePoC exploitHIGH2020-07-27
The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's n...
CVEs:CVE-2020-8558
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
kubernetes |
— |
— |
Open SourcePoC exploitHIGH2020-07-27
Improper Authentication in Kubernetes
CVEs:CVE-2020-8558
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitHIGH2020-07-15
Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| containerd |
affected |
SUSE:Linux Enterprise Module for Containers 15 SP2 |
containerd |
— |
| docker |
affected |
SUSE:Linux Enterprise Module for Containers 15 SP2 |
docker |
— |
| docker-runc |
affected |
SUSE:Linux Enterprise Module for Containers 15 SP2 |
docker-runc |
— |
| golang-github-docker-libnetwork |
affected |
SUSE:Linux Enterprise Module for Containers 15 SP2 |
golang-github-docker-libnetwork |
— |
GooglePoC exploitHIGH2020-07-07
CVEs:CVE-2020-0225
Open SourcePoC exploitHIGH2020-07-07
In a2dp_vendor_ldac_decoder_decode_packet of a2dp_vendor_ldac_decoder.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction i...
CVEs:CVE-2020-0225
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitNONE2020-07-01
ASB-A-148588557
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
GooglePoC exploitHIGH2020-07-09
Improper Authorization in Google OAuth Client
CVEs:CVE-2020-7692
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| com.google.oauth-client:google-oauth-client |
affected |
Maven |
com.google.oauth-client:google-oauth-client |
— |
GooglePoC exploitCRITICAL2020-07-09
PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorizati...
CVEs:CVE-2020-7692
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| oauth_client_library_for_java |
affected |
google |
— |
— |
GooglePoC exploitCRITICAL2020-07-09
DEBIAN-CVE-2020-7692
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google-oauth-client-java |
affected |
Debian:11 |
google-oauth-client-java |
— |
| google-oauth-client-java |
affected |
Debian:12 |
google-oauth-client-java |
— |
| google-oauth-client-java |
affected |
Debian:13 |
google-oauth-client-java |
— |
| google-oauth-client-java |
affected |
Debian:14 |
google-oauth-client-java |
— |
GooglePoC exploitMEDIUM2020-07-29
The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type...
CVEs:CVE-2020-8553
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ingress-nginx |
affected |
kubernetes |
— |
— |
Open SourcePoC exploitMEDIUM2020-07-29
ingress-nginx component for Kubernetes allows file overwrite
CVEs:CVE-2020-8553
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ingress-nginx |
affected |
k8s.io |
k8s.io/ingress-nginx |
— |
Open SourcePoC exploitMEDIUM2020-07-23
DEBIAN-CVE-2020-8557
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
Debian:11 |
kubernetes |
— |
| kubernetes |
affected |
Debian:12 |
kubernetes |
— |
| kubernetes |
affected |
Debian:13 |
kubernetes |
— |
| kubernetes |
affected |
Debian:14 |
kubernetes |
— |
Open SourcePoC exploitMEDIUM2020-07-23
Denial of service in Kubernetes
CVEs:CVE-2020-8557
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes/pkg/kubelet |
affected |
k8s.io |
k8s.io/kubernetes/pkg/kubelet |
— |
Open SourcePoC exploitMEDIUM2020-07-23
Denial of service in Kubernetes
CVEs:CVE-2020-8557
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes/pkg/kubelet |
affected |
k8s.io |
k8s.io/kubernetes/pkg/kubelet |
— |
Open SourcePoC exploitMEDIUM2020-07-23
The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet evi...
CVEs:CVE-2020-8557
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
kubernetes |
— |
— |
GooglePoC exploitHIGH2020-07-01
ASB-A-153715664
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
Open SourcePoC exploitHIGH2020-07-07
In createWithSurfaceParent of Client.cpp, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege in the graphics server with no additional execution privileges needed. User interaction is not nee...
CVEs:CVE-2020-0226
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2020-07-07
CVEs:CVE-2020-0226
Open SourcePoC exploitHIGH2020-07-07
In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing background data usage or launching from the background, with no addi...
CVEs:CVE-2020-0227
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2020-07-07
CVEs:CVE-2020-0227
GoogleCoalition ESS < 30%CRITICAL2020-07-28
Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6541
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-07-28
CVEs:CVE-2020-6541
GoogleCoalition ESS < 30%HIGH2020-07-01
ASB-A-130373736
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-07-22
DEBIAN-CVE-2020-6513
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2020-07-20
Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVEs:CVE-2020-6513
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-07-20
CVEs:CVE-2020-6513
Open SourceCoalition ESS < 30%HIGH2020-07-22
DEBIAN-CVE-2020-6512
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2020-07-20
Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6512
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-07-20
CVEs:CVE-2020-6512
Open SourceCoalition ESS < 30%MEDIUM2020-07-17
CVE-2020-15586 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
GoogleCoalition ESS < 30%MEDIUM2020-07-17
CVEs:CVE-2020-15586
GoogleCoalition ESS < 30%MEDIUM2020-07-17
Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the same time.
CVEs:CVE-2020-15586
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cf-deployment |
affected |
cloudfoundry |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| go |
affected |
golang |
— |
— |
| leap |
affected |
opensuse |
— |
— |
| routing-release |
affected |
cloudfoundry |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-07-17
DEBIAN-CVE-2020-15586
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-07-22
DEBIAN-CVE-2020-6524
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2020-07-20
Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6524
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-07-20
CVEs:CVE-2020-6524
Open SourceCoalition ESS < 30%CRITICAL2020-07-22
DEBIAN-CVE-2020-6517
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2020-07-20
Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6517
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-07-20
CVEs:CVE-2020-6517
Open SourceCoalition ESS < 30%CRITICAL2020-07-22
DEBIAN-CVE-2020-6523
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2020-07-20
Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6523
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-07-20
CVEs:CVE-2020-6523
Open SourceCoalition ESS < 30%CRITICAL2020-07-22
DEBIAN-CVE-2020-6520
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2020-07-20
Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6520
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-07-20
CVEs:CVE-2020-6520
GoogleCoalition ESS < 30%HIGH2020-07-01
ASB-A-130374366
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-07-22
DEBIAN-CVE-2020-6518
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2020-07-20
CVEs:CVE-2020-6518
GoogleCoalition ESS < 30%HIGH2020-07-20
Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6518
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-07-22
DEBIAN-CVE-2020-6515
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2020-07-20
CVEs:CVE-2020-6515
GoogleCoalition ESS < 30%HIGH2020-07-20
Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6515
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-07-02
RCE vulnerability in ElasticBox Jenkins Kubernetes CI/CD Plugin
CVEs:CVE-2020-2211
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| com.elasticbox.jenkins-ci.plugins:kubernetes-ci |
affected |
Maven |
com.elasticbox.jenkins-ci.plugins:kubernetes-ci |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-07-02
Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
CVEs:CVE-2020-2211
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes_ci |
affected |
jenkins |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-07-22
DEBIAN-CVE-2020-6533
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2020-07-20
Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6533
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%2020-07-20
CVEs:CVE-2020-6533
Open SourceCoalition ESS < 30%CRITICAL2020-07-22
DEBIAN-CVE-2020-6534
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2020-07-20
Heap buffer overflow in WebRTC in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6534
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%2020-07-20
CVEs:CVE-2020-6534
Open SourceCoalition ESS < 30%CRITICAL2020-07-22
DEBIAN-CVE-2020-6525
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2020-07-20
Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6525
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%2020-07-20
CVEs:CVE-2020-6525
Open SourceCoalition ESS < 30%MEDIUM2020-07-17
CVE-2020-14039 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
GoogleCoalition ESS < 30%MEDIUM2020-07-17
CVEs:CVE-2020-14039
GoogleCoalition ESS < 30%MEDIUM2020-07-17
In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete.
CVEs:CVE-2020-14039
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
| leap |
affected |
opensuse |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-07-22
DEBIAN-CVE-2020-6526
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%2020-07-20
CVEs:CVE-2020-6526
GoogleCoalition ESS < 30%MEDIUM2020-07-20
Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVEs:CVE-2020-6526
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-07-22
DEBIAN-CVE-2020-6521
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%2020-07-20
CVEs:CVE-2020-6521
GoogleCoalition ESS < 30%HIGH2020-07-20
Side-channel information leakage in autofill in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVEs:CVE-2020-6521
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-07-22
DEBIAN-CVE-2020-6511
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
GoogleCoalition ESS < 30%2020-07-20
CVEs:CVE-2020-6511
GoogleCoalition ESS < 30%HIGH2020-07-20
Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2020-6511
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-07-22
DEBIAN-CVE-2020-6522
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2020-07-20
Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2020-6522
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%2020-07-20
CVEs:CVE-2020-6522
Open SourceCoalition ESS < 30%CRITICAL2020-07-22
DEBIAN-CVE-2020-6510
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%2020-07-20
CVEs:CVE-2020-6510
GoogleCoalition ESS < 30%CRITICAL2020-07-20
Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6510
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-07-07
In FastKeyAccumulator::GetKeysSlow of keys.cc, there is a possible out of bounds write due to type confusion. This could lead to remote code execution when processing a proxy configuration with no additional execution privileges needed. User interactio...
CVEs:CVE-2020-0224
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-07-07
CVEs:CVE-2020-0224
Open SourceCoalition ESS < 30%HIGH2020-07-01
ASB-A-147664838
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| external/chromium-libpac |
affected |
platform |
platform/external/chromium-libpac |
— |
| external/v8 |
affected |
platform |
platform/external/v8 |
— |
Open SourceCoalition ESS < 30%HIGH2020-07-22
DEBIAN-CVE-2020-6531
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2020-07-20
Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2020-6531
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%2020-07-20
CVEs:CVE-2020-6531
GoogleCoalition ESS < 30%CRITICAL2020-07-28
Type confusion in V8 in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVEs:CVE-2020-6537
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-07-28
CVEs:CVE-2020-6537
Open SourceCoalition ESS < 30%CRITICAL2020-07-22
DEBIAN-CVE-2020-6527
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%2020-07-20
CVEs:CVE-2020-6527
GoogleCoalition ESS < 30%CRITICAL2020-07-20
Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVEs:CVE-2020-6527
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2020-07-28
Buffer overflow in Skia in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6540
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-07-28
CVEs:CVE-2020-6540
Open SourceCoalition ESS < 30%MEDIUM2020-07-22
DEBIAN-CVE-2020-6528
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2020-07-20
Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.89 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2020-6528
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%2020-07-20
CVEs:CVE-2020-6528
Open SourceCoalition ESS < 30%HIGH2020-07-22
DEBIAN-CVE-2020-6530
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%2020-07-20
CVEs:CVE-2020-6530
GoogleCoalition ESS < 30%HIGH2020-07-20
Out of bounds memory access in developer tools in Google Chrome prior to 84.0.4147.89 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
CVEs:CVE-2020-6530
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-07-22
DEBIAN-CVE-2020-6536
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2020-07-20
Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to install a PWA to spoof the contents of the Omnibox (URL bar) via a crafted PWA.
CVEs:CVE-2020-6536
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%2020-07-20
CVEs:CVE-2020-6536
Open SourceCoalition ESS < 30%MEDIUM2020-07-22
DEBIAN-CVE-2020-6535
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2020-07-20
Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page.
CVEs:CVE-2020-6535
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%2020-07-20
CVEs:CVE-2020-6535
Open SourceCoalition ESS < 30%MEDIUM2020-07-22
DEBIAN-CVE-2020-6529
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2020-07-20
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2020-6529
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%2020-07-20
CVEs:CVE-2020-6529
Open SourceCoalition ESS < 30%HIGH2020-07-01
An incorrect access control flaw was found in the operator, openshift-service-mesh/istio-rhel8-operator all versions through 1.1.3. This flaw allows an attacker with a basic level of access to the cluster to deploy a custom gateway/pod to any namespace...
CVEs:CVE-2020-14306
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio-operator |
affected |
istio-operator_project |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-07-28
CVEs:CVE-2020-6532
GoogleCoalition ESS < 30%CRITICAL2020-07-28
Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6532
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-07-23
DEBIAN-CVE-2019-11252
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
Debian:11 |
kubernetes |
— |
| kubernetes |
affected |
Debian:12 |
kubernetes |
— |
| kubernetes |
affected |
Debian:13 |
kubernetes |
— |
| kubernetes |
affected |
Debian:14 |
kubernetes |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-07-23
The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages in mount failure logs and events for AzureFile and CephFS volumes.
CVEs:CVE-2019-11252
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
kubernetes |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2020-07-28
Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2020-6538
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%2020-07-28
CVEs:CVE-2020-6538
GoogleCoalition ESS < 30%CRITICAL2020-07-28
Use after free in CSS in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6539
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-07-28
CVEs:CVE-2020-6539
Open SourceCoalition ESS < 30%CRITICAL2020-07-22
DEBIAN-CVE-2020-6505
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-07-22
DEBIAN-CVE-2020-6509
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-07-22
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP2 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2020-07-07
CVEs:CVE-2020-15509
Open SourceCoalition ESS < 30%MEDIUM2020-07-07
Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communication while showing the user that the communication is purportedly encry...
CVEs:CVE-2020-15509
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android_ble_library |
affected |
nordicsemi |
— |
— |
| dfu_library |
affected |
nordicsemi |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-07-07
There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid ID: A-156333727
CVEs:CVE-2020-0231
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-07-07
CVEs:CVE-2020-0231
GoogleCoalition ESS < 30%CRITICAL2020-07-01
ASB-A-156333727
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2020-07-07
There is an improper configuration of recorder related service. Product: AndroidVersions: Android SoCAndroid ID: A-156333723
CVEs:CVE-2020-0228
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-07-07
CVEs:CVE-2020-0228
GoogleCoalition ESS < 30%2020-07-01
ASB-A-156333723
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2020-07-07
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via the KNOX API. The Samsung ID is SVE-2020-17318 (July 2020).
CVEs:CVE-2020-15579
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-07-07
CVEs:CVE-2020-15579
GoogleCoalition ESS < 30%NONE2020-07-19
Security update for google-compute-engine
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google-compute-engine |
affected |
openSUSE:Leap 15.2 |
google-compute-engine |
— |
GoogleCoalition ESS < 30%NONE2020-07-18
Security update for google-compute-engine
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google-compute-engine |
affected |
openSUSE:Leap 15.1 |
google-compute-engine |
— |
GoogleCoalition ESS < 30%NONE2020-07-15
Security update for google-compute-engine
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google-compute-engine |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP1 |
google-compute-engine |
— |
| google-compute-engine |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP2 |
google-compute-engine |
— |
GoogleCoalition ESS < 30%2020-07-07
CVEs:CVE-2020-15581
Open SourceCoalition ESS < 30%MEDIUM2020-07-07
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The kernel logging feature allows attackers to discover virtual addresses via vectors involving shared memory. The Samsung ID is SVE-2020-17605 (July 2020).
CVEs:CVE-2020-15581
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-07-07
An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can trigger an out-of-bounds access and device reset via a 4K wallpaper image because ImageProcessHelper mishandles boundary checks. The Samsung ID is SVE-2020-18056 (Ju...
CVEs:CVE-2020-15584
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-07-07
CVEs:CVE-2020-15584
Open SourceCoalition ESS < 30%CRITICAL2020-07-07
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 7885 chipsets) software. The Bluetooth Low Energy (BLE) component has a buffer overflow with a resultant deadlock or crash. The Samsung ID is SVE-2020-16870 (July 2020).
CVEs:CVE-2020-15582
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-07-07
CVEs:CVE-2020-15582
Open SourceCoalition ESS < 30%HIGH2020-07-07
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. StickerProvider allows directory traversal for access to system files. The Samsung ID is SVE-2020-17665 (July 2020).
CVEs:CVE-2020-15583
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-07-07
CVEs:CVE-2020-15583
GoogleCoalition ESS < 30%2020-07-01
ASB-A-147103019
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GoogleCoalition ESS < 30%HIGH2020-07-07
CVEs:CVE-2020-0122
Open SourceCoalition ESS < 30%HIGH2020-07-07
In the permission declaration for com.google.android.providers.gsf.permission.WRITE_GSERVICES in AndroidManifest.xml, there is a possible permissions bypass. This could lead to local escalation of privilege with System execution privileges needed. User...
CVEs:CVE-2020-0122
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%NONE2020-07-01
ASB-A-147247775
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2020-07-17
CVEs:CVE-2020-0305
Open SourceCoalition ESS < 30%HIGH2020-07-17
In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A...
CVEs:CVE-2020-0305
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%LOW2020-07-07
CVEs:CVE-2020-0107
Open SourceCoalition ESS < 30%MEDIUM2020-07-07
In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed f...
CVEs:CVE-2020-0107
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-07-07
CVEs:CVE-2020-15577
Open SourceCoalition ESS < 30%MEDIUM2020-07-07
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Cameralyzer allows attackers to write files to the SD card. The Samsung ID is SVE-2020-16830 (July 2020).
CVEs:CVE-2020-15577
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-07-07
CVEs:CVE-2020-15580
Open SourceCoalition ESS < 30%MEDIUM2020-07-07
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) by enrolling a new lock password. The Samsung ID is SVE-2020-17328 (July 2020).
CVEs:CVE-2020-15580
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-07-07
CVEs:CVE-2020-15578
Open SourceCoalition ESS < 30%MEDIUM2020-07-07
An issue was discovered on Samsung mobile devices with O(8.x) software. FactoryCamera does not properly restrict runtime permissions. The Samsung ID is SVE-2020-17270 (July 2020).
CVEs:CVE-2020-15578
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%NONE2020-07-01
ASB-A-135368228
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
GoogleAll remainingCRITICAL2020-07-14
Heap-use-after-free in draco::Metadata::AddSubMetadata
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| draco |
affected |
OSS-Fuzz |
— |
— |
| draco |
affected |
Google |
— |
— |
| draco |
affected |
OSS-Fuzz |
draco |
— |
Open SourceAll remaining2020-07-13
chromium - regression update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:10 |
chromium |
— |
Open SourceAll remaining2020-07-04
chromium - regression update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:10 |
chromium |
— |