Google Security Advisories · July 2020 — Google Security Advisories
186 advisories 125 CVEs 2 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2020-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

SUSE-SU-2020:1972-1

Open SourceExploitedCISA KEV listedHIGH2020-07-21

Security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
dracut-saltboot affected SUSE:Manager Client Tools 15 dracut-saltboot
golang-github-prometheus-prometheus affected SUSE:Manager Client Tools 15 golang-github-prometheus-prometheus
grafana affected SUSE:Manager Client Tools 15 grafana
koan affected SUSE:Manager Client Tools 15 koan
mgr-cfg affected SUSE:Manager Client Tools 15 mgr-cfg
mgr-custom-info affected SUSE:Manager Client Tools 15 mgr-custom-info
mgr-daemon affected SUSE:Manager Client Tools 15 mgr-daemon
mgr-osad affected SUSE:Manager Client Tools 15 mgr-osad
mgr-push affected SUSE:Manager Client Tools 15 mgr-push
mgr-virtualization affected SUSE:Manager Client Tools 15 mgr-virtualization
rhnlib affected SUSE:Manager Client Tools 15 rhnlib
spacecmd affected SUSE:Manager Client Tools 15 spacecmd
spacewalk-client-tools affected SUSE:Manager Client Tools 15 spacewalk-client-tools
spacewalk-koan affected SUSE:Manager Client Tools 15 spacewalk-koan
spacewalk-oscap affected SUSE:Manager Client Tools 15 spacewalk-oscap
spacewalk-remote-utils affected SUSE:Manager Client Tools 15 spacewalk-remote-utils
supportutils-plugin-susemanager-client affected SUSE:Manager Client Tools 15 supportutils-plugin-susemanager-client
suseRegisterInfo affected SUSE:Manager Client Tools 15 suseRegisterInfo
uyuni-base affected SUSE:Manager Client Tools 15 uyuni-base
uyuni-common-libs affected SUSE:Manager Client Tools 15 uyuni-common-libs
zypp-plugin-spacewalk affected SUSE:Manager Client Tools 15 zypp-plugin-spacewalk
Upstream advisory

SUSE-SU-2020:1970-1

Open SourceExploitedCISA KEV listedHIGH2020-07-21

Security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
cobbler affected SUSE:OpenStack Cloud 8 cobbler
cobbler affected SUSE:HPE Helion OpenStack 8 cobbler
cobbler affected SUSE:OpenStack Cloud 9 cobbler
cobbler affected SUSE:Manager Client Tools 12 cobbler
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 12 SP5 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:OpenStack Cloud 9 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:OpenStack Cloud Crowbar 8 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:OpenStack Cloud Crowbar 9 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server for SAP Applications 12 SP5 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Manager Client Tools 12 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server for SAP Applications 12 SP3 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server for SAP Applications 12 SP4 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 12 SP3-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 12 SP3-BCL golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 12 SP4-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:HPE Helion OpenStack 8 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:OpenStack Cloud 8 golang-github-prometheus-node_exporter
golang-github-prometheus-prometheus affected SUSE:Manager Client Tools 12 golang-github-prometheus-prometheus
grafana affected SUSE:Manager Client Tools 12 grafana
mgr-cfg affected SUSE:Manager Client Tools 12 mgr-cfg
mgr-custom-info affected SUSE:Manager Client Tools 12 mgr-custom-info
mgr-daemon affected SUSE:Manager Client Tools 12 mgr-daemon
mgr-osad affected SUSE:Manager Client Tools 12 mgr-osad
mgr-push affected SUSE:Manager Client Tools 12 mgr-push
mgr-virtualization affected SUSE:Manager Client Tools 12 mgr-virtualization
rhnlib affected SUSE:Manager Client Tools 12 rhnlib
spacecmd affected SUSE:Manager Client Tools 12 spacecmd
spacewalk-client-tools affected SUSE:Manager Client Tools 12 spacewalk-client-tools
spacewalk-koan affected SUSE:Manager Client Tools 12 spacewalk-koan
spacewalk-oscap affected SUSE:Manager Client Tools 12 spacewalk-oscap
spacewalk-remote-utils affected SUSE:Manager Client Tools 12 spacewalk-remote-utils
supportutils-plugin-susemanager-client affected SUSE:Manager Client Tools 12 supportutils-plugin-susemanager-client
suseRegisterInfo affected SUSE:Manager Client Tools 12 suseRegisterInfo
uyuni-base affected SUSE:Manager Client Tools 12 uyuni-base
uyuni-common-libs affected SUSE:Manager Client Tools 12 uyuni-common-libs
zypp-plugin-spacewalk affected SUSE:Manager Client Tools 12 zypp-plugin-spacewalk
Upstream advisory

DEBIAN-CVE-2020-6507

Open SourceWeaponized exploitCRITICAL2020-07-22

DEBIAN-CVE-2020-6507

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DSA-4714-1

Open SourceWeaponized exploit2020-07-01

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:10 chromium
Upstream advisory

openSUSE-SU-2020:1061-1

Open SourceWeaponized exploitCRITICAL2020-07-26

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2020:1048-1

Open SourceWeaponized exploitCRITICAL2020-07-23

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP2 chromium
Upstream advisory

DEBIAN-CVE-2020-6519

Open SourceWeaponized exploitMEDIUM2020-07-22

DEBIAN-CVE-2020-6519

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

openSUSE-SU-2020:1021-1

Open SourceWeaponized exploitCRITICAL2020-07-20

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

CVE-2020-6519

GoogleWeaponized exploitMEDIUM2020-07-20

Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVEs:CVE-2020-6519

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

openSUSE-SU-2020:1020-1

Open SourceWeaponized exploitCRITICAL2020-07-20

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

DEBIAN-CVE-2020-6514

Open SourceWeaponized exploitMEDIUM2020-07-22

DEBIAN-CVE-2020-6514

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
firefox-esr affected Debian:11 firefox-esr
firefox-esr affected Debian:12 firefox-esr
firefox-esr affected Debian:13 firefox-esr
firefox-esr affected Debian:14 firefox-esr
thunderbird affected Debian:11 thunderbird
thunderbird affected Debian:12 thunderbird
thunderbird affected Debian:13 thunderbird
thunderbird affected Debian:14 thunderbird
Upstream advisory

CVE-2020-6514

GoogleWeaponized exploitMEDIUM2020-07-20

Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.

CVEs:CVE-2020-6514

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
ipados affected apple
iphone_os affected apple
leap affected opensuse
safari affected apple
tvos affected apple
ubuntu_linux affected canonical
watchos affected apple
Upstream advisory

CVE-2020-0230

Open SourceWeaponized exploitCRITICAL2020-07-07

There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid ID: A-156337262

CVEs:CVE-2020-0230

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-156337262

GoogleWeaponized exploitCRITICAL2020-07-01

ASB-A-156337262

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

DEBIAN-CVE-2020-8559

Open SourcePoC exploitCRITICAL2020-07-22

DEBIAN-CVE-2020-8559

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2020-8559

Open SourcePoC exploitMEDIUM2020-07-22

Privilege Escalation in Kubernetes

CVEs:CVE-2020-8559

Affected products

ProductStatusVendorPackageEcosystem
apimachinery affected k8s.io k8s.io/apimachinery
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2020-8559

Open SourcePoC exploitCRITICAL2020-07-22

The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise t...

CVEs:CVE-2020-8559

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2020-8559

Open SourcePoC exploitMEDIUM2020-07-22

Privilege Escalation in Kubernetes

CVEs:CVE-2020-8559

Affected products

ProductStatusVendorPackageEcosystem
apimachinery affected k8s.io k8s.io/apimachinery
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

DEBIAN-CVE-2020-6516

Open SourcePoC exploitMEDIUM2020-07-22

DEBIAN-CVE-2020-6516

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6516

GooglePoC exploitMEDIUM2020-07-20

Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2020-6516

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6506

Open SourcePoC exploitCRITICAL2020-07-22

DEBIAN-CVE-2020-6506

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2020-8558

Open SourcePoC exploitHIGH2020-07-27

DEBIAN-CVE-2020-8558

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2020-8558

Open SourcePoC exploitHIGH2020-07-27

The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's n...

CVEs:CVE-2020-8558

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2020-8558

Open SourcePoC exploitHIGH2020-07-27

Improper Authentication in Kubernetes

CVEs:CVE-2020-8558

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

SUSE-SU-2020:1657-2

Open SourcePoC exploitHIGH2020-07-15

Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork

Affected products

ProductStatusVendorPackageEcosystem
containerd affected SUSE:Linux Enterprise Module for Containers 15 SP2 containerd
docker affected SUSE:Linux Enterprise Module for Containers 15 SP2 docker
docker-runc affected SUSE:Linux Enterprise Module for Containers 15 SP2 docker-runc
golang-github-docker-libnetwork affected SUSE:Linux Enterprise Module for Containers 15 SP2 golang-github-docker-libnetwork
Upstream advisory

CVE-2020-0225

Open SourcePoC exploitHIGH2020-07-07

In a2dp_vendor_ldac_decoder_decode_packet of a2dp_vendor_ldac_decoder.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction i...

CVEs:CVE-2020-0225

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-148588557

GooglePoC exploitNONE2020-07-01

ASB-A-148588557

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2020-7692

GooglePoC exploitHIGH2020-07-09

Improper Authorization in Google OAuth Client

CVEs:CVE-2020-7692

Affected products

ProductStatusVendorPackageEcosystem
com.google.oauth-client:google-oauth-client affected Maven com.google.oauth-client:google-oauth-client
Upstream advisory

CVE-2020-7692

GooglePoC exploitCRITICAL2020-07-09

PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorizati...

CVEs:CVE-2020-7692

Affected products

ProductStatusVendorPackageEcosystem
oauth_client_library_for_java affected google
Upstream advisory

DEBIAN-CVE-2020-7692

GooglePoC exploitCRITICAL2020-07-09

DEBIAN-CVE-2020-7692

Affected products

ProductStatusVendorPackageEcosystem
google-oauth-client-java affected Debian:11 google-oauth-client-java
google-oauth-client-java affected Debian:12 google-oauth-client-java
google-oauth-client-java affected Debian:13 google-oauth-client-java
google-oauth-client-java affected Debian:14 google-oauth-client-java
Upstream advisory

CVE-2020-8553

GooglePoC exploitMEDIUM2020-07-29

The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type...

CVEs:CVE-2020-8553

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected kubernetes
Upstream advisory

CVE-2020-8553

Open SourcePoC exploitMEDIUM2020-07-29

ingress-nginx component for Kubernetes allows file overwrite

CVEs:CVE-2020-8553

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected k8s.io k8s.io/ingress-nginx
Upstream advisory

DEBIAN-CVE-2020-8557

Open SourcePoC exploitMEDIUM2020-07-23

DEBIAN-CVE-2020-8557

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2020-8557

Open SourcePoC exploitMEDIUM2020-07-23

Denial of service in Kubernetes

CVEs:CVE-2020-8557

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/pkg/kubelet affected k8s.io k8s.io/kubernetes/pkg/kubelet
Upstream advisory

CVE-2020-8557

Open SourcePoC exploitMEDIUM2020-07-23

Denial of service in Kubernetes

CVEs:CVE-2020-8557

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/pkg/kubelet affected k8s.io k8s.io/kubernetes/pkg/kubelet
Upstream advisory

CVE-2020-8557

Open SourcePoC exploitMEDIUM2020-07-23

The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet evi...

CVEs:CVE-2020-8557

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

ASB-A-153715664

GooglePoC exploitHIGH2020-07-01

ASB-A-153715664

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2020-0226

Open SourcePoC exploitHIGH2020-07-07

In createWithSurfaceParent of Client.cpp, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege in the graphics server with no additional execution privileges needed. User interaction is not nee...

CVEs:CVE-2020-0226

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0227

Open SourcePoC exploitHIGH2020-07-07

In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing background data usage or launching from the background, with no addi...

CVEs:CVE-2020-0227

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-6541

GoogleCoalition ESS < 30%CRITICAL2020-07-28

Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6541

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

ASB-A-130373736

GoogleCoalition ESS < 30%HIGH2020-07-01

ASB-A-130373736

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

DEBIAN-CVE-2020-6513

Open SourceCoalition ESS < 30%CRITICAL2020-07-22

DEBIAN-CVE-2020-6513

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6513

GoogleCoalition ESS < 30%CRITICAL2020-07-20

Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2020-6513

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6512

Open SourceCoalition ESS < 30%HIGH2020-07-22

DEBIAN-CVE-2020-6512

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6512

GoogleCoalition ESS < 30%HIGH2020-07-20

Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6512

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

AZL-79042

Open SourceCoalition ESS < 30%MEDIUM2020-07-17

CVE-2020-15586 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

CVE-2020-15586

GoogleCoalition ESS < 30%MEDIUM2020-07-17

Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the same time.

CVEs:CVE-2020-15586

Affected products

ProductStatusVendorPackageEcosystem
cf-deployment affected cloudfoundry
debian_linux affected debian
fedora affected fedoraproject
go affected golang
leap affected opensuse
routing-release affected cloudfoundry
Upstream advisory

DEBIAN-CVE-2020-15586

Open SourceCoalition ESS < 30%MEDIUM2020-07-17

DEBIAN-CVE-2020-15586

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

DEBIAN-CVE-2020-6524

Open SourceCoalition ESS < 30%CRITICAL2020-07-22

DEBIAN-CVE-2020-6524

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6524

GoogleCoalition ESS < 30%HIGH2020-07-20

Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6524

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6517

Open SourceCoalition ESS < 30%CRITICAL2020-07-22

DEBIAN-CVE-2020-6517

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6517

GoogleCoalition ESS < 30%HIGH2020-07-20

Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6517

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6523

Open SourceCoalition ESS < 30%CRITICAL2020-07-22

DEBIAN-CVE-2020-6523

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6523

GoogleCoalition ESS < 30%HIGH2020-07-20

Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6523

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6520

Open SourceCoalition ESS < 30%CRITICAL2020-07-22

DEBIAN-CVE-2020-6520

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6520

GoogleCoalition ESS < 30%HIGH2020-07-20

Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6520

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

ASB-A-130374366

GoogleCoalition ESS < 30%HIGH2020-07-01

ASB-A-130374366

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

DEBIAN-CVE-2020-6518

Open SourceCoalition ESS < 30%CRITICAL2020-07-22

DEBIAN-CVE-2020-6518

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6518

GoogleCoalition ESS < 30%HIGH2020-07-20

Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6518

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6515

Open SourceCoalition ESS < 30%CRITICAL2020-07-22

DEBIAN-CVE-2020-6515

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6515

GoogleCoalition ESS < 30%HIGH2020-07-20

Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6515

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2020-2211

Open SourceCoalition ESS < 30%HIGH2020-07-02

RCE vulnerability in ElasticBox Jenkins Kubernetes CI/CD Plugin

CVEs:CVE-2020-2211

Affected products

ProductStatusVendorPackageEcosystem
com.elasticbox.jenkins-ci.plugins:kubernetes-ci affected Maven com.elasticbox.jenkins-ci.plugins:kubernetes-ci
Upstream advisory

CVE-2020-2211

Open SourceCoalition ESS < 30%CRITICAL2020-07-02

Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

CVEs:CVE-2020-2211

Affected products

ProductStatusVendorPackageEcosystem
kubernetes_ci affected jenkins
Upstream advisory

DEBIAN-CVE-2020-6533

Open SourceCoalition ESS < 30%HIGH2020-07-22

DEBIAN-CVE-2020-6533

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6533

GoogleCoalition ESS < 30%HIGH2020-07-20

Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6533

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6534

Open SourceCoalition ESS < 30%CRITICAL2020-07-22

DEBIAN-CVE-2020-6534

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

CVE-2020-6534

GoogleCoalition ESS < 30%CRITICAL2020-07-20

Heap buffer overflow in WebRTC in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6534

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6525

Open SourceCoalition ESS < 30%CRITICAL2020-07-22

DEBIAN-CVE-2020-6525

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

CVE-2020-6525

GoogleCoalition ESS < 30%CRITICAL2020-07-20

Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6525

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

AZL-79080

Open SourceCoalition ESS < 30%MEDIUM2020-07-17

CVE-2020-14039 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

CVE-2020-14039

GoogleCoalition ESS < 30%MEDIUM2020-07-17

In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete.

CVEs:CVE-2020-14039

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6526

Open SourceCoalition ESS < 30%MEDIUM2020-07-22

DEBIAN-CVE-2020-6526

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6526

GoogleCoalition ESS < 30%MEDIUM2020-07-20

Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2020-6526

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6521

Open SourceCoalition ESS < 30%HIGH2020-07-22

DEBIAN-CVE-2020-6521

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6521

GoogleCoalition ESS < 30%HIGH2020-07-20

Side-channel information leakage in autofill in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2020-6521

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6511

Open SourceCoalition ESS < 30%HIGH2020-07-22

DEBIAN-CVE-2020-6511

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

CVE-2020-6511

GoogleCoalition ESS < 30%HIGH2020-07-20

Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2020-6511

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6522

Open SourceCoalition ESS < 30%CRITICAL2020-07-22

DEBIAN-CVE-2020-6522

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

CVE-2020-6522

GoogleCoalition ESS < 30%CRITICAL2020-07-20

Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-6522

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6510

Open SourceCoalition ESS < 30%CRITICAL2020-07-22

DEBIAN-CVE-2020-6510

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6510

GoogleCoalition ESS < 30%CRITICAL2020-07-20

Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6510

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2020-0224

Open SourceCoalition ESS < 30%HIGH2020-07-07

In FastKeyAccumulator::GetKeysSlow of keys.cc, there is a possible out of bounds write due to type confusion. This could lead to remote code execution when processing a proxy configuration with no additional execution privileges needed. User interactio...

CVEs:CVE-2020-0224

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-147664838

Open SourceCoalition ESS < 30%HIGH2020-07-01

ASB-A-147664838

Affected products

ProductStatusVendorPackageEcosystem
external/chromium-libpac affected platform platform/external/chromium-libpac
external/v8 affected platform platform/external/v8
Upstream advisory

DEBIAN-CVE-2020-6531

Open SourceCoalition ESS < 30%HIGH2020-07-22

DEBIAN-CVE-2020-6531

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6531

GoogleCoalition ESS < 30%HIGH2020-07-20

Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2020-6531

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2020-6537

GoogleCoalition ESS < 30%CRITICAL2020-07-28

Type confusion in V8 in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVEs:CVE-2020-6537

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2020-6527

Open SourceCoalition ESS < 30%CRITICAL2020-07-22

DEBIAN-CVE-2020-6527

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6527

GoogleCoalition ESS < 30%CRITICAL2020-07-20

Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVEs:CVE-2020-6527

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2020-6540

GoogleCoalition ESS < 30%CRITICAL2020-07-28

Buffer overflow in Skia in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6540

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2020-6528

Open SourceCoalition ESS < 30%MEDIUM2020-07-22

DEBIAN-CVE-2020-6528

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6528

GoogleCoalition ESS < 30%MEDIUM2020-07-20

Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.89 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2020-6528

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6530

Open SourceCoalition ESS < 30%HIGH2020-07-22

DEBIAN-CVE-2020-6530

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6530

GoogleCoalition ESS < 30%HIGH2020-07-20

Out of bounds memory access in developer tools in Google Chrome prior to 84.0.4147.89 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

CVEs:CVE-2020-6530

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6536

Open SourceCoalition ESS < 30%MEDIUM2020-07-22

DEBIAN-CVE-2020-6536

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6536

GoogleCoalition ESS < 30%MEDIUM2020-07-20

Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to install a PWA to spoof the contents of the Omnibox (URL bar) via a crafted PWA.

CVEs:CVE-2020-6536

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6535

Open SourceCoalition ESS < 30%MEDIUM2020-07-22

DEBIAN-CVE-2020-6535

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6535

GoogleCoalition ESS < 30%MEDIUM2020-07-20

Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page.

CVEs:CVE-2020-6535

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6529

Open SourceCoalition ESS < 30%MEDIUM2020-07-22

DEBIAN-CVE-2020-6529

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6529

GoogleCoalition ESS < 30%MEDIUM2020-07-20

Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2020-6529

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2020-14306

Open SourceCoalition ESS < 30%HIGH2020-07-01

An incorrect access control flaw was found in the operator, openshift-service-mesh/istio-rhel8-operator all versions through 1.1.3. This flaw allows an attacker with a basic level of access to the cluster to deploy a custom gateway/pod to any namespace...

CVEs:CVE-2020-14306

Affected products

ProductStatusVendorPackageEcosystem
istio-operator affected istio-operator_project
Upstream advisory

CVE-2020-6532

GoogleCoalition ESS < 30%CRITICAL2020-07-28

Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6532

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2019-11252

Open SourceCoalition ESS < 30%MEDIUM2020-07-23

DEBIAN-CVE-2019-11252

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2019-11252

Open SourceCoalition ESS < 30%MEDIUM2020-07-23

The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages in mount failure logs and events for AzureFile and CephFS volumes.

CVEs:CVE-2019-11252

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2020-6538

GoogleCoalition ESS < 30%MEDIUM2020-07-28

Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2020-6538

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2020-6539

GoogleCoalition ESS < 30%CRITICAL2020-07-28

Use after free in CSS in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6539

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2020-6505

Open SourceCoalition ESS < 30%CRITICAL2020-07-22

DEBIAN-CVE-2020-6505

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6509

Open SourceCoalition ESS < 30%CRITICAL2020-07-22

DEBIAN-CVE-2020-6509

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

openSUSE-SU-2020:1032-1

Open SourceCoalition ESS < 30%CRITICAL2020-07-22

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP2 chromium
Upstream advisory

CVE-2020-15509

Open SourceCoalition ESS < 30%MEDIUM2020-07-07

Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communication while showing the user that the communication is purportedly encry...

CVEs:CVE-2020-15509

Affected products

ProductStatusVendorPackageEcosystem
android_ble_library affected nordicsemi
dfu_library affected nordicsemi
Upstream advisory

CVE-2020-0231

Open SourceCoalition ESS < 30%CRITICAL2020-07-07

There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid ID: A-156333727

CVEs:CVE-2020-0231

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-156333727

GoogleCoalition ESS < 30%CRITICAL2020-07-01

ASB-A-156333727

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2020-0228

Open SourceCoalition ESS < 30%HIGH2020-07-07

There is an improper configuration of recorder related service. Product: AndroidVersions: Android SoCAndroid ID: A-156333723

CVEs:CVE-2020-0228

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-156333723

GoogleCoalition ESS < 30%2020-07-01

ASB-A-156333723

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2020-15579

Open SourceCoalition ESS < 30%HIGH2020-07-07

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via the KNOX API. The Samsung ID is SVE-2020-17318 (July 2020).

CVEs:CVE-2020-15579

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

openSUSE-SU-2020:1014-1

GoogleCoalition ESS < 30%NONE2020-07-19

Security update for google-compute-engine

Affected products

ProductStatusVendorPackageEcosystem
google-compute-engine affected openSUSE:Leap 15.2 google-compute-engine
Upstream advisory

openSUSE-SU-2020:0996-1

GoogleCoalition ESS < 30%NONE2020-07-18

Security update for google-compute-engine

Affected products

ProductStatusVendorPackageEcosystem
google-compute-engine affected openSUSE:Leap 15.1 google-compute-engine
Upstream advisory

SUSE-SU-2020:1934-1

GoogleCoalition ESS < 30%NONE2020-07-15

Security update for google-compute-engine

Affected products

ProductStatusVendorPackageEcosystem
google-compute-engine affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 google-compute-engine
google-compute-engine affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 google-compute-engine
Upstream advisory

CVE-2020-15581

Open SourceCoalition ESS < 30%MEDIUM2020-07-07

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The kernel logging feature allows attackers to discover virtual addresses via vectors involving shared memory. The Samsung ID is SVE-2020-17605 (July 2020).

CVEs:CVE-2020-15581

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-15584

Open SourceCoalition ESS < 30%HIGH2020-07-07

An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can trigger an out-of-bounds access and device reset via a 4K wallpaper image because ImageProcessHelper mishandles boundary checks. The Samsung ID is SVE-2020-18056 (Ju...

CVEs:CVE-2020-15584

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-15582

Open SourceCoalition ESS < 30%CRITICAL2020-07-07

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 7885 chipsets) software. The Bluetooth Low Energy (BLE) component has a buffer overflow with a resultant deadlock or crash. The Samsung ID is SVE-2020-16870 (July 2020).

CVEs:CVE-2020-15582

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-15583

Open SourceCoalition ESS < 30%HIGH2020-07-07

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. StickerProvider allows directory traversal for access to system files. The Samsung ID is SVE-2020-17665 (July 2020).

CVEs:CVE-2020-15583

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-147103019

GoogleCoalition ESS < 30%2020-07-01

ASB-A-147103019

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2020-0122

Open SourceCoalition ESS < 30%HIGH2020-07-07

In the permission declaration for com.google.android.providers.gsf.permission.WRITE_GSERVICES in AndroidManifest.xml, there is a possible permissions bypass. This could lead to local escalation of privilege with System execution privileges needed. User...

CVEs:CVE-2020-0122

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-147247775

GoogleCoalition ESS < 30%NONE2020-07-01

ASB-A-147247775

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2020-0305

Open SourceCoalition ESS < 30%HIGH2020-07-17

In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A...

CVEs:CVE-2020-0305

Affected products

ProductStatusVendorPackageEcosystem
android affected google
leap affected opensuse
Upstream advisory

CVE-2020-0107

Open SourceCoalition ESS < 30%MEDIUM2020-07-07

In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2020-0107

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-15577

Open SourceCoalition ESS < 30%MEDIUM2020-07-07

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Cameralyzer allows attackers to write files to the SD card. The Samsung ID is SVE-2020-16830 (July 2020).

CVEs:CVE-2020-15577

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-15580

Open SourceCoalition ESS < 30%MEDIUM2020-07-07

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) by enrolling a new lock password. The Samsung ID is SVE-2020-17328 (July 2020).

CVEs:CVE-2020-15580

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-15578

Open SourceCoalition ESS < 30%MEDIUM2020-07-07

An issue was discovered on Samsung mobile devices with O(8.x) software. FactoryCamera does not properly restrict runtime permissions. The Samsung ID is SVE-2020-17270 (July 2020).

CVEs:CVE-2020-15578

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-135368228

GoogleEPSS <= 49%NONE2020-07-01

ASB-A-135368228

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

OSV-2020-828

GoogleAll remainingCRITICAL2020-07-14

Heap-use-after-free in draco::Metadata::AddSubMetadata

Affected products

ProductStatusVendorPackageEcosystem
draco affected OSS-Fuzz
draco affected Google
draco affected OSS-Fuzz draco
Upstream advisory

DSA-4714-3

Open SourceAll remaining2020-07-13

chromium - regression update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:10 chromium
Upstream advisory

DSA-4714-2

Open SourceAll remaining2020-07-04

chromium - regression update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:10 chromium
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.