Advisories
Open SourceExploitedCISA KEV listedCRITICAL2020-08-28
Security update for SUSE Manager Server 4.1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cobbler |
affected |
SUSE:Manager Server Module 4.1 |
cobbler |
— |
| golang-github-QubitProducts-exporter_exporter |
affected |
SUSE:Manager Server Module 4.1 |
golang-github-QubitProducts-exporter_exporter |
— |
| golang-github-QubitProducts-exporter_exporter |
affected |
SUSE:Manager Proxy Module 4.1 |
golang-github-QubitProducts-exporter_exporter |
— |
| google-gson |
affected |
SUSE:Manager Server Module 4.1 |
google-gson |
— |
| httpcomponents-client |
affected |
SUSE:Manager Server Module 4.1 |
httpcomponents-client |
— |
| httpcomponents-core |
affected |
SUSE:Manager Server Module 4.1 |
httpcomponents-core |
— |
| ical4j |
affected |
SUSE:Manager Server Module 4.1 |
ical4j |
— |
| image-sync-formula |
affected |
SUSE:Manager Server Module 4.1 |
image-sync-formula |
— |
| mgr-libmod |
affected |
SUSE:Manager Server Module 4.1 |
mgr-libmod |
— |
| mgr-osad |
affected |
SUSE:Manager Server Module 4.1 |
mgr-osad |
— |
| mgr-osad |
affected |
SUSE:Manager Proxy Module 4.1 |
mgr-osad |
— |
| openvpn-formula |
affected |
SUSE:Manager Server Module 4.1 |
openvpn-formula |
— |
| patterns-suse-manager |
affected |
SUSE:Manager Server Module 4.1 |
patterns-suse-manager |
— |
| patterns-suse-manager |
affected |
SUSE:Manager Proxy Module 4.1 |
patterns-suse-manager |
— |
| prometheus-exporters-formula |
affected |
SUSE:Manager Server Module 4.1 |
prometheus-exporters-formula |
— |
| pxe-default-image-sle15 |
affected |
SUSE:Manager Server Module 4.1 |
pxe-default-image-sle15 |
— |
| saltboot-formula |
affected |
SUSE:Manager Server Module 4.1 |
saltboot-formula |
— |
| spacecmd |
affected |
SUSE:Manager Server Module 4.1 |
spacecmd |
— |
| spacecmd |
affected |
SUSE:Manager Proxy Module 4.1 |
spacecmd |
— |
| spacewalk-backend |
affected |
SUSE:Manager Server Module 4.1 |
spacewalk-backend |
— |
| spacewalk-backend |
affected |
SUSE:Manager Proxy Module 4.1 |
spacewalk-backend |
— |
| spacewalk-branding |
affected |
SUSE:Manager Server Module 4.1 |
spacewalk-branding |
— |
| spacewalk-certs-tools |
affected |
SUSE:Manager Proxy Module 4.1 |
spacewalk-certs-tools |
— |
| spacewalk-certs-tools |
affected |
SUSE:Manager Server Module 4.1 |
spacewalk-certs-tools |
— |
| spacewalk-java |
affected |
SUSE:Manager Server Module 4.1 |
spacewalk-java |
— |
| spacewalk-proxy |
affected |
SUSE:Manager Proxy Module 4.1 |
spacewalk-proxy |
— |
| spacewalk-utils |
affected |
SUSE:Manager Server Module 4.1 |
spacewalk-utils |
— |
| spacewalk-web |
affected |
SUSE:Manager Proxy Module 4.1 |
spacewalk-web |
— |
| spacewalk-web |
affected |
SUSE:Manager Server Module 4.1 |
spacewalk-web |
— |
| susemanager |
affected |
SUSE:Manager Server Module 4.1 |
susemanager |
— |
| susemanager-doc-indexes |
affected |
SUSE:Manager Server Module 4.1 |
susemanager-doc-indexes |
— |
| susemanager-docs_en |
affected |
SUSE:Manager Server Module 4.1 |
susemanager-docs_en |
— |
| susemanager-frontend-libs |
affected |
SUSE:Manager Server Module 4.1 |
susemanager-frontend-libs |
— |
| susemanager-schema |
affected |
SUSE:Manager Server Module 4.1 |
susemanager-schema |
— |
| susemanager-sls |
affected |
SUSE:Manager Server Module 4.1 |
susemanager-sls |
— |
| susemanager-sync-data |
affected |
SUSE:Manager Server Module 4.1 |
susemanager-sync-data |
— |
| suseRegisterInfo |
affected |
SUSE:Manager Server Module 4.1 |
suseRegisterInfo |
— |
| suseRegisterInfo |
affected |
SUSE:Manager Proxy Module 4.1 |
suseRegisterInfo |
— |
| uyuni-common-libs |
affected |
SUSE:Manager Proxy Module 4.1 |
uyuni-common-libs |
— |
| uyuni-common-libs |
affected |
SUSE:Manager Server Module 4.1 |
uyuni-common-libs |
— |
| virtual-host-gatherer |
affected |
SUSE:Manager Server Module 4.1 |
virtual-host-gatherer |
— |
| virtualization-host-formula |
affected |
SUSE:Manager Server Module 4.1 |
virtualization-host-formula |
— |
| yomi-formula |
affected |
SUSE:Manager Server Module 4.1 |
yomi-formula |
— |
Open SourceExploitedCISA KEV listedHIGH2020-08-06
Red Hat Security Advisory: Red Hat OpenShift Service Mesh security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ior |
affected |
Red Hat:service_mesh:1.1::el8 |
ior |
— |
| kiali |
affected |
Red Hat:service_mesh:1.1::el7 |
kiali |
— |
| servicemesh |
affected |
Red Hat:service_mesh:1.1::el8 |
servicemesh |
— |
| servicemesh-citadel |
affected |
Red Hat:service_mesh:1.1::el8 |
servicemesh-citadel |
— |
| servicemesh-cni |
affected |
Red Hat:service_mesh:1.1::el8 |
servicemesh-cni |
— |
| servicemesh-galley |
affected |
Red Hat:service_mesh:1.1::el8 |
servicemesh-galley |
— |
| servicemesh-grafana |
affected |
Red Hat:service_mesh:1.1::el8 |
servicemesh-grafana |
— |
| servicemesh-grafana-prometheus |
affected |
Red Hat:service_mesh:1.1::el8 |
servicemesh-grafana-prometheus |
— |
| servicemesh-istioctl |
affected |
Red Hat:service_mesh:1.1::el8 |
servicemesh-istioctl |
— |
| servicemesh-mixc |
affected |
Red Hat:service_mesh:1.1::el8 |
servicemesh-mixc |
— |
| servicemesh-mixs |
affected |
Red Hat:service_mesh:1.1::el8 |
servicemesh-mixs |
— |
| servicemesh-operator |
affected |
Red Hat:service_mesh:1.1::el8 |
servicemesh-operator |
— |
| servicemesh-pilot-agent |
affected |
Red Hat:service_mesh:1.1::el8 |
servicemesh-pilot-agent |
— |
| servicemesh-pilot-discovery |
affected |
Red Hat:service_mesh:1.1::el8 |
servicemesh-pilot-discovery |
— |
| servicemesh-prometheus |
affected |
Red Hat:service_mesh:1.1::el8 |
servicemesh-prometheus |
— |
| servicemesh-sidecar-injector |
affected |
Red Hat:service_mesh:1.1::el8 |
servicemesh-sidecar-injector |
— |
GoogleExploitedCISA KEV listedCRITICAL2020-08-12
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the c...
CVEs:CVE-2020-1380
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| internet_explorer |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2020-08-12
Scripting Engine Memory Corruption Vulnerability
CVEs:CVE-2020-1380
GoogleExploitedCISA KEV listedHIGH2020-08-12
CVEs:CVE-2020-1380
Google CloudExploitedVulnCheck KEV listed2020-08-27
Date published: 2020-08-27 (High)
Google CloudExploitedVulnCheck KEV listed2020-08-27
GCP-COMPUTE-20200827 (High)
GooglePoC exploitMEDIUM2020-08-01
ASB-A-145728612
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
GooglePoC exploitHIGH2020-08-03
CVEs:CVE-2020-0240
Open SourcePoC exploitHIGH2020-08-03
In NewFixedDoubleArray of factory.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: Andr...
CVEs:CVE-2020-0240
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2020-08-11
Bugfixes on cilium, gangway and skuba and security fix for Kubernetes (cve-2020-8557)
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
SUSE:Linux Enterprise Module for Containers 15 SP1 |
kubernetes |
— |
GooglePoC exploitHIGH2020-08-03
CVEs:CVE-2020-0108
Open SourcePoC exploitHIGH2020-08-03
In postNotification of ServiceRecord.java, there is a possible bypass of foreground process restrictions due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is ...
CVEs:CVE-2020-0108
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2020-08-03
In NuPlayerStreamListener of NuPlayerStreamListener.cpp, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2020-0241
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2020-08-03
CVEs:CVE-2020-0241
GooglePoC exploitHIGH2020-08-03
CVEs:CVE-2020-0242
Open SourcePoC exploitHIGH2020-08-03
In reset of NuPlayerDriver.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2020-0242
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-08-15
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP2 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-08-15
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP1 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-08-14
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
openSUSE:Leap 15.1 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.2 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2020-08-11
CVEs:CVE-2020-6549
GoogleCoalition ESS < 30%HIGH2020-08-11
Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6549
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-11
CVEs:CVE-2020-6550
GoogleCoalition ESS < 30%HIGH2020-08-11
Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6550
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-11
CVEs:CVE-2020-6551
GoogleCoalition ESS < 30%HIGH2020-08-11
Use after free in WebXR in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6551
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-08-12
Security update of chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP2 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-08-07
Security update of chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP1 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-08-06
Security update of chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
openSUSE:Leap 15.1 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.2 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2020-08-18
Updated golang packages fix security vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Mageia:7 |
golang |
— |
Open SourceCoalition ESS < 30%HIGH2020-08-06
CVE-2020-16845 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
GoogleCoalition ESS < 30%HIGH2020-08-06
Withdrawn Advisory: Infinite loop in xz
CVEs:CVE-2020-16845
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ulikunitz/xz |
affected |
github.com |
github.com/ulikunitz/xz |
— |
GoogleCoalition ESS < 30%HIGH2020-08-06
Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.
CVEs:CVE-2020-16845
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| go |
affected |
golang |
— |
— |
| leap |
affected |
opensuse |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-08-06
DEBIAN-CVE-2020-16845
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-08-26
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
openSUSE:Leap 15.2 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-08-26
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
openSUSE:Leap 15.1 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2020-08-19
CVEs:CVE-2020-6556
GoogleCoalition ESS < 30%HIGH2020-08-19
Heap buffer overflow in SwiftShader in Google Chrome prior to 84.0.4147.135 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6556
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-12
A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Library versions prior to 1.7.2. A malicious attacker could create an apk which targets a specific application, and if a victim were to in...
CVEs:CVE-2020-8913
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| play_core_library |
affected |
android |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-12
CVEs:CVE-2020-8913
GoogleCoalition ESS < 30%HIGH2020-08-11
Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.125 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6548
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-11
CVEs:CVE-2020-6548
Open SourceCoalition ESS < 30%NONE2020-08-25
Updated mysql-connector-python packages fix security vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| mysql-connector-python |
affected |
Mageia:7 |
mysql-connector-python |
— |
| protobuf |
affected |
Mageia:7 |
protobuf |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-08-31
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
openSUSE:Leap 15.2 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2020-08-26
CVEs:CVE-2020-6559
GoogleCoalition ESS < 30%HIGH2020-08-26
Use after free in presentation API in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6559
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-11
Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVEs:CVE-2020-6555
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%2020-08-11
CVEs:CVE-2020-6555
GoogleCoalition ESS < 30%CRITICAL2020-08-11
Use after free in ANGLE in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6542
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-11
CVEs:CVE-2020-6542
GoogleCoalition ESS < 30%CRITICAL2020-08-26
Insufficient policy enforcement in iOSWeb in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVEs:CVE-2020-6558
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2020-08-26
CVEs:CVE-2020-6558
Open SourceCoalition ESS < 30%HIGH2020-08-23
DEBIAN-CVE-2020-7711
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-russellhaering-goxmldsig |
affected |
Debian:11 |
golang-github-russellhaering-goxmldsig |
— |
| golang-github-russellhaering-goxmldsig |
affected |
Debian:12 |
golang-github-russellhaering-goxmldsig |
— |
GoogleCoalition ESS < 30%CRITICAL2020-08-26
Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.
CVEs:CVE-2020-6563
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2020-08-26
CVEs:CVE-2020-6563
GoogleCoalition ESS < 30%CRITICAL2020-08-26
Insufficient policy enforcement in autofill in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2020-6560
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2020-08-26
CVEs:CVE-2020-6560
GoogleCoalition ESS < 30%MEDIUM2020-08-26
CVEs:CVE-2020-6566
GoogleCoalition ESS < 30%CRITICAL2020-08-26
Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2020-6566
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2020-08-26
Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.
CVEs:CVE-2020-6564
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2020-08-26
CVEs:CVE-2020-6564
GoogleCoalition ESS < 30%2020-08-26
CVEs:CVE-2020-6561
GoogleCoalition ESS < 30%MEDIUM2020-08-26
Inappropriate implementation in Content Security Policy in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2020-6561
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-11
CVEs:CVE-2020-6552
GoogleCoalition ESS < 30%HIGH2020-08-11
Use after free in Blink in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6552
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-11
CVEs:CVE-2020-6553
GoogleCoalition ESS < 30%HIGH2020-08-11
Use after free in offline mode in Google Chrome on iOS prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6553
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2020-08-26
CVEs:CVE-2020-6567
GoogleCoalition ESS < 30%MEDIUM2020-08-26
Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVEs:CVE-2020-6567
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2020-08-26
Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVEs:CVE-2020-6568
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2020-08-26
CVEs:CVE-2020-6568
GoogleCoalition ESS < 30%2020-08-26
CVEs:CVE-2020-6562
GoogleCoalition ESS < 30%CRITICAL2020-08-26
Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2020-6562
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2020-08-26
CVEs:CVE-2020-6565
GoogleCoalition ESS < 30%MEDIUM2020-08-26
Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2020-6565
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-11
CVEs:CVE-2020-6543
GoogleCoalition ESS < 30%CRITICAL2020-08-11
Use after free in task scheduling in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6543
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2020-08-11
Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6544
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-11
CVEs:CVE-2020-6544
GoogleCoalition ESS < 30%HIGH2020-08-11
CVEs:CVE-2020-6545
GoogleCoalition ESS < 30%CRITICAL2020-08-11
Use after free in audio in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6545
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%2020-08-26
CVEs:CVE-2020-6571
GoogleCoalition ESS < 30%MEDIUM2020-08-26
Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
CVEs:CVE-2020-6571
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2020-08-26
Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6569
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%2020-08-26
CVEs:CVE-2020-6569
GoogleCoalition ESS < 30%2020-08-26
CVEs:CVE-2020-6570
GoogleCoalition ESS < 30%HIGH2020-08-26
Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive information via a crafted WebRTC interaction.
CVEs:CVE-2020-6570
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-11
Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page.
CVEs:CVE-2020-6547
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%2020-08-11
CVEs:CVE-2020-6547
GoogleCoalition ESS < 30%HIGH2020-08-01
ASB-A-156071259
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
GoogleCoalition ESS < 30%LOW2020-08-31
CVEs:CVE-2020-20626
GoogleCoalition ESS < 30%HIGH2020-08-31
lara-google-analytics.php in Lara Google Analytics plugin through 2.0.4 for WordPress allows authenticated stored XSS.
CVEs:CVE-2020-20626
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| lara\'s_google_analytics |
affected |
lara\'s_google_analytics_project |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-08-31
An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. RKP allows arbitrary code execution. The Samsung ID is SVE-2020-17435 (August 2020).
CVEs:CVE-2020-25053
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-31
CVEs:CVE-2020-25053
GoogleCoalition ESS < 30%HIGH2020-08-03
CVEs:CVE-2020-0253
Open SourceCoalition ESS < 30%HIGH2020-08-03
There is a possible memory corruption due to a use after free.Product: AndroidVersions: Android SoCAndroid ID: A-152647365
CVEs:CVE-2020-0253
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-08-01
ASB-A-152225183
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%CRITICAL2020-08-01
ASB-A-152236803
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%CRITICAL2020-08-01
ASB-A-152647365
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2020-08-01
ASB-A-152647626
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2020-08-01
ASB-A-152647751
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2020-08-31
CVEs:CVE-2020-25052
Open SourceCoalition ESS < 30%CRITICAL2020-08-31
An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. H-Arx allows attackers to execute arbitrary code or cause a denial of service (memory corruption) because indexes are mishandled. The Samsung ID is SVE-2020-...
CVEs:CVE-2020-25052
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-11
CVEs:CVE-2020-6554
GoogleCoalition ESS < 30%CRITICAL2020-08-11
Use after free in extensions in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.
CVEs:CVE-2020-6554
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-03
CVEs:CVE-2020-0252
Open SourceCoalition ESS < 30%HIGH2020-08-03
There is a possible memory corruption due to a use after free.Product: AndroidVersions: Android SoCAndroid ID: A-152236803
CVEs:CVE-2020-0252
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-31
CVEs:CVE-2020-25065
Open SourceCoalition ESS < 30%HIGH2020-08-31
An issue was discovered on LG mobile devices with Android OS 4.4, 5.0, 5.1, 6.0, 7.0, 7.1, 8.0, 8.1, 9.0, and 10 software. Key logging may occur because of an obsolete API. The LG ID is LVE-SMP-170010 (August 2020).
CVEs:CVE-2020-25065
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-03
CVEs:CVE-2020-0251
Open SourceCoalition ESS < 30%HIGH2020-08-03
There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-152647626
CVEs:CVE-2020-0251
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-08-03
There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-152647751
CVEs:CVE-2020-0254
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-03
CVEs:CVE-2020-0254
GoogleCoalition ESS < 30%HIGH2020-08-31
CVEs:CVE-2020-25062
Open SourceCoalition ESS < 30%CRITICAL2020-08-31
An issue was discovered on LG mobile devices with Android OS 9 and 10 software. LGTelephonyProvider allows a bypass of intended privilege restrictions. The LG ID is LVE-SMP-200017 (July 2020).
CVEs:CVE-2020-25062
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-08-03
There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-152225183
CVEs:CVE-2020-0260
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-08-03
CVEs:CVE-2020-0260
Open SourceCoalition ESS < 30%CRITICAL2020-08-31
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. The network_management service does not properly restrict configuration changes. The LG ID is LVE-SMP-200012 (July 2020).
CVEs:CVE-2020-25058
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-31
CVEs:CVE-2020-25058
Open SourceCoalition ESS < 30%CRITICAL2020-08-31
An issue was discovered on LG mobile devices with Android OS 9 and 10 software on the VZW network. lge_property allows property overwrites. The LG ID is LVE-SMP-200016 (July 2020).
CVEs:CVE-2020-25061
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-31
CVEs:CVE-2020-25061
Open SourceCoalition ESS < 30%CRITICAL2020-08-31
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. StatusBarService has insufficient DEX access control. The Samsung ID is SVE-2020-17797 (August 2020).
CVEs:CVE-2020-25049
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-31
CVEs:CVE-2020-25049
Open SourceCoalition ESS < 30%CRITICAL2020-08-31
An issue was discovered on LG mobile devices with Android OS 10 software. MDMService does not properly restrict APK installations. The LG ID is LVE-SMP-200011 (July 2020).
CVEs:CVE-2020-25057
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-31
CVEs:CVE-2020-25057
GoogleCoalition ESS < 30%HIGH2020-08-31
CVEs:CVE-2020-25055
Open SourceCoalition ESS < 30%CRITICAL2020-08-31
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The persona service allows attackers (who control an unprivileged SecureFolder process) to bypass admin restrictions in KnoxContainer. The Samsung ID is SVE-20...
CVEs:CVE-2020-25055
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-08-31
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. The CMC service allows attackers to obtain sensitive information. The Samsung ID is SVE-2020-17288 (August 2020).
CVEs:CVE-2020-25050
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-08-31
CVEs:CVE-2020-25050
GoogleCoalition ESS < 30%2020-08-31
CVEs:CVE-2020-25059
Open SourceCoalition ESS < 30%HIGH2020-08-31
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A service crash may occur because of incorrect input validation. The LG ID is LVE-SMP-200013 (July 2020).
CVEs:CVE-2020-25059
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-08-31
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. An application crash can occur because of incorrect application-level input validation. The LG ID is LVE-SMP-200018 (July 2020).
CVEs:CVE-2020-25063
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-08-31
CVEs:CVE-2020-25063
GoogleCoalition ESS < 30%2020-08-31
CVEs:CVE-2020-25056
Open SourceCoalition ESS < 30%HIGH2020-08-31
An issue was discovered on Samsung mobile devices with Q(10.0) (Galaxy S20) software. Because HAL improperly checks versions, bootloading by the S.LSI NFC chipset is mishandled. The Samsung ID is SVE-2020-16169 (August 2020).
CVEs:CVE-2020-25056
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-08-31
CVEs:CVE-2020-25051
Open SourceCoalition ESS < 30%HIGH2020-08-31
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via AppInfo. The Samsung ID is SVE-2020-17758 (August 2020).
CVEs:CVE-2020-25051
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%NONE2020-08-11
Security update for google-compute-engine
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google-compute-engine |
affected |
SUSE:Linux Enterprise Module for Public Cloud 12 |
google-compute-engine |
— |
Open SourceCoalition ESS < 30%HIGH2020-08-31
An issue was discovered on LG mobile devices with Android OS 4.4, 5.0, 5.1, 6.0, 7.0, 7.1, 8.0, 8.1, 9.0, and 10 software. Certain automated testing is mishandled. The LG ID is LVE-SMP-200019 (August 2020).
CVEs:CVE-2020-25064
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-08-31
CVEs:CVE-2020-25064
Open SourceCoalition ESS < 30%MEDIUM2020-08-03
In stopZygoteLocked of AppZygote.java, there is an insufficient cleanup. This could lead to local information disclosure in the application that is started next with no additional execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2020-0258
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2020-08-03
CVEs:CVE-2020-0258
GoogleCoalition ESS < 30%CRITICAL2020-08-12
A buffer length validation vulnerability in Asylo versions prior to 0.6.0 allows an attacker to read data they should not have access to. The 'enc_untrusted_recvfrom' function generates a return value which is deserialized by 'MessageReader', and copie...
CVEs:CVE-2020-8905
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| asylo |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-08-12
CVEs:CVE-2020-8905
GoogleCoalition ESS < 30%CRITICAL2020-08-12
An arbitrary memory overwrite vulnerability in the trusted memory of Asylo exists in versions prior to 0.6.0. As the ecall_restore function fails to validate the range of the output_len pointer, an attacker can manipulate the tmp_output_len value and w...
CVEs:CVE-2020-8904
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| asylo |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-08-12
CVEs:CVE-2020-8904
GoogleCoalition ESS < 30%HIGH2020-08-03
CVEs:CVE-2020-0256
Open SourceCoalition ESS < 30%HIGH2020-08-03
In LoadPartitionTable of gpt.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege when inserting a malicious USB device, with no additional execution privileges needed. User interac...
CVEs:CVE-2020-0256
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-11
Inappropriate implementation in installer in Google Chrome prior to 84.0.4147.125 allowed a local attacker to potentially elevate privilege via a crafted filesystem.
CVEs:CVE-2020-6546
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-11
CVEs:CVE-2020-6546
Open SourceCoalition ESS < 30%MEDIUM2020-08-03
In getDocumentMetadata of DocumentsContract.java, there is a possible disclosure of location metadata from a file due to a permissions bypass. This could lead to local information disclosure from a file (eg. a photo) containing location metadata with n...
CVEs:CVE-2020-0239
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-08-03
CVEs:CVE-2020-0239
GoogleCoalition ESS < 30%HIGH2020-08-11
An improperly initialized 'migrationAuth' value in Google's go-tpm TPM1.2 library versions prior to 0.3.0 can lead an eavesdropping attacker to discover the auth value for a key created with CreateWrapKey. An attacker listening in on the channel can co...
CVEs:CVE-2020-8918
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go-tpm |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-11
TPM 1.2 key authorization values vulnerable to TPM transport eavesdropper in go-tpm
CVEs:CVE-2020-8918
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google/go-tpm |
affected |
github.com |
github.com/google/go-tpm |
— |
Open SourceCoalition ESS < 30%HIGH2020-08-03
In SpecializeCommon of com_android_internal_os_Zygote.cpp, there is a permissions bypass due to an incomplete cleanup. This could lead to local escalation of privilege in isolated processes with no additional execution privileges needed. User interacti...
CVEs:CVE-2020-0257
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-03
CVEs:CVE-2020-0257
GoogleCoalition ESS < 30%HIGH2020-08-03
CVEs:CVE-2020-0261
Open SourceCoalition ESS < 30%HIGH2020-08-03
In C2 flame devices, there is a possible bypass of seccomp due to a missing configuration file. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An...
CVEs:CVE-2020-0261
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-08-03
In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2020-0248
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-08-03
CVEs:CVE-2020-0248
Open SourceCoalition ESS < 30%MEDIUM2020-08-03
In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2020-0249
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-08-03
CVEs:CVE-2020-0249
GoogleCoalition ESS < 30%LOW2020-08-31
CVEs:CVE-2020-25048
Open SourceCoalition ESS < 30%MEDIUM2020-08-31
An issue was discovered on Samsung mobile devices with Q(10.0) (with ONEUI 2.1) software. In the Lockscreen state, the Quick Share feature allows unauthenticated downloads, aka file injection. The Samsung ID is SVE-2020-17760 (August 2020).
CVEs:CVE-2020-25048
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-08-03
CVEs:CVE-2020-0259
Open SourceCoalition ESS < 30%HIGH2020-08-03
In android_verity_ctr of dm-android-verity.c, there is a possible way to modify a dm-verity protected filesystem due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...
CVEs:CVE-2020-0259
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%NONE2020-08-01
ASB-A-157941353
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2020-08-03
CVEs:CVE-2020-0243
Open SourceCoalition ESS < 30%HIGH2020-08-03
In clearPropValue of MediaAnalyticsItem.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional execution privileges needed. User interaction is not needed...
CVEs:CVE-2020-0243
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-08-31
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The USB driver leaks address information via kernel logging. The Samsung IDs are SVE-2020-17602, SVE-2020-17603, SVE-2020-17604 (August 2020).
CVEs:CVE-2020-25046
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-08-31
CVEs:CVE-2020-25046
GoogleCoalition ESS < 30%LOW2020-08-31
CVEs:CVE-2020-25047
Open SourceCoalition ESS < 30%CRITICAL2020-08-31
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (released in China and India) software. The S Secure application does not enforce the intended password requirement for a locked application. The Samsung IDs are SVE-2020-16746, ...
CVEs:CVE-2020-25047
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-08-03
CVEs:CVE-2020-0250
Open SourceCoalition ESS < 30%MEDIUM2020-08-03
In requestCellInfoUpdateInternal of PhoneInterfaceManager.java, there is a missing permission check. This could lead to local information disclosure of location data with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2020-0250
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-08-03
CVEs:CVE-2020-0247
Open SourceCoalition ESS < 30%MEDIUM2020-08-03
In Threshold::getHistogram of ImageProcessHelper.java, there is a possible crash loop due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation.Product: A...
CVEs:CVE-2020-0247
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-08-31
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Local users can gain privileges because of LAF and SBL1 flaws. The LG ID is LVE-SMP-200015 (July 2020).
CVEs:CVE-2020-25060
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-08-31
CVEs:CVE-2020-25060
Open SourceCoalition ESS < 30%HIGH2020-08-03
In updatePreferenceIntents of AccountTypePreferenceLoader, there is a possible confused deputy attack due to a race condition. This could lead to local escalation of privilege and launching privileged activities with no additional execution privileges ...
CVEs:CVE-2020-0238
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-08-03
CVEs:CVE-2020-0238
Open SourceEPSS <= 49%2020-08-10
golang-github-seccomp-libseccomp-golang - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-seccomp-libseccomp-golang |
affected |
Debian:9 |
golang-github-seccomp-libseccomp-golang |
— |
GoogleEPSS <= 49%NONE2020-08-01
ASB-A-155485360
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
Open SourceAll remainingHIGH2020-08-19
Denial of Service in protobufjs
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobufjs |
affected |
npm |
protobufjs |
— |
Open SourceAll remainingHIGH2020-08-19
Denial of Service in protobufjs
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobufjs |
affected |
npm |
protobufjs |
— |
Open SourceAll remainingCRITICAL2020-08-11
Cross-Site Scripting in @progress/kendo-angular-editor
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kendo-angular-editor |
affected |
progress |
@progress/kendo-angular-editor |
— |
Open SourceAll remainingCRITICAL2020-08-11
Cross-Site Scripting in @progress/kendo-angular-editor
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kendo-angular-editor |
affected |
progress |
@progress/kendo-angular-editor |
— |
Open SourceAll remainingCRITICAL2020-08-05
XSS via JQLite DOM manipulation functions in AngularJS
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular |
affected |
npm |
angular |
— |
Open SourceAll remainingCRITICAL2020-08-05
XSS via JQLite DOM manipulation functions in AngularJS
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular |
affected |
npm |
angular |
— |