AZL-79064
CVE-2020-24553 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
CVE-2020-24553 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a Content-Type header.
CVEs:CVE-2020-24553
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| communications_cloud_native_core_policy | affected | oracle | — | — |
| fedora | affected | fedoraproject | — | — |
| go | affected | golang | — | — |
| leap | affected | opensuse | — | — |
CVEs:CVE-2020-24553
DEBIAN-CVE-2020-24553
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
Information Exposure in cordova-android
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cordova-android | affected | npm | cordova-android | — |
Information Exposure in cordova-android
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cordova-android | affected | npm | cordova-android | — |
Red Hat Security Advisory: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:enterprise_linux:8::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:enterprise_linux:8::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:enterprise_linux:8::appstream | delve-debugsource | — |
| golang | affected | Red Hat:enterprise_linux:8::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:8::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:8::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:8::appstream | golang-misc | — |
| golang-race | affected | Red Hat:enterprise_linux:8::appstream | golang-race | — |
| golang-src | affected | Red Hat:enterprise_linux:8::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:8::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:8::appstream | go-toolset | — |
In allocExcessBits of bitalloc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2020-0380
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0380
DEBIAN-CVE-2020-26160
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-dgrijalva-jwt-go | affected | Debian:11 | golang-github-dgrijalva-jwt-go | — |
| golang-github-dgrijalva-jwt-go | affected | Debian:12 | golang-github-dgrijalva-jwt-go | — |
CVEs:CVE-2020-0245
In DecodeFrameCombinedMode of combined_decode.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for ex...
CVEs:CVE-2020-0245
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0381
In Parse_wave of eas_mdls.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote information disclosure in a highly constrained process with no additional execution privileges needed. User interaction is not ne...
CVEs:CVE-2020-0381
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-25279
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The baseband component has a buffer overflow via an abnormal SETUP message, leading to execution of arbitrary code. The Samsung ID is SVE-202...
CVEs:CVE-2020-25279
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0391
In applyPolicy of PackageManagerService.java, there is possible arbitrary command execution as System due to an unenforced protected-broadcast. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...
CVEs:CVE-2020-0391
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In setInstallerPackageName of PackageManagerService.java, there is a missing permission check. This could lead to local escalation of privilege and granting spurious permissions with no additional execution privileges needed. User interaction is not ne...
CVEs:CVE-2020-0401
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0401
In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege and untrusted devices accessing contact lists with no additional execution privileges n...
CVEs:CVE-2020-0394
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0394
CVEs:CVE-2020-0392
In getLayerDebugInfo of SurfaceFlinger.cpp, there is a possible code execution due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produc...
CVEs:CVE-2020-0392
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges neede...
CVEs:CVE-2020-0074
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0074
DEBIAN-CVE-2020-6549
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6550
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6551
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian | — | — |
DEBIAN-CVE-2020-6541
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6556
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 Gi...
CVEs:CVE-2020-8927
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| brotli | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| leap | affected | opensuse | — | — |
| .net | affected | microsoft | — | — |
| .net_core | affected | microsoft | — | — |
| powershell | affected | microsoft | — | — |
| ubuntu_linux | affected | canonical | — | — |
| visual_studio_2019 | affected | microsoft | — | — |
| visual_studio_2022 | affected | microsoft | — | — |
Integer overflow in the bundled Brotli C library
CVEs:CVE-2020-8927
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| brotli | affected | PyPI | brotli | — |
| compu-brotli-sys | affected | crates.io | compu-brotli-sys | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm | — |
| Microsoft.NETCore.App.Runtime.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.osx-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.osx-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.win-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.win-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.win-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.win-x86 | — |
| Microsoft.NETCore.App.Runtime.osx-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.osx-arm64 | — |
| Microsoft.NETCore.App.Runtime.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.win-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm | — |
| Microsoft.NETCore.App.Runtime.win-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm64 | — |
| Microsoft.NETCore.App.Runtime.win-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x64 | — |
| Microsoft.NETCore.App.Runtime.win-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x86 | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP2 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP1 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Leap 15.1 | chromium | — |
| chromium | affected | openSUSE:Leap 15.2 | chromium | — |
CVEs:CVE-2020-15965
Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVEs:CVE-2020-15965
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| backports_sle | affected | opensuse | — | — |
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| leap | affected | opensuse | — | — |
DEBIAN-CVE-2020-15965
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-15964
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| backports_sle | affected | opensuse | — | — |
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| leap | affected | opensuse | — | — |
CVEs:CVE-2020-15964
DEBIAN-CVE-2020-15964
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6548
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP1 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP2 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Leap 15.1 | chromium | — |
| chromium | affected | openSUSE:Leap 15.2 | chromium | — |
DEBIAN-CVE-2020-6559
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP1 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP2 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Leap 15.1 | chromium | — |
DEBIAN-CVE-2020-6555
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6542
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-25614
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-antchfx-xmlquery | affected | Debian:11 | golang-github-antchfx-xmlquery | — |
| golang-github-antchfx-xmlquery | affected | Debian:12 | golang-github-antchfx-xmlquery | — |
| golang-github-antchfx-xmlquery | affected | Debian:13 | golang-github-antchfx-xmlquery | — |
| golang-github-antchfx-xmlquery | affected | Debian:14 | golang-github-antchfx-xmlquery | — |
Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVEs:CVE-2020-15962
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| backports_sle | affected | opensuse | — | — |
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| leap | affected | opensuse | — | — |
CVEs:CVE-2020-15962
DEBIAN-CVE-2020-15962
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2020-15960
Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVEs:CVE-2020-15960
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| backports_sle | affected | opensuse | — | — |
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| leap | affected | opensuse | — | — |
DEBIAN-CVE-2020-15960
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6573
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2020-6573
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| backports_sle | affected | opensuse | — | — |
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| leap | affected | opensuse | — | — |
CVEs:CVE-2020-6573
DEBIAN-CVE-2020-6563
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6560
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
DEBIAN-CVE-2020-6576
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in offscreen canvas in Google Chrome prior to 85.0.4183.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6576
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| backports_sle | affected | opensuse | — | — |
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| leap | affected | opensuse | — | — |
CVEs:CVE-2020-6576
DEBIAN-CVE-2020-6566
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6537
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6564
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Security update for golang-github-prometheus-prometheus
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-prometheus-prometheus | affected | SUSE:Enterprise Storage 6 | golang-github-prometheus-prometheus | — |
DEBIAN-CVE-2020-6561
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6552
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6553
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6540
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6567
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6568
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6562
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6565
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2020-15961
Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
CVEs:CVE-2020-15961
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| backports_sle | affected | opensuse | — | — |
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| leap | affected | opensuse | — | — |
CVEs:CVE-2020-15963
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
CVEs:CVE-2020-15963
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| backports_sle | affected | opensuse | — | — |
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| leap | affected | opensuse | — | — |
DEBIAN-CVE-2020-15961
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-15963
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6543
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6544
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6545
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6575
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2020-6575
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| backports_sle | affected | opensuse | — | — |
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| leap | affected | opensuse | — | — |
CVEs:CVE-2020-6575
ASB-A-150693748
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.
CVEs:CVE-2020-15966
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| backports_sle | affected | opensuse | — | — |
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| leap | affected | opensuse | — | — |
CVEs:CVE-2020-15966
DEBIAN-CVE-2020-15966
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6571
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6532
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
PYSEC-2020-125
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-282
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-317
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Integer truncation in Shard API usage
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Integer truncation in Shard API usage
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-317
CVEs:CVE-2020-15202
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `Shard` API in TensorFlow expects the last argument to be a function taking two `int64` (i.e., `long long`) arguments. However, there are several places in TensorFlow where a lamb...
CVEs:CVE-2020-15202
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| leap | affected | opensuse | — | — |
| tensorflow | affected | — | — |
Integer truncation in Shard API usage
CVEs:CVE-2020-15202
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
DEBIAN-CVE-2020-6569
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
PYSEC-2020-130
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-287
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-322
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault and data corruption in tensorflow-lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault and data corruption in tensorflow-lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-322
CVEs:CVE-2020-15207
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, to mimic Python's indexing with negative values, TFLite uses `ResolveAxis` to convert negative values to positive indices. However, the only check that the converted index is now...
CVEs:CVE-2020-15207
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| leap | affected | opensuse | — | — |
| tensorflow | affected | — | — |
Segfault and data corruption in tensorflow-lite
CVEs:CVE-2020-15207
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
DEBIAN-CVE-2020-15959
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2020-15959
Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via social engineering.
CVEs:CVE-2020-15959
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| backports_sle | affected | opensuse | — | — |
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| leap | affected | opensuse | — | — |
DEBIAN-CVE-2020-6570
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2020-6547
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2020-0354
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andr...
CVEs:CVE-2020-0354
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PYSEC-2020-128
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-285
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-320
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Data leak in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Data leak in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-320
CVEs:CVE-2020-15205
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Data leak in Tensorflow
CVEs:CVE-2020-15205
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGrams` lacks validation. This allows a user to pass values that can cause heap overflow errors and even leak contents of memory In the...
CVEs:CVE-2020-15205
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| leap | affected | opensuse | — | — |
| tensorflow | affected | — | — |
PYSEC-2020-117
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-274
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-309
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Denial of Service in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Denial of Service in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-309
CVEs:CVE-2020-15194
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Denial of Service in Tensorflow
CVEs:CVE-2020-15194
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `SparseFillEmptyRowsGrad` implementation has incomplete validation of the shapes of its arguments. Although `reverse_index_map_t` and `grad_values_t` are accessed in a similar pat...
CVEs:CVE-2020-15194
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| leap | affected | opensuse | — | — |
| tensorflow | affected | — | — |
DEBIAN-CVE-2020-6538
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2020-0279
In the AAC parser, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersio...
CVEs:CVE-2020-0279
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
DEBIAN-CVE-2020-6539
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
PYSEC-2020-126
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-283
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-318
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Denial of Service in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Denial of Service in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-318
CVEs:CVE-2020-15203
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Denial of Service in Tensorflow
CVEs:CVE-2020-15203
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, by controlling the `fill` argument of tf.strings.as_string, a malicious attacker is able to trigger a format string vulnerability due to the way the internal format use in a `printf` ...
CVEs:CVE-2020-15203
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| leap | affected | opensuse | — | — |
| tensorflow | affected | — | — |
PYSEC-2020-129
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-286
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-321
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Denial of Service in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Denial of Service in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Denial of Service in Tensorflow
CVEs:CVE-2020-15206
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-321
CVEs:CVE-2020-15206
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, changing the TensorFlow's `SavedModel` protocol buffer and altering the name of required keys results in segfaults and data corruption while loading the model. This can cause a denial...
CVEs:CVE-2020-15206
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| leap | affected | opensuse | — | — |
| tensorflow | affected | — | — |
PYSEC-2020-118
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-275
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-310
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-310
CVEs:CVE-2020-15195
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in Tensorflow
CVEs:CVE-2020-15195
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the implementation of `SparseFillEmptyRowsGrad` uses a double indexing pattern. It is possible for `reverse_index_map(i)` to be an index outside of bounds of `grad_values`, thus resul...
CVEs:CVE-2020-15195
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| leap | affected | opensuse | — | — |
| tensorflow | affected | — | — |
PYSEC-2020-113
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-270
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-305
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-305
CVEs:CVE-2020-15190
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `tf.raw_ops.Switch` operation takes as input a tensor and a boolean and outputs two tensors. Depending on the boolean value, one of the tensors is exactly the input tensor whereas...
CVEs:CVE-2020-15190
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| leap | affected | opensuse | — | — |
| tensorflow | affected | — | — |
Segfault in Tensorflow
CVEs:CVE-2020-15190
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-134
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-291
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-326
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Out of bounds access in tensorflow-lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Out of bounds access in tensorflow-lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, saved models in the flatbuffer format use a double indexing scheme: a model has a set of subgraphs, each subgraph has a set of operators and each operator has a set of input/outp...
CVEs:CVE-2020-15211
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| leap | affected | opensuse | — | — |
| tensorflow | affected | — | — |
PYSEC-2020-326
CVEs:CVE-2020-15211
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Out of bounds access in tensorflow-lite
CVEs:CVE-2020-15211
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-131
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-288
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-323
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Data corruption in tensorflow-lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Data corruption in tensorflow-lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-323
CVEs:CVE-2020-15208
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of two tensors, TFLite uses a `DCHECK` which is no-op outside of debug compilation modes. Since the function always returns the dimensi...
CVEs:CVE-2020-15208
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| leap | affected | opensuse | — | — |
| tensorflow | affected | — | — |
Data corruption in tensorflow-lite
CVEs:CVE-2020-15208
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-119
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-127
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-276
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-284
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-311
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-319
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In Tensorflow version 2.3.0, the `SparseCountSparseOutput` and `RaggedCountSparseOutput` implementations don't validate that the `weights` tensor has the same shape as the data. The check exists for `DenseCountSparseOutput`, where both tensors are full...
CVEs:CVE-2020-15196
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Heap buffer overflow in Tensorflow
CVEs:CVE-2020-15196
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-311
CVEs:CVE-2020-15196
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault in Tensorflow
CVEs:CVE-2020-15204
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In eager mode, TensorFlow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1 does not set the session state. Hence, calling `tf.raw_ops.GetSessionHandle` or `tf.raw_ops.GetSessionHandleV2` results in a null pointer dereference In linked snippet, in ...
CVEs:CVE-2020-15204
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| leap | affected | opensuse | — | — |
| tensorflow | affected | — | — |
PYSEC-2020-319
CVEs:CVE-2020-15204
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-114
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-271
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-306
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Undefined behavior in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Undefined behavior in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes an invalid argument to `dlpack.to_dlpack` the expected validations will cause variables to bind to `nullptr` while setting a `status` variable to the error condition. However, this `status...
CVEs:CVE-2020-15191
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| leap | affected | opensuse | — | — |
| tensorflow | affected | — | — |
PYSEC-2020-306
CVEs:CVE-2020-15191
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Undefined behavior in Tensorflow
CVEs:CVE-2020-15191
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
DEBIAN-CVE-2020-15216
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-russellhaering-goxmldsig | affected | Debian:11 | golang-github-russellhaering-goxmldsig | — |
| golang-github-russellhaering-goxmldsig | affected | Debian:12 | golang-github-russellhaering-goxmldsig | — |
PYSEC-2020-123
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-280
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-315
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault in Tensorflow
CVEs:CVE-2020-15200
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-315
CVEs:CVE-2020-15200
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` implementation does not validate that the input arguments form a valid ragged tensor. In particular, there is no validation that the values in the `splits` tensor generate a valid partit...
CVEs:CVE-2020-15200
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
CVEs:CVE-2020-0333
In UrlQuerySanitizer, there is a possible improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID...
CVEs:CVE-2020-0333
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In libFraunhoferAAC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVers...
CVEs:CVE-2020-0355
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0355
In libDRCdec, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: A...
CVEs:CVE-2020-0364
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0364
In libsonivox, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: ...
CVEs:CVE-2020-0324
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0324
In tremolo, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: And...
CVEs:CVE-2020-0270
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0270
PYSEC-2020-115
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-272
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-307
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Memory leak in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Memory leak in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-307
CVEs:CVE-2020-15192
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes a list of strings to `dlpack.to_dlpack` there is a memory leak following an expected validation failure. The issue occurs because the `status` argument during validation failures is not pr...
CVEs:CVE-2020-15192
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| leap | affected | opensuse | — | — |
| tensorflow | affected | — | — |
Memory leak in Tensorflow
CVEs:CVE-2020-15192
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-116
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-273
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-308
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Memory corruption in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Memory corruption in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-308
CVEs:CVE-2020-15193
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In Tensorflow before versions 2.2.1 and 2.3.1, the implementation of `dlpack.to_dlpack` can be made to use uninitialized memory resulting in further memory corruption. This is because the pybind11 glue code assumes that the argument is a tensor. Howeve...
CVEs:CVE-2020-15193
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| leap | affected | opensuse | — | — |
| tensorflow | affected | — | — |
Memory corruption in Tensorflow
CVEs:CVE-2020-15193
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-122
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-279
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-314
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Denial of Service in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Denial of Service in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Denial of Service in Tensorflow
CVEs:CVE-2020-15199
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` does not validate that the input arguments form a valid ragged tensor. In particular, there is no validation that the `splits` tensor has the minimum required number of elements. Code us...
CVEs:CVE-2020-15199
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
PYSEC-2020-314
CVEs:CVE-2020-15199
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CVEs:CVE-2020-0300
In NFC, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android...
CVEs:CVE-2020-0300
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0286
In Bluetooth AVRCP, there is a possible leak of audio metadata due to residual data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...
CVEs:CVE-2020-0286
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PYSEC-2020-132
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-289
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-324
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Null pointer dereference in tensorflow-lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Null pointer dereference in tensorflow-lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Null pointer dereference in tensorflow-lite
CVEs:CVE-2020-15209
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, a crafted TFLite model can force a node to have as input a tensor backed by a `nullptr` buffer. This can be achieved by changing a buffer index in the flatbuffer serialization to...
CVEs:CVE-2020-15209
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| leap | affected | opensuse | — | — |
| tensorflow | affected | — | — |
PYSEC-2020-324
CVEs:CVE-2020-15209
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In libstagefright, there is possible CPU exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Andr...
CVEs:CVE-2020-0351
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0351
PYSEC-2020-136
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-293
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-328
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Denial of service in tensorflow-lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Denial of service in tensorflow-lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-328
CVEs:CVE-2020-15213
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger a denial of service by causing an out of memory allocation in the implementation of segment sum. Since code uses the last element of the tensor holding them to det...
CVEs:CVE-2020-15213
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Denial of service in tensorflow-lite
CVEs:CVE-2020-15213
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-133
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-290
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-325
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segmentation fault in tensorflow-lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segmentation fault in tensorflow-lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segmentation fault in tensorflow-lite
CVEs:CVE-2020-15210
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an operator, then, depending on the operator, we can observe a segmentation fault or just memory corrupti...
CVEs:CVE-2020-15210
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| leap | affected | opensuse | — | — |
| tensorflow | affected | — | — |
PYSEC-2020-325
CVEs:CVE-2020-15210
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-135
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-292
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-327
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Out of bounds access in tensorflow-lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Out of bounds access in tensorflow-lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-327
CVEs:CVE-2020-15212
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger writes outside of bounds of heap allocated buffers by inserting negative elements in the segment ids tensor. Users having access to `segment_ids_data` can alter `o...
CVEs:CVE-2020-15212
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Out of bounds access in tensorflow-lite
CVEs:CVE-2020-15212
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Stored XSS vulnerability in android-lint Plugin
CVEs:CVE-2020-2262
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jvnet.hudson.plugins:android-lint | affected | Maven | org.jvnet.hudson.plugins:android-lint | — |
Jenkins Android Lint Plugin 2.6 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to the plugin's post-build step.
CVEs:CVE-2020-2262
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android_lint | affected | jenkins | — | — |
In libAACdec, there is a possible out of bounds read due to missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: And...
CVEs:CVE-2020-0370
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0370
CVEs:CVE-2020-0361
In libDRCdec, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: A...
CVEs:CVE-2020-0361
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In libcodec2_soft_mp3dec, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: Androi...
CVEs:CVE-2020-0340
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0340
PYSEC-2020-120
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-277
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-312
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Denial of Service in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Denial of Service in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input arguments form a valid sparse tensor. In particular, there is no validation that the `indices` tensor has rank 2. This tensor must be a ma...
CVEs:CVE-2020-15197
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Denial of Service in Tensorflow
CVEs:CVE-2020-15197
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-312
CVEs:CVE-2020-15197
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersion...
CVEs:CVE-2020-0362
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0362
In libmp4extractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:...
CVEs:CVE-2020-0353
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0353
CVEs:CVE-2020-0321
In the mp3 extractor, there is a possible out of bounds write due to uninitialized data. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Andr...
CVEs:CVE-2020-0321
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0264
In libstagefright, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Androi...
CVEs:CVE-2020-0264
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0348
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over NFC with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A...
CVEs:CVE-2020-0348
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PYSEC-2020-137
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-294
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-329
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Out of bounds write in tensorflow-lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Out of bounds write in tensorflow-lite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-329
CVEs:CVE-2020-15214
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger a write out bounds / segmentation fault if the segment ids are not sorted. Code assumes that the segment ids are in increasing order, using the last element of the...
CVEs:CVE-2020-15214
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Out of bounds write in tensorflow-lite
CVEs:CVE-2020-15214
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CVEs:CVE-2020-25278
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The Quram image codec library allows attackers to overwrite memory and execute arbitrary code via crafted JPEG data that is mishandled during decoding. The Sam...
CVEs:CVE-2020-25278
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Parse_ins of eas_mdls.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure in the media extractor process with no additional execution privileges needed. User interaction is neede...
CVEs:CVE-2020-0383
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0383
In Parse_art of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote information disclosure in the media extractor with no additional execution privileges needed. User interaction is needed for...
CVEs:CVE-2020-0384
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0384
CVEs:CVE-2020-0385
In Parse_insh of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote information disclosure in the media extractor with no additional execution privileges needed. User interaction is needed fo...
CVEs:CVE-2020-0385
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0363
In libmedia, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: And...
CVEs:CVE-2020-0363
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0332
In libstagefright, there is a possible dead loop due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11A...
CVEs:CVE-2020-0332
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersion...
CVEs:CVE-2020-0320
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0320
CVEs:CVE-2020-0301
In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersion...
CVEs:CVE-2020-0301
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In libmkvextractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:...
CVEs:CVE-2020-0287
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0287
There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-149871374
CVEs:CVE-2020-0123
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0123
ASB-A-149871374
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Integer overflow in the bundled Brotli C library
CVEs:CVE-2020-36846
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| brotli | affected | PyPI | brotli | — |
| compu-brotli-sys | affected | crates.io | compu-brotli-sys | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm | — |
| Microsoft.NETCore.App.Runtime.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.osx-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.osx-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.win-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.win-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.win-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.win-x86 | — |
| Microsoft.NETCore.App.Runtime.osx-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.osx-arm64 | — |
| Microsoft.NETCore.App.Runtime.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.win-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm | — |
| Microsoft.NETCore.App.Runtime.win-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm64 | — |
| Microsoft.NETCore.App.Runtime.win-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x64 | — |
| Microsoft.NETCore.App.Runtime.win-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x86 | — |
A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library. Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length o...
CVEs:CVE-2020-36846
PYSEC-2020-29
CVEs:CVE-2020-36846
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| brotli | affected | PyPI | brotli | — |
| compu-brotli-sys | affected | crates.io | compu-brotli-sys | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm | — |
| Microsoft.NETCore.App.Runtime.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.osx-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.osx-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.win-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.win-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.win-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.win-x86 | — |
| Microsoft.NETCore.App.Runtime.osx-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.osx-arm64 | — |
| Microsoft.NETCore.App.Runtime.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.win-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm | — |
| Microsoft.NETCore.App.Runtime.win-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm64 | — |
| Microsoft.NETCore.App.Runtime.win-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x64 | — |
| Microsoft.NETCore.App.Runtime.win-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x86 | — |
CVEs:CVE-2020-0282
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure. System execution privileges, a Firmware compromise, and User interaction are needed for exploitation.Product: AndroidVersion...
CVEs:CVE-2020-0282
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure. System execution privileges, a Firmware compromise, and User interaction is needed for exploitation.Product: AndroidVersions...
CVEs:CVE-2020-0281
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0281
DEBIAN-CVE-2020-6554
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
PYSEC-2020-124
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-281
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-316
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in Tensorflow
CVEs:CVE-2020-15201
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-316
CVEs:CVE-2020-15201
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` implementation does not validate that the input arguments form a valid ragged tensor. In particular, there is no validation that the values in the `splits` tensor generate a valid partit...
CVEs:CVE-2020-15201
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-156333725
CVEs:CVE-2020-0229
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0229
CVEs:CVE-2020-0278
There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-160812574
CVEs:CVE-2020-0278
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0342
There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-160812576
CVEs:CVE-2020-0342
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-156333725
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-160812574
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-160812576
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In the Media extractor, there is a possible use after free due to improper locking. This could lead to remote code execution in the media extractor with no additional execution privileges needed. User interaction is needed for exploitation.Product: And...
CVEs:CVE-2020-0303
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0303
In WindowManager, there is a possible launch of an unexpected app due to a confused deputy. This could lead to local escalation of privilege due to launching a malicious app instead of the one the user intended, with no additional execution privileges ...
CVEs:CVE-2020-0267
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0267
PYSEC-2020-121
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-278
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-313
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in Tensorflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow in Tensorflow
CVEs:CVE-2020-15198
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-313
CVEs:CVE-2020-15198
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input arguments form a valid sparse tensor. In particular, there is no validation that the `indices` tensor has the same shape as the `values` o...
CVEs:CVE-2020-15198
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
CVEs:CVE-2020-0427
In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2020-0427
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| debian_linux | affected | debian | — | — |
| leap | affected | opensuse | — | — |
| starwind_virtual_san | affected | starwindsoftware | — | — |
In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. This could lead to local escalation of privilege and account hijacking with no additional execution privileges needed. User interactio...
CVEs:CVE-2020-0387
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0387
CVEs:CVE-2020-25283
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. BT manager allows attackers to bypass intended access restrictions on a certain mode. The LG ID is LVE-SMP-200021 (September 2020).
CVEs:CVE-2020-25283
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0360
In Notification Access Confirmation, there is a possible permissions bypass due to uninformed consent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidV...
CVEs:CVE-2020-0360
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Integrated Circuit Card) allows attackers to bypass intended access restrictions on property values. The LG ID is LVE-SMP-200020 (Septem...
CVEs:CVE-2020-25282
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-25282
CVEs:CVE-2020-0319
In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is needed for exploitation.Product: Andr...
CVEs:CVE-2020-0319
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0406
In libmpeg2dec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if another exploit allowed this to be triggered with different parameters, with no additional execution privileges n...
CVEs:CVE-2020-0406
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0130
In screencap, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege in a system process with User execution privileges needed. User interaction is not needed for exploitation.Product: A...
CVEs:CVE-2020-0130
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0366
In PackageInstaller, there is a possible permissions bypass due to a tapjacking vulnerability. This could lead to local escalation of privilege using an app set as the default Assist app with User execution privileges needed. User interaction is needed...
CVEs:CVE-2020-0366
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Security update for for SUSE Manager 4.1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-gson | affected | SUSE:Manager Server Module 4.1 | google-gson | — |
| httpcomponents-client | affected | SUSE:Manager Server Module 4.1 | httpcomponents-client | — |
| httpcomponents-core | affected | SUSE:Manager Server Module 4.1 | httpcomponents-core | — |
| salt-netapi-client | affected | SUSE:Manager Server Module 4.1 | salt-netapi-client | — |
| spacewalk-admin | affected | SUSE:Manager Server Module 4.1 | spacewalk-admin | — |
| spacewalk-java | affected | SUSE:Manager Server Module 4.1 | spacewalk-java | — |
| spacewalk-setup | affected | SUSE:Manager Server Module 4.1 | spacewalk-setup | — |
In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverability with User execution privileges...
CVEs:CVE-2020-0386
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0386
Insufficient policy enforcement in installer in Google Chrome on OS X prior to 85.0.4183.102 allowed a local attacker to potentially achieve privilege escalation via a crafted binary.
CVEs:CVE-2020-6574
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| backports_sle | affected | opensuse | — | — |
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| leap | affected | opensuse | — | — |
CVEs:CVE-2020-6574
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Applications with sensitive security settings (such as the package verifier application) mishandle unknown-source installations. The LG ID is LVE-SMP-190...
CVEs:CVE-2020-25281
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-25281
In the Bluetooth service, there is a possible spoofing attack due to a logic error. This could lead to remote information disclosure of sensitive information with no additional execution privileges needed. User interaction is needed for exploitation.Pr...
CVEs:CVE-2020-0379
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0379
An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-09-29, as used in COVID-19 applications on Android and iOS. It allows a user to be put in a position where he or she can be coerced into proving or disp...
CVEs:CVE-2020-24721
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| exposure_notifications | affected | — | — | |
| exposure_notifications | affected | apple | — | — |
CVEs:CVE-2020-24721
In netd, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android...
CVEs:CVE-2020-0365
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0365
ASB-A-148816706
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
CVEs:CVE-2020-0404
In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not n...
CVEs:CVE-2020-0404
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| communications_cloud_native_core_binding_support_function | affected | oracle | — | — |
| communications_cloud_native_core_network_exposure_function | affected | oracle | — | — |
| communications_cloud_native_core_policy | affected | oracle | — | — |
ASB-A-111893654
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: And...
CVEs:CVE-2020-0344
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0344
In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: And...
CVEs:CVE-2020-0352
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0352
ASB-A-157905780
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
ASB-A-157906588
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
In skb_to_mamac of networking.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produc...
CVEs:CVE-2020-0432
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| leap | affected | opensuse | — | — |
CVEs:CVE-2020-0432
CVEs:CVE-2020-0431
In kbd_keycode of keyboard.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produc...
CVEs:CVE-2020-0431
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| leap | affected | opensuse | — | — |
CVEs:CVE-2020-0293
In Java network APIs, there is possible access to sensitive network state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation...
CVEs:CVE-2020-0293
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-147102899
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
ASB-A-147104886
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
CVEs:CVE-2020-0345
In DocumentsUI, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Andro...
CVEs:CVE-2020-0345
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0430
In skb_headlen of /include/linux/skbuff.h, there is a possible out of bounds read due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation...
CVEs:CVE-2020-0430
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0396
In various places in Telephony, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2020-0396
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0399
In showLimitedSimFunctionWarningNotification of NotificationMgr.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not n...
CVEs:CVE-2020-0399
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0347
In iptables, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A...
CVEs:CVE-2020-0347
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0429
In l2tp_session_delete and related functions of l2tp_core.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2020-0429
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In showNotification of EmergencyCallbackModeService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2020-0395
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0395
CVEs:CVE-2020-0397
In getNotificationBuilder of CarrierServiceStateTracker.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2020-0397
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0306
In LLVM, there is a possible ineffective stack cookie placement due to stack frame double reservation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...
CVEs:CVE-2020-0306
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In createEmergencyLocationUserNotification of GnssVisibilityControl.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interac...
CVEs:CVE-2020-0388
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0388
CVEs:CVE-2020-0294
In bindWallpaperComponentLocked of WallpaperManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not neede...
CVEs:CVE-2020-0294
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege and the setting of supported EUICC countries with no additional execution privileges needed. User interaction is not...
CVEs:CVE-2020-0375
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0375
CVEs:CVE-2020-0374
In NFC, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11An...
CVEs:CVE-2020-0374
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In factory reset protection, there is a possible FRP bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: And...
CVEs:CVE-2020-0266
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0266
CVEs:CVE-2020-0275
In MediaProvider, there is a possible way to access ContentResolver and MediaStore entries the app shouldn't have access to due to a permissions bypass. This could lead to local escalation of privilege, with no additional execution privileges needed. U...
CVEs:CVE-2020-0275
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges and a compromised Firmware needed. User interaction is not needed for exploitation.Prod...
CVEs:CVE-2020-0291
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0291
In the Settings app, there is an insecure default value. This could lead to local escalation of privilege and tapjacking with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: ...
CVEs:CVE-2020-0271
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0271
CVEs:CVE-2020-0336
In SurfaceFlinger, there is possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11...
CVEs:CVE-2020-0336
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In NotificationManagerService, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: Android...
CVEs:CVE-2020-0313
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos and MediaTek chipsets) software. Unauthenticated attackers can execute LTE/5G commands by sending a debugging command over USB. The Samsung ID is SVE-2020-16979 (September 2020).
CVEs:CVE-2020-25280
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-25280
CVEs:CVE-2020-0359
In GLESRenderEngine, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...
CVEs:CVE-2020-0359
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0346
In Mediaserver, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if integer sanitization were not enabled (which it is by default), with no additional execution privileges needed. User...
CVEs:CVE-2020-0346
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In decrypt and decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2020-0393
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0393
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges and a compromised Firmware needed. User interaction is not needed for exploitation.Prod...
CVEs:CVE-2020-0292
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0292
In Pixel's use of the Catpipe library, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2020-0434
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0434
In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android...
CVEs:CVE-2020-0338
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0338
In createSaveNotification of RecordingService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2020-0389
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0389
CVEs:CVE-2020-0403
In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This could lead to local escalation of privilege in the TEE, with System execution privileges required. User interaction is not needed for...
CVEs:CVE-2020-0403
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0307
In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-...
CVEs:CVE-2020-0307
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0302
In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-...
CVEs:CVE-2020-0302
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is not needed for exploitation.Product: ...
CVEs:CVE-2020-0350
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0350
CVEs:CVE-2020-0335
In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is not needed for exploitation.Product: ...
CVEs:CVE-2020-0335
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is not needed for exploitation.Product: ...
CVEs:CVE-2020-0334
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0334
In RunInternal of dumpstate.cpp, there is a possible user consent bypass due to an uncaught exception. This could lead to local information disclosure of bug report data with System execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2020-0382
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0382
CVEs:CVE-2020-0349
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11A...
CVEs:CVE-2020-0349
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In WiFi tethering, there is a possible attacker controlled intent due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...
CVEs:CVE-2020-0262
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0262
In apexd, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-1...
CVEs:CVE-2020-0322
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0322
CVEs:CVE-2020-0369
In libavb, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: An...
CVEs:CVE-2020-0369
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In blk_mq_queue_tag_busy_iter of blk-mq-tag.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2020-0433
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0433
CVEs:CVE-2020-0273
In hwservicemanager, there is a possible out of bounds write due to freeing a wild pointer. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2020-0273
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In the Audio HAL, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...
CVEs:CVE-2020-0356
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0356
CVEs:CVE-2020-0426
In SyncManager, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...
CVEs:CVE-2020-0426
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Android Auto Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi...
CVEs:CVE-2020-0269
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0269
In NFC, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11And...
CVEs:CVE-2020-0326
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0326
In devicepolicy service, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...
CVEs:CVE-2020-0297
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0297
In ADB server and USB server, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...
CVEs:CVE-2020-0296
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0296
In libavb, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A...
CVEs:CVE-2020-0323
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0323
CVEs:CVE-2020-0330
In iorap, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege and code execution with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...
CVEs:CVE-2020-0330
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0327
In core networking, there is a missing permission check. This could lead to local information disclosure of app network usage with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11And...
CVEs:CVE-2020-0327
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0310
In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-...
CVEs:CVE-2020-0310
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0299
In Bluetooth, there is a possible spoofing of bluetooth device metadata due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: ...
CVEs:CVE-2020-0299
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Bluetooth, there is a possible control over Bluetooth enabled state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2020-0298
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0298
CVEs:CVE-2020-0308
In Window Manager, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: An...
CVEs:CVE-2020-0308
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0325
In NFC, there is a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-145079309
CVEs:CVE-2020-0325
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In libhwbinder, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: A...
CVEs:CVE-2020-0272
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0272
In the camera, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android...
CVEs:CVE-2020-0328
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0328
In the app zygote SE Policy, there is a possible permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 An...
CVEs:CVE-2020-0390
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0390
In Settings, there is a possible permissions bypass. This could lead to local information disclosure of the device's IMEI with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android...
CVEs:CVE-2020-0331
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0331
CVEs:CVE-2020-0315
In Zen Mode, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-...
CVEs:CVE-2020-0315
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In InputManagerService, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersion...
CVEs:CVE-2020-0311
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0311
In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-...
CVEs:CVE-2020-0304
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0304
CVEs:CVE-2020-0295
In Telecom, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-1...
CVEs:CVE-2020-0295
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Battery Saver, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: And...
CVEs:CVE-2020-0312
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0312
In MediaProvider, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local information disclosure, with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...
CVEs:CVE-2020-0337
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0337
In the OMX encoder, there is a possible out of bounds read due to invalid input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android...
CVEs:CVE-2020-0329
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0329
In the OMX parser, there is a possible information disclosure due to a returned raw pointer. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2020-0274
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0274
CVEs:CVE-2020-0425
There is a possible way to view notifications even when the "Lockdown" feature is on. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...
CVEs:CVE-2020-0425
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0265
In Telephony, there are possible leaks of sensitive data due to missing permission checks. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...
CVEs:CVE-2020-0265
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0405
In NetworkStackNotifier, there is a possible permissions bypass due to an unsafe implicit PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: An...
CVEs:CVE-2020-0405
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In the System UI, there is a possible system crash due to an uncaught exception. This could lead to local permanent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...
CVEs:CVE-2020-0318
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0318
CVEs:CVE-2020-0314
In AudioService, there are missing permission checks. This could lead to local information disclosure of audio configuration with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andro...
CVEs:CVE-2020-0314
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In NetworkStatsService, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...
CVEs:CVE-2020-0343
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0343
CVEs:CVE-2020-0341
In DisplayManager, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2020-0341
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In NetworkPolicyManagerService, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing a malicious app to modify the device's data plan with no additional execution privileges...
CVEs:CVE-2020-0277
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0277
In the audio server, there is a missing permission check. This could lead to local escalation of privilege regarding audio settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions...
CVEs:CVE-2020-0089
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0089
In the Bluetooth server, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System privileges and a Firmware compromise needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2020-0309
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0309
CVEs:CVE-2020-0285
In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi...
CVEs:CVE-2020-0285
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0284
In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi...
CVEs:CVE-2020-0284
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0289
In PackageManager, there is a missing permission check. This could lead to local information disclosure across users with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11And...
CVEs:CVE-2020-0289
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In PackageManager, there is a missing permission check. This could lead to local information disclosure across user boundaries with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: And...
CVEs:CVE-2020-0288
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0288
CVEs:CVE-2020-0276
In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi...
CVEs:CVE-2020-0276
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0263
In the Accessibility service, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...
CVEs:CVE-2020-0263
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0316
In Telephony, there is a missing permission check. This could lead to local information disclosure of radio data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android...
CVEs:CVE-2020-0316
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In ActivityManager, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:...
CVEs:CVE-2020-0372
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0372
In UsageStatsManager, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Produc...
CVEs:CVE-2020-0317
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0317
CVEs:CVE-2020-0290
In PackageManager, there is a missing permission check. This could lead to local information disclosure across users with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11And...
CVEs:CVE-2020-0290
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In SurfaceFlinger, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the graphics server with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2020-0357
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0357
In SurfaceFlinger, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-1...
CVEs:CVE-2020-0358
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0358
In NFC, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID...
CVEs:CVE-2020-0268
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0268
In various functions in fscrypt_ice.c and related files in some implementations of f2fs encryption that use encryption hardware which only supports 32-bit IVs (Initialization Vectors), 64-bit IVs are used and later are truncated to 32 bits. This may ca...
CVEs:CVE-2020-0407
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0407
CVEs:CVE-2020-0428
In CamX code, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android kern...
CVEs:CVE-2020-0428
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-153450752
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2020-0373
In SoundTriggerHwService, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...
CVEs:CVE-2020-0373
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Malicious Package in angular-location-update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-location-update | affected | npm | angular-location-update | — |
Malicious Package in angular-location-update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-location-update | affected | npm | angular-location-update | — |
Denial of Service in grpc-ts-health-check
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| grpc-ts-health-check | affected | npm | grpc-ts-health-check | — |
Denial of Service in grpc-ts-health-check
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| grpc-ts-health-check | affected | npm | grpc-ts-health-check | — |
Cross-Site Scripting in google-closure-library
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-closure-library | affected | npm | google-closure-library | — |
Cross-Site Scripting in google-closure-library
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-closure-library | affected | npm | google-closure-library | — |
Improper Authorization in googleapis
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| googleapis | affected | npm | googleapis | — |
Improper Authorization in googleapis
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| googleapis | affected | npm | googleapis | — |
Malicious Package in angular-material-sidenav-rnd
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-material-sidenav-rnd | affected | npm | angular-material-sidenav-rnd | — |
Malicious Package in angular-material-sidenav-rnd
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-material-sidenav-rnd | affected | npm | angular-material-sidenav-rnd | — |
Malicious Package in angular-bmap
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-bmap | affected | npm | angular-bmap | — |
Malicious Package in angular-bmap
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-bmap | affected | npm | angular-bmap | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.