Google Security Advisories · September 2020 — Google Security Advisories
631 advisories 377 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2020-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

AZL-79064

Open SourceWeaponized exploitCRITICAL2020-09-02

CVE-2020-24553 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

CVE-2020-24553

GoogleWeaponized exploitCRITICAL2020-09-02

Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a Content-Type header.

CVEs:CVE-2020-24553

Affected products

ProductStatusVendorPackageEcosystem
communications_cloud_native_core_policy affected oracle
fedora affected fedoraproject
go affected golang
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-24553

Open SourceWeaponized exploitCRITICAL2020-09-02

DEBIAN-CVE-2020-24553

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

GHSA-gwpf-62xp-vrg6

Open SourceWeaponized exploitHIGH2020-09-11

Information Exposure in cordova-android

Affected products

ProductStatusVendorPackageEcosystem
cordova-android affected npm cordova-android
Upstream advisory

GHSA-gwpf-62xp-vrg6

Open SourceWeaponized exploitHIGH2020-09-11

Information Exposure in cordova-android

Affected products

ProductStatusVendorPackageEcosystem
cordova-android affected npm cordova-android
Upstream advisory

RHSA-2020:3665

Open SourcePoC exploitHIGH2020-09-08

Red Hat Security Advisory: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:enterprise_linux:8::appstream delve
delve-debuginfo affected Red Hat:enterprise_linux:8::appstream delve-debuginfo
delve-debugsource affected Red Hat:enterprise_linux:8::appstream delve-debugsource
golang affected Red Hat:enterprise_linux:8::appstream golang
golang-bin affected Red Hat:enterprise_linux:8::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:8::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:8::appstream golang-misc
golang-race affected Red Hat:enterprise_linux:8::appstream golang-race
golang-src affected Red Hat:enterprise_linux:8::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:8::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:8::appstream go-toolset
Upstream advisory

CVE-2020-0380

Open SourcePoC exploitHIGH2020-09-09

In allocExcessBits of bitalloc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2020-0380

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2020-26160

Open SourcePoC exploitHIGH2020-09-30

DEBIAN-CVE-2020-26160

Affected products

ProductStatusVendorPackageEcosystem
golang-github-dgrijalva-jwt-go affected Debian:11 golang-github-dgrijalva-jwt-go
golang-github-dgrijalva-jwt-go affected Debian:12 golang-github-dgrijalva-jwt-go
Upstream advisory

CVE-2020-0245

Open SourcePoC exploitHIGH2020-09-09

In DecodeFrameCombinedMode of combined_decode.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for ex...

CVEs:CVE-2020-0245

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0381

Open SourcePoC exploitHIGH2020-09-09

In Parse_wave of eas_mdls.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote information disclosure in a highly constrained process with no additional execution privileges needed. User interaction is not ne...

CVEs:CVE-2020-0381

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-25279

Open SourcePoC exploitCRITICAL2020-09-11

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The baseband component has a buffer overflow via an abnormal SETUP message, leading to execution of arbitrary code. The Samsung ID is SVE-202...

CVEs:CVE-2020-25279

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0391

Open SourcePoC exploitHIGH2020-09-09

In applyPolicy of PackageManagerService.java, there is possible arbitrary command execution as System due to an unenforced protected-broadcast. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...

CVEs:CVE-2020-0391

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0401

Open SourcePoC exploitHIGH2020-09-09

In setInstallerPackageName of PackageManagerService.java, there is a missing permission check. This could lead to local escalation of privilege and granting spurious permissions with no additional execution privileges needed. User interaction is not ne...

CVEs:CVE-2020-0401

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0394

Open SourcePoC exploitHIGH2020-09-09

In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege and untrusted devices accessing contact lists with no additional execution privileges n...

CVEs:CVE-2020-0394

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0392

Open SourcePoC exploitHIGH2020-09-09

In getLayerDebugInfo of SurfaceFlinger.cpp, there is a possible code execution due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produc...

CVEs:CVE-2020-0392

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0074

Open SourcePoC exploitHIGH2020-09-09

In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges neede...

CVEs:CVE-2020-0074

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2020-6549

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6549

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6550

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6550

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6551

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6551

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian
Upstream advisory

DEBIAN-CVE-2020-6541

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6541

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6556

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6556

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-8927

GoogleCoalition ESS < 30%CRITICAL2020-09-15

A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 Gi...

CVEs:CVE-2020-8927

Affected products

ProductStatusVendorPackageEcosystem
brotli affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
.net affected microsoft
.net_core affected microsoft
powershell affected microsoft
ubuntu_linux affected canonical
visual_studio_2019 affected microsoft
visual_studio_2022 affected microsoft
Upstream advisory

CVE-2020-8927

Open SourceCoalition ESS < 30%MEDIUM2020-09-15

Integer overflow in the bundled Brotli C library

CVEs:CVE-2020-8927

Affected products

ProductStatusVendorPackageEcosystem
brotli affected PyPI brotli
compu-brotli-sys affected crates.io compu-brotli-sys
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.browser-wasm
Microsoft.NETCore.App.Runtime.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-arm
Microsoft.NETCore.App.Runtime.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-arm64
Microsoft.NETCore.App.Runtime.linux-musl-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm
Microsoft.NETCore.App.Runtime.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm64
Microsoft.NETCore.App.Runtime.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-x64
Microsoft.NETCore.App.Runtime.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-x64
Microsoft.NETCore.App.Runtime.Mono.android-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm
Microsoft.NETCore.App.Runtime.Mono.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm
Microsoft.NETCore.App.Runtime.Mono.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm
Microsoft.NETCore.App.Runtime.Mono.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64
Microsoft.NETCore.App.Runtime.Mono.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-arm64
Microsoft.NETCore.App.Runtime.Mono.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x64
Microsoft.NETCore.App.Runtime.Mono.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x86
Microsoft.NETCore.App.Runtime.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.osx-arm64
Microsoft.NETCore.App.Runtime.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.osx-x64
Microsoft.NETCore.App.Runtime.win-arm affected NuGet Microsoft.NETCore.App.Runtime.win-arm
Microsoft.NETCore.App.Runtime.win-arm64 affected NuGet Microsoft.NETCore.App.Runtime.win-arm64
Microsoft.NETCore.App.Runtime.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.win-x64
Microsoft.NETCore.App.Runtime.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.win-x86
Upstream advisory

openSUSE-SU-2020:1550-1

Open SourceCoalition ESS < 30%CRITICAL2020-09-27

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP2 chromium
Upstream advisory

openSUSE-SU-2020:1542-1

Open SourceCoalition ESS < 30%CRITICAL2020-09-26

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2020:1527-1

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

CVE-2020-15965

GoogleCoalition ESS < 30%HIGH2020-09-21

Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVEs:CVE-2020-15965

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-15965

Open SourceCoalition ESS < 30%HIGH2020-09-21

DEBIAN-CVE-2020-15965

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-15964

GoogleCoalition ESS < 30%HIGH2020-09-21

Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-15964

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-15964

Open SourceCoalition ESS < 30%HIGH2020-09-21

DEBIAN-CVE-2020-15964

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6548

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6548

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

openSUSE-SU-2020:1514-1

Open SourceCoalition ESS < 30%CRITICAL2020-09-24

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2020:1510-1

Open SourceCoalition ESS < 30%CRITICAL2020-09-23

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP2 chromium
Upstream advisory

openSUSE-SU-2020:1499-1

Open SourceCoalition ESS < 30%CRITICAL2020-09-22

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

DEBIAN-CVE-2020-6559

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6559

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

openSUSE-SU-2020:1328-1

Open SourceCoalition ESS < 30%CRITICAL2020-09-03

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2020:1322-1

Open SourceCoalition ESS < 30%CRITICAL2020-09-02

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP2 chromium
Upstream advisory

openSUSE-SU-2020:1309-1

Open SourceCoalition ESS < 30%CRITICAL2020-09-01

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

DEBIAN-CVE-2020-6555

Open SourceCoalition ESS < 30%HIGH2020-09-21

DEBIAN-CVE-2020-6555

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6542

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6542

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-25614

Open SourceCoalition ESS < 30%CRITICAL2020-09-16

DEBIAN-CVE-2020-25614

Affected products

ProductStatusVendorPackageEcosystem
golang-github-antchfx-xmlquery affected Debian:11 golang-github-antchfx-xmlquery
golang-github-antchfx-xmlquery affected Debian:12 golang-github-antchfx-xmlquery
golang-github-antchfx-xmlquery affected Debian:13 golang-github-antchfx-xmlquery
golang-github-antchfx-xmlquery affected Debian:14 golang-github-antchfx-xmlquery
Upstream advisory

CVE-2020-15962

GoogleCoalition ESS < 30%HIGH2020-09-21

Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVEs:CVE-2020-15962

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-15962

Open SourceCoalition ESS < 30%HIGH2020-09-21

DEBIAN-CVE-2020-15962

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-15960

GoogleCoalition ESS < 30%CRITICAL2020-09-21

Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVEs:CVE-2020-15960

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-15960

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-15960

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6573

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6573

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6573

GoogleCoalition ESS < 30%CRITICAL2020-09-09

Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-6573

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6563

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6563

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6560

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6560

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

DEBIAN-CVE-2020-6576

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6576

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6576

GoogleCoalition ESS < 30%CRITICAL2020-09-09

Use after free in offscreen canvas in Google Chrome prior to 85.0.4183.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6576

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6566

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6566

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6537

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6537

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6564

Open SourceCoalition ESS < 30%MEDIUM2020-09-21

DEBIAN-CVE-2020-6564

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

SUSE-SU-2020:2606-1

Open SourceCoalition ESS < 30%HIGH2020-09-11

Security update for golang-github-prometheus-prometheus

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-prometheus affected SUSE:Enterprise Storage 6 golang-github-prometheus-prometheus
Upstream advisory

DEBIAN-CVE-2020-6561

Open SourceCoalition ESS < 30%MEDIUM2020-09-21

DEBIAN-CVE-2020-6561

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6552

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6552

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6553

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6553

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6540

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6540

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6567

Open SourceCoalition ESS < 30%MEDIUM2020-09-21

DEBIAN-CVE-2020-6567

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6568

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6568

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6562

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6562

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6565

Open SourceCoalition ESS < 30%MEDIUM2020-09-21

DEBIAN-CVE-2020-6565

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-15961

GoogleCoalition ESS < 30%CRITICAL2020-09-21

Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

CVEs:CVE-2020-15961

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2020-15963

GoogleCoalition ESS < 30%CRITICAL2020-09-21

Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

CVEs:CVE-2020-15963

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-15961

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-15961

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-15963

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-15963

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6543

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6543

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6544

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6544

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6545

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6545

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6575

Open SourceCoalition ESS < 30%HIGH2020-09-21

DEBIAN-CVE-2020-6575

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6575

GoogleCoalition ESS < 30%HIGH2020-09-09

Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-6575

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

ASB-A-150693748

GoogleCoalition ESS < 30%HIGH2020-09-01

ASB-A-150693748

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2020-15966

GoogleCoalition ESS < 30%CRITICAL2020-09-21

Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.

CVEs:CVE-2020-15966

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-15966

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-15966

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6571

Open SourceCoalition ESS < 30%MEDIUM2020-09-21

DEBIAN-CVE-2020-6571

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6532

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6532

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

PYSEC-2020-125

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-125

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-282

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-282

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-317

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-317

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h6fg-mjxg-hqq4

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Integer truncation in Shard API usage

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h6fg-mjxg-hqq4

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Integer truncation in Shard API usage

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15202

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-317

CVEs:CVE-2020-15202

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15202

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `Shard` API in TensorFlow expects the last argument to be a function taking two `int64` (i.e., `long long`) arguments. However, there are several places in TensorFlow where a lamb...

CVEs:CVE-2020-15202

Affected products

ProductStatusVendorPackageEcosystem
leap affected opensuse
tensorflow affected google
Upstream advisory

CVE-2020-15202

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Integer truncation in Shard API usage

CVEs:CVE-2020-15202

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

DEBIAN-CVE-2020-6569

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6569

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

PYSEC-2020-130

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-130

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-287

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-287

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-322

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-322

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-q4qf-3fc6-8x34

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Segfault and data corruption in tensorflow-lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-q4qf-3fc6-8x34

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Segfault and data corruption in tensorflow-lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15207

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-322

CVEs:CVE-2020-15207

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15207

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, to mimic Python's indexing with negative values, TFLite uses `ResolveAxis` to convert negative values to positive indices. However, the only check that the converted index is now...

CVEs:CVE-2020-15207

Affected products

ProductStatusVendorPackageEcosystem
leap affected opensuse
tensorflow affected google
Upstream advisory

CVE-2020-15207

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Segfault and data corruption in tensorflow-lite

CVEs:CVE-2020-15207

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

DEBIAN-CVE-2020-15959

Open SourceCoalition ESS < 30%HIGH2020-09-21

DEBIAN-CVE-2020-15959

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-15959

GoogleCoalition ESS < 30%HIGH2020-09-09

Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via social engineering.

CVEs:CVE-2020-15959

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6570

Open SourceCoalition ESS < 30%HIGH2020-09-21

DEBIAN-CVE-2020-6570

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6547

Open SourceCoalition ESS < 30%HIGH2020-09-21

DEBIAN-CVE-2020-6547

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-0354

Open SourceCoalition ESS < 30%CRITICAL2020-09-18

In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andr...

CVEs:CVE-2020-0354

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PYSEC-2020-128

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-128

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-285

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-285

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-320

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-320

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-g7p5-5759-qv46

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Data leak in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-g7p5-5759-qv46

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Data leak in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15205

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-320

CVEs:CVE-2020-15205

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15205

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Data leak in Tensorflow

CVEs:CVE-2020-15205

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15205

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGrams` lacks validation. This allows a user to pass values that can cause heap overflow errors and even leak contents of memory In the...

CVEs:CVE-2020-15205

Affected products

ProductStatusVendorPackageEcosystem
leap affected opensuse
tensorflow affected google
Upstream advisory

PYSEC-2020-117

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-117

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-274

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-274

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-309

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-309

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9mqp-7v2h-2382

Open SourceCoalition ESS < 30%HIGH2020-09-25

Denial of Service in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9mqp-7v2h-2382

Open SourceCoalition ESS < 30%HIGH2020-09-25

Denial of Service in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15194

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

PYSEC-2020-309

CVEs:CVE-2020-15194

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15194

Open SourceCoalition ESS < 30%HIGH2020-09-25

Denial of Service in Tensorflow

CVEs:CVE-2020-15194

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15194

Open SourceCoalition ESS < 30%HIGH2020-09-25

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `SparseFillEmptyRowsGrad` implementation has incomplete validation of the shapes of its arguments. Although `reverse_index_map_t` and `grad_values_t` are accessed in a similar pat...

CVEs:CVE-2020-15194

Affected products

ProductStatusVendorPackageEcosystem
leap affected opensuse
tensorflow affected google
Upstream advisory

DEBIAN-CVE-2020-6538

Open SourceCoalition ESS < 30%MEDIUM2020-09-21

DEBIAN-CVE-2020-6538

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-0279

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In the AAC parser, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersio...

CVEs:CVE-2020-0279

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2020-6539

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6539

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

PYSEC-2020-126

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-126

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-283

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-283

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-318

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-318

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xmq7-7fxm-rr79

Open SourceCoalition ESS < 30%HIGH2020-09-25

Denial of Service in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xmq7-7fxm-rr79

Open SourceCoalition ESS < 30%HIGH2020-09-25

Denial of Service in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15203

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-318

CVEs:CVE-2020-15203

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15203

Open SourceCoalition ESS < 30%HIGH2020-09-25

Denial of Service in Tensorflow

CVEs:CVE-2020-15203

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15203

Open SourceCoalition ESS < 30%HIGH2020-09-25

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, by controlling the `fill` argument of tf.strings.as_string, a malicious attacker is able to trigger a format string vulnerability due to the way the internal format use in a `printf` ...

CVEs:CVE-2020-15203

Affected products

ProductStatusVendorPackageEcosystem
leap affected opensuse
tensorflow affected google
Upstream advisory

PYSEC-2020-129

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-129

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-286

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-286

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-321

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-321

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-w5gh-2wr2-pm6g

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Denial of Service in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-w5gh-2wr2-pm6g

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Denial of Service in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15206

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Denial of Service in Tensorflow

CVEs:CVE-2020-15206

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15206

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-321

CVEs:CVE-2020-15206

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15206

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, changing the TensorFlow's `SavedModel` protocol buffer and altering the name of required keys results in segfaults and data corruption while loading the model. This can cause a denial...

CVEs:CVE-2020-15206

Affected products

ProductStatusVendorPackageEcosystem
leap affected opensuse
tensorflow affected google
Upstream advisory

PYSEC-2020-118

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-118

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-275

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-275

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-310

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-310

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-63xm-rx5p-xvqr

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Heap buffer overflow in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-63xm-rx5p-xvqr

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Heap buffer overflow in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15195

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-310

CVEs:CVE-2020-15195

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15195

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Heap buffer overflow in Tensorflow

CVEs:CVE-2020-15195

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15195

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the implementation of `SparseFillEmptyRowsGrad` uses a double indexing pattern. It is possible for `reverse_index_map(i)` to be an index outside of bounds of `grad_values`, thus resul...

CVEs:CVE-2020-15195

Affected products

ProductStatusVendorPackageEcosystem
leap affected opensuse
tensorflow affected google
Upstream advisory

PYSEC-2020-113

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-113

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-270

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-270

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-305

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-305

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4g9f-63rx-5cw4

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

Segfault in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4g9f-63rx-5cw4

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

Segfault in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15190

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

PYSEC-2020-305

CVEs:CVE-2020-15190

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15190

Open SourceCoalition ESS < 30%HIGH2020-09-25

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `tf.raw_ops.Switch` operation takes as input a tensor and a boolean and outputs two tensors. Depending on the boolean value, one of the tensors is exactly the input tensor whereas...

CVEs:CVE-2020-15190

Affected products

ProductStatusVendorPackageEcosystem
leap affected opensuse
tensorflow affected google
Upstream advisory

CVE-2020-15190

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

Segfault in Tensorflow

CVEs:CVE-2020-15190

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2020-134

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-134

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-291

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-291

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-326

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-326

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cvpc-8phh-8f45

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

Out of bounds access in tensorflow-lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cvpc-8phh-8f45

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

Out of bounds access in tensorflow-lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15211

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, saved models in the flatbuffer format use a double indexing scheme: a model has a set of subgraphs, each subgraph has a set of operators and each operator has a set of input/outp...

CVEs:CVE-2020-15211

Affected products

ProductStatusVendorPackageEcosystem
leap affected opensuse
tensorflow affected google
Upstream advisory

CVE-2020-15211

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

PYSEC-2020-326

CVEs:CVE-2020-15211

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15211

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

Out of bounds access in tensorflow-lite

CVEs:CVE-2020-15211

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2020-131

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-131

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-288

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-288

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-323

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-323

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mxjj-953w-2c2v

Open SourceCoalition ESS < 30%HIGH2020-09-25

Data corruption in tensorflow-lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mxjj-953w-2c2v

Open SourceCoalition ESS < 30%HIGH2020-09-25

Data corruption in tensorflow-lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15208

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-323

CVEs:CVE-2020-15208

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15208

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of two tensors, TFLite uses a `DCHECK` which is no-op outside of debug compilation modes. Since the function always returns the dimensi...

CVEs:CVE-2020-15208

Affected products

ProductStatusVendorPackageEcosystem
leap affected opensuse
tensorflow affected google
Upstream advisory

CVE-2020-15208

Open SourceCoalition ESS < 30%HIGH2020-09-25

Data corruption in tensorflow-lite

CVEs:CVE-2020-15208

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2020-119

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-119

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-127

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-127

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-276

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-276

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-284

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-284

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-311

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-311

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2020-319

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-319

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-q8gv-q7wr-9jf8

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

Segfault in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-q8gv-q7wr-9jf8

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

Segfault in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-pg59-2f92-5cph

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Heap buffer overflow in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-pg59-2f92-5cph

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Heap buffer overflow in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15196

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

In Tensorflow version 2.3.0, the `SparseCountSparseOutput` and `RaggedCountSparseOutput` implementations don't validate that the `weights` tensor has the same shape as the data. The check exists for `DenseCountSparseOutput`, where both tensors are full...

CVEs:CVE-2020-15196

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2020-15196

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Heap buffer overflow in Tensorflow

CVEs:CVE-2020-15196

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15196

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-311

CVEs:CVE-2020-15196

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15204

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

Segfault in Tensorflow

CVEs:CVE-2020-15204

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15204

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

In eager mode, TensorFlow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1 does not set the session state. Hence, calling `tf.raw_ops.GetSessionHandle` or `tf.raw_ops.GetSessionHandleV2` results in a null pointer dereference In linked snippet, in ...

CVEs:CVE-2020-15204

Affected products

ProductStatusVendorPackageEcosystem
leap affected opensuse
tensorflow affected google
Upstream advisory

CVE-2020-15204

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

PYSEC-2020-319

CVEs:CVE-2020-15204

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2020-114

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-114

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-271

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-271

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-306

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-306

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-q8qj-fc9q-cphr

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

Undefined behavior in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-q8qj-fc9q-cphr

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

Undefined behavior in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15191

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes an invalid argument to `dlpack.to_dlpack` the expected validations will cause variables to bind to `nullptr` while setting a `status` variable to the error condition. However, this `status...

CVEs:CVE-2020-15191

Affected products

ProductStatusVendorPackageEcosystem
leap affected opensuse
tensorflow affected google
Upstream advisory

CVE-2020-15191

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

PYSEC-2020-306

CVEs:CVE-2020-15191

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15191

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

Undefined behavior in Tensorflow

CVEs:CVE-2020-15191

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

DEBIAN-CVE-2020-15216

Open SourceCoalition ESS < 30%MEDIUM2020-09-29

DEBIAN-CVE-2020-15216

Affected products

ProductStatusVendorPackageEcosystem
golang-github-russellhaering-goxmldsig affected Debian:11 golang-github-russellhaering-goxmldsig
golang-github-russellhaering-goxmldsig affected Debian:12 golang-github-russellhaering-goxmldsig
Upstream advisory

PYSEC-2020-123

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-123

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-280

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-280

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-315

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-315

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-x7rp-74x2-mjf3

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Segfault in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-x7rp-74x2-mjf3

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Segfault in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15200

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Segfault in Tensorflow

CVEs:CVE-2020-15200

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15200

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-315

CVEs:CVE-2020-15200

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15200

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` implementation does not validate that the input arguments form a valid ragged tensor. In particular, there is no validation that the values in the `splits` tensor generate a valid partit...

CVEs:CVE-2020-15200

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2020-0333

Open SourceCoalition ESS < 30%CRITICAL2020-09-17

In UrlQuerySanitizer, there is a possible improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID...

CVEs:CVE-2020-0333

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0355

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In libFraunhoferAAC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVers...

CVEs:CVE-2020-0355

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0364

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In libDRCdec, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: A...

CVEs:CVE-2020-0364

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0324

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In libsonivox, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: ...

CVEs:CVE-2020-0324

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0270

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In tremolo, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: And...

CVEs:CVE-2020-0270

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PYSEC-2020-115

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-115

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-272

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-272

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-307

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-307

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8fxw-76px-3rxv

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

Memory leak in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8fxw-76px-3rxv

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

Memory leak in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15192

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

PYSEC-2020-307

CVEs:CVE-2020-15192

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15192

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes a list of strings to `dlpack.to_dlpack` there is a memory leak following an expected validation failure. The issue occurs because the `status` argument during validation failures is not pr...

CVEs:CVE-2020-15192

Affected products

ProductStatusVendorPackageEcosystem
leap affected opensuse
tensorflow affected google
Upstream advisory

CVE-2020-15192

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

Memory leak in Tensorflow

CVEs:CVE-2020-15192

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2020-116

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-116

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-273

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-273

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-308

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-308

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rjjg-hgv6-h69v

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Memory corruption in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rjjg-hgv6-h69v

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Memory corruption in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15193

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-308

CVEs:CVE-2020-15193

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15193

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

In Tensorflow before versions 2.2.1 and 2.3.1, the implementation of `dlpack.to_dlpack` can be made to use uninitialized memory resulting in further memory corruption. This is because the pybind11 glue code assumes that the argument is a tensor. Howeve...

CVEs:CVE-2020-15193

Affected products

ProductStatusVendorPackageEcosystem
leap affected opensuse
tensorflow affected google
Upstream advisory

CVE-2020-15193

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Memory corruption in Tensorflow

CVEs:CVE-2020-15193

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2020-122

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-122

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-279

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-279

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-314

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-314

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-x5cp-9pcf-pp3h

Open SourceCoalition ESS < 30%HIGH2020-09-25

Denial of Service in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-x5cp-9pcf-pp3h

Open SourceCoalition ESS < 30%HIGH2020-09-25

Denial of Service in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15199

Open SourceCoalition ESS < 30%HIGH2020-09-25

Denial of Service in Tensorflow

CVEs:CVE-2020-15199

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15199

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` does not validate that the input arguments form a valid ragged tensor. In particular, there is no validation that the `splits` tensor has the minimum required number of elements. Code us...

CVEs:CVE-2020-15199

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2020-15199

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-314

CVEs:CVE-2020-15199

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-0300

Open SourceCoalition ESS < 30%HIGH2020-09-18

In NFC, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android...

CVEs:CVE-2020-0300

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0286

Open SourceCoalition ESS < 30%HIGH2020-09-18

In Bluetooth AVRCP, there is a possible leak of audio metadata due to residual data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...

CVEs:CVE-2020-0286

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PYSEC-2020-132

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-132

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-289

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-289

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-324

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-324

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qh32-6jjc-qprm

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Null pointer dereference in tensorflow-lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qh32-6jjc-qprm

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Null pointer dereference in tensorflow-lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15209

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Null pointer dereference in tensorflow-lite

CVEs:CVE-2020-15209

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15209

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, a crafted TFLite model can force a node to have as input a tensor backed by a `nullptr` buffer. This can be achieved by changing a buffer index in the flatbuffer serialization to...

CVEs:CVE-2020-15209

Affected products

ProductStatusVendorPackageEcosystem
leap affected opensuse
tensorflow affected google
Upstream advisory

CVE-2020-15209

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-324

CVEs:CVE-2020-15209

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-0351

Open SourceCoalition ESS < 30%HIGH2020-09-17

In libstagefright, there is possible CPU exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Andr...

CVEs:CVE-2020-0351

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PYSEC-2020-136

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-136

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-293

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-293

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-328

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-328

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hjmq-236j-8m87

Open SourceCoalition ESS < 30%HIGH2020-09-25

Denial of service in tensorflow-lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hjmq-236j-8m87

Open SourceCoalition ESS < 30%HIGH2020-09-25

Denial of service in tensorflow-lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15213

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

PYSEC-2020-328

CVEs:CVE-2020-15213

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15213

Open SourceCoalition ESS < 30%HIGH2020-09-25

In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger a denial of service by causing an out of memory allocation in the implementation of segment sum. Since code uses the last element of the tensor holding them to det...

CVEs:CVE-2020-15213

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2020-15213

Open SourceCoalition ESS < 30%HIGH2020-09-25

Denial of service in tensorflow-lite

CVEs:CVE-2020-15213

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2020-133

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-133

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-290

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-290

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-325

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-325

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-x9j7-x98r-r4w2

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Segmentation fault in tensorflow-lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-x9j7-x98r-r4w2

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Segmentation fault in tensorflow-lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15210

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Segmentation fault in tensorflow-lite

CVEs:CVE-2020-15210

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15210

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an operator, then, depending on the operator, we can observe a segmentation fault or just memory corrupti...

CVEs:CVE-2020-15210

Affected products

ProductStatusVendorPackageEcosystem
leap affected opensuse
tensorflow affected google
Upstream advisory

CVE-2020-15210

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-325

CVEs:CVE-2020-15210

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2020-135

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-135

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-292

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-292

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-327

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-327

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hx2x-85gr-wrpq

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Out of bounds access in tensorflow-lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hx2x-85gr-wrpq

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Out of bounds access in tensorflow-lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15212

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-327

CVEs:CVE-2020-15212

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15212

Open SourceCoalition ESS < 30%HIGH2020-09-25

In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger writes outside of bounds of heap allocated buffers by inserting negative elements in the segment ids tensor. Users having access to `segment_ids_data` can alter `o...

CVEs:CVE-2020-15212

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2020-15212

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Out of bounds access in tensorflow-lite

CVEs:CVE-2020-15212

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-2262

Open SourceCoalition ESS < 30%HIGH2020-09-16

Stored XSS vulnerability in android-lint Plugin

CVEs:CVE-2020-2262

Affected products

ProductStatusVendorPackageEcosystem
org.jvnet.hudson.plugins:android-lint affected Maven org.jvnet.hudson.plugins:android-lint
Upstream advisory

CVE-2020-2262

Open SourceCoalition ESS < 30%CRITICAL2020-09-16

Jenkins Android Lint Plugin 2.6 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to the plugin's post-build step.

CVEs:CVE-2020-2262

Affected products

ProductStatusVendorPackageEcosystem
android_lint affected jenkins
Upstream advisory

CVE-2020-0370

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In libAACdec, there is a possible out of bounds read due to missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: And...

CVEs:CVE-2020-0370

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0361

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In libDRCdec, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: A...

CVEs:CVE-2020-0361

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0340

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In libcodec2_soft_mp3dec, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: Androi...

CVEs:CVE-2020-0340

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PYSEC-2020-120

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-120

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-277

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-277

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-312

Open SourceCoalition ESS < 30%HIGH2020-09-25

PYSEC-2020-312

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qc53-44cj-vfvx

Open SourceCoalition ESS < 30%HIGH2020-09-25

Denial of Service in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qc53-44cj-vfvx

Open SourceCoalition ESS < 30%HIGH2020-09-25

Denial of Service in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15197

Open SourceCoalition ESS < 30%HIGH2020-09-25

In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input arguments form a valid sparse tensor. In particular, there is no validation that the `indices` tensor has rank 2. This tensor must be a ma...

CVEs:CVE-2020-15197

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2020-15197

Open SourceCoalition ESS < 30%HIGH2020-09-25

Denial of Service in Tensorflow

CVEs:CVE-2020-15197

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15197

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

PYSEC-2020-312

CVEs:CVE-2020-15197

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-0362

Open SourceCoalition ESS < 30%HIGH2020-09-17

In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersion...

CVEs:CVE-2020-0362

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0353

Open SourceCoalition ESS < 30%HIGH2020-09-17

In libmp4extractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:...

CVEs:CVE-2020-0353

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0321

Open SourceCoalition ESS < 30%HIGH2020-09-17

In the mp3 extractor, there is a possible out of bounds write due to uninitialized data. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Andr...

CVEs:CVE-2020-0321

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0264

Open SourceCoalition ESS < 30%HIGH2020-09-17

In libstagefright, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Androi...

CVEs:CVE-2020-0264

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0348

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over NFC with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A...

CVEs:CVE-2020-0348

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PYSEC-2020-137

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-137

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-294

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-294

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-329

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-329

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-p2cq-cprg-frvm

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Out of bounds write in tensorflow-lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-p2cq-cprg-frvm

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Out of bounds write in tensorflow-lite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15214

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-329

CVEs:CVE-2020-15214

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15214

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger a write out bounds / segmentation fault if the segment ids are not sorted. Code assumes that the segment ids are in increasing order, using the last element of the...

CVEs:CVE-2020-15214

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2020-15214

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Out of bounds write in tensorflow-lite

CVEs:CVE-2020-15214

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-25278

Open SourceCoalition ESS < 30%CRITICAL2020-09-11

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The Quram image codec library allows attackers to overwrite memory and execute arbitrary code via crafted JPEG data that is mishandled during decoding. The Sam...

CVEs:CVE-2020-25278

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0383

Open SourceCoalition ESS < 30%HIGH2020-09-09

In Parse_ins of eas_mdls.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure in the media extractor process with no additional execution privileges needed. User interaction is neede...

CVEs:CVE-2020-0383

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0384

Open SourceCoalition ESS < 30%HIGH2020-09-09

In Parse_art of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote information disclosure in the media extractor with no additional execution privileges needed. User interaction is needed for...

CVEs:CVE-2020-0384

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0385

Open SourceCoalition ESS < 30%HIGH2020-09-09

In Parse_insh of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote information disclosure in the media extractor with no additional execution privileges needed. User interaction is needed fo...

CVEs:CVE-2020-0385

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0363

Open SourceCoalition ESS < 30%HIGH2020-09-17

In libmedia, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: And...

CVEs:CVE-2020-0363

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0332

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In libstagefright, there is a possible dead loop due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11A...

CVEs:CVE-2020-0332

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0320

Open SourceCoalition ESS < 30%HIGH2020-09-17

In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersion...

CVEs:CVE-2020-0320

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0301

Open SourceCoalition ESS < 30%HIGH2020-09-17

In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersion...

CVEs:CVE-2020-0301

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0287

Open SourceCoalition ESS < 30%HIGH2020-09-17

In libmkvextractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:...

CVEs:CVE-2020-0287

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0123

Open SourceCoalition ESS < 30%HIGH2020-09-09

There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-149871374

CVEs:CVE-2020-0123

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-149871374

GoogleCoalition ESS < 30%CRITICAL2020-09-01

ASB-A-149871374

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2020-36846

Open SourceCoalition ESS < 30%CRITICAL2021-12-20

Integer overflow in the bundled Brotli C library

CVEs:CVE-2020-36846

Affected products

ProductStatusVendorPackageEcosystem
brotli affected PyPI brotli
compu-brotli-sys affected crates.io compu-brotli-sys
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.browser-wasm
Microsoft.NETCore.App.Runtime.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-arm
Microsoft.NETCore.App.Runtime.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-arm64
Microsoft.NETCore.App.Runtime.linux-musl-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm
Microsoft.NETCore.App.Runtime.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm64
Microsoft.NETCore.App.Runtime.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-x64
Microsoft.NETCore.App.Runtime.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-x64
Microsoft.NETCore.App.Runtime.Mono.android-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm
Microsoft.NETCore.App.Runtime.Mono.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm
Microsoft.NETCore.App.Runtime.Mono.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm
Microsoft.NETCore.App.Runtime.Mono.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64
Microsoft.NETCore.App.Runtime.Mono.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-arm64
Microsoft.NETCore.App.Runtime.Mono.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x64
Microsoft.NETCore.App.Runtime.Mono.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x86
Microsoft.NETCore.App.Runtime.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.osx-arm64
Microsoft.NETCore.App.Runtime.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.osx-x64
Microsoft.NETCore.App.Runtime.win-arm affected NuGet Microsoft.NETCore.App.Runtime.win-arm
Microsoft.NETCore.App.Runtime.win-arm64 affected NuGet Microsoft.NETCore.App.Runtime.win-arm64
Microsoft.NETCore.App.Runtime.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.win-x64
Microsoft.NETCore.App.Runtime.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.win-x86
Upstream advisory

CVE-2020-36846

GoogleCoalition ESS < 30%CRITICAL2020-09-15

A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library.  Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length o...

CVEs:CVE-2020-36846

Upstream advisory

CVE-2020-36846

Open SourceCoalition ESS < 30%MEDIUM2020-09-15

PYSEC-2020-29

CVEs:CVE-2020-36846

Affected products

ProductStatusVendorPackageEcosystem
brotli affected PyPI brotli
compu-brotli-sys affected crates.io compu-brotli-sys
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.browser-wasm
Microsoft.NETCore.App.Runtime.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-arm
Microsoft.NETCore.App.Runtime.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-arm64
Microsoft.NETCore.App.Runtime.linux-musl-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm
Microsoft.NETCore.App.Runtime.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm64
Microsoft.NETCore.App.Runtime.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-x64
Microsoft.NETCore.App.Runtime.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-x64
Microsoft.NETCore.App.Runtime.Mono.android-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm
Microsoft.NETCore.App.Runtime.Mono.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm
Microsoft.NETCore.App.Runtime.Mono.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm
Microsoft.NETCore.App.Runtime.Mono.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64
Microsoft.NETCore.App.Runtime.Mono.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-arm64
Microsoft.NETCore.App.Runtime.Mono.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x64
Microsoft.NETCore.App.Runtime.Mono.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x86
Microsoft.NETCore.App.Runtime.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.osx-arm64
Microsoft.NETCore.App.Runtime.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.osx-x64
Microsoft.NETCore.App.Runtime.win-arm affected NuGet Microsoft.NETCore.App.Runtime.win-arm
Microsoft.NETCore.App.Runtime.win-arm64 affected NuGet Microsoft.NETCore.App.Runtime.win-arm64
Microsoft.NETCore.App.Runtime.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.win-x64
Microsoft.NETCore.App.Runtime.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.win-x86
Upstream advisory

CVE-2020-0282

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure. System execution privileges, a Firmware compromise, and User interaction are needed for exploitation.Product: AndroidVersion...

CVEs:CVE-2020-0282

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0281

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure. System execution privileges, a Firmware compromise, and User interaction is needed for exploitation.Product: AndroidVersions...

CVEs:CVE-2020-0281

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2020-6554

Open SourceCoalition ESS < 30%CRITICAL2020-09-21

DEBIAN-CVE-2020-6554

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

PYSEC-2020-124

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-124

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-281

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-281

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-316

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

PYSEC-2020-316

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-p5f8-gfw5-33w4

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Heap buffer overflow in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-p5f8-gfw5-33w4

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Heap buffer overflow in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15201

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Heap buffer overflow in Tensorflow

CVEs:CVE-2020-15201

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15201

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

PYSEC-2020-316

CVEs:CVE-2020-15201

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15201

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` implementation does not validate that the input arguments form a valid ragged tensor. In particular, there is no validation that the values in the `splits` tensor generate a valid partit...

CVEs:CVE-2020-15201

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2020-0229

Open SourceCoalition ESS < 30%HIGH2020-09-09

There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-156333725

CVEs:CVE-2020-0229

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0278

Open SourceCoalition ESS < 30%HIGH2020-09-09

There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-160812574

CVEs:CVE-2020-0278

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0342

Open SourceCoalition ESS < 30%HIGH2020-09-09

There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-160812576

CVEs:CVE-2020-0342

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-156333725

GoogleCoalition ESS < 30%CRITICAL2020-09-01

ASB-A-156333725

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-160812574

GoogleCoalition ESS < 30%CRITICAL2020-09-01

ASB-A-160812574

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-160812576

GoogleCoalition ESS < 30%CRITICAL2020-09-01

ASB-A-160812576

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2020-0303

Open SourceCoalition ESS < 30%HIGH2020-09-17

In the Media extractor, there is a possible use after free due to improper locking. This could lead to remote code execution in the media extractor with no additional execution privileges needed. User interaction is needed for exploitation.Product: And...

CVEs:CVE-2020-0303

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0267

Open SourceCoalition ESS < 30%HIGH2020-09-17

In WindowManager, there is a possible launch of an unexpected app due to a confused deputy. This could lead to local escalation of privilege due to launching a malicious app instead of the one the user intended, with no additional execution privileges ...

CVEs:CVE-2020-0267

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PYSEC-2020-121

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-121

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-278

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-278

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-313

Open SourceCoalition ESS < 30%2020-09-25

PYSEC-2020-313

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-jc87-6vpp-7ff3

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Heap buffer overflow in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-jc87-6vpp-7ff3

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Heap buffer overflow in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15198

Open SourceCoalition ESS < 30%CRITICAL2020-09-25

Heap buffer overflow in Tensorflow

CVEs:CVE-2020-15198

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15198

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

PYSEC-2020-313

CVEs:CVE-2020-15198

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-15198

Open SourceCoalition ESS < 30%MEDIUM2020-09-25

In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input arguments form a valid sparse tensor. In particular, there is no validation that the `indices` tensor has the same shape as the `values` o...

CVEs:CVE-2020-15198

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2020-0427

Open SourceCoalition ESS < 30%HIGH2020-09-09

In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2020-0427

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
leap affected opensuse
starwind_virtual_san affected starwindsoftware
Upstream advisory

CVE-2020-0387

Open SourceCoalition ESS < 30%HIGH2020-09-09

In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. This could lead to local escalation of privilege and account hijacking with no additional execution privileges needed. User interactio...

CVEs:CVE-2020-0387

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-25283

Open SourceCoalition ESS < 30%CRITICAL2020-09-11

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. BT manager allows attackers to bypass intended access restrictions on a certain mode. The LG ID is LVE-SMP-200021 (September 2020).

CVEs:CVE-2020-25283

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0360

Open SourceCoalition ESS < 30%HIGH2020-09-17

In Notification Access Confirmation, there is a possible permissions bypass due to uninformed consent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidV...

CVEs:CVE-2020-0360

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-25282

Open SourceCoalition ESS < 30%CRITICAL2020-09-11

An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Integrated Circuit Card) allows attackers to bypass intended access restrictions on property values. The LG ID is LVE-SMP-200020 (Septem...

CVEs:CVE-2020-25282

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0319

Open SourceCoalition ESS < 30%HIGH2020-09-18

In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is needed for exploitation.Product: Andr...

CVEs:CVE-2020-0319

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0406

Open SourceCoalition ESS < 30%HIGH2020-09-17

In libmpeg2dec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if another exploit allowed this to be triggered with different parameters, with no additional execution privileges n...

CVEs:CVE-2020-0406

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0130

Open SourceCoalition ESS < 30%HIGH2020-09-17

In screencap, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege in a system process with User execution privileges needed. User interaction is not needed for exploitation.Product: A...

CVEs:CVE-2020-0130

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0366

Open SourceCoalition ESS < 30%HIGH2020-09-17

In PackageInstaller, there is a possible permissions bypass due to a tapjacking vulnerability. This could lead to local escalation of privilege using an app set as the default Assist app with User execution privileges needed. User interaction is needed...

CVEs:CVE-2020-0366

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

SUSE-SU-2020:2647-1

GoogleCoalition ESS < 30%NONE2020-09-16

Security update for for SUSE Manager 4.1

Affected products

ProductStatusVendorPackageEcosystem
google-gson affected SUSE:Manager Server Module 4.1 google-gson
httpcomponents-client affected SUSE:Manager Server Module 4.1 httpcomponents-client
httpcomponents-core affected SUSE:Manager Server Module 4.1 httpcomponents-core
salt-netapi-client affected SUSE:Manager Server Module 4.1 salt-netapi-client
spacewalk-admin affected SUSE:Manager Server Module 4.1 spacewalk-admin
spacewalk-java affected SUSE:Manager Server Module 4.1 spacewalk-java
spacewalk-setup affected SUSE:Manager Server Module 4.1 spacewalk-setup
Upstream advisory

CVE-2020-0386

Open SourceCoalition ESS < 30%MEDIUM2020-09-09

In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverability with User execution privileges...

CVEs:CVE-2020-0386

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-6574

GoogleCoalition ESS < 30%HIGH2020-09-09

Insufficient policy enforcement in installer in Google Chrome on OS X prior to 85.0.4183.102 allowed a local attacker to potentially achieve privilege escalation via a crafted binary.

CVEs:CVE-2020-6574

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2020-25281

Open SourceCoalition ESS < 30%CRITICAL2020-09-11

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Applications with sensitive security settings (such as the package verifier application) mishandle unknown-source installations. The LG ID is LVE-SMP-190...

CVEs:CVE-2020-25281

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0379

Open SourceCoalition ESS < 30%MEDIUM2020-09-09

In the Bluetooth service, there is a possible spoofing attack due to a logic error. This could lead to remote information disclosure of sensitive information with no additional execution privileges needed. User interaction is needed for exploitation.Pr...

CVEs:CVE-2020-0379

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-24721

GoogleCoalition ESS < 30%CRITICAL2020-09-30

An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-09-29, as used in COVID-19 applications on Android and iOS. It allows a user to be put in a position where he or she can be coerced into proving or disp...

CVEs:CVE-2020-24721

Affected products

ProductStatusVendorPackageEcosystem
exposure_notifications affected google
exposure_notifications affected apple
Upstream advisory

CVE-2020-0365

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In netd, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android...

CVEs:CVE-2020-0365

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-148816706

GoogleCoalition ESS < 30%2020-09-01

ASB-A-148816706

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2020-0404

Open SourceCoalition ESS < 30%MEDIUM2020-09-09

In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not n...

CVEs:CVE-2020-0404

Affected products

ProductStatusVendorPackageEcosystem
android affected google
communications_cloud_native_core_binding_support_function affected oracle
communications_cloud_native_core_network_exposure_function affected oracle
communications_cloud_native_core_policy affected oracle
Upstream advisory

ASB-A-111893654

GoogleCoalition ESS < 30%NONE2020-09-01

ASB-A-111893654

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2020-0344

Open SourceCoalition ESS < 30%HIGH2020-09-17

In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: And...

CVEs:CVE-2020-0344

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0352

Open SourceCoalition ESS < 30%HIGH2020-09-17

In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: And...

CVEs:CVE-2020-0352

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-157905780

GoogleCoalition ESS < 30%2020-09-01

ASB-A-157905780

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-157906588

GoogleCoalition ESS < 30%2020-09-01

ASB-A-157906588

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2020-0432

Open SourceCoalition ESS < 30%HIGH2020-09-09

In skb_to_mamac of networking.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produc...

CVEs:CVE-2020-0432

Affected products

ProductStatusVendorPackageEcosystem
android affected google
leap affected opensuse
Upstream advisory

CVE-2020-0431

Open SourceCoalition ESS < 30%HIGH2020-09-09

In kbd_keycode of keyboard.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produc...

CVEs:CVE-2020-0431

Affected products

ProductStatusVendorPackageEcosystem
android affected google
leap affected opensuse
Upstream advisory

CVE-2020-0293

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In Java network APIs, there is possible access to sensitive network state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation...

CVEs:CVE-2020-0293

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-147102899

GoogleCoalition ESS < 30%2020-09-01

ASB-A-147102899

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-147104886

GoogleCoalition ESS < 30%2020-09-01

ASB-A-147104886

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2020-0345

Open SourceCoalition ESS < 30%HIGH2020-09-17

In DocumentsUI, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Andro...

CVEs:CVE-2020-0345

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0430

Open SourceCoalition ESS < 30%HIGH2020-09-09

In skb_headlen of /include/linux/skbuff.h, there is a possible out of bounds read due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation...

CVEs:CVE-2020-0430

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0396

Open SourceCoalition ESS < 30%MEDIUM2020-09-09

In various places in Telephony, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2020-0396

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0399

Open SourceCoalition ESS < 30%MEDIUM2020-09-09

In showLimitedSimFunctionWarningNotification of NotificationMgr.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not n...

CVEs:CVE-2020-0399

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0347

Open SourceCoalition ESS < 30%HIGH2020-09-18

In iptables, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A...

CVEs:CVE-2020-0347

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0429

Open SourceCoalition ESS < 30%HIGH2020-09-09

In l2tp_session_delete and related functions of l2tp_core.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2020-0429

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0395

Open SourceCoalition ESS < 30%MEDIUM2020-09-09

In showNotification of EmergencyCallbackModeService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2020-0395

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0397

Open SourceCoalition ESS < 30%MEDIUM2020-09-09

In getNotificationBuilder of CarrierServiceStateTracker.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2020-0397

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0306

Open SourceCoalition ESS < 30%HIGH2020-09-17

In LLVM, there is a possible ineffective stack cookie placement due to stack frame double reservation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...

CVEs:CVE-2020-0306

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0388

Open SourceCoalition ESS < 30%HIGH2020-09-09

In createEmergencyLocationUserNotification of GnssVisibilityControl.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interac...

CVEs:CVE-2020-0388

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0294

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In bindWallpaperComponentLocked of WallpaperManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not neede...

CVEs:CVE-2020-0294

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0375

Open SourceCoalition ESS < 30%HIGH2020-09-17

In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege and the setting of supported EUICC countries with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2020-0375

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0374

Open SourceCoalition ESS < 30%HIGH2020-09-17

In NFC, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11An...

CVEs:CVE-2020-0374

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0266

Open SourceCoalition ESS < 30%HIGH2020-09-17

In factory reset protection, there is a possible FRP bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: And...

CVEs:CVE-2020-0266

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0275

Open SourceCoalition ESS < 30%HIGH2020-09-17

In MediaProvider, there is a possible way to access ContentResolver and MediaStore entries the app shouldn't have access to due to a permissions bypass. This could lead to local escalation of privilege, with no additional execution privileges needed. U...

CVEs:CVE-2020-0275

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0291

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges and a compromised Firmware needed. User interaction is not needed for exploitation.Prod...

CVEs:CVE-2020-0291

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0271

Open SourceCoalition ESS < 30%HIGH2020-09-18

In the Settings app, there is an insecure default value. This could lead to local escalation of privilege and tapjacking with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: ...

CVEs:CVE-2020-0271

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0336

Open SourceCoalition ESS < 30%HIGH2020-09-17

In SurfaceFlinger, there is possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11...

CVEs:CVE-2020-0336

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0313

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In NotificationManagerService, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: Android...

CVEs:CVE-2020-0313

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-25280

Open SourceCoalition ESS < 30%MEDIUM2020-09-11

An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos and MediaTek chipsets) software. Unauthenticated attackers can execute LTE/5G commands by sending a debugging command over USB. The Samsung ID is SVE-2020-16979 (September 2020).

CVEs:CVE-2020-25280

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0359

Open SourceCoalition ESS < 30%HIGH2020-09-17

In GLESRenderEngine, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...

CVEs:CVE-2020-0359

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0346

Open SourceCoalition ESS < 30%HIGH2020-09-17

In Mediaserver, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if integer sanitization were not enabled (which it is by default), with no additional execution privileges needed. User...

CVEs:CVE-2020-0346

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0393

Open SourceCoalition ESS < 30%MEDIUM2020-09-09

In decrypt and decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2020-0393

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0292

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges and a compromised Firmware needed. User interaction is not needed for exploitation.Prod...

CVEs:CVE-2020-0292

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0434

Open SourceCoalition ESS < 30%HIGH2020-09-09

In Pixel's use of the Catpipe library, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2020-0434

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0338

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android...

CVEs:CVE-2020-0338

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0389

Open SourceCoalition ESS < 30%MEDIUM2020-09-09

In createSaveNotification of RecordingService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2020-0389

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0403

Open SourceCoalition ESS < 30%HIGH2020-09-09

In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This could lead to local escalation of privilege in the TEE, with System execution privileges required. User interaction is not needed for...

CVEs:CVE-2020-0403

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0307

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-...

CVEs:CVE-2020-0307

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0302

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-...

CVEs:CVE-2020-0302

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0350

Open SourceCoalition ESS < 30%HIGH2020-09-18

In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is not needed for exploitation.Product: ...

CVEs:CVE-2020-0350

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0335

Open SourceCoalition ESS < 30%HIGH2020-09-18

In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is not needed for exploitation.Product: ...

CVEs:CVE-2020-0335

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0334

Open SourceCoalition ESS < 30%HIGH2020-09-18

In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is not needed for exploitation.Product: ...

CVEs:CVE-2020-0334

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0382

Open SourceCoalition ESS < 30%MEDIUM2020-09-09

In RunInternal of dumpstate.cpp, there is a possible user consent bypass due to an uncaught exception. This could lead to local information disclosure of bug report data with System execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2020-0382

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0349

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11A...

CVEs:CVE-2020-0349

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0262

Open SourceCoalition ESS < 30%HIGH2020-09-18

In WiFi tethering, there is a possible attacker controlled intent due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...

CVEs:CVE-2020-0262

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0322

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In apexd, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-1...

CVEs:CVE-2020-0322

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0369

Open SourceCoalition ESS < 30%HIGH2020-09-17

In libavb, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: An...

CVEs:CVE-2020-0369

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0433

Open SourceCoalition ESS < 30%HIGH2020-09-09

In blk_mq_queue_tag_busy_iter of blk-mq-tag.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2020-0433

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0273

Open SourceCoalition ESS < 30%HIGH2020-09-18

In hwservicemanager, there is a possible out of bounds write due to freeing a wild pointer. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2020-0273

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0356

Open SourceCoalition ESS < 30%HIGH2020-09-17

In the Audio HAL, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...

CVEs:CVE-2020-0356

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0426

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In SyncManager, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...

CVEs:CVE-2020-0426

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0269

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In Android Auto Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi...

CVEs:CVE-2020-0269

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0326

Open SourceCoalition ESS < 30%HIGH2020-09-18

In NFC, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11And...

CVEs:CVE-2020-0326

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0297

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In devicepolicy service, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...

CVEs:CVE-2020-0297

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0296

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In ADB server and USB server, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...

CVEs:CVE-2020-0296

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0323

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In libavb, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A...

CVEs:CVE-2020-0323

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0330

Open SourceCoalition ESS < 30%HIGH2020-09-17

In iorap, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege and code execution with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...

CVEs:CVE-2020-0330

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0327

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In core networking, there is a missing permission check. This could lead to local information disclosure of app network usage with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11And...

CVEs:CVE-2020-0327

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0310

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-...

CVEs:CVE-2020-0310

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0299

Open SourceCoalition ESS < 30%HIGH2020-09-18

In Bluetooth, there is a possible spoofing of bluetooth device metadata due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: ...

CVEs:CVE-2020-0299

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0298

Open SourceCoalition ESS < 30%HIGH2020-09-18

In Bluetooth, there is a possible control over Bluetooth enabled state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2020-0298

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0308

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In Window Manager, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: An...

CVEs:CVE-2020-0308

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0325

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In NFC, there is a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-145079309

CVEs:CVE-2020-0325

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0272

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In libhwbinder, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: A...

CVEs:CVE-2020-0272

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0328

Open SourceCoalition ESS < 30%HIGH2020-09-17

In the camera, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android...

CVEs:CVE-2020-0328

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0390

Open SourceCoalition ESS < 30%MEDIUM2020-09-09

In the app zygote SE Policy, there is a possible permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 An...

CVEs:CVE-2020-0390

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0331

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In Settings, there is a possible permissions bypass. This could lead to local information disclosure of the device's IMEI with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android...

CVEs:CVE-2020-0331

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0315

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In Zen Mode, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-...

CVEs:CVE-2020-0315

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0311

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In InputManagerService, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersion...

CVEs:CVE-2020-0311

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0304

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-...

CVEs:CVE-2020-0304

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0295

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In Telecom, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-1...

CVEs:CVE-2020-0295

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0312

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In Battery Saver, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: And...

CVEs:CVE-2020-0312

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0337

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In MediaProvider, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local information disclosure, with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...

CVEs:CVE-2020-0337

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0329

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In the OMX encoder, there is a possible out of bounds read due to invalid input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android...

CVEs:CVE-2020-0329

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0274

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In the OMX parser, there is a possible information disclosure due to a returned raw pointer. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2020-0274

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0425

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

There is a possible way to view notifications even when the "Lockdown" feature is on. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...

CVEs:CVE-2020-0425

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0265

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In Telephony, there are possible leaks of sensitive data due to missing permission checks. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...

CVEs:CVE-2020-0265

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0405

Open SourceCoalition ESS < 30%HIGH2020-09-18

In NetworkStackNotifier, there is a possible permissions bypass due to an unsafe implicit PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: An...

CVEs:CVE-2020-0405

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0318

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In the System UI, there is a possible system crash due to an uncaught exception. This could lead to local permanent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...

CVEs:CVE-2020-0318

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0314

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In AudioService, there are missing permission checks. This could lead to local information disclosure of audio configuration with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andro...

CVEs:CVE-2020-0314

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0343

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In NetworkStatsService, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...

CVEs:CVE-2020-0343

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0341

Open SourceCoalition ESS < 30%HIGH2020-09-17

In DisplayManager, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2020-0341

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0277

Open SourceCoalition ESS < 30%HIGH2020-09-17

In NetworkPolicyManagerService, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing a malicious app to modify the device's data plan with no additional execution privileges...

CVEs:CVE-2020-0277

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0089

Open SourceCoalition ESS < 30%HIGH2020-09-18

In the audio server, there is a missing permission check. This could lead to local escalation of privilege regarding audio settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions...

CVEs:CVE-2020-0089

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0309

Open SourceCoalition ESS < 30%HIGH2020-09-18

In the Bluetooth server, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System privileges and a Firmware compromise needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2020-0309

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0285

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi...

CVEs:CVE-2020-0285

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0284

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi...

CVEs:CVE-2020-0284

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0289

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In PackageManager, there is a missing permission check. This could lead to local information disclosure across users with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11And...

CVEs:CVE-2020-0289

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0288

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In PackageManager, there is a missing permission check. This could lead to local information disclosure across user boundaries with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: And...

CVEs:CVE-2020-0288

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0276

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi...

CVEs:CVE-2020-0276

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0263

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In the Accessibility service, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...

CVEs:CVE-2020-0263

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0316

Open SourceCoalition ESS < 30%MEDIUM2020-09-18

In Telephony, there is a missing permission check. This could lead to local information disclosure of radio data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android...

CVEs:CVE-2020-0316

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0372

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In ActivityManager, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:...

CVEs:CVE-2020-0372

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0317

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In UsageStatsManager, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Produc...

CVEs:CVE-2020-0317

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0290

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In PackageManager, there is a missing permission check. This could lead to local information disclosure across users with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11And...

CVEs:CVE-2020-0290

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0357

Open SourceCoalition ESS < 30%HIGH2020-09-17

In SurfaceFlinger, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the graphics server with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2020-0357

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0358

Open SourceCoalition ESS < 30%HIGH2020-09-17

In SurfaceFlinger, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-1...

CVEs:CVE-2020-0358

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0268

Open SourceCoalition ESS < 30%HIGH2020-09-18

In NFC, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID...

CVEs:CVE-2020-0268

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0407

Open SourceCoalition ESS < 30%MEDIUM2020-09-09

In various functions in fscrypt_ice.c and related files in some implementations of f2fs encryption that use encryption hardware which only supports 32-bit IVs (Initialization Vectors), 64-bit IVs are used and later are truncated to 32 bits. This may ca...

CVEs:CVE-2020-0407

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0428

Open SourceCoalition ESS < 30%HIGH2020-09-09

In CamX code, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android kern...

CVEs:CVE-2020-0428

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-153450752

GoogleCoalition ESS < 30%MEDIUM2020-09-01

ASB-A-153450752

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2020-0373

Open SourceCoalition ESS < 30%MEDIUM2020-09-17

In SoundTriggerHwService, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...

CVEs:CVE-2020-0373

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-53jx-4wwh-gcqj

Open SourceAll remainingCRITICAL2020-09-11

Malicious Package in angular-location-update

Affected products

ProductStatusVendorPackageEcosystem
angular-location-update affected npm angular-location-update
Upstream advisory

GHSA-53jx-4wwh-gcqj

Open SourceAll remaining2020-09-11

Malicious Package in angular-location-update

Affected products

ProductStatusVendorPackageEcosystem
angular-location-update affected npm angular-location-update
Upstream advisory

GHSA-m86m-5m44-pc93

Open SourceAll remainingHIGH2020-09-03

Denial of Service in grpc-ts-health-check

Affected products

ProductStatusVendorPackageEcosystem
grpc-ts-health-check affected npm grpc-ts-health-check
Upstream advisory

GHSA-m86m-5m44-pc93

Open SourceAll remainingHIGH2020-09-03

Denial of Service in grpc-ts-health-check

Affected products

ProductStatusVendorPackageEcosystem
grpc-ts-health-check affected npm grpc-ts-health-check
Upstream advisory

GHSA-r9q4-w3fm-wrm2

GoogleAll remainingCRITICAL2020-09-02

Cross-Site Scripting in google-closure-library

Affected products

ProductStatusVendorPackageEcosystem
google-closure-library affected npm google-closure-library
Upstream advisory

GHSA-r9q4-w3fm-wrm2

GoogleAll remainingCRITICAL2020-09-02

Cross-Site Scripting in google-closure-library

Affected products

ProductStatusVendorPackageEcosystem
google-closure-library affected npm google-closure-library
Upstream advisory

GHSA-7543-mr7h-6v86

Open SourceAll remaining2020-09-02

Improper Authorization in googleapis

Affected products

ProductStatusVendorPackageEcosystem
googleapis affected npm googleapis
Upstream advisory

GHSA-7543-mr7h-6v86

Open SourceAll remainingHIGH2020-09-02

Improper Authorization in googleapis

Affected products

ProductStatusVendorPackageEcosystem
googleapis affected npm googleapis
Upstream advisory

GHSA-qmxf-fxq7-w59f

Open SourceAll remainingCRITICAL2020-09-01

Malicious Package in angular-material-sidenav-rnd

Affected products

ProductStatusVendorPackageEcosystem
angular-material-sidenav-rnd affected npm angular-material-sidenav-rnd
Upstream advisory

GHSA-qmxf-fxq7-w59f

Open SourceAll remainingCRITICAL2020-09-01

Malicious Package in angular-material-sidenav-rnd

Affected products

ProductStatusVendorPackageEcosystem
angular-material-sidenav-rnd affected npm angular-material-sidenav-rnd
Upstream advisory

GHSA-w8hg-mxvh-9h57

Open SourceAll remainingCRITICAL2020-09-01

Malicious Package in angular-bmap

Affected products

ProductStatusVendorPackageEcosystem
angular-bmap affected npm angular-bmap
Upstream advisory

GHSA-w8hg-mxvh-9h57

Open SourceAll remainingCRITICAL2020-09-01

Malicious Package in angular-bmap

Affected products

ProductStatusVendorPackageEcosystem
angular-bmap affected npm angular-bmap
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.