Google Security Advisories · November 2020 — Google Security Advisories
243 advisories 150 CVEs 37 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2020-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 37 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

openSUSE-SU-2020:1937-1

Open SourceExploitedCISA KEV listedCRITICAL2020-11-15

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2020:1831-1

Open SourceExploitedCISA KEV listedCRITICAL2020-11-05

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
chromium affected openSUSE:Leap 15.1 chromium
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

openSUSE-SU-2020:1829-1

Open SourceExploitedCISA KEV listedCRITICAL2020-11-05

Security update for chromium, gn

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP2 chromium
gn affected SUSE:Package Hub 15 SP2 gn
Upstream advisory

DEBIAN-CVE-2020-16009

Open SourceExploitedCISA KEV listedHIGH2020-11-03

DEBIAN-CVE-2020-16009

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-16009

Project ZeroExploitedCISA KEV listed2020-11-03

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-16009

Upstream advisory

CVE-2020-16009

Open SourceExploitedCISA KEV listedHIGH2020-11-03

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-16009

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
cefsharp affected cefsharp
chrome affected google
debian_linux affected debian
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2020-16009

GoogleExploitedCISA KEV listedHIGH2020-11-03

Inappropriate implementation in V8

CVEs:CVE-2020-16009

Affected products

ProductStatusVendorPackageEcosystem
CefSharp.Common affected NuGet CefSharp.Common
CefSharp.WinForms affected NuGet CefSharp.WinForms
CefSharp.Wpf affected NuGet CefSharp.Wpf
CefSharp.Wpf.HwndHost affected NuGet CefSharp.Wpf.HwndHost
Upstream advisory

CVE-2020-27930

Project ZeroExploitedCISA KEV listed2020-11-06

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. Processing a maliciously crafted font may lead to arbitrary code execution.

CVEs:CVE-2020-27930

Upstream advisory

CVE-2020-27930

GoogleExploitedCISA KEV listedCRITICAL2020-11-06

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2...

CVEs:CVE-2020-27930

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2020-4006

GoogleExploitedCISA KEV listedCRITICAL2020-11-23

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

CVEs:CVE-2020-4006

Affected products

ProductStatusVendorPackageEcosystem
cloud_foundation affected vmware
identity_manager affected vmware
identity_manager_connector affected vmware
one_access affected vmware
vrealize_suite_lifecycle_manager affected vmware
Upstream advisory

CVE-2020-4006

Project ZeroExploitedCISA KEV listed2020-11-23

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

CVEs:CVE-2020-4006

Upstream advisory

CVE-2020-27950

Project ZeroExploitedCISA KEV listed2020-11-06

A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to disclose kernel memory.

CVEs:CVE-2020-27950

Upstream advisory

CVE-2020-27950

GoogleExploitedCISA KEV listedHIGH2020-11-06

A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Cata...

CVEs:CVE-2020-27950

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
watchos affected apple
Upstream advisory

CVE-2020-27932

GoogleExploitedCISA KEV listedCRITICAL2020-11-06

A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, wat...

CVEs:CVE-2020-27932

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
macos affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2020-27932

Project ZeroExploitedCISA KEV listed2020-11-06

A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2020-27932

Upstream advisory

CVE-2020-16010

GoogleExploitedCISA KEV listedCRITICAL2020-11-03

Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-16010

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16010

Project ZeroExploitedCISA KEV listed2020-11-03

Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-16010

Upstream advisory

CVE-2020-17087

GoogleExploitedCISA KEV listedCRITICAL2020-11-11

Windows Kernel Local Elevation of Privilege Vulnerability

CVEs:CVE-2020-17087

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1803 affected microsoft
windows_10_1809 affected microsoft
windows_10_1903 affected microsoft
windows_10_1909 affected microsoft
windows_10_2004 affected microsoft
windows_10_20h2 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
Upstream advisory

openSUSE-SU-2020:2016-1

Open SourceExploitedCISA KEV listedCRITICAL2020-11-25

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP2 chromium
Upstream advisory

openSUSE-SU-2020:2013-1

Open SourceExploitedCISA KEV listedCRITICAL2020-11-25

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2020:1943-1

Open SourceExploitedCISA KEV listedCRITICAL2020-11-16

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2020:1929-1

Open SourceExploitedCISA KEV listedCRITICAL2020-11-15

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
chromium affected SUSE:Package Hub 15 SP2 chromium
chromium affected openSUSE:Leap 15.1 chromium
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

CVE-2020-16013

GoogleExploitedCISA KEV listedHIGH2020-11-12

Inappropriate implementation in V8 in CefSharp

CVEs:CVE-2020-16013

Affected products

ProductStatusVendorPackageEcosystem
CefSharp.Common affected NuGet CefSharp.Common
CefSharp.WinForms affected NuGet CefSharp.WinForms
CefSharp.Wpf affected NuGet CefSharp.Wpf
CefSharp.Wpf.HwndHost affected NuGet CefSharp.Wpf.HwndHost
Upstream advisory

CVE-2020-16013

GoogleExploitedCISA KEV listedHIGH2020-11-12

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-16013

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16013

Project ZeroExploitedCISA KEV listed2020-11-12

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-16013

Upstream advisory

CVE-2020-16017

GoogleExploitedCISA KEV listedHIGH2020-11-12

Use after free in CefSharp

CVEs:CVE-2020-16017

Affected products

ProductStatusVendorPackageEcosystem
CefSharp.Common affected NuGet CefSharp.Common
CefSharp.WinForms affected NuGet CefSharp.WinForms
CefSharp.Wpf affected NuGet CefSharp.Wpf
CefSharp.Wpf.HwndHost affected NuGet CefSharp.Wpf.HwndHost
Upstream advisory

CVE-2020-16017

Project ZeroExploitedCISA KEV listed2020-11-12

Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-16017

Upstream advisory

CVE-2020-16017

GoogleExploitedCISA KEV listedCRITICAL2020-11-12

Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-16017

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-15994

GoogleExploitedVulnCheck KEV listedCRITICAL2020-11-03

Use after free in V8 in Google Chrome prior to 86.0.4240.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-15994

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MGASA-2020-0424

Open SourceWeaponized exploitCRITICAL2020-11-15

Updated golang packages fix a security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:7 golang
Upstream advisory

RHSA-2020:5168

Open SourceActive exploitation (sightings)HIGH2020-11-23

Red Hat Security Advisory: rh-eclipse security, bug fix and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
rh-eclipse affected Red Hat:devtools:2020 rh-eclipse
rh-eclipse-ant affected Red Hat:devtools:2020 rh-eclipse-ant
rh-eclipse-ant-antlr affected Red Hat:devtools:2020 rh-eclipse-ant-antlr
rh-eclipse-ant-apache-bcel affected Red Hat:devtools:2020 rh-eclipse-ant-apache-bcel
rh-eclipse-ant-apache-bsf affected Red Hat:devtools:2020 rh-eclipse-ant-apache-bsf
rh-eclipse-ant-apache-log4j affected Red Hat:devtools:2020 rh-eclipse-ant-apache-log4j
rh-eclipse-ant-apache-oro affected Red Hat:devtools:2020 rh-eclipse-ant-apache-oro
rh-eclipse-ant-apache-regexp affected Red Hat:devtools:2020 rh-eclipse-ant-apache-regexp
rh-eclipse-ant-apache-resolver affected Red Hat:devtools:2020 rh-eclipse-ant-apache-resolver
rh-eclipse-ant-apache-xalan2 affected Red Hat:devtools:2020 rh-eclipse-ant-apache-xalan2
rh-eclipse-ant-commons-logging affected Red Hat:devtools:2020 rh-eclipse-ant-commons-logging
rh-eclipse-ant-commons-net affected Red Hat:devtools:2020 rh-eclipse-ant-commons-net
rh-eclipse-ant-imageio affected Red Hat:devtools:2020 rh-eclipse-ant-imageio
rh-eclipse-ant-javadoc affected Red Hat:devtools:2020 rh-eclipse-ant-javadoc
rh-eclipse-ant-javamail affected Red Hat:devtools:2020 rh-eclipse-ant-javamail
rh-eclipse-ant-jdepend affected Red Hat:devtools:2020 rh-eclipse-ant-jdepend
rh-eclipse-ant-jmf affected Red Hat:devtools:2020 rh-eclipse-ant-jmf
rh-eclipse-ant-jsch affected Red Hat:devtools:2020 rh-eclipse-ant-jsch
rh-eclipse-ant-junit affected Red Hat:devtools:2020 rh-eclipse-ant-junit
rh-eclipse-ant-junit5 affected Red Hat:devtools:2020 rh-eclipse-ant-junit5
rh-eclipse-ant-lib affected Red Hat:devtools:2020 rh-eclipse-ant-lib
rh-eclipse-antlr32 affected Red Hat:devtools:2020 rh-eclipse-antlr32
rh-eclipse-antlr32-java affected Red Hat:devtools:2020 rh-eclipse-antlr32-java
rh-eclipse-antlr32-javadoc affected Red Hat:devtools:2020 rh-eclipse-antlr32-javadoc
rh-eclipse-antlr32-maven-plugin affected Red Hat:devtools:2020 rh-eclipse-antlr32-maven-plugin
rh-eclipse-antlr32-tool affected Red Hat:devtools:2020 rh-eclipse-antlr32-tool
rh-eclipse-ant-manual affected Red Hat:devtools:2020 rh-eclipse-ant-manual
rh-eclipse-ant-swing affected Red Hat:devtools:2020 rh-eclipse-ant-swing
rh-eclipse-ant-testutil affected Red Hat:devtools:2020 rh-eclipse-ant-testutil
rh-eclipse-ant-xz affected Red Hat:devtools:2020 rh-eclipse-ant-xz
rh-eclipse-apache-sshd affected Red Hat:devtools:2020 rh-eclipse-apache-sshd
rh-eclipse-apache-sshd-javadoc affected Red Hat:devtools:2020 rh-eclipse-apache-sshd-javadoc
rh-eclipse-apiguardian affected Red Hat:devtools:2020 rh-eclipse-apiguardian
rh-eclipse-apiguardian-javadoc affected Red Hat:devtools:2020 rh-eclipse-apiguardian-javadoc
rh-eclipse-args4j affected Red Hat:devtools:2020 rh-eclipse-args4j
rh-eclipse-args4j-javadoc affected Red Hat:devtools:2020 rh-eclipse-args4j-javadoc
rh-eclipse-args4j-parent affected Red Hat:devtools:2020 rh-eclipse-args4j-parent
rh-eclipse-batik affected Red Hat:devtools:2020 rh-eclipse-batik
rh-eclipse-batik-css affected Red Hat:devtools:2020 rh-eclipse-batik-css
rh-eclipse-batik-demo affected Red Hat:devtools:2020 rh-eclipse-batik-demo
rh-eclipse-batik-javadoc affected Red Hat:devtools:2020 rh-eclipse-batik-javadoc
rh-eclipse-batik-rasterizer affected Red Hat:devtools:2020 rh-eclipse-batik-rasterizer
rh-eclipse-batik-slideshow affected Red Hat:devtools:2020 rh-eclipse-batik-slideshow
rh-eclipse-batik-squiggle affected Red Hat:devtools:2020 rh-eclipse-batik-squiggle
rh-eclipse-batik-svgpp affected Red Hat:devtools:2020 rh-eclipse-batik-svgpp
rh-eclipse-batik-ttf2svg affected Red Hat:devtools:2020 rh-eclipse-batik-ttf2svg
rh-eclipse-batik-util affected Red Hat:devtools:2020 rh-eclipse-batik-util
rh-eclipse-bouncycastle affected Red Hat:devtools:2020 rh-eclipse-bouncycastle
rh-eclipse-bouncycastle-javadoc affected Red Hat:devtools:2020 rh-eclipse-bouncycastle-javadoc
rh-eclipse-bouncycastle-mail affected Red Hat:devtools:2020 rh-eclipse-bouncycastle-mail
rh-eclipse-bouncycastle-pg affected Red Hat:devtools:2020 rh-eclipse-bouncycastle-pg
rh-eclipse-bouncycastle-pkix affected Red Hat:devtools:2020 rh-eclipse-bouncycastle-pkix
rh-eclipse-bouncycastle-tls affected Red Hat:devtools:2020 rh-eclipse-bouncycastle-tls
rh-eclipse-cbi-plugins affected Red Hat:devtools:2020 rh-eclipse-cbi-plugins
rh-eclipse-cbi-plugins-javadoc affected Red Hat:devtools:2020 rh-eclipse-cbi-plugins-javadoc
rh-eclipse-decentxml affected Red Hat:devtools:2020 rh-eclipse-decentxml
rh-eclipse-decentxml-javadoc affected Red Hat:devtools:2020 rh-eclipse-decentxml-javadoc
rh-eclipse-ecj affected Red Hat:devtools:2020 rh-eclipse-ecj
rh-eclipse-eclipse affected Red Hat:devtools:2020 rh-eclipse-eclipse
rh-eclipse-eclipse-contributor-tools affected Red Hat:devtools:2020 rh-eclipse-eclipse-contributor-tools
rh-eclipse-eclipse-debuginfo affected Red Hat:devtools:2020 rh-eclipse-eclipse-debuginfo
rh-eclipse-eclipse-ecf affected Red Hat:devtools:2020 rh-eclipse-eclipse-ecf
rh-eclipse-eclipse-ecf-core affected Red Hat:devtools:2020 rh-eclipse-eclipse-ecf-core
rh-eclipse-eclipse-ecf-runtime affected Red Hat:devtools:2020 rh-eclipse-eclipse-ecf-runtime
rh-eclipse-eclipse-ecf-sdk affected Red Hat:devtools:2020 rh-eclipse-eclipse-ecf-sdk
rh-eclipse-eclipse-egit affected Red Hat:devtools:2020 rh-eclipse-eclipse-egit
rh-eclipse-eclipse-emf affected Red Hat:devtools:2020 rh-eclipse-eclipse-emf
rh-eclipse-eclipse-emf-core affected Red Hat:devtools:2020 rh-eclipse-eclipse-emf-core
rh-eclipse-eclipse-emf-runtime affected Red Hat:devtools:2020 rh-eclipse-eclipse-emf-runtime
rh-eclipse-eclipse-emf-sdk affected Red Hat:devtools:2020 rh-eclipse-eclipse-emf-sdk
rh-eclipse-eclipse-emf-xsd affected Red Hat:devtools:2020 rh-eclipse-eclipse-emf-xsd
rh-eclipse-eclipse-equinox-osgi affected Red Hat:devtools:2020 rh-eclipse-eclipse-equinox-osgi
rh-eclipse-eclipse-gef affected Red Hat:devtools:2020 rh-eclipse-eclipse-gef
rh-eclipse-eclipse-gef-sdk affected Red Hat:devtools:2020 rh-eclipse-eclipse-gef-sdk
rh-eclipse-eclipse-jdt affected Red Hat:devtools:2020 rh-eclipse-eclipse-jdt
rh-eclipse-eclipse-jgit affected Red Hat:devtools:2020 rh-eclipse-eclipse-jgit
rh-eclipse-eclipse-license affected Red Hat:devtools:2020 rh-eclipse-eclipse-license
rh-eclipse-eclipse-license1 affected Red Hat:devtools:2020 rh-eclipse-eclipse-license1
rh-eclipse-eclipse-license2 affected Red Hat:devtools:2020 rh-eclipse-eclipse-license2
rh-eclipse-eclipse-m2e-core affected Red Hat:devtools:2020 rh-eclipse-eclipse-m2e-core
rh-eclipse-eclipse-m2e-workspace affected Red Hat:devtools:2020 rh-eclipse-eclipse-m2e-workspace
rh-eclipse-eclipse-m2e-workspace-javadoc affected Red Hat:devtools:2020 rh-eclipse-eclipse-m2e-workspace-javadoc
rh-eclipse-eclipse-mpc affected Red Hat:devtools:2020 rh-eclipse-eclipse-mpc
rh-eclipse-eclipse-p2-discovery affected Red Hat:devtools:2020 rh-eclipse-eclipse-p2-discovery
rh-eclipse-eclipse-pde affected Red Hat:devtools:2020 rh-eclipse-eclipse-pde
rh-eclipse-eclipse-platform affected Red Hat:devtools:2020 rh-eclipse-eclipse-platform
rh-eclipse-eclipse-pydev affected Red Hat:devtools:2020 rh-eclipse-eclipse-pydev
rh-eclipse-eclipse-pydev-debuginfo affected Red Hat:devtools:2020 rh-eclipse-eclipse-pydev-debuginfo
rh-eclipse-eclipse-subclipse affected Red Hat:devtools:2020 rh-eclipse-eclipse-subclipse
rh-eclipse-eclipse-swt affected Red Hat:devtools:2020 rh-eclipse-eclipse-swt
rh-eclipse-eclipse-webtools affected Red Hat:devtools:2020 rh-eclipse-eclipse-webtools
rh-eclipse-eclipse-webtools-common affected Red Hat:devtools:2020 rh-eclipse-eclipse-webtools-common
rh-eclipse-eclipse-webtools-servertools affected Red Hat:devtools:2020 rh-eclipse-eclipse-webtools-servertools
rh-eclipse-eclipse-webtools-sourceediting affected Red Hat:devtools:2020 rh-eclipse-eclipse-webtools-sourceediting
rh-eclipse-ed25519-java affected Red Hat:devtools:2020 rh-eclipse-ed25519-java
rh-eclipse-felix-gogo-command affected Red Hat:devtools:2020 rh-eclipse-felix-gogo-command
rh-eclipse-felix-gogo-command-javadoc affected Red Hat:devtools:2020 rh-eclipse-felix-gogo-command-javadoc
rh-eclipse-felix-gogo-parent affected Red Hat:devtools:2020 rh-eclipse-felix-gogo-parent
rh-eclipse-felix-gogo-runtime affected Red Hat:devtools:2020 rh-eclipse-felix-gogo-runtime
rh-eclipse-felix-gogo-runtime-javadoc affected Red Hat:devtools:2020 rh-eclipse-felix-gogo-runtime-javadoc
rh-eclipse-felix-gogo-shell affected Red Hat:devtools:2020 rh-eclipse-felix-gogo-shell
rh-eclipse-felix-gogo-shell-javadoc affected Red Hat:devtools:2020 rh-eclipse-felix-gogo-shell-javadoc
rh-eclipse-felix-scr affected Red Hat:devtools:2020 rh-eclipse-felix-scr
rh-eclipse-felix-scr-javadoc affected Red Hat:devtools:2020 rh-eclipse-felix-scr-javadoc
rh-eclipse-javaewah affected Red Hat:devtools:2020 rh-eclipse-javaewah
rh-eclipse-javaewah-javadoc affected Red Hat:devtools:2020 rh-eclipse-javaewah-javadoc
rh-eclipse-javaparser affected Red Hat:devtools:2020 rh-eclipse-javaparser
rh-eclipse-javaparser-javadoc affected Red Hat:devtools:2020 rh-eclipse-javaparser-javadoc
rh-eclipse-jchardet affected Red Hat:devtools:2020 rh-eclipse-jchardet
rh-eclipse-jchardet-javadoc affected Red Hat:devtools:2020 rh-eclipse-jchardet-javadoc
rh-eclipse-jctools affected Red Hat:devtools:2020 rh-eclipse-jctools
rh-eclipse-jctools-javadoc affected Red Hat:devtools:2020 rh-eclipse-jctools-javadoc
rh-eclipse-jetty affected Red Hat:devtools:2020 rh-eclipse-jetty
rh-eclipse-jetty-client affected Red Hat:devtools:2020 rh-eclipse-jetty-client
rh-eclipse-jetty-continuation affected Red Hat:devtools:2020 rh-eclipse-jetty-continuation
rh-eclipse-jetty-http affected Red Hat:devtools:2020 rh-eclipse-jetty-http
rh-eclipse-jetty-io affected Red Hat:devtools:2020 rh-eclipse-jetty-io
rh-eclipse-jetty-jaas affected Red Hat:devtools:2020 rh-eclipse-jetty-jaas
rh-eclipse-jetty-javadoc affected Red Hat:devtools:2020 rh-eclipse-jetty-javadoc
rh-eclipse-jetty-jmx affected Red Hat:devtools:2020 rh-eclipse-jetty-jmx
rh-eclipse-jetty-security affected Red Hat:devtools:2020 rh-eclipse-jetty-security
rh-eclipse-jetty-server affected Red Hat:devtools:2020 rh-eclipse-jetty-server
rh-eclipse-jetty-servlet affected Red Hat:devtools:2020 rh-eclipse-jetty-servlet
rh-eclipse-jetty-util affected Red Hat:devtools:2020 rh-eclipse-jetty-util
rh-eclipse-jetty-webapp affected Red Hat:devtools:2020 rh-eclipse-jetty-webapp
rh-eclipse-jetty-xml affected Red Hat:devtools:2020 rh-eclipse-jetty-xml
rh-eclipse-jffi affected Red Hat:devtools:2020 rh-eclipse-jffi
rh-eclipse-jffi-debuginfo affected Red Hat:devtools:2020 rh-eclipse-jffi-debuginfo
rh-eclipse-jffi-javadoc affected Red Hat:devtools:2020 rh-eclipse-jffi-javadoc
rh-eclipse-jffi-native affected Red Hat:devtools:2020 rh-eclipse-jffi-native
rh-eclipse-jgit affected Red Hat:devtools:2020 rh-eclipse-jgit
rh-eclipse-jgit-javadoc affected Red Hat:devtools:2020 rh-eclipse-jgit-javadoc
rh-eclipse-jna affected Red Hat:devtools:2020 rh-eclipse-jna
rh-eclipse-jna-contrib affected Red Hat:devtools:2020 rh-eclipse-jna-contrib
rh-eclipse-jna-debuginfo affected Red Hat:devtools:2020 rh-eclipse-jna-debuginfo
rh-eclipse-jna-javadoc affected Red Hat:devtools:2020 rh-eclipse-jna-javadoc
rh-eclipse-jnr-constants affected Red Hat:devtools:2020 rh-eclipse-jnr-constants
rh-eclipse-jnr-constants-javadoc affected Red Hat:devtools:2020 rh-eclipse-jnr-constants-javadoc
rh-eclipse-jnr-ffi affected Red Hat:devtools:2020 rh-eclipse-jnr-ffi
rh-eclipse-jnr-ffi-javadoc affected Red Hat:devtools:2020 rh-eclipse-jnr-ffi-javadoc
rh-eclipse-jnr-netdb affected Red Hat:devtools:2020 rh-eclipse-jnr-netdb
rh-eclipse-jnr-netdb-javadoc affected Red Hat:devtools:2020 rh-eclipse-jnr-netdb-javadoc
rh-eclipse-jnr-posix affected Red Hat:devtools:2020 rh-eclipse-jnr-posix
rh-eclipse-jnr-posix-javadoc affected Red Hat:devtools:2020 rh-eclipse-jnr-posix-javadoc
rh-eclipse-jnr-x86asm affected Red Hat:devtools:2020 rh-eclipse-jnr-x86asm
rh-eclipse-jnr-x86asm-javadoc affected Red Hat:devtools:2020 rh-eclipse-jnr-x86asm-javadoc
rh-eclipse-jsch-agent-proxy affected Red Hat:devtools:2020 rh-eclipse-jsch-agent-proxy
rh-eclipse-jsch-agent-proxy-connector-factory affected Red Hat:devtools:2020 rh-eclipse-jsch-agent-proxy-connector-factory
rh-eclipse-jsch-agent-proxy-core affected Red Hat:devtools:2020 rh-eclipse-jsch-agent-proxy-core
rh-eclipse-jsch-agent-proxy-javadoc affected Red Hat:devtools:2020 rh-eclipse-jsch-agent-proxy-javadoc
rh-eclipse-jsch-agent-proxy-jsch affected Red Hat:devtools:2020 rh-eclipse-jsch-agent-proxy-jsch
rh-eclipse-jsch-agent-proxy-pageant affected Red Hat:devtools:2020 rh-eclipse-jsch-agent-proxy-pageant
rh-eclipse-jsch-agent-proxy-sshagent affected Red Hat:devtools:2020 rh-eclipse-jsch-agent-proxy-sshagent
rh-eclipse-jsch-agent-proxy-trilead-ssh2 affected Red Hat:devtools:2020 rh-eclipse-jsch-agent-proxy-trilead-ssh2
rh-eclipse-jsch-agent-proxy-usocket-jna affected Red Hat:devtools:2020 rh-eclipse-jsch-agent-proxy-usocket-jna
rh-eclipse-jsch-agent-proxy-usocket-nc affected Red Hat:devtools:2020 rh-eclipse-jsch-agent-proxy-usocket-nc
rh-eclipse-junit5 affected Red Hat:devtools:2020 rh-eclipse-junit5
rh-eclipse-junit5-guide affected Red Hat:devtools:2020 rh-eclipse-junit5-guide
rh-eclipse-junit5-javadoc affected Red Hat:devtools:2020 rh-eclipse-junit5-javadoc
rh-eclipse-jython affected Red Hat:devtools:2020 rh-eclipse-jython
rh-eclipse-jython-demo affected Red Hat:devtools:2020 rh-eclipse-jython-demo
rh-eclipse-jython-javadoc affected Red Hat:devtools:2020 rh-eclipse-jython-javadoc
rh-eclipse-jzlib affected Red Hat:devtools:2020 rh-eclipse-jzlib
rh-eclipse-jzlib-demo affected Red Hat:devtools:2020 rh-eclipse-jzlib-demo
rh-eclipse-jzlib-javadoc affected Red Hat:devtools:2020 rh-eclipse-jzlib-javadoc
rh-eclipse-lucene affected Red Hat:devtools:2020 rh-eclipse-lucene
rh-eclipse-lucene-analysis affected Red Hat:devtools:2020 rh-eclipse-lucene-analysis
rh-eclipse-lucene-analyzers-smartcn affected Red Hat:devtools:2020 rh-eclipse-lucene-analyzers-smartcn
rh-eclipse-lucene-backward-codecs affected Red Hat:devtools:2020 rh-eclipse-lucene-backward-codecs
rh-eclipse-lucene-classification affected Red Hat:devtools:2020 rh-eclipse-lucene-classification
rh-eclipse-lucene-codecs affected Red Hat:devtools:2020 rh-eclipse-lucene-codecs
rh-eclipse-lucene-grouping affected Red Hat:devtools:2020 rh-eclipse-lucene-grouping
rh-eclipse-lucene-highlighter affected Red Hat:devtools:2020 rh-eclipse-lucene-highlighter
rh-eclipse-lucene-javadoc affected Red Hat:devtools:2020 rh-eclipse-lucene-javadoc
rh-eclipse-lucene-join affected Red Hat:devtools:2020 rh-eclipse-lucene-join
rh-eclipse-lucene-memory affected Red Hat:devtools:2020 rh-eclipse-lucene-memory
rh-eclipse-lucene-misc affected Red Hat:devtools:2020 rh-eclipse-lucene-misc
rh-eclipse-lucene-monitor affected Red Hat:devtools:2020 rh-eclipse-lucene-monitor
rh-eclipse-lucene-queries affected Red Hat:devtools:2020 rh-eclipse-lucene-queries
rh-eclipse-lucene-queryparser affected Red Hat:devtools:2020 rh-eclipse-lucene-queryparser
rh-eclipse-lucene-sandbox affected Red Hat:devtools:2020 rh-eclipse-lucene-sandbox
rh-eclipse-lucene-suggest affected Red Hat:devtools:2020 rh-eclipse-lucene-suggest
rh-eclipse-maven-archetype affected Red Hat:devtools:2020 rh-eclipse-maven-archetype
rh-eclipse-maven-archetype-catalog affected Red Hat:devtools:2020 rh-eclipse-maven-archetype-catalog
rh-eclipse-maven-archetype-common affected Red Hat:devtools:2020 rh-eclipse-maven-archetype-common
rh-eclipse-maven-archetype-descriptor affected Red Hat:devtools:2020 rh-eclipse-maven-archetype-descriptor
rh-eclipse-maven-archetype-javadoc affected Red Hat:devtools:2020 rh-eclipse-maven-archetype-javadoc
rh-eclipse-maven-archetype-packaging affected Red Hat:devtools:2020 rh-eclipse-maven-archetype-packaging
rh-eclipse-maven-archetype-plugin affected Red Hat:devtools:2020 rh-eclipse-maven-archetype-plugin
rh-eclipse-maven-indexer affected Red Hat:devtools:2020 rh-eclipse-maven-indexer
rh-eclipse-maven-indexer-javadoc affected Red Hat:devtools:2020 rh-eclipse-maven-indexer-javadoc
rh-eclipse-netty affected Red Hat:devtools:2020 rh-eclipse-netty
rh-eclipse-objectweb-asm affected Red Hat:devtools:2020 rh-eclipse-objectweb-asm
rh-eclipse-objectweb-asm-javadoc affected Red Hat:devtools:2020 rh-eclipse-objectweb-asm-javadoc
rh-eclipse-opentest4j affected Red Hat:devtools:2020 rh-eclipse-opentest4j
rh-eclipse-opentest4j-javadoc affected Red Hat:devtools:2020 rh-eclipse-opentest4j-javadoc
rh-eclipse-os-maven-plugin affected Red Hat:devtools:2020 rh-eclipse-os-maven-plugin
rh-eclipse-os-maven-plugin-javadoc affected Red Hat:devtools:2020 rh-eclipse-os-maven-plugin-javadoc
rh-eclipse-runtime affected Red Hat:devtools:2020 rh-eclipse-runtime
rh-eclipse-sac affected Red Hat:devtools:2020 rh-eclipse-sac
rh-eclipse-sac-javadoc affected Red Hat:devtools:2020 rh-eclipse-sac-javadoc
rh-eclipse-sat4j affected Red Hat:devtools:2020 rh-eclipse-sat4j
rh-eclipse-scldevel affected Red Hat:devtools:2020 rh-eclipse-scldevel
rh-eclipse-sequence-library affected Red Hat:devtools:2020 rh-eclipse-sequence-library
rh-eclipse-sequence-library-javadoc affected Red Hat:devtools:2020 rh-eclipse-sequence-library-javadoc
rh-eclipse-sqljet affected Red Hat:devtools:2020 rh-eclipse-sqljet
rh-eclipse-sqljet-javadoc affected Red Hat:devtools:2020 rh-eclipse-sqljet-javadoc
rh-eclipse-stringtemplate affected Red Hat:devtools:2020 rh-eclipse-stringtemplate
rh-eclipse-stringtemplate-javadoc affected Red Hat:devtools:2020 rh-eclipse-stringtemplate-javadoc
rh-eclipse-svnkit affected Red Hat:devtools:2020 rh-eclipse-svnkit
rh-eclipse-svnkit-cli affected Red Hat:devtools:2020 rh-eclipse-svnkit-cli
rh-eclipse-svnkit-javadoc affected Red Hat:devtools:2020 rh-eclipse-svnkit-javadoc
rh-eclipse-svnkit-javahl affected Red Hat:devtools:2020 rh-eclipse-svnkit-javahl
rh-eclipse-takari-polyglot affected Red Hat:devtools:2020 rh-eclipse-takari-polyglot
rh-eclipse-takari-polyglot-atom affected Red Hat:devtools:2020 rh-eclipse-takari-polyglot-atom
rh-eclipse-takari-polyglot-common affected Red Hat:devtools:2020 rh-eclipse-takari-polyglot-common
rh-eclipse-takari-polyglot-javadoc affected Red Hat:devtools:2020 rh-eclipse-takari-polyglot-javadoc
rh-eclipse-takari-polyglot-maven-plugin affected Red Hat:devtools:2020 rh-eclipse-takari-polyglot-maven-plugin
rh-eclipse-takari-polyglot-translate-plugin affected Red Hat:devtools:2020 rh-eclipse-takari-polyglot-translate-plugin
rh-eclipse-takari-polyglot-xml affected Red Hat:devtools:2020 rh-eclipse-takari-polyglot-xml
rh-eclipse-trilead-ssh2 affected Red Hat:devtools:2020 rh-eclipse-trilead-ssh2
rh-eclipse-trilead-ssh2-javadoc affected Red Hat:devtools:2020 rh-eclipse-trilead-ssh2-javadoc
rh-eclipse-tycho affected Red Hat:devtools:2020 rh-eclipse-tycho
rh-eclipse-tycho-javadoc affected Red Hat:devtools:2020 rh-eclipse-tycho-javadoc
rh-eclipse-univocity-parsers affected Red Hat:devtools:2020 rh-eclipse-univocity-parsers
rh-eclipse-univocity-parsers-javadoc affected Red Hat:devtools:2020 rh-eclipse-univocity-parsers-javadoc
rh-eclipse-ws-commons-util affected Red Hat:devtools:2020 rh-eclipse-ws-commons-util
rh-eclipse-ws-commons-util-javadoc affected Red Hat:devtools:2020 rh-eclipse-ws-commons-util-javadoc
rh-eclipse-xmlgraphics-commons affected Red Hat:devtools:2020 rh-eclipse-xmlgraphics-commons
rh-eclipse-xmlgraphics-commons-javadoc affected Red Hat:devtools:2020 rh-eclipse-xmlgraphics-commons-javadoc
rh-eclipse-xml-maven-plugin affected Red Hat:devtools:2020 rh-eclipse-xml-maven-plugin
rh-eclipse-xml-maven-plugin-javadoc affected Red Hat:devtools:2020 rh-eclipse-xml-maven-plugin-javadoc
rh-eclipse-xmlrpc affected Red Hat:devtools:2020 rh-eclipse-xmlrpc
rh-eclipse-xmlrpc-client affected Red Hat:devtools:2020 rh-eclipse-xmlrpc-client
rh-eclipse-xmlrpc-common affected Red Hat:devtools:2020 rh-eclipse-xmlrpc-common
rh-eclipse-xmlrpc-javadoc affected Red Hat:devtools:2020 rh-eclipse-xmlrpc-javadoc
rh-eclipse-xmlrpc-server affected Red Hat:devtools:2020 rh-eclipse-xmlrpc-server
Upstream advisory

AZL-79068

Open SourcePoC exploitHIGH2020-11-18

CVE-2020-28362 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

CVE-2020-28362

GooglePoC exploitHIGH2020-11-18

Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.

CVEs:CVE-2020-28362

Affected products

ProductStatusVendorPackageEcosystem
cloud_insights_telegraf_agent affected netapp
fedora affected fedoraproject
go affected golang
trident affected netapp
Upstream advisory

DEBIAN-CVE-2020-28362

Open SourcePoC exploitHIGH2020-11-18

DEBIAN-CVE-2020-28362

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

CVE-2020-0452

Open SourcePoC exploitCRITICAL2020-11-03

In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privi...

CVEs:CVE-2020-0452

Affected products

ProductStatusVendorPackageEcosystem
android affected google
fedora affected fedoraproject
Upstream advisory

openSUSE-SU-2020:2055-1

Open SourcePoC exploitCRITICAL2020-11-26

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2020:2032-1

Open SourcePoC exploitCRITICAL2020-11-26

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

openSUSE-SU-2020:2026-1

Open SourcePoC exploitCRITICAL2020-11-26

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP2 chromium
Upstream advisory

openSUSE-SU-2020:2021-1

Open SourcePoC exploitCRITICAL2020-11-25

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

openSUSE-SU-2020:2012-1

Open SourcePoC exploitCRITICAL2020-11-25

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP2 chromium
Upstream advisory

openSUSE-SU-2020:2010-1

Open SourcePoC exploitCRITICAL2020-11-24

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

CVE-2020-16012

GooglePoC exploitHIGH2020-11-17

Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2020-16012

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
firefox affected mozilla
Upstream advisory

CVE-2020-0451

Open SourcePoC exploitHIGH2020-11-03

In sbrDecoder_AssignQmfChannels2SbrChannels of sbrdecoder.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed fo...

CVEs:CVE-2020-0451

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0443

Open SourcePoC exploitHIGH2020-11-03

In LocaleList of LocaleList.java, there is a possible forced reboot due to an uncaught exception. This could lead to local denial of service requiring factory reset to restore with User execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2020-0443

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0418

Open SourcePoC exploitHIGH2020-11-03

In getPermissionInfosForGroup of Utils.java, there is a logic error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID:...

CVEs:CVE-2020-0418

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0453

Open SourcePoC exploitMEDIUM2020-11-03

In updateNotification of BeamTransferManager.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2020-0453

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0409

Open SourcePoC exploitHIGH2020-11-03

In create of FileMap.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andr...

CVEs:CVE-2020-0409

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-28343

Open SourcePoC exploitCRITICAL2020-11-08

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 980, 9820, and 9830 chipsets) software. The NPU driver allows attackers to execute arbitrary code because of unintended write and read operations on memory. The Samsung I...

CVEs:CVE-2020-28343

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0444

Open SourcePoC exploitHIGH2020-11-03

In audit_free_lsm_field of auditfilter.c, there is a possible bad kfree due to a logic error in audit_data_to_entry. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2020-0444

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0439

Open SourcePoC exploitHIGH2020-11-03

In generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due to an incorrect permission check. This could lead to local escalation of privilege that allows instant apps access to permissions not allowed for instant a...

CVEs:CVE-2020-0439

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2020-16002

Open SourceCoalition ESS 30-63%CRITICAL2020-11-03

DEBIAN-CVE-2020-16002

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DLA-2459-1

Open SourceCoalition ESS < 30%2020-11-21

golang-1.7 - security update

Affected products

ProductStatusVendorPackageEcosystem
golang-1.7 affected Debian:9 golang-1.7
Upstream advisory

DLA-2460-1

Open SourceCoalition ESS < 30%2020-11-21

golang-1.8 - security update

Affected products

ProductStatusVendorPackageEcosystem
golang-1.8 affected Debian:9 golang-1.8
Upstream advisory

CVE-2020-7768

Open SourceCoalition ESS < 30%HIGH2020-11-11

Prototype pollution in grpc and @grpc/grpc-js

CVEs:CVE-2020-7768

Affected products

ProductStatusVendorPackageEcosystem
grpc affected npm grpc
grpc-js affected grpc @grpc/grpc-js
Upstream advisory

CVE-2020-7768

Open SourceCoalition ESS < 30%HIGH2020-11-11

Prototype pollution in grpc and @grpc/grpc-js

CVEs:CVE-2020-7768

Affected products

ProductStatusVendorPackageEcosystem
grpc affected npm grpc
grpc-js affected grpc @grpc/grpc-js
Upstream advisory

CVE-2020-7768

Open SourceCoalition ESS < 30%CRITICAL2020-11-11

The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.

CVEs:CVE-2020-7768

Affected products

ProductStatusVendorPackageEcosystem
grpc affected grpc
Upstream advisory

DEBIAN-CVE-2020-15972

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-15972

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-16011

GoogleCoalition ESS < 30%CRITICAL2020-11-03

Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-16011

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
leap affected opensuse
Upstream advisory

CVE-2020-28367

GoogleCoalition ESS < 30%CRITICAL2020-11-18

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags specified via a #cgo directive.

CVEs:CVE-2020-28367

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

DEBIAN-CVE-2020-28367

Open SourceCoalition ESS < 30%CRITICAL2020-11-18

DEBIAN-CVE-2020-28367

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

CVE-2020-28366

GoogleCoalition ESS < 30%CRITICAL2020-11-18

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symbol name in a linked object file.

CVEs:CVE-2020-28366

Affected products

ProductStatusVendorPackageEcosystem
cloud_insights_telegraf_agent affected netapp
fedora affected fedoraproject
go affected golang
trident affected netapp
Upstream advisory

DEBIAN-CVE-2020-28366

Open SourceCoalition ESS < 30%CRITICAL2020-11-18

DEBIAN-CVE-2020-28366

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

CVE-2020-16025

GoogleCoalition ESS < 30%CRITICAL2020-11-18

Heap buffer overflow in clipboard in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-16025

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-26521

Open SourceCoalition ESS < 30%HIGH2020-11-06

DEBIAN-CVE-2020-26521

Affected products

ProductStatusVendorPackageEcosystem
golang-github-nats-io-jwt affected Debian:12 golang-github-nats-io-jwt
golang-github-nats-io-jwt affected Debian:13 golang-github-nats-io-jwt
golang-github-nats-io-jwt affected Debian:14 golang-github-nats-io-jwt
Upstream advisory

DEBIAN-CVE-2020-26892

Open SourceCoalition ESS < 30%CRITICAL2020-11-06

DEBIAN-CVE-2020-26892

Affected products

ProductStatusVendorPackageEcosystem
golang-github-nats-io-jwt affected Debian:12 golang-github-nats-io-jwt
golang-github-nats-io-jwt affected Debian:13 golang-github-nats-io-jwt
golang-github-nats-io-jwt affected Debian:14 golang-github-nats-io-jwt
Upstream advisory

CVE-2020-16024

GoogleCoalition ESS < 30%CRITICAL2020-11-18

Heap buffer overflow in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-16024

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-15969

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-15969

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
firefox-esr affected Debian:11 firefox-esr
firefox-esr affected Debian:12 firefox-esr
firefox-esr affected Debian:13 firefox-esr
firefox-esr affected Debian:14 firefox-esr
thunderbird affected Debian:11 thunderbird
thunderbird affected Debian:12 thunderbird
thunderbird affected Debian:13 thunderbird
thunderbird affected Debian:14 thunderbird
Upstream advisory

DEBIAN-CVE-2020-16005

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-16005

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16006

Open SourceCoalition ESS < 30%HIGH2020-11-03

DEBIAN-CVE-2020-16006

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

CVE-2020-16005

GoogleCoalition ESS < 30%CRITICAL2020-11-03

Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-16005

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2020-16006

GoogleCoalition ESS < 30%HIGH2020-11-03

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-16006

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-15985

Open SourceCoalition ESS < 30%MEDIUM2020-11-03

DEBIAN-CVE-2020-15985

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-15979

Open SourceCoalition ESS < 30%HIGH2020-11-03

DEBIAN-CVE-2020-15979

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16000

Open SourceCoalition ESS < 30%HIGH2020-11-03

DEBIAN-CVE-2020-16000

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16001

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-16001

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-15968

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-15968

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6557

Open SourceCoalition ESS < 30%MEDIUM2020-11-03

DEBIAN-CVE-2020-6557

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2020-16004

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-16004

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-16004

GoogleCoalition ESS < 30%CRITICAL2020-11-03

Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-16004

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-15978

Open SourceCoalition ESS < 30%HIGH2020-11-03

DEBIAN-CVE-2020-15978

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16003

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-16003

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

DEBIAN-CVE-2020-15974

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-15974

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-15976

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-15976

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-15977

Open SourceCoalition ESS < 30%HIGH2020-11-03

DEBIAN-CVE-2020-15977

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-15991

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-15991

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

DEBIAN-CVE-2020-15992

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-15992

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-15990

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-15990

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-15967

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-15967

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-15970

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-15970

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-15971

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-15971

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-15981

Open SourceCoalition ESS < 30%HIGH2020-11-03

DEBIAN-CVE-2020-15981

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

DEBIAN-CVE-2020-15982

Open SourceCoalition ESS < 30%HIGH2020-11-03

DEBIAN-CVE-2020-15982

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-15975

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-15975

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-0449

Open SourceCoalition ESS < 30%HIGH2020-11-03

In btm_sec_disconnected of btm_sec.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution in the Bluetooth server with no additional execution privileges needed. User interaction is needed for exploi...

CVEs:CVE-2020-0449

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2020-15986

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-15986

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-15984

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-15984

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-15995

GoogleCoalition ESS < 30%CRITICAL2020-11-03

Out of bounds write in V8 in Google Chrome prior to 86.0.4240.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-15995

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2020-15995

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-15995

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-2307

Open SourceCoalition ESS < 30%MEDIUM2020-11-04

Exposure of Sensitive Information to an Unauthorized Actor in Jenkins Kubernetes Plugin

CVEs:CVE-2020-2307

Affected products

ProductStatusVendorPackageEcosystem
org.csanchez.jenkins.plugins:kubernetes affected Maven org.csanchez.jenkins.plugins:kubernetes
Upstream advisory

CVE-2020-2307

Open SourceCoalition ESS < 30%MEDIUM2020-11-04

Jenkins Kubernetes Plugin 1.27.3 and earlier allows low-privilege users to access possibly sensitive Jenkins controller environment variables.

CVEs:CVE-2020-2307

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected jenkins
Upstream advisory

DEBIAN-CVE-2020-15988

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-15988

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-2308

Open SourceCoalition ESS < 30%MEDIUM2020-11-04

Missing Authorization in Jenkins Kubernetes Plugin

CVEs:CVE-2020-2308

Affected products

ProductStatusVendorPackageEcosystem
org.csanchez.jenkins.plugins:kubernetes affected Maven org.csanchez.jenkins.plugins:kubernetes
Upstream advisory

CVE-2020-2308

Open SourceCoalition ESS < 30%MEDIUM2020-11-04

A missing permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to list global pod template names.

CVEs:CVE-2020-2308

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected jenkins
Upstream advisory

DEBIAN-CVE-2020-16008

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-16008

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-16008

GoogleCoalition ESS < 30%CRITICAL2020-11-03

Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet.

CVEs:CVE-2020-16008

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
Upstream advisory

CVE-2020-2309

Open SourceCoalition ESS < 30%MEDIUM2020-11-04

Missing authorization in Jenkins Kubernetes Plugin

CVEs:CVE-2020-2309

Affected products

ProductStatusVendorPackageEcosystem
org.csanchez.jenkins.plugins:kubernetes affected Maven org.csanchez.jenkins.plugins:kubernetes
Upstream advisory

CVE-2020-2309

Open SourceCoalition ESS < 30%MEDIUM2020-11-04

A missing/An incorrect permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

CVEs:CVE-2020-2309

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected jenkins
Upstream advisory

DEBIAN-CVE-2020-15989

Open SourceCoalition ESS < 30%HIGH2020-11-03

DEBIAN-CVE-2020-15989

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-15993

GoogleCoalition ESS < 30%CRITICAL2020-11-03

Use after free in printing in Google Chrome prior to 86.0.4240.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-15993

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-0441

Open SourceCoalition ESS < 30%HIGH2020-11-03

In Message and toBundle of Notification.java, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service requiring a device reset to fix with no additional execution privileges needed. User int...

CVEs:CVE-2020-0441

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2020-15987

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-15987

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-0442

Open SourceCoalition ESS < 30%HIGH2020-11-03

In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation. This could lead to remote denial of service if a malicious contact file is received, with no additional execution privileges needed...

CVEs:CVE-2020-0442

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2020-15973

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

DEBIAN-CVE-2020-15973

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-16035

GoogleCoalition ESS < 30%HIGH2020-11-18

Insufficient data validation in cros-disks in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass noexec restrictions via a malicious file.

CVEs:CVE-2020-16035

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16014

GoogleCoalition ESS < 30%CRITICAL2020-11-18

Use after free in PPAPI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-16014

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16015

GoogleCoalition ESS < 30%HIGH2020-11-18

Insufficient data validation in WASM in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-16015

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16018

GoogleCoalition ESS < 30%CRITICAL2020-11-18

Use after free in payments in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-16018

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16026

GoogleCoalition ESS < 30%CRITICAL2020-11-18

Use after free in WebRTC in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-16026

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-xwhf-g6j5-j5gc

Open SourceCoalition ESS < 30%MEDIUM2020-11-13

Float cast overflow undefined behavior

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xwhf-g6j5-j5gc

Open SourceCoalition ESS < 30%MEDIUM2020-11-13

Float cast overflow undefined behavior

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-16029

GoogleCoalition ESS < 30%HIGH2020-11-18

Inappropriate implementation in PDFium in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass navigation restrictions via a crafted PDF file.

CVEs:CVE-2020-16029

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16027

GoogleCoalition ESS < 30%CRITICAL2020-11-18

Insufficient policy enforcement in developer tools in Google Chrome prior to 87.0.4280.66 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from the user's disk via a crafted Chrome Ex...

CVEs:CVE-2020-16027

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16028

GoogleCoalition ESS < 30%CRITICAL2020-11-18

Heap buffer overflow in WebRTC in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-16028

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-15997

GoogleCoalition ESS < 30%CRITICAL2020-11-03

Use after free in Mojo in Google Chrome prior to 86.0.4240.99 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-15997

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-rrfp-j2mp-hq9c

Open SourceCoalition ESS < 30%HIGH2020-11-13

Segfault in `tf.quantization.quantize_and_dequantize`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rrfp-j2mp-hq9c

Open SourceCoalition ESS < 30%HIGH2020-11-13

Segfault in `tf.quantization.quantize_and_dequantize`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-16023

GoogleCoalition ESS < 30%CRITICAL2020-11-18

Use after free in WebCodecs in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-16023

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-0450

Open SourceCoalition ESS < 30%MEDIUM2020-11-03

In rw_i93_sm_format of rw_i93.cc, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure over NFC with no additional execution privileges needed. User interaction is needed for exploitation.Pr...

CVEs:CVE-2020-0450

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-16019

GoogleCoalition ESS < 30%HIGH2020-11-18

Inappropriate implementation in filesystem in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass noexec restrictions via a malicious file.

CVEs:CVE-2020-16019

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16020

GoogleCoalition ESS < 30%HIGH2020-11-18

Inappropriate implementation in cryptohome in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass discretionary access control via a malicious file.

CVEs:CVE-2020-16020

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16016

GoogleCoalition ESS < 30%CRITICAL2020-11-15

Inappropriate implementation in base in Google Chrome prior to 86.0.4240.193 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-16016

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-15996

GoogleCoalition ESS < 30%CRITICAL2020-11-03

Use after free in passwords in Google Chrome prior to 86.0.4240.99 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-15996

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16022

GoogleCoalition ESS < 30%CRITICAL2020-11-18

Insufficient policy enforcement in networking in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially bypass firewall controls via a crafted HTML page.

CVEs:CVE-2020-16022

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16036

GoogleCoalition ESS < 30%MEDIUM2020-11-18

Inappropriate implementation in cookies in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass cookie restrictions via a crafted HTML page.

CVEs:CVE-2020-16036

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-15998

GoogleCoalition ESS < 30%CRITICAL2020-11-03

Use after free in USB in Google Chrome prior to 86.0.4240.99 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-15998

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16033

GoogleCoalition ESS < 30%MEDIUM2020-11-18

Inappropriate implementation in WebUSB in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof security UI via a crafted HTML page.

CVEs:CVE-2020-16033

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16031

GoogleCoalition ESS < 30%MEDIUM2020-11-18

Insufficient data validation in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2020-16031

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16032

GoogleCoalition ESS < 30%MEDIUM2020-11-18

Insufficient data validation in sharing in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2020-16032

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16030

GoogleCoalition ESS < 30%CRITICAL2020-11-18

Insufficient data validation in Blink in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.

CVEs:CVE-2020-16030

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16021

GoogleCoalition ESS < 30%CRITICAL2020-11-18

Race in image burner in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to perform OS-level privilege escalation via a malicious file.

CVEs:CVE-2020-16021

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-25655

Open SourceCoalition ESS < 30%MEDIUM2020-11-09

An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permission. In this s...

CVEs:CVE-2020-25655

Affected products

ProductStatusVendorPackageEcosystem
advanced_cluster_management_for_kubernetes affected redhat
Upstream advisory

CVE-2020-0447

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-168251617

CVEs:CVE-2020-0447

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-168251617

GoogleCoalition ESS < 30%CRITICAL2020-11-01

ASB-A-168251617

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2020-7765

Open SourceCoalition ESS < 30%MEDIUM2020-11-16

Uncontrolled Resource Consumption in firebase

CVEs:CVE-2020-7765

Affected products

ProductStatusVendorPackageEcosystem
util affected firebase @firebase/util
Upstream advisory

CVE-2020-7765

Open SourceCoalition ESS < 30%MEDIUM2020-11-16

This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the DeepCopy.ts file. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.

CVEs:CVE-2020-7765

Affected products

ProductStatusVendorPackageEcosystem
firebase\/util affected google
Upstream advisory

CVE-2020-7765

Open SourceCoalition ESS < 30%MEDIUM2020-11-16

Uncontrolled Resource Consumption in firebase

CVEs:CVE-2020-7765

Affected products

ProductStatusVendorPackageEcosystem
util affected firebase @firebase/util
Upstream advisory

CVE-2020-0445

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-168264527

CVEs:CVE-2020-0445

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-168264527

GoogleCoalition ESS < 30%CRITICAL2020-11-01

ASB-A-168264527

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2020-0446

Open SourceCoalition ESS < 30%CRITICAL2020-11-03

There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-168264528

CVEs:CVE-2020-0446

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-168264528

GoogleCoalition ESS < 30%CRITICAL2020-11-01

ASB-A-168264528

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2020-16034

GoogleCoalition ESS < 30%MEDIUM2020-11-18

Inappropriate implementation in WebRTC in Google Chrome prior to 87.0.4280.66 allowed a local attacker to bypass policy restrictions via a crafted HTML page.

CVEs:CVE-2020-16034

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-28340

Open SourceCoalition ESS < 30%CRITICAL2020-11-08

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypass Factory Reset Protection (FRP) via Secure Folder. The Samsung ID is SVE-2020-18546 (November 2020).

CVEs:CVE-2020-28340

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-28344

Open SourceCoalition ESS < 30%HIGH2020-11-08

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. System services may crash because of the lack of a NULL parameter check. The LG ID is LVE-SMP-200024 (November 2020).

CVEs:CVE-2020-28344

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-28345

Open SourceCoalition ESS < 30%HIGH2020-11-08

An issue was discovered on LG mobile devices with Android OS 10 software. The Wi-Fi subsystem may crash because of the lack of a NULL parameter check. The LG ID is LVE-SMP-200025 (November 2020).

CVEs:CVE-2020-28345

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2020-15983

Open SourceCoalition ESS < 30%HIGH2020-11-03

DEBIAN-CVE-2020-15983

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-16007

GoogleCoalition ESS < 30%HIGH2020-11-03

Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem.

CVEs:CVE-2020-16007

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
leap affected opensuse
Upstream advisory

CVE-2020-25688

Open SourceCoalition ESS < 30%CRITICAL2020-11-23

A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all installations using the same certificates. If an atta...

CVEs:CVE-2020-25688

Affected products

ProductStatusVendorPackageEcosystem
advanced_cluster_management_for_kubernetes affected redhat
Upstream advisory

DEBIAN-CVE-2020-15980

Open SourceCoalition ESS < 30%HIGH2020-11-03

DEBIAN-CVE-2020-15980

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-0454

Open SourceCoalition ESS < 30%MEDIUM2020-11-03

In callCallbackForRequest of ConnectivityService.java, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure of the current SSID with User execution privileges needed. User interaction ...

CVEs:CVE-2020-0454

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0438

Open SourceCoalition ESS < 30%HIGH2020-11-03

In the AIBinder_Class constructor of ibinder.cpp, there is a possible arbitrary code execution due to uninitialized data. This could lead to local escalation of privilege if a process were using libbinder_ndk in a vulnerable way with no additional exec...

CVEs:CVE-2020-0438

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0424

Open SourceCoalition ESS < 30%MEDIUM2020-11-03

In send_vc of res_send.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2020-0424

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0448

Open SourceCoalition ESS < 30%MEDIUM2020-11-03

In getPhoneAccountsForPackage of TelecomServiceImpl.java, there is a possible way to access a tracking identifier due to a missing permission check. This could lead to local information disclosure of the identifier, which could be used to track an acco...

CVEs:CVE-2020-0448

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0437

Open SourceCoalition ESS < 30%MEDIUM2020-11-03

In CellBroadcastReceiver's intent handlers, there is a possible denial of service due to a missing permission check. This could lead to local denial of service of emergency alerts with no additional execution privileges needed. User interaction is not ...

CVEs:CVE-2020-0437

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-28342

Open SourceEPSS <= 49%CRITICAL2020-11-08

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (China / India) software. The S Secure application allows attackers to bypass authentication for a locked Gallery application via the Reminder application. The Samsung ID is SVE-...

CVEs:CVE-2020-28342

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-28341

Open SourceEPSS <= 49%CRITICAL2020-11-08

An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos990 chipsets) software. The S3K250AF Secure Element CC EAL 5+ chip allows attackers to execute arbitrary code and obtain sensitive information via a buffer overflow. The Samsung ID i...

CVEs:CVE-2020-28341

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MGASA-2020-0413

Open SourceAll remaining2020-11-13

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:7 chromium-browser-stable
Upstream advisory

ALBA-2020:5097

GoogleAll remaining2020-11-12

eclipse:rhel8 bug fix update

Affected products

ProductStatusVendorPackageEcosystem
apache-commons-compress affected AlmaLinux:8 apache-commons-compress
apache-commons-jxpath affected AlmaLinux:8 apache-commons-jxpath
apiguardian affected AlmaLinux:8 apiguardian
batik-css affected AlmaLinux:8 batik-css
batik-util affected AlmaLinux:8 batik-util
eclipse-ecf-core affected AlmaLinux:8 eclipse-ecf-core
eclipse-ecf-runtime affected AlmaLinux:8 eclipse-ecf-runtime
eclipse-emf-core affected AlmaLinux:8 eclipse-emf-core
eclipse-emf-runtime affected AlmaLinux:8 eclipse-emf-runtime
eclipse-emf-xsd affected AlmaLinux:8 eclipse-emf-xsd
eclipse-equinox-osgi affected AlmaLinux:8 eclipse-equinox-osgi
eclipse-jdt affected AlmaLinux:8 eclipse-jdt
eclipse-p2-discovery affected AlmaLinux:8 eclipse-p2-discovery
eclipse-pde affected AlmaLinux:8 eclipse-pde
eclipse-platform affected AlmaLinux:8 eclipse-platform
eclipse-swt affected AlmaLinux:8 eclipse-swt
felix-gogo-command affected AlmaLinux:8 felix-gogo-command
felix-gogo-runtime affected AlmaLinux:8 felix-gogo-runtime
felix-gogo-shell affected AlmaLinux:8 felix-gogo-shell
felix-scr affected AlmaLinux:8 felix-scr
glassfish-annotation-api affected AlmaLinux:8 glassfish-annotation-api
glassfish-el affected AlmaLinux:8 glassfish-el
glassfish-el-api affected AlmaLinux:8 glassfish-el-api
glassfish-jsp affected AlmaLinux:8 glassfish-jsp
glassfish-jsp-api affected AlmaLinux:8 glassfish-jsp-api
glassfish-servlet-api affected AlmaLinux:8 glassfish-servlet-api
google-gson affected AlmaLinux:8 google-gson
hamcrest affected AlmaLinux:8 hamcrest
hamcrest-core affected AlmaLinux:8 hamcrest-core
icu4j affected AlmaLinux:8 icu4j
jetty-continuation affected AlmaLinux:8 jetty-continuation
jetty-http affected AlmaLinux:8 jetty-http
jetty-io affected AlmaLinux:8 jetty-io
jetty-security affected AlmaLinux:8 jetty-security
jetty-server affected AlmaLinux:8 jetty-server
jetty-servlet affected AlmaLinux:8 jetty-servlet
jetty-util affected AlmaLinux:8 jetty-util
jsch affected AlmaLinux:8 jsch
junit affected AlmaLinux:8 junit
junit5 affected AlmaLinux:8 junit5
jzlib affected AlmaLinux:8 jzlib
lucene affected AlmaLinux:8 lucene
lucene-analysis affected AlmaLinux:8 lucene-analysis
lucene-analyzers-smartcn affected AlmaLinux:8 lucene-analyzers-smartcn
lucene-queries affected AlmaLinux:8 lucene-queries
lucene-queryparser affected AlmaLinux:8 lucene-queryparser
lucene-sandbox affected AlmaLinux:8 lucene-sandbox
objectweb-asm affected AlmaLinux:8 objectweb-asm
opentest4j affected AlmaLinux:8 opentest4j
sat4j affected AlmaLinux:8 sat4j
univocity-parsers affected AlmaLinux:8 univocity-parsers
xml-commons-apis affected AlmaLinux:8 xml-commons-apis
xmlgraphics-commons affected AlmaLinux:8 xmlgraphics-commons
xz-java affected AlmaLinux:8 xz-java
Upstream advisory

ALBA-2020:4790

GoogleAll remainingHIGH2020-11-03

google-noto-fonts bug fix and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
google-noto-fonts-common affected AlmaLinux:8 google-noto-fonts-common
google-noto-kufi-arabic-fonts affected AlmaLinux:8 google-noto-kufi-arabic-fonts
google-noto-mono-fonts affected AlmaLinux:8 google-noto-mono-fonts
google-noto-naskh-arabic-fonts affected AlmaLinux:8 google-noto-naskh-arabic-fonts
google-noto-naskh-arabic-ui-fonts affected AlmaLinux:8 google-noto-naskh-arabic-ui-fonts
google-noto-nastaliq-urdu-fonts affected AlmaLinux:8 google-noto-nastaliq-urdu-fonts
google-noto-sans-armenian-fonts affected AlmaLinux:8 google-noto-sans-armenian-fonts
google-noto-sans-avestan-fonts affected AlmaLinux:8 google-noto-sans-avestan-fonts
google-noto-sans-balinese-fonts affected AlmaLinux:8 google-noto-sans-balinese-fonts
google-noto-sans-bamum-fonts affected AlmaLinux:8 google-noto-sans-bamum-fonts
google-noto-sans-batak-fonts affected AlmaLinux:8 google-noto-sans-batak-fonts
google-noto-sans-bengali-fonts affected AlmaLinux:8 google-noto-sans-bengali-fonts
google-noto-sans-bengali-ui-fonts affected AlmaLinux:8 google-noto-sans-bengali-ui-fonts
google-noto-sans-brahmi-fonts affected AlmaLinux:8 google-noto-sans-brahmi-fonts
google-noto-sans-buginese-fonts affected AlmaLinux:8 google-noto-sans-buginese-fonts
google-noto-sans-buhid-fonts affected AlmaLinux:8 google-noto-sans-buhid-fonts
google-noto-sans-canadian-aboriginal-fonts affected AlmaLinux:8 google-noto-sans-canadian-aboriginal-fonts
google-noto-sans-carian-fonts affected AlmaLinux:8 google-noto-sans-carian-fonts
google-noto-sans-cham-fonts affected AlmaLinux:8 google-noto-sans-cham-fonts
google-noto-sans-cherokee-fonts affected AlmaLinux:8 google-noto-sans-cherokee-fonts
google-noto-sans-coptic-fonts affected AlmaLinux:8 google-noto-sans-coptic-fonts
google-noto-sans-cuneiform-fonts affected AlmaLinux:8 google-noto-sans-cuneiform-fonts
google-noto-sans-cypriot-fonts affected AlmaLinux:8 google-noto-sans-cypriot-fonts
google-noto-sans-deseret-fonts affected AlmaLinux:8 google-noto-sans-deseret-fonts
google-noto-sans-devanagari-fonts affected AlmaLinux:8 google-noto-sans-devanagari-fonts
google-noto-sans-devanagari-ui-fonts affected AlmaLinux:8 google-noto-sans-devanagari-ui-fonts
google-noto-sans-egyptian-hieroglyphs-fonts affected AlmaLinux:8 google-noto-sans-egyptian-hieroglyphs-fonts
google-noto-sans-ethiopic-fonts affected AlmaLinux:8 google-noto-sans-ethiopic-fonts
google-noto-sans-fonts affected AlmaLinux:8 google-noto-sans-fonts
google-noto-sans-georgian-fonts affected AlmaLinux:8 google-noto-sans-georgian-fonts
google-noto-sans-glagolitic-fonts affected AlmaLinux:8 google-noto-sans-glagolitic-fonts
google-noto-sans-gothic-fonts affected AlmaLinux:8 google-noto-sans-gothic-fonts
google-noto-sans-gujarati-fonts affected AlmaLinux:8 google-noto-sans-gujarati-fonts
google-noto-sans-gujarati-ui-fonts affected AlmaLinux:8 google-noto-sans-gujarati-ui-fonts
google-noto-sans-gurmukhi-fonts affected AlmaLinux:8 google-noto-sans-gurmukhi-fonts
google-noto-sans-gurmukhi-ui-fonts affected AlmaLinux:8 google-noto-sans-gurmukhi-ui-fonts
google-noto-sans-hanunoo-fonts affected AlmaLinux:8 google-noto-sans-hanunoo-fonts
google-noto-sans-hebrew-fonts affected AlmaLinux:8 google-noto-sans-hebrew-fonts
google-noto-sans-imperial-aramaic-fonts affected AlmaLinux:8 google-noto-sans-imperial-aramaic-fonts
google-noto-sans-inscriptional-pahlavi-fonts affected AlmaLinux:8 google-noto-sans-inscriptional-pahlavi-fonts
google-noto-sans-inscriptional-parthian-fonts affected AlmaLinux:8 google-noto-sans-inscriptional-parthian-fonts
google-noto-sans-javanese-fonts affected AlmaLinux:8 google-noto-sans-javanese-fonts
google-noto-sans-kaithi-fonts affected AlmaLinux:8 google-noto-sans-kaithi-fonts
google-noto-sans-kannada-fonts affected AlmaLinux:8 google-noto-sans-kannada-fonts
google-noto-sans-kannada-ui-fonts affected AlmaLinux:8 google-noto-sans-kannada-ui-fonts
google-noto-sans-kayah-li-fonts affected AlmaLinux:8 google-noto-sans-kayah-li-fonts
google-noto-sans-kharoshthi-fonts affected AlmaLinux:8 google-noto-sans-kharoshthi-fonts
google-noto-sans-khmer-fonts affected AlmaLinux:8 google-noto-sans-khmer-fonts
google-noto-sans-khmer-ui-fonts affected AlmaLinux:8 google-noto-sans-khmer-ui-fonts
google-noto-sans-lao-fonts affected AlmaLinux:8 google-noto-sans-lao-fonts
google-noto-sans-lao-ui-fonts affected AlmaLinux:8 google-noto-sans-lao-ui-fonts
google-noto-sans-lepcha-fonts affected AlmaLinux:8 google-noto-sans-lepcha-fonts
google-noto-sans-limbu-fonts affected AlmaLinux:8 google-noto-sans-limbu-fonts
google-noto-sans-linear-b-fonts affected AlmaLinux:8 google-noto-sans-linear-b-fonts
google-noto-sans-lisu-fonts affected AlmaLinux:8 google-noto-sans-lisu-fonts
google-noto-sans-lycian-fonts affected AlmaLinux:8 google-noto-sans-lycian-fonts
google-noto-sans-lydian-fonts affected AlmaLinux:8 google-noto-sans-lydian-fonts
google-noto-sans-malayalam-fonts affected AlmaLinux:8 google-noto-sans-malayalam-fonts
google-noto-sans-malayalam-ui-fonts affected AlmaLinux:8 google-noto-sans-malayalam-ui-fonts
google-noto-sans-mandaic-fonts affected AlmaLinux:8 google-noto-sans-mandaic-fonts
google-noto-sans-meetei-mayek-fonts affected AlmaLinux:8 google-noto-sans-meetei-mayek-fonts
google-noto-sans-mongolian-fonts affected AlmaLinux:8 google-noto-sans-mongolian-fonts
google-noto-sans-myanmar-fonts affected AlmaLinux:8 google-noto-sans-myanmar-fonts
google-noto-sans-myanmar-ui-fonts affected AlmaLinux:8 google-noto-sans-myanmar-ui-fonts
google-noto-sans-new-tai-lue-fonts affected AlmaLinux:8 google-noto-sans-new-tai-lue-fonts
google-noto-sans-nko-fonts affected AlmaLinux:8 google-noto-sans-nko-fonts
google-noto-sans-ogham-fonts affected AlmaLinux:8 google-noto-sans-ogham-fonts
google-noto-sans-ol-chiki-fonts affected AlmaLinux:8 google-noto-sans-ol-chiki-fonts
google-noto-sans-old-italic-fonts affected AlmaLinux:8 google-noto-sans-old-italic-fonts
google-noto-sans-old-persian-fonts affected AlmaLinux:8 google-noto-sans-old-persian-fonts
google-noto-sans-old-south-arabian-fonts affected AlmaLinux:8 google-noto-sans-old-south-arabian-fonts
google-noto-sans-old-turkic-fonts affected AlmaLinux:8 google-noto-sans-old-turkic-fonts
google-noto-sans-oriya-fonts affected AlmaLinux:8 google-noto-sans-oriya-fonts
google-noto-sans-oriya-ui-fonts affected AlmaLinux:8 google-noto-sans-oriya-ui-fonts
google-noto-sans-osmanya-fonts affected AlmaLinux:8 google-noto-sans-osmanya-fonts
google-noto-sans-phags-pa-fonts affected AlmaLinux:8 google-noto-sans-phags-pa-fonts
google-noto-sans-phoenician-fonts affected AlmaLinux:8 google-noto-sans-phoenician-fonts
google-noto-sans-rejang-fonts affected AlmaLinux:8 google-noto-sans-rejang-fonts
google-noto-sans-runic-fonts affected AlmaLinux:8 google-noto-sans-runic-fonts
google-noto-sans-samaritan-fonts affected AlmaLinux:8 google-noto-sans-samaritan-fonts
google-noto-sans-saurashtra-fonts affected AlmaLinux:8 google-noto-sans-saurashtra-fonts
google-noto-sans-shavian-fonts affected AlmaLinux:8 google-noto-sans-shavian-fonts
google-noto-sans-sinhala-fonts affected AlmaLinux:8 google-noto-sans-sinhala-fonts
google-noto-sans-sundanese-fonts affected AlmaLinux:8 google-noto-sans-sundanese-fonts
google-noto-sans-syloti-nagri-fonts affected AlmaLinux:8 google-noto-sans-syloti-nagri-fonts
google-noto-sans-symbols-fonts affected AlmaLinux:8 google-noto-sans-symbols-fonts
google-noto-sans-syriac-eastern-fonts affected AlmaLinux:8 google-noto-sans-syriac-eastern-fonts
google-noto-sans-syriac-estrangela-fonts affected AlmaLinux:8 google-noto-sans-syriac-estrangela-fonts
google-noto-sans-syriac-western-fonts affected AlmaLinux:8 google-noto-sans-syriac-western-fonts
google-noto-sans-tagalog-fonts affected AlmaLinux:8 google-noto-sans-tagalog-fonts
google-noto-sans-tagbanwa-fonts affected AlmaLinux:8 google-noto-sans-tagbanwa-fonts
google-noto-sans-tai-le-fonts affected AlmaLinux:8 google-noto-sans-tai-le-fonts
google-noto-sans-tai-tham-fonts affected AlmaLinux:8 google-noto-sans-tai-tham-fonts
google-noto-sans-tai-viet-fonts affected AlmaLinux:8 google-noto-sans-tai-viet-fonts
google-noto-sans-tamil-fonts affected AlmaLinux:8 google-noto-sans-tamil-fonts
google-noto-sans-tamil-ui-fonts affected AlmaLinux:8 google-noto-sans-tamil-ui-fonts
google-noto-sans-telugu-fonts affected AlmaLinux:8 google-noto-sans-telugu-fonts
google-noto-sans-telugu-ui-fonts affected AlmaLinux:8 google-noto-sans-telugu-ui-fonts
google-noto-sans-thaana-fonts affected AlmaLinux:8 google-noto-sans-thaana-fonts
google-noto-sans-thai-fonts affected AlmaLinux:8 google-noto-sans-thai-fonts
google-noto-sans-thai-ui-fonts affected AlmaLinux:8 google-noto-sans-thai-ui-fonts
google-noto-sans-tibetan-fonts affected AlmaLinux:8 google-noto-sans-tibetan-fonts
google-noto-sans-tifinagh-fonts affected AlmaLinux:8 google-noto-sans-tifinagh-fonts
google-noto-sans-ugaritic-fonts affected AlmaLinux:8 google-noto-sans-ugaritic-fonts
google-noto-sans-ui-fonts affected AlmaLinux:8 google-noto-sans-ui-fonts
google-noto-sans-vai-fonts affected AlmaLinux:8 google-noto-sans-vai-fonts
google-noto-sans-yi-fonts affected AlmaLinux:8 google-noto-sans-yi-fonts
google-noto-serif-armenian-fonts affected AlmaLinux:8 google-noto-serif-armenian-fonts
google-noto-serif-bengali-fonts affected AlmaLinux:8 google-noto-serif-bengali-fonts
google-noto-serif-devanagari-fonts affected AlmaLinux:8 google-noto-serif-devanagari-fonts
google-noto-serif-fonts affected AlmaLinux:8 google-noto-serif-fonts
google-noto-serif-georgian-fonts affected AlmaLinux:8 google-noto-serif-georgian-fonts
google-noto-serif-gujarati-fonts affected AlmaLinux:8 google-noto-serif-gujarati-fonts
google-noto-serif-kannada-fonts affected AlmaLinux:8 google-noto-serif-kannada-fonts
google-noto-serif-khmer-fonts affected AlmaLinux:8 google-noto-serif-khmer-fonts
google-noto-serif-lao-fonts affected AlmaLinux:8 google-noto-serif-lao-fonts
google-noto-serif-malayalam-fonts affected AlmaLinux:8 google-noto-serif-malayalam-fonts
google-noto-serif-tamil-fonts affected AlmaLinux:8 google-noto-serif-tamil-fonts
google-noto-serif-telugu-fonts affected AlmaLinux:8 google-noto-serif-telugu-fonts
google-noto-serif-thai-fonts affected AlmaLinux:8 google-noto-serif-thai-fonts
Upstream advisory

ALEA-2020:4748

GoogleAll remainingHIGH2020-11-03

maven:3.6 bug fix and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
aopalliance affected AlmaLinux:8 aopalliance
apache-commons-cli affected AlmaLinux:8 apache-commons-cli
apache-commons-codec affected AlmaLinux:8 apache-commons-codec
apache-commons-io affected AlmaLinux:8 apache-commons-io
apache-commons-lang3 affected AlmaLinux:8 apache-commons-lang3
atinject affected AlmaLinux:8 atinject
cdi-api affected AlmaLinux:8 cdi-api
geronimo-annotation affected AlmaLinux:8 geronimo-annotation
google-guice affected AlmaLinux:8 google-guice
guava affected AlmaLinux:8 guava
httpcomponents-core affected AlmaLinux:8 httpcomponents-core
jansi affected AlmaLinux:8 jansi
jcl-over-slf4j affected AlmaLinux:8 jcl-over-slf4j
jsoup affected AlmaLinux:8 jsoup
jsr-305 affected AlmaLinux:8 jsr-305
maven-resolver affected AlmaLinux:8 maven-resolver
maven-shared-utils affected AlmaLinux:8 maven-shared-utils
maven-wagon affected AlmaLinux:8 maven-wagon
plexus-cipher affected AlmaLinux:8 plexus-cipher
plexus-classworlds affected AlmaLinux:8 plexus-classworlds
plexus-containers-component-annotations affected AlmaLinux:8 plexus-containers-component-annotations
plexus-interpolation affected AlmaLinux:8 plexus-interpolation
plexus-sec-dispatcher affected AlmaLinux:8 plexus-sec-dispatcher
plexus-utils affected AlmaLinux:8 plexus-utils
sisu affected AlmaLinux:8 sisu
slf4j affected AlmaLinux:8 slf4j
Upstream advisory

ALBA-2020:4733

Open SourceAll remainingHIGH2020-11-03

protobuf bug fix and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected AlmaLinux:8 protobuf
protobuf-compiler affected AlmaLinux:8 protobuf-compiler
protobuf-devel affected AlmaLinux:8 protobuf-devel
protobuf-lite affected AlmaLinux:8 protobuf-lite
protobuf-lite-devel affected AlmaLinux:8 protobuf-lite-devel
python3-protobuf affected AlmaLinux:8 python3-protobuf
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.