Google Security Advisories · December 2020 — Google Security Advisories
328 advisories 186 CVEs 6 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2020-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 6 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

openSUSE-SU-2020:2229-1

Open SourceExploitedVulnCheck KEV listedCRITICAL2020-12-11

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2020:2216-1

Open SourceExploitedVulnCheck KEV listedCRITICAL2020-12-09

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

openSUSE-SU-2020:2213-1

Open SourceExploitedVulnCheck KEV listedCRITICAL2020-12-08

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP2 chromium
Upstream advisory

CVE-2020-16040

GoogleExploitedVulnCheck KEV listedMEDIUM2020-12-07

Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-16040

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

openSUSE-SU-2020:2181-1

Open SourceExploitedVulnCheck KEV listedCRITICAL2020-12-07

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

SUSE-SU-2020:3938-1

Open SourceActive exploitation (sightings)CRITICAL2020-12-28

Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork

Affected products

ProductStatusVendorPackageEcosystem
containerd affected SUSE:Linux Enterprise Module for Containers 12 containerd
docker affected SUSE:Linux Enterprise Module for Containers 12 docker
docker-runc affected SUSE:Linux Enterprise Module for Containers 12 docker-runc
golang-github-docker-libnetwork affected SUSE:Linux Enterprise Module for Containers 12 golang-github-docker-libnetwork
Upstream advisory

DEBIAN-CVE-2020-35381

Open SourceActive exploitation (sightings)HIGH2020-12-15

DEBIAN-CVE-2020-35381

Affected products

ProductStatusVendorPackageEcosystem
golang-github-buger-jsonparser affected Debian:11 golang-github-buger-jsonparser
golang-github-buger-jsonparser affected Debian:12 golang-github-buger-jsonparser
golang-github-buger-jsonparser affected Debian:13 golang-github-buger-jsonparser
golang-github-buger-jsonparser affected Debian:14 golang-github-buger-jsonparser
Upstream advisory

CVE-2020-0458

Open SourceActive exploitation (sightings)HIGH2020-12-08

In SPDIFEncoder::writeBurstBufferBytes and related methods of SPDIFEncoder.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interactio...

CVEs:CVE-2020-0458

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27024

Open SourceActive exploitation (sightings)HIGH2020-12-15

In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure triggered by a malformed Bluetooth packet, with no additional execution privileges n...

CVEs:CVE-2020-27024

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27038

Open SourceActive exploitation (sightings)HIGH2020-12-15

In process of C2SoftVorbisDec.cpp, there is a possible resource exhaustion due to a memory leak. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVer...

CVEs:CVE-2020-27038

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27029

Open SourceActive exploitation (sightings)MEDIUM2020-12-15

In TextView of TextView.java, there is a possible app hang due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersion...

CVEs:CVE-2020-27029

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27050

Open SourceActive exploitation (sightings)HIGH2020-12-15

In rw_i93_send_cmd_write_multi_blocks of rw_i93.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for e...

CVEs:CVE-2020-27050

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27045

Open SourceActive exploitation (sightings)HIGH2020-12-15

In CE_SendRawFrame of ce_main.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Produc...

CVEs:CVE-2020-27045

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27048

Open SourceActive exploitation (sightings)HIGH2020-12-15

In RW_SendRawFrame of rw_main.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Produc...

CVEs:CVE-2020-27048

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27051

Open SourceActive exploitation (sightings)HIGH2020-12-15

In NFA_RwI93WriteMultipleBlocks of nfa_rw_api.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploi...

CVEs:CVE-2020-27051

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27047

Open SourceActive exploitation (sightings)MEDIUM2020-12-15

In ce_t4t_update_binary of ce_t4t.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Prod...

CVEs:CVE-2020-27047

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27026

Open SourceActive exploitation (sightings)MEDIUM2020-12-15

During boot, the device unlock interface behaves differently depending on if a fingerprint registered to the device is present. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed f...

CVEs:CVE-2020-27026

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0482

Open SourceActive exploitation (sightings)MEDIUM2020-12-15

In command of IncidentService.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2020-0482

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0280

Open SourceActive exploitation (sightings)MEDIUM2020-12-15

In nci_proc_ee_management_rsp of nci_hrcv.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitat...

CVEs:CVE-2020-0280

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27028

Open SourceActive exploitation (sightings)MEDIUM2020-12-15

In filter_incoming_event of hci_layer.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2020-27028

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27040

Open SourceActive exploitation (sightings)MEDIUM2020-12-15

In phNxpNciHal_core_initialized of phNxpNciHal.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interaction is not ...

CVEs:CVE-2020-27040

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27030

Open SourceActive exploitation (sightings)HIGH2020-12-15

In onCreate of HandleApiCalls.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege that allows an app to set or dismiss the alarm with no additional execution privileges needed. User int...

CVEs:CVE-2020-27030

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27021

Open SourceActive exploitation (sightings)MEDIUM2020-12-15

In avrc_ctrl_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2020-27021

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27039

Open SourceActive exploitation (sightings)MEDIUM2020-12-15

In postNotification of ServiceRecord.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Prod...

CVEs:CVE-2020-27039

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0484

Open SourceActive exploitation (sightings)HIGH2020-12-15

In destroyResources of ComposerClient.h, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: And...

CVEs:CVE-2020-0484

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0469

Open SourceActive exploitation (sightings)MEDIUM2020-12-08

In addEscrowToken of LockSettingsService.java, there is a possible loss of the synthetic password due to logic error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2020-0469

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27043

Open SourceActive exploitation (sightings)MEDIUM2020-12-15

In nfc_enabled of nfc_main.cc, there is a possible out of bounds read due to an incorrect increment. This could lead to local information disclosure via firmware with System execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2020-27043

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27025

Open SourceActive exploitation (sightings)MEDIUM2020-12-15

In EapFailureNotifier.java and SimRequiredNotifier.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2020-27025

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27052

Open SourceActive exploitation (sightings)HIGH2020-12-15

In getLockTaskLaunchMode of ActivityRecord.java, there is a possible way for any app to start in Lock Task Mode due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...

CVEs:CVE-2020-27052

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27053

Open SourceActive exploitation (sightings)HIGH2020-12-15

In broadcastWifiCredentialChanged of ClientModeImpl.java, there is a possible location permission bypass due to a missing permission check. This could lead to local information disclosure of the WiFi network name with System execution privileges needed...

CVEs:CVE-2020-27053

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0485

Open SourceActive exploitation (sightings)HIGH2020-12-15

In areFunctionsSupported of UsbBackend.java, there is a possible access to tethering from a guest account due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...

CVEs:CVE-2020-0485

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27056

Open SourceActive exploitation (sightings)MEDIUM2020-12-15

In SELinux policies of mls, there is a missing permission check. This could lead to local information disclosure of package metadata with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersion...

CVEs:CVE-2020-27056

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27057

Open SourceActive exploitation (sightings)MEDIUM2020-12-15

In getGpuStatsGlobalInfo and getGpuStatsAppInfo of GpuService.cpp, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure of gpu statistics with User execution privileges needed. User in...

CVEs:CVE-2020-27057

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0497

Open SourceActive exploitation (sightings)MEDIUM2020-12-15

In canUseBiometric of BiometricServiceBase, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A...

CVEs:CVE-2020-0497

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0477

Open SourceActive exploitation (sightings)HIGH2020-12-15

In sendLinkConfigurationChangedBroadcast of ClientModeImpl.java, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of the current network configuration with no additional execu...

CVEs:CVE-2020-0477

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27035

Open SourceActive exploitation (sightings)HIGH2020-12-15

In priorLinearAllocation of C2AllocatorIon.cpp, there is a possible use-after-free due to improper locking. This could lead to local information disclosure in the media codec with no additional execution privileges needed. User interaction is not neede...

CVEs:CVE-2020-27035

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MGASA-2020-0468

Open SourcePoC exploit2020-12-21

Updated golang-googlecode-net package fixes security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
golang-googlecode-net affected Mageia:7 golang-googlecode-net
Upstream advisory

DLA-2485-1

Open SourcePoC exploit2020-12-09

golang-golang-x-net-dev - security update

Affected products

ProductStatusVendorPackageEcosystem
golang-golang-x-net-dev affected Debian:9 golang-golang-x-net-dev
Upstream advisory

DEBIAN-CVE-2020-29652

Open SourcePoC exploitHIGH2020-12-17

DEBIAN-CVE-2020-29652

Affected products

ProductStatusVendorPackageEcosystem
golang-go.crypto affected Debian:11 golang-go.crypto
golang-go.crypto affected Debian:12 golang-go.crypto
golang-go.crypto affected Debian:13 golang-go.crypto
golang-go.crypto affected Debian:14 golang-go.crypto
Upstream advisory

CVE-2020-29652

Open SourcePoC exploitHIGH2020-12-17

golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability

CVEs:CVE-2020-29652

Affected products

ProductStatusVendorPackageEcosystem
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

CVE-2020-29652

Open SourcePoC exploitHIGH2020-12-17

golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability

CVEs:CVE-2020-29652

Affected products

ProductStatusVendorPackageEcosystem
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

CVE-2020-29652

GooglePoC exploitHIGH2020-12-17

A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers.

CVEs:CVE-2020-29652

Affected products

ProductStatusVendorPackageEcosystem
ssh affected golang
Upstream advisory

AZL-6448

Open SourcePoC exploitMEDIUM2020-12-14

CVE-2020-29509 affecting package golang for versions less than 1.20.10-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-78900

Open SourcePoC exploitMEDIUM2020-12-14

CVE-2020-29509 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

CVE-2020-29509

GooglePoC exploitCRITICAL2020-12-14

The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of...

CVEs:CVE-2020-29509

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
trident affected netapp
Upstream advisory

CVE-2020-29509

GooglePoC exploitCRITICAL2020-12-14

Authentication Bypass in github.com/russellhaering/gosaml2

CVEs:CVE-2020-29509

Affected products

ProductStatusVendorPackageEcosystem
russellhaering/gosaml2 affected github.com github.com/russellhaering/gosaml2
Upstream advisory

DEBIAN-CVE-2020-29509

Open SourcePoC exploitMEDIUM2020-12-14

DEBIAN-CVE-2020-29509

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

AZL-6449

Open SourcePoC exploitMEDIUM2020-12-14

CVE-2020-29511 affecting package golang for versions less than 1.20.10-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-78896

Open SourcePoC exploitMEDIUM2020-12-14

CVE-2020-29511 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

CVE-2020-29511

GooglePoC exploitCRITICAL2020-12-14

The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of p...

CVEs:CVE-2020-29511

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
trident affected netapp
Upstream advisory

DEBIAN-CVE-2020-29511

Open SourcePoC exploitMEDIUM2020-12-14

DEBIAN-CVE-2020-29511

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

SUSE-SU-2020:3760-1

Open SourcePoC exploitHIGH2020-12-23

Security changes in Kubernetes, etcd, and helm; Bugfix in cri-o package

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected SUSE:Linux Enterprise Module for Containers 15 SP1 kubernetes
Upstream advisory

CVE-2020-0463

Open SourcePoC exploitHIGH2020-12-08

In sdp_server_handle_client_req of sdp_server.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure from the bluetooth server with no additional execution privileges needed. User inte...

CVEs:CVE-2020-0463

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-8908

GooglePoC exploitLOW2020-12-10

A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default...

CVEs:CVE-2020-8908

Affected products

ProductStatusVendorPackageEcosystem
active_iq_unified_manager affected netapp
commerce_guided_search affected oracle
communications_cloud_native_core_network_repository_function affected oracle
communications_cloud_native_core_network_slice_selection_function affected oracle
communications_pricing_design_center affected oracle
data_integrator affected oracle
guava affected google
nosql_database affected oracle
peoplesoft_enterprise_peopletools affected oracle
primavera_unifier affected oracle
quarkus affected quarkus
retail_customer_management_and_segmentation_foundation affected oracle
weblogic_server affected oracle
Upstream advisory

CVE-2020-8908

GooglePoC exploitLOW2020-12-10

Information Disclosure in Guava

CVEs:CVE-2020-8908

Affected products

ProductStatusVendorPackageEcosystem
com.google.guava:guava affected Maven com.google.guava:guava
Upstream advisory

CVE-2020-27068

Open SourcePoC exploitCRITICAL2020-12-15

Product: AndroidVersions: Android kernelAndroid ID: A-127973231References: Upstream kernel

CVEs:CVE-2020-27068

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2020-8566

Open SourcePoC exploitMEDIUM2020-12-07

DEBIAN-CVE-2020-8566

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:14 kubernetes
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
Upstream advisory

CVE-2020-8566

Open SourcePoC exploitMEDIUM2020-12-07

Sensitive Information leak via Log File in Kubernetes

CVEs:CVE-2020-8566

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

CVE-2020-8566

Open SourcePoC exploitMEDIUM2020-12-07

In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during provisioning of Ceph RBD persistent claims. This affec...

CVEs:CVE-2020-8566

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

DEBIAN-CVE-2020-8565

Open SourcePoC exploitMEDIUM2020-12-07

DEBIAN-CVE-2020-8565

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:14 kubernetes
kubernetes affected Debian:12 kubernetes
Upstream advisory

CVE-2020-8565

Open SourcePoC exploitMEDIUM2020-12-07

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1....

CVEs:CVE-2020-8565

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2020-8565

Open SourcePoC exploitMEDIUM2020-12-07

Kubernetes client-go vulnerable to Sensitive Information Leak via Log File

CVEs:CVE-2020-8565

Affected products

ProductStatusVendorPackageEcosystem
client-go affected k8s.io k8s.io/client-go
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2020-8563

Open SourcePoC exploitMEDIUM2020-12-07

In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This affects < v1.19.3.

CVEs:CVE-2020-8563

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2020-8563

Open SourcePoC exploitMEDIUM2020-12-07

Sensitive Information leak via Log File in Kubernetes

CVEs:CVE-2020-8563

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

DEBIAN-CVE-2020-8564

Open SourcePoC exploitMEDIUM2020-12-07

DEBIAN-CVE-2020-8564

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2020-8564

Open SourcePoC exploitMEDIUM2020-12-07

Kubernetes Sensitive Information leak via Log File

CVEs:CVE-2020-8564

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

CVE-2020-8564

Open SourcePoC exploitMEDIUM2020-12-07

In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19...

CVEs:CVE-2020-8564

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2020-0465

Open SourcePoC exploitHIGH2020-12-08

In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2020-0465

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0466

Open SourcePoC exploitHIGH2020-12-08

In do_epoll_ctl and ep_loop_check_proc of eventpoll.c, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2020-0466

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-147802478

GooglePoC exploitHIGH2020-12-01

ASB-A-147802478

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

ASB-A-162844689

GooglePoC exploitHIGH2020-12-01

ASB-A-162844689

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

ASB-A-150693166

GooglePoC exploitNONE2020-12-01

ASB-A-150693166

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2020-0499

Open SourceCoalition ESS < 30%HIGH2020-12-15

In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed ...

CVEs:CVE-2020-0499

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2020-29529

Open SourceCoalition ESS < 30%HIGH2020-12-03

DEBIAN-CVE-2020-29529

Affected products

ProductStatusVendorPackageEcosystem
golang-github-hashicorp-go-slug affected Debian:11 golang-github-hashicorp-go-slug
golang-github-hashicorp-go-slug affected Debian:12 golang-github-hashicorp-go-slug
Upstream advisory

CVE-2020-16041

GoogleCoalition ESS < 30%HIGH2020-12-07

Out of bounds read in networking in Google Chrome prior to 87.0.4280.88 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2020-16041

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-29510

GoogleCoalition ESS < 30%CRITICAL2020-12-14

The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of proces...

CVEs:CVE-2020-29510

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
trident affected netapp
Upstream advisory

DEBIAN-CVE-2020-29510

Open SourceCoalition ESS < 30%MEDIUM2020-12-14

DEBIAN-CVE-2020-29510

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

DEBIAN-CVE-2020-35380

Open SourceCoalition ESS < 30%HIGH2020-12-15

DEBIAN-CVE-2020-35380

Affected products

ProductStatusVendorPackageEcosystem
golang-github-tidwall-gjson affected Debian:11 golang-github-tidwall-gjson
golang-github-tidwall-gjson affected Debian:12 golang-github-tidwall-gjson
golang-github-tidwall-gjson affected Debian:13 golang-github-tidwall-gjson
golang-github-tidwall-gjson affected Debian:14 golang-github-tidwall-gjson
Upstream advisory

CVE-2020-16037

GoogleCoalition ESS < 30%CRITICAL2020-12-07

Use after free in clipboard in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-16037

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16038

GoogleCoalition ESS < 30%CRITICAL2020-12-07

Use after free in media in Google Chrome on OS X prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-16038

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16039

GoogleCoalition ESS < 30%CRITICAL2020-12-07

Use after free in extensions in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-16039

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-16042

GoogleCoalition ESS < 30%HIGH2020-12-07

Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2020-16042

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-0494

Open SourceCoalition ESS < 30%HIGH2020-12-15

In ih264d_parse_ave of ih264d_sei.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Prod...

CVEs:CVE-2020-0494

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0492

Open SourceCoalition ESS < 30%HIGH2020-12-15

In BitstreamFillCache of bitstream.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.P...

CVEs:CVE-2020-0492

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0460

Open SourceCoalition ESS < 30%HIGH2020-12-08

In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly installed certificates due to a logic error. This could lead to remote information disclosure with no additional execution privileges needed. User interacti...

CVEs:CVE-2020-0460

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0490

Open SourceCoalition ESS < 30%MEDIUM2020-12-15

In floor1_info_unpack of floor1.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Produc...

CVEs:CVE-2020-0490

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0488

Open SourceCoalition ESS < 30%MEDIUM2020-12-15

In ihevc_inter_pred_chroma_copy_ssse3 of ihevc_inter_pred_filters_ssse3_intr.c, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User ...

CVEs:CVE-2020-0488

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0491

Open SourceCoalition ESS < 30%HIGH2020-12-15

In readBlock of MatroskaExtractor.cpp, there is a possible denial of service due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: An...

CVEs:CVE-2020-0491

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0470

Open SourceCoalition ESS < 30%HIGH2020-12-08

In extend_frame_highbd of restoration.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation...

CVEs:CVE-2020-0470

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0489

Open SourceCoalition ESS < 30%HIGH2020-12-15

In Parse_data of eas_mdls.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in the media extractor with no additional execution privileges needed. User interaction is needed for exploitat...

CVEs:CVE-2020-0489

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PYSEC-2020-141

Open SourceCoalition ESS < 30%2020-12-10

PYSEC-2020-141

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-300

Open SourceCoalition ESS < 30%2020-12-10

PYSEC-2020-300

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-335

Open SourceCoalition ESS < 30%2020-12-10

PYSEC-2020-335

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-26269

Open SourceCoalition ESS < 30%CRITICAL2020-12-10

TensorFlow vulnerable to heap out of bounds read in filesystem glob matching

CVEs:CVE-2020-26269

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-26269

Open SourceCoalition ESS < 30%CRITICAL2020-12-10

PYSEC-2020-335

CVEs:CVE-2020-26269

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-26269

Open SourceCoalition ESS < 30%HIGH2020-12-10

In TensorFlow release candidate versions 2.4.0rc*, the general implementation for matching filesystem paths to globbing pattern is vulnerable to an access out of bounds of the array holding the directories. There are multiple invariants and preconditio...

CVEs:CVE-2020-26269

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2020-0455

Open SourceCoalition ESS < 30%CRITICAL2020-12-08

There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-170372514

CVEs:CVE-2020-0455

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0456

Open SourceCoalition ESS < 30%CRITICAL2020-12-08

There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-170378843

CVEs:CVE-2020-0456

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0457

Open SourceCoalition ESS < 30%CRITICAL2020-12-08

There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-170367562

CVEs:CVE-2020-0457

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-170367562

GoogleCoalition ESS < 30%CRITICAL2020-12-01

ASB-A-170367562

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-170372514

GoogleCoalition ESS < 30%CRITICAL2020-12-01

ASB-A-170372514

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-170378843

GoogleCoalition ESS < 30%CRITICAL2020-12-01

ASB-A-170378843

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2020-27055

Open SourceCoalition ESS < 30%HIGH2020-12-15

In isSubmittable and showWarningMessagesIfAppropriate of WifiConfigController.java and WifiConfigController2.java, there is a possible insecure WiFi configuration due to improper input validation. This could lead to remote information disclosure with n...

CVEs:CVE-2020-27055

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0498

Open SourceCoalition ESS < 30%HIGH2020-12-15

In decode_packed_entry_number of codebook.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitat...

CVEs:CVE-2020-0498

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-35550

Open SourceCoalition ESS < 30%CRITICAL2020-12-18

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypass Factory Reset Protection (FRP) via StatusBar. The Samsung ID is SVE-2020-17888 (December 2020).

CVEs:CVE-2020-35550

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0099

Open SourceCoalition ESS < 30%HIGH2020-12-08

In addWindow of WindowManagerService.java, there is a possible window overlay attack due to an insecure default value. This could lead to local escalation of privilege via tapjacking with no additional execution privileges needed. User interaction is n...

CVEs:CVE-2020-0099

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0478

Open SourceCoalition ESS < 30%HIGH2020-12-15

In extend_frame_lowbd of restoration.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation....

CVEs:CVE-2020-0478

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-35693

Open SourceCoalition ESS < 30%HIGH2020-12-24

On some Samsung phones and tablets running Android through 7.1.1, it is possible for an attacker-controlled Bluetooth Low Energy (BLE) device to pair silently with a vulnerable target device, without any user interaction, when the target device's Bluet...

CVEs:CVE-2020-35693

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-35553

Open SourceCoalition ESS < 30%HIGH2020-12-18

An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Qualcomm SM8250 chipsets) software. They allows attackers to cause a denial of service (unlock failure) by triggering a power-shortage incident that causes a false-positive att...

CVEs:CVE-2020-35553

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-35551

Open SourceCoalition ESS < 30%CRITICAL2020-12-18

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. They allow attackers to conduct RPMB state-change attacks because an unauthorized RPMB write operation can be replayed, a related issue to CV...

CVEs:CVE-2020-35551

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27049

Open SourceCoalition ESS < 30%HIGH2020-12-15

In rw_t3t_send_raw_frame of rw_t3t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.P...

CVEs:CVE-2020-27049

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0475

Open SourceCoalition ESS < 30%HIGH2020-12-15

In createInputConsumer of WindowManagerService.java, there is a possible way to block and intercept input events due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User in...

CVEs:CVE-2020-0475

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0480

Open SourceCoalition ESS < 30%HIGH2020-12-15

In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing a caller to copy, move, or delete files accessible to DocumentsProvider with...

CVEs:CVE-2020-0480

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0479

Open SourceCoalition ESS < 30%HIGH2020-12-15

In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a malicious app to access files available to the DocumentProvider without user permission, with no additional ...

CVEs:CVE-2020-0479

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0244

Open SourceCoalition ESS < 30%MEDIUM2020-12-15

In writeBurstBufferBytes of SPDIFEncoder.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no clear exfiltration path, with no additional execution privileges needed. User...

CVEs:CVE-2020-0244

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-8920

GoogleCoalition ESS < 30%HIGH2020-12-10

An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an ...

CVEs:CVE-2020-8920

Affected products

ProductStatusVendorPackageEcosystem
gerrit affected google
Upstream advisory

CVE-2020-8920

GoogleCoalition ESS < 30%LOW2020-12-10

Information leak in Gerrit

CVEs:CVE-2020-8920

Affected products

ProductStatusVendorPackageEcosystem
com.google.gerrit:gerrit-plugin-api affected Maven com.google.gerrit:gerrit-plugin-api
Upstream advisory

CVE-2020-35552

Open SourceCoalition ESS < 30%MEDIUM2020-12-18

An issue was discovered in the GPS daemon on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (non-Qualcomm chipsets) software. Attackers can obtain sensitive location information because the configuration file is incorrect. The Samsung ID is SV...

CVEs:CVE-2020-35552

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-8919

GoogleCoalition ESS < 30%HIGH2020-12-10

An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the default set of priviledges to read all other user's person...

CVEs:CVE-2020-8919

Affected products

ProductStatusVendorPackageEcosystem
gerrit affected google
Upstream advisory

PYSEC-2020-254

Open SourceCoalition ESS < 30%CRITICAL2020-12-10

PYSEC-2020-254

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-297

Open SourceCoalition ESS < 30%CRITICAL2020-12-10

PYSEC-2020-297

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-332

Open SourceCoalition ESS < 30%CRITICAL2020-12-10

PYSEC-2020-332

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qhxx-j73r-qpm2

Open SourceCoalition ESS < 30%CRITICAL2020-12-10

Uninitialized memory access in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qhxx-j73r-qpm2

Open SourceCoalition ESS < 30%CRITICAL2020-12-10

Uninitialized memory access in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-26266

Open SourceCoalition ESS < 30%CRITICAL2020-12-10

Uninitialized memory access in TensorFlow

CVEs:CVE-2020-26266

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-26266

Open SourceCoalition ESS < 30%CRITICAL2020-12-10

In affected versions of TensorFlow under certain cases a saved model can trigger use of uninitialized values during code execution. This is caused by having tensor buffers be filled with the default value of the type but forgetting to default initializ...

CVEs:CVE-2020-26266

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2020-26266

Open SourceCoalition ESS < 30%MEDIUM2020-12-10

PYSEC-2020-332

CVEs:CVE-2020-26266

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2020-140

Open SourceCoalition ESS < 30%HIGH2020-12-10

PYSEC-2020-140

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-298

Open SourceCoalition ESS < 30%HIGH2020-12-10

PYSEC-2020-298

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-333

Open SourceCoalition ESS < 30%HIGH2020-12-10

PYSEC-2020-333

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-c9f3-9wfr-wgh7

Open SourceCoalition ESS < 30%HIGH2020-12-10

Lack of validation in data format attributes in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-c9f3-9wfr-wgh7

Open SourceCoalition ESS < 30%HIGH2020-12-10

Lack of validation in data format attributes in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-26267

Open SourceCoalition ESS < 30%HIGH2020-12-10

In affected versions of TensorFlow the tf.raw_ops.DataFormatVecPermute API does not validate the src_format and dst_format attributes. The code assumes that these two arguments define a permutation of NHWC. This can result in uninitialized memory acces...

CVEs:CVE-2020-26267

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2020-26267

Open SourceCoalition ESS < 30%MEDIUM2020-12-10

PYSEC-2020-333

CVEs:CVE-2020-26267

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-26267

Open SourceCoalition ESS < 30%HIGH2020-12-10

Lack of validation in data format attributes in TensorFlow

CVEs:CVE-2020-26267

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2020-257

Open SourceCoalition ESS < 30%2020-12-10

PYSEC-2020-257

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-302

Open SourceCoalition ESS < 30%2020-12-10

PYSEC-2020-302

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-337

Open SourceCoalition ESS < 30%2020-12-10

PYSEC-2020-337

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-q263-fvxm-m5mw

Open SourceCoalition ESS < 30%MEDIUM2020-12-10

Heap out of bounds access in MakeEdge in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-q263-fvxm-m5mw

Open SourceCoalition ESS < 30%MEDIUM2020-12-10

Heap out of bounds access in MakeEdge in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-26271

Open SourceCoalition ESS < 30%MEDIUM2020-12-10

In affected versions of TensorFlow under certain cases, loading a saved model can result in accessing uninitialized memory while building the computation graph. The MakeEdge function creates an edge between one output tensor of the src node (given by o...

CVEs:CVE-2020-26271

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2020-26271

Open SourceCoalition ESS < 30%MEDIUM2020-12-10

PYSEC-2020-337

CVEs:CVE-2020-26271

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-26271

Open SourceCoalition ESS < 30%MEDIUM2020-12-10

Heap out of bounds access in MakeEdge in TensorFlow

CVEs:CVE-2020-26271

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2020-255

Open SourceCoalition ESS < 30%HIGH2020-12-10

PYSEC-2020-255

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-299

Open SourceCoalition ESS < 30%HIGH2020-12-10

PYSEC-2020-299

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-334

Open SourceCoalition ESS < 30%HIGH2020-12-10

PYSEC-2020-334

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hhvc-g5hv-48c6

Open SourceCoalition ESS < 30%HIGH2020-12-10

Write to immutable memory region in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hhvc-g5hv-48c6

Open SourceCoalition ESS < 30%HIGH2020-12-10

Write to immutable memory region in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-26268

Open SourceCoalition ESS < 30%HIGH2020-12-10

In affected versions of TensorFlow the tf.raw_ops.ImmutableConst operation returns a constant tensor created from a memory mapped file which is assumed immutable. However, if the type of the tensor is not an integral type, the operation crashes the Pyt...

CVEs:CVE-2020-26268

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2020-26268

Open SourceCoalition ESS < 30%HIGH2020-12-10

Write to immutable memory region in TensorFlow

CVEs:CVE-2020-26268

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-26268

Open SourceCoalition ESS < 30%MEDIUM2020-12-10

PYSEC-2020-334

CVEs:CVE-2020-26268

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

ASB-A-157906412

GoogleCoalition ESS < 30%2020-12-01

ASB-A-157906412

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2022-42544

Open SourceCoalition ESS < 30%HIGH2020-12-15

In getView of AddAppNetworksFragment.java, there is a possible way to mislead the user about network add requests due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User in...

CVEs:CVE-2022-42544

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-168051734

GoogleCoalition ESS < 30%2020-12-01

ASB-A-168051734

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2020-27023

Open SourceCoalition ESS < 30%MEDIUM2020-12-15

In setErrorPlaybackState of BluetoothMediaBrowserService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed...

CVEs:CVE-2020-27023

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0467

Open SourceCoalition ESS < 30%MEDIUM2020-12-08

In onUserStopped of Vpn.java, there is a possible resetting of user preferences due to a logic issue. This could lead to local information disclosure of secure network traffic over a non-VPN link with no additional execution privileges needed. User int...

CVEs:CVE-2020-0467

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0016

Open SourceCoalition ESS < 30%HIGH2020-12-08

In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...

CVEs:CVE-2020-0016

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0440

Open SourceCoalition ESS < 30%HIGH2020-12-08

In createVirtualDisplay of DisplayManagerService.java, there is a possible way to create a trusted virtual display due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User ...

CVEs:CVE-2020-0440

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-171413483

GoogleCoalition ESS < 30%NONE2020-12-01

ASB-A-171413483

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2020-0019

Open SourceCoalition ESS < 30%MEDIUM2020-12-08

In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local information disclosure in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersion...

CVEs:CVE-2020-0019

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-171413798

GoogleCoalition ESS < 30%MEDIUM2020-12-01

ASB-A-171413798

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PYSEC-2020-256

Open SourceCoalition ESS < 30%HIGH2020-12-10

PYSEC-2020-256

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

PYSEC-2020-301

Open SourceCoalition ESS < 30%HIGH2020-12-10

PYSEC-2020-301

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2020-336

Open SourceCoalition ESS < 30%HIGH2020-12-10

PYSEC-2020-336

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-m648-33qf-v3gp

Open SourceCoalition ESS < 30%HIGH2020-12-10

CHECK-fail in LSTM with zero-length input in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-m648-33qf-v3gp

Open SourceCoalition ESS < 30%HIGH2020-12-10

CHECK-fail in LSTM with zero-length input in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-26270

Open SourceCoalition ESS < 30%HIGH2020-12-10

CHECK-fail in LSTM with zero-length input in TensorFlow

CVEs:CVE-2020-26270

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-26270

Open SourceCoalition ESS < 30%HIGH2020-12-10

In affected versions of TensorFlow running an LSTM/GRU model where the LSTM/GRU layer receives an input with zero-length results in a CHECK failure when using the CUDA backend. This can result in a query-of-death vulnerability, via denial of service, i...

CVEs:CVE-2020-26270

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2020-26270

Open SourceCoalition ESS < 30%MEDIUM2020-12-10

PYSEC-2020-336

CVEs:CVE-2020-26270

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2020-0464

Open SourceCoalition ESS < 30%HIGH2020-12-08

In resolv_cache_lookup of res_cache.cpp, there is a possible side channel information disclosure. This could lead to local information disclosure of accessed web resources with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2020-0464

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27066

Open SourceCoalition ESS < 30%HIGH2020-12-15

In xfrm6_tunnel_free_spi of net/ipv6/xfrm6_tunnel.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2020-27066

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27046

Open SourceCoalition ESS < 30%MEDIUM2020-12-15

In nfc_ncif_proc_ee_action of nfc_ncif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Pr...

CVEs:CVE-2020-27046

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-8944

GoogleCoalition ESS < 30%MEDIUM2020-12-15

An arbitrary memory write vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to ecall_restore using the attribute output which fails to check the range of a pointer. An attacker can use this pointer to write to arbi...

CVEs:CVE-2020-8944

Affected products

ProductStatusVendorPackageEcosystem
asylo affected google
Upstream advisory

CVE-2020-0500

Open SourceCoalition ESS < 30%MEDIUM2020-12-15

In startInputUncheckedLocked of InputMethodManager.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2020-0500

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0459

Open SourceCoalition ESS < 30%HIGH2020-12-08

In sendConfiguredNetworkChangedBroadcast of WifiConfigManager.java, there is a possible leak of sensitive WiFi configuration data due to a missing permission check. This could lead to local information disclosure of WiFi network names with no additiona...

CVEs:CVE-2020-0459

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27037

Open SourceCoalition ESS < 30%MEDIUM2020-12-15

In phNxpNciHal_core_initialized of phNxpNciHal.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interaction is not ...

CVEs:CVE-2020-27037

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0368

Open SourceCoalition ESS < 30%MEDIUM2020-12-15

In queryInternal of CallLogProvider.java, there is a possible permission bypass due to improper input validation. This could lead to local information disclosure of voicemail metadata with User execution privileges needed. User interaction is not neede...

CVEs:CVE-2020-0368

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27033

Open SourceCoalition ESS < 30%MEDIUM2020-12-15

In nfc_ncif_proc_get_routing of nfc_ncif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2020-27033

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27031

Open SourceCoalition ESS < 30%MEDIUM2020-12-15

In nfc_data_event of nfc_ncif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: An...

CVEs:CVE-2020-27031

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0476

Open SourceCoalition ESS < 30%MEDIUM2020-12-15

In onNotificationRemoved of Assistant.java, there is a possible leak of sensitive information to logs. This could lead to local information disclosure with System execution privileges required. User interaction is not needed for exploitation.Product: A...

CVEs:CVE-2020-0476

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0473

Open SourceCoalition ESS < 30%MEDIUM2020-12-15

In updateIncomingFileConfirmNotification of BluetoothOppNotification.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing an attacker with physical possession of the device to transfer files to it over...

CVEs:CVE-2020-0473

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27036

Open SourceCoalition ESS < 30%HIGH2020-12-15

In phNxpNciHal_send_ext_cmd of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC server with System execution privileges needed. User interaction is no...

CVEs:CVE-2020-27036

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0468

Open SourceCoalition ESS < 30%MEDIUM2020-12-08

In listen() and related functions of TelephonyRegistry.java, there is a possible permissions bypass of location permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges neede...

CVEs:CVE-2020-0468

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27034

Open SourceCoalition ESS < 30%MEDIUM2020-12-15

In createSimSelectNotification of SimSelectNotification.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2020-27034

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27044

Open SourceCoalition ESS < 30%HIGH2020-12-15

In restartWrite of Parcel.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andr...

CVEs:CVE-2020-27044

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27027

Open SourceCoalition ESS < 30%MEDIUM2020-12-15

In nfc_ncif_proc_get_routing of nfc_ncif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2020-27027

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0483

Open SourceCoalition ESS < 30%HIGH2020-12-15

In DrmManagerService::~DrmManagerService() of DrmManagerService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed...

CVEs:CVE-2020-0483

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-35549

Open SourceCoalition ESS < 30%MEDIUM2020-12-18

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Any application may establish itself as the default dialer, without user interaction. The Samsung ID is SVE-2020-19172 (December 2020).

CVEs:CVE-2020-35549

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27054

Open SourceCoalition ESS < 30%HIGH2020-12-15

In onFactoryReset of BluetoothManagerService.java, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVer...

CVEs:CVE-2020-27054

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27067

Open SourceCoalition ESS < 30%HIGH2020-12-15

In the l2tp subsystem, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andro...

CVEs:CVE-2020-27067

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-8935

GoogleCoalition ESS < 30%HIGH2020-12-15

An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allow an attacker to make an Ecall_restore function call to reallocate untrusted code and overwrite sections of the Enclave memory address. We recommend updating your library.

CVEs:CVE-2020-8935

Affected products

ProductStatusVendorPackageEcosystem
asylo affected google
Upstream advisory

CVE-2020-35548

Open SourceCoalition ESS < 30%HIGH2020-12-18

An issue was discovered in Finder on Samsung mobile devices with Q(10.0) software. A call to a non-existent provider allows attackers to cause a denial of service. The Samsung ID is SVE-2020-18629 (December 2020).

CVEs:CVE-2020-35548

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27041

Open SourceCoalition ESS < 30%MEDIUM2020-12-15

In showProvisioningNotification of ConnectivityService.java, there is an unsafe PendingIntent. This could lead to local information disclosure of notification data with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2020-27041

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0495

Open SourceCoalition ESS < 30%HIGH2020-12-15

In decode_Huffman of JBig2_SddProc.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2020-0495

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0493

Open SourceCoalition ESS < 30%MEDIUM2020-12-15

In CPDF_SampledFunc::v_Call of cpdf_sampledfunc.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed...

CVEs:CVE-2020-0493

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0486

Open SourceCoalition ESS < 30%HIGH2020-12-15

In openAssetFileListener of ContactsProvider2.java, there is a possible permission bypass due to an insecure default value. This could lead to local escalation of privilege to change contact data with no additional execution privileges needed. User int...

CVEs:CVE-2020-0486

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27032

Open SourceCoalition ESS < 30%MEDIUM2020-12-15

In getRadioAccessFamily of PhoneInterfaceManager.java, there is a possible read of privileged data due to a missing permission check. This could lead to local information disclosure of radio data with no additional execution privileges needed. User int...

CVEs:CVE-2020-27032

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-8941

GoogleCoalition ESS < 30%MEDIUM2020-12-15

An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_inet_pton using an attacker controlled klinux_addr_buffer parameter. The parameter size is unchecked allowing the attacker...

CVEs:CVE-2020-8941

Affected products

ProductStatusVendorPackageEcosystem
asylo affected google
Upstream advisory

CVE-2020-0496

Open SourceCoalition ESS < 30%HIGH2020-12-15

In CPDF_RenderStatus::LoadSMask of cpdf_renderstatus.cpp, there is a possible memory corruption due to a use-after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2020-0496

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-35554

Open SourceCoalition ESS < 30%HIGH2020-12-18

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. There is a WebView SSL error-handler vulnerability. The LG ID is LVE-SMP-200026 (December 2020).

CVEs:CVE-2020-35554

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-35555

Open SourceCoalition ESS < 30%HIGH2020-12-18

An issue was discovered on LG mobile devices with Android OS 10 software. When a dual-screen configuration is supported, the device does not lock upon disconnection of a call with the cover closed. The LG ID is LVE-SMP-200027 (December 2020).

CVEs:CVE-2020-35555

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-8936

GoogleCoalition ESS < 30%MEDIUM2020-12-15

An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allows an attacker to make a host call to UntrustedCall. UntrustedCall failed to validate the buffer range within sgx_params and allowed the host to return a pointer that was an ...

CVEs:CVE-2020-8936

Affected products

ProductStatusVendorPackageEcosystem
asylo affected google
Upstream advisory

CVE-2020-8939

GoogleCoalition ESS < 30%MEDIUM2020-12-15

An out of bounds read on the enc_untrusted_inet_ntop function allows an attack to extend the result size that is used by memcpy() to read memory from within the enclave heap. We recommend upgrading past commit 6ff3b77ffe110a33a2f93848a6333f33616f02c4

CVEs:CVE-2020-8939

Affected products

ProductStatusVendorPackageEcosystem
asylo affected google
Upstream advisory

CVE-2020-8940

GoogleCoalition ESS < 30%MEDIUM2020-12-15

An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_recvmsg using an attacker controlled result parameter. The parameter size is unchecked allowing the attacker to read memor...

CVEs:CVE-2020-8940

Affected products

ProductStatusVendorPackageEcosystem
asylo affected google
Upstream advisory

CVE-2020-8942

GoogleCoalition ESS < 30%MEDIUM2020-12-15

An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_read whose return size was not validated against the requrested size. The parameter size is unchecked allowing the attacke...

CVEs:CVE-2020-8942

Affected products

ProductStatusVendorPackageEcosystem
asylo affected google
Upstream advisory

CVE-2020-0481

Open SourceCoalition ESS < 30%LOW2020-12-15

In AndroidManifest.xml, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a non-system app to send a broadcast it shouldn't have permissions to send, with no additional execution privileges needed. User i...

CVEs:CVE-2020-0481

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-8943

GoogleCoalition ESS < 30%MEDIUM2020-12-15

An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_recvfrom whose return size was not validated against the requested size. The parameter size is unchecked allowing the atta...

CVEs:CVE-2020-8943

Affected products

ProductStatusVendorPackageEcosystem
asylo affected google
Upstream advisory

CVE-2022-42543

Open SourceCoalition ESS < 30%MEDIUM2020-12-15

In fdt_path_offset_namelen of fdt_ro.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Pr...

CVEs:CVE-2022-42543

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-8937

GoogleCoalition ESS < 30%MEDIUM2020-12-15

An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allows an attacker to make a host call to enc_untrusted_create_wait_queue that uses a pointer queue that relies on UntrustedLocalMemcpy, which fails to validate where the pointer...

CVEs:CVE-2020-8937

Affected products

ProductStatusVendorPackageEcosystem
asylo affected google
Upstream advisory

CVE-2020-8938

GoogleCoalition ESS < 30%MEDIUM2020-12-15

An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allows an attacker to make a host call to FromkLinuxSockAddr with attacker controlled content and size of klinux_addr which allows an attacker to write memory values from within ...

CVEs:CVE-2020-8938

Affected products

ProductStatusVendorPackageEcosystem
asylo affected google
Upstream advisory

CVE-2020-0474

Open SourceCoalition ESS < 30%HIGH2020-12-15

In HalCamera::requestNewFrame of HalCamera.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation...

CVEs:CVE-2020-0474

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MGASA-2020-0455

Open SourceAll remaining2020-12-09

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:7 chromium-browser-stable
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.