Google Security Advisories · January 2021 — Google Security Advisories
264 advisories 170 CVEs 18 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2021-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 18 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

DSA-4824-1

Open SourceExploitedCISA KEV listed2021-01-01

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:10 chromium
Upstream advisory

CVE-2021-1647

GoogleExploitedCISA KEV listedCRITICAL2021-01-12

Microsoft Defender Remote Code Execution Vulnerability

CVEs:CVE-2021-1647

Affected products

ProductStatusVendorPackageEcosystem
security_essentials affected microsoft
system_center_endpoint_protection affected microsoft
windows_defender affected microsoft
Upstream advisory

CVE-2020-6572

GoogleExploitedCISA KEV listedCRITICAL2021-01-14

Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

CVEs:CVE-2020-6572

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6572

Open SourceExploitedCISA KEV listedCRITICAL2021-01-14

DEBIAN-CVE-2020-6572

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6572

Project ZeroExploitedCISA KEV listed2021-01-14

Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

CVEs:CVE-2020-6572

Upstream advisory

DEBIAN-CVE-2020-16013

Open SourceExploitedCISA KEV listedHIGH2021-01-08

DEBIAN-CVE-2020-16013

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16017

Open SourceExploitedCISA KEV listedCRITICAL2021-01-08

DEBIAN-CVE-2020-16017

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-1782

Project ZeroExploitedCISA KEV listed2021-01-27

A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited..

CVEs:CVE-2021-1782

Upstream advisory

CVE-2021-1782

GoogleExploitedCISA KEV listedHIGH2021-01-27

A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able t...

CVEs:CVE-2021-1782

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-11261

Project ZeroExploitedCISA KEV listed2021-01-04

Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVEs:CVE-2020-11261

Upstream advisory

CVE-2020-11261

GoogleExploitedCISA KEV listedCRITICAL2021-01-04

Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobi...

CVEs:CVE-2020-11261

Affected products

ProductStatusVendorPackageEcosystem
apq8009_firmware affected qualcomm
apq8009w_firmware affected qualcomm
apq8017_firmware affected qualcomm
apq8037_firmware affected qualcomm
apq8053_firmware affected qualcomm
apq8064au_firmware affected qualcomm
apq8096au_firmware affected qualcomm
aqt1000_firmware affected qualcomm
ar8031_firmware affected qualcomm
ar8035_firmware affected qualcomm
ar8151_firmware affected qualcomm
csra6620_firmware affected qualcomm
csra6640_firmware affected qualcomm
csrb31024_firmware affected qualcomm
fsm10055_firmware affected qualcomm
fsm10056_firmware affected qualcomm
mdm9650_firmware affected qualcomm
msm8909w_firmware affected qualcomm
msm8917_firmware affected qualcomm
msm8920_firmware affected qualcomm
msm8937_firmware affected qualcomm
msm8940_firmware affected qualcomm
msm8953_firmware affected qualcomm
msm8996au_firmware affected qualcomm
pm215_firmware affected qualcomm
pm3003a_firmware affected qualcomm
pm4125_firmware affected qualcomm
pm439_firmware affected qualcomm
pm456_firmware affected qualcomm
pm6125_firmware affected qualcomm
pm6150a_firmware affected qualcomm
pm6150_firmware affected qualcomm
pm6150l_firmware affected qualcomm
pm6250_firmware affected qualcomm
pm6350_firmware affected qualcomm
pm640a_firmware affected qualcomm
pm640l_firmware affected qualcomm
pm640p_firmware affected qualcomm
pm660a_firmware affected qualcomm
pm660_firmware affected qualcomm
pm660l_firmware affected qualcomm
pm670a_firmware affected qualcomm
pm670_firmware affected qualcomm
pm670l_firmware affected qualcomm
pm7150a_firmware affected qualcomm
pm7150l_firmware affected qualcomm
pm7250b_firmware affected qualcomm
pm7250_firmware affected qualcomm
pm7350c_firmware affected qualcomm
pm8004_firmware affected qualcomm
pm8005_firmware affected qualcomm
pm8008_firmware affected qualcomm
pm8009_firmware affected qualcomm
pm8150a_firmware affected qualcomm
pm8150b_firmware affected qualcomm
pm8150c_firmware affected qualcomm
pm8150_firmware affected qualcomm
pm8150l_firmware affected qualcomm
pm8250_firmware affected qualcomm
pm8350b_firmware affected qualcomm
pm8350bh_firmware affected qualcomm
pm8350bhs_firmware affected qualcomm
pm8350c_firmware affected qualcomm
pm8350_firmware affected qualcomm
pm855a_firmware affected qualcomm
pm855b_firmware affected qualcomm
pm855_firmware affected qualcomm
pm855l_firmware affected qualcomm
pm855p_firmware affected qualcomm
pm8909_firmware affected qualcomm
pm8916_firmware affected qualcomm
pm8937_firmware affected qualcomm
pm8940_firmware affected qualcomm
pm8953_firmware affected qualcomm
pm8996_firmware affected qualcomm
pm8998_firmware affected qualcomm
pmc1000h_firmware affected qualcomm
pmd9655_firmware affected qualcomm
pme605_firmware affected qualcomm
pmi632_firmware affected qualcomm
pmi8937_firmware affected qualcomm
pmi8952_firmware affected qualcomm
pmi8994_firmware affected qualcomm
pmi8996_firmware affected qualcomm
pmi8998_firmware affected qualcomm
pmk7350_firmware affected qualcomm
pmk8001_firmware affected qualcomm
pmk8002_firmware affected qualcomm
pmk8003_firmware affected qualcomm
pmk8350_firmware affected qualcomm
pmm6155au_firmware affected qualcomm
pmm8155au_firmware affected qualcomm
pmm855au_firmware affected qualcomm
pmm8996au_firmware affected qualcomm
pmr525_firmware affected qualcomm
pmr735a_firmware affected qualcomm
pmr735b_firmware affected qualcomm
pmw3100_firmware affected qualcomm
pmx20_firmware affected qualcomm
pmx24_firmware affected qualcomm
pmx50_firmware affected qualcomm
pmx55_firmware affected qualcomm
qat3514_firmware affected qualcomm
qat3516_firmware affected qualcomm
qat3518_firmware affected qualcomm
qat3519_firmware affected qualcomm
qat3522_firmware affected qualcomm
qat3550_firmware affected qualcomm
qat3555_firmware affected qualcomm
qat5515_firmware affected qualcomm
qat5516_firmware affected qualcomm
qat5522_firmware affected qualcomm
qat5533_firmware affected qualcomm
qat5568_firmware affected qualcomm
qbt1000_firmware affected qualcomm
qbt1500_firmware affected qualcomm
qbt2000_firmware affected qualcomm
qca4020_firmware affected qualcomm
qca6174a_firmware affected qualcomm
qca6310_firmware affected qualcomm
qca6320_firmware affected qualcomm
qca6335_firmware affected qualcomm
qca6390_firmware affected qualcomm
qca6391_firmware affected qualcomm
qca6420_firmware affected qualcomm
qca6421_firmware affected qualcomm
qca6426_firmware affected qualcomm
qca6430_firmware affected qualcomm
qca6431_firmware affected qualcomm
qca6436_firmware affected qualcomm
qca6564a_firmware affected qualcomm
qca6564au_firmware affected qualcomm
qca6564_firmware affected qualcomm
qca6574a_firmware affected qualcomm
qca6574au_firmware affected qualcomm
qca6574_firmware affected qualcomm
qca6584au_firmware affected qualcomm
qca6595au_firmware affected qualcomm
qca6696_firmware affected qualcomm
qca8337_firmware affected qualcomm
qca9377_firmware affected qualcomm
qca9379_firmware affected qualcomm
qcc1110_firmware affected qualcomm
qcm2290_firmware affected qualcomm
qcm4290_firmware affected qualcomm
qcm6125_firmware affected qualcomm
qcs2290_firmware affected qualcomm
qcs405_firmware affected qualcomm
qcs410_firmware affected qualcomm
qcs4290_firmware affected qualcomm
qcs603_firmware affected qualcomm
qcs605_firmware affected qualcomm
qcs610_firmware affected qualcomm
qcs6125_firmware affected qualcomm
qdm2301_firmware affected qualcomm
qdm2302_firmware affected qualcomm
qdm2305_firmware affected qualcomm
qdm2307_firmware affected qualcomm
qdm2308_firmware affected qualcomm
qdm2310_firmware affected qualcomm
qdm3301_firmware affected qualcomm
qdm3302_firmware affected qualcomm
qdm4643_firmware affected qualcomm
qdm4650_firmware affected qualcomm
qdm5579_firmware affected qualcomm
qdm5620_firmware affected qualcomm
qdm5621_firmware affected qualcomm
qdm5650_firmware affected qualcomm
qdm5652_firmware affected qualcomm
qdm5670_firmware affected qualcomm
qdm5671_firmware affected qualcomm
qdm5677_firmware affected qualcomm
qdm5679_firmware affected qualcomm
qet4100_firmware affected qualcomm
qet4101_firmware affected qualcomm
qet5100_firmware affected qualcomm
qet5100m_firmware affected qualcomm
qet6100_firmware affected qualcomm
qet6110_firmware affected qualcomm
qfe2101_firmware affected qualcomm
qfe2520_firmware affected qualcomm
qfe2550_firmware affected qualcomm
qfe3340_firmware affected qualcomm
qfe4301_firmware affected qualcomm
qfe4302_firmware affected qualcomm
qfe4303_firmware affected qualcomm
qfe4305_firmware affected qualcomm
qfe4308_firmware affected qualcomm
qfe4309_firmware affected qualcomm
qfe4320_firmware affected qualcomm
qfe4373fc_firmware affected qualcomm
qfs2530_firmware affected qualcomm
qfs2580_firmware affected qualcomm
qfs2608_firmware affected qualcomm
qfs2630_firmware affected qualcomm
qln1020_firmware affected qualcomm
qln1021aq_firmware affected qualcomm
qln1030_firmware affected qualcomm
qln1031_firmware affected qualcomm
qln1036aq_firmware affected qualcomm
qln4640_firmware affected qualcomm
qln4642_firmware affected qualcomm
qln4650_firmware affected qualcomm
qln5020_firmware affected qualcomm
qln5030_firmware affected qualcomm
qln5040_firmware affected qualcomm
qpa2625_firmware affected qualcomm
qpa4340_firmware affected qualcomm
qpa4360_firmware affected qualcomm
qpa4361_firmware affected qualcomm
qpa5373_firmware affected qualcomm
qpa5460_firmware affected qualcomm
qpa5461_firmware affected qualcomm
qpa5580_firmware affected qualcomm
qpa5581_firmware affected qualcomm
qpa6560_firmware affected qualcomm
qpa8673_firmware affected qualcomm
qpa8675_firmware affected qualcomm
qpa8686_firmware affected qualcomm
qpa8801_firmware affected qualcomm
qpa8802_firmware affected qualcomm
qpa8803_firmware affected qualcomm
qpa8821_firmware affected qualcomm
qpa8842_firmware affected qualcomm
qpm2630_firmware affected qualcomm
qpm4621_firmware affected qualcomm
qpm4630_firmware affected qualcomm
qpm4640_firmware affected qualcomm
qpm4641_firmware affected qualcomm
qpm4650_firmware affected qualcomm
qpm5541_firmware affected qualcomm
qpm5577_firmware affected qualcomm
qpm5579_firmware affected qualcomm
qpm5620_firmware affected qualcomm
qpm5621_firmware affected qualcomm
qpm5641_firmware affected qualcomm
qpm5657_firmware affected qualcomm
qpm5658_firmware affected qualcomm
qpm5670_firmware affected qualcomm
qpm5677_firmware affected qualcomm
qpm5679_firmware affected qualcomm
qpm5870_firmware affected qualcomm
qpm5875_firmware affected qualcomm
qpm6325_firmware affected qualcomm
qpm6375_firmware affected qualcomm
qpm6582_firmware affected qualcomm
qpm6585_firmware affected qualcomm
qpm6621_firmware affected qualcomm
qpm6670_firmware affected qualcomm
qpm8820_firmware affected qualcomm
qpm8830_firmware affected qualcomm
qpm8870_firmware affected qualcomm
qpm8895_firmware affected qualcomm
qsm7250_firmware affected qualcomm
qsm8250_firmware affected qualcomm
qsw6310_firmware affected qualcomm
qsw8573_firmware affected qualcomm
qsw8574_firmware affected qualcomm
qtc410s_firmware affected qualcomm
qtc800h_firmware affected qualcomm
qtc800s_firmware affected qualcomm
qtc800t_firmware affected qualcomm
qtc801s_firmware affected qualcomm
qtm525_firmware affected qualcomm
qtm527_firmware affected qualcomm
qualcomm215_firmware affected qualcomm
rgr7640au_firmware affected qualcomm
rsw8577_firmware affected qualcomm
sa415m_firmware affected qualcomm
sa515m_firmware affected qualcomm
sa6145p_firmware affected qualcomm
sa6155_firmware affected qualcomm
sa6155p_firmware affected qualcomm
sa8155_firmware affected qualcomm
sa8155p_firmware affected qualcomm
sd205_firmware affected qualcomm
sd210_firmware affected qualcomm
sd429_firmware affected qualcomm
sd439_firmware affected qualcomm
sd450_firmware affected qualcomm
sd_455_firmware affected qualcomm
sd460_firmware affected qualcomm
sd632_firmware affected qualcomm
sd_636_firmware affected qualcomm
sd660_firmware affected qualcomm
sd662_firmware affected qualcomm
sd665_firmware affected qualcomm
sd670_firmware affected qualcomm
sd_675_firmware affected qualcomm
sd675_firmware affected qualcomm
sd690_5g_firmware affected qualcomm
sd710_firmware affected qualcomm
sd720g_firmware affected qualcomm
sd730_firmware affected qualcomm
sd750g_firmware affected qualcomm
sd765_firmware affected qualcomm
sd765g_firmware affected qualcomm
sd768g_firmware affected qualcomm
sd820_firmware affected qualcomm
sd821_firmware affected qualcomm
sd835_firmware affected qualcomm
sd845_firmware affected qualcomm
sd855_firmware affected qualcomm
sd865_5g_firmware affected qualcomm
sd888_5g_firmware affected qualcomm
sd_8c_firmware affected qualcomm
sd_8cx_firmware affected qualcomm
sda429w_firmware affected qualcomm
sdm429w_firmware affected qualcomm
sdm630_firmware affected qualcomm
sdm830_firmware affected qualcomm
sdr051_firmware affected qualcomm
sdr052_firmware affected qualcomm
sdr425_firmware affected qualcomm
sdr660_firmware affected qualcomm
sdr660g_firmware affected qualcomm
sdr675_firmware affected qualcomm
sdr735_firmware affected qualcomm
sdr735g_firmware affected qualcomm
sdr8150_firmware affected qualcomm
sdr8250_firmware affected qualcomm
sdr845_firmware affected qualcomm
sdr865_firmware affected qualcomm
sdw2500_firmware affected qualcomm
sdw3100_firmware affected qualcomm
sdx20_firmware affected qualcomm
sdx20m_firmware affected qualcomm
sdx24_firmware affected qualcomm
sdx50m_firmware affected qualcomm
sdx55_firmware affected qualcomm
sdx55m_firmware affected qualcomm
sdxr1_firmware affected qualcomm
sdxr2_5g_firmware affected qualcomm
sm4125_firmware affected qualcomm
sm4350_firmware affected qualcomm
sm6250_firmware affected qualcomm
sm6250p_firmware affected qualcomm
sm7250p_firmware affected qualcomm
sm7350_firmware affected qualcomm
smb1350_firmware affected qualcomm
smb1351_firmware affected qualcomm
smb1354_firmware affected qualcomm
smb1355_firmware affected qualcomm
smb1357_firmware affected qualcomm
smb1358_firmware affected qualcomm
smb1360_firmware affected qualcomm
smb1380_firmware affected qualcomm
smb1381_firmware affected qualcomm
smb1390_firmware affected qualcomm
smb1394_firmware affected qualcomm
smb1395_firmware affected qualcomm
smb1396_firmware affected qualcomm
smb1398_firmware affected qualcomm
smb231_firmware affected qualcomm
smb2351_firmware affected qualcomm
smr525_firmware affected qualcomm
smr526_firmware affected qualcomm
wcd9326_firmware affected qualcomm
wcd9335_firmware affected qualcomm
wcd9340_firmware affected qualcomm
wcd9341_firmware affected qualcomm
wcd9370_firmware affected qualcomm
wcd9371_firmware affected qualcomm
wcd9375_firmware affected qualcomm
wcd9380_firmware affected qualcomm
wcd9385_firmware affected qualcomm
wcn3610_firmware affected qualcomm
wcn3615_firmware affected qualcomm
wcn3620_firmware affected qualcomm
wcn3660b_firmware affected qualcomm
wcn3660_firmware affected qualcomm
wcn3680b_firmware affected qualcomm
wcn3680_firmware affected qualcomm
wcn3910_firmware affected qualcomm
wcn3950_firmware affected qualcomm
wcn3980_firmware affected qualcomm
wcn3988_firmware affected qualcomm
wcn3990_firmware affected qualcomm
wcn3991_firmware affected qualcomm
wcn3998_firmware affected qualcomm
wcn3999_firmware affected qualcomm
wcn6740_firmware affected qualcomm
wcn6750_firmware affected qualcomm
wcn6850_firmware affected qualcomm
wcn6851_firmware affected qualcomm
wcn6856_firmware affected qualcomm
wgr7640_firmware affected qualcomm
wsa8810_firmware affected qualcomm
wsa8815_firmware affected qualcomm
wsa8830_firmware affected qualcomm
wsa8835_firmware affected qualcomm
wtr2955_firmware affected qualcomm
wtr2965_firmware affected qualcomm
wtr3905_firmware affected qualcomm
wtr3925_firmware affected qualcomm
wtr3950_firmware affected qualcomm
wtr4905_firmware affected qualcomm
wtr5975_firmware affected qualcomm
wtr6955_firmware affected qualcomm
Upstream advisory

ASB-A-161373974

GoogleExploitedCISA KEV listed2021-01-01

ASB-A-161373974

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

DEBIAN-CVE-2020-16040

Open SourceExploitedVulnCheck KEV listedMEDIUM2021-01-08

DEBIAN-CVE-2020-16040

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-0311

Open SourceActive exploitation (sightings)HIGH2021-01-04

In ElementaryStreamQueue::dequeueAccessUnitH264() of ESQueue.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction i...

CVEs:CVE-2021-0311

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-20191

GoogleActive exploitation (sightings)MEDIUM2021-01-17

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The hi...

CVEs:CVE-2021-20191

Affected products

ProductStatusVendorPackageEcosystem
ansible affected redhat
ansible_tower affected redhat
cisco_nx-os_collection affected redhat
community_general_collection affected redhat
community_network_collection affected redhat
docker_community_collection affected redhat
google_cloud_platform_ansible_collection affected redhat
virtualization affected oracle
Upstream advisory

CVE-2021-20191

GoogleActive exploitation (sightings)HIGH2021-01-17

Insertion of Sensitive Information into Log File in ansible

CVEs:CVE-2021-20191

Affected products

ProductStatusVendorPackageEcosystem
ansible affected PyPI ansible
Upstream advisory

openSUSE-SU-2021:0186-1

Open SourcePoC exploitCRITICAL2021-01-28

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP2 chromium
Upstream advisory

openSUSE-SU-2021:0177-1

Open SourcePoC exploitCRITICAL2021-01-27

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2021:0173-1

Open SourcePoC exploitCRITICAL2021-01-27

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

openSUSE-SU-2021:0166-1

Open SourcePoC exploitCRITICAL2021-01-26

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

CVE-2021-21132

Open SourcePoC exploitCRITICAL2021-01-20

Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.

CVEs:CVE-2021-21132

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

CVE-2021-21135

Open SourcePoC exploitMEDIUM2021-01-20

Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2021-21135

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

CVE-2021-21118

Open SourcePoC exploitHIGH2021-01-20

Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVEs:CVE-2021-21118

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

CVE-2021-21123

Open SourcePoC exploitMEDIUM2021-01-20

Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

CVEs:CVE-2021-21123

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

AZL-31696

Open SourcePoC exploitHIGH2021-01-21

CVE-2020-8554 affecting package python-kubernetes for versions less than 21.7.0-1

Affected products

ProductStatusVendorPackageEcosystem
python-kubernetes affected Azure Linux:2 python-kubernetes
Upstream advisory

AZL-31731

Open SourcePoC exploitHIGH2021-01-21

CVE-2020-8554 affecting package kubernetes for versions less than 1.28.3-1

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Azure Linux:2 kubernetes
Upstream advisory

AZL-34893

Open SourcePoC exploitHIGH2021-01-21

CVE-2020-8554 affecting package kubernetes for versions less than 1.28.3-2

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Azure Linux:3 kubernetes
Upstream advisory

AZL-35135

Open SourcePoC exploitHIGH2021-01-21

CVE-2020-8554 affecting package python-kubernetes for versions less than 21.7.0-1

Affected products

ProductStatusVendorPackageEcosystem
python-kubernetes affected Azure Linux:3 python-kubernetes
Upstream advisory

DEBIAN-CVE-2020-8554

Open SourcePoC exploitHIGH2021-01-21

DEBIAN-CVE-2020-8554

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:14 kubernetes
kubernetes affected Debian:13 kubernetes
Upstream advisory

CVE-2020-8554

Open SourcePoC exploitMEDIUM2021-01-21

Unverified Ownership in Kubernetes

CVEs:CVE-2020-8554

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2020-8554

Open SourcePoC exploitHIGH2021-01-21

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considere...

CVEs:CVE-2020-8554

Affected products

ProductStatusVendorPackageEcosystem
communications_cloud_native_core_network_slice_selection_function affected oracle
communications_cloud_native_core_policy affected oracle
communications_cloud_native_core_service_communication_proxy affected oracle
kubernetes affected k8s.io
kubernetes affected kubernetes
Kubernetes affected Kubernetes
kubernetes/pkg/kubelet/server affected k8s.io
Upstream advisory

RHSA-2021:0079

Open SourcePoC exploitMEDIUM2021-01-20

Red Hat Security Advisory: OpenShift Container Platform 3.11.374 bug fix and security update

Affected products

ProductStatusVendorPackageEcosystem
atomic-enterprise-service-catalog affected Red Hat:openshift:3.11::el7 atomic-enterprise-service-catalog
atomic-enterprise-service-catalog-svcat affected Red Hat:openshift:3.11::el7 atomic-enterprise-service-catalog-svcat
atomic-openshift affected Red Hat:openshift:3.11::el7 atomic-openshift
atomic-openshift-clients affected Red Hat:openshift:3.11::el7 atomic-openshift-clients
atomic-openshift-clients-redistributable affected Red Hat:openshift:3.11::el7 atomic-openshift-clients-redistributable
atomic-openshift-cluster-autoscaler affected Red Hat:openshift:3.11::el7 atomic-openshift-cluster-autoscaler
atomic-openshift-descheduler affected Red Hat:openshift:3.11::el7 atomic-openshift-descheduler
atomic-openshift-docker-excluder affected Red Hat:openshift:3.11::el7 atomic-openshift-docker-excluder
atomic-openshift-dockerregistry affected Red Hat:openshift:3.11::el7 atomic-openshift-dockerregistry
atomic-openshift-excluder affected Red Hat:openshift:3.11::el7 atomic-openshift-excluder
atomic-openshift-hyperkube affected Red Hat:openshift:3.11::el7 atomic-openshift-hyperkube
atomic-openshift-hypershift affected Red Hat:openshift:3.11::el7 atomic-openshift-hypershift
atomic-openshift-master affected Red Hat:openshift:3.11::el7 atomic-openshift-master
atomic-openshift-metrics-server affected Red Hat:openshift:3.11::el7 atomic-openshift-metrics-server
atomic-openshift-node affected Red Hat:openshift:3.11::el7 atomic-openshift-node
atomic-openshift-node-problem-detector affected Red Hat:openshift:3.11::el7 atomic-openshift-node-problem-detector
atomic-openshift-pod affected Red Hat:openshift:3.11::el7 atomic-openshift-pod
atomic-openshift-sdn-ovs affected Red Hat:openshift:3.11::el7 atomic-openshift-sdn-ovs
atomic-openshift-service-idler affected Red Hat:openshift:3.11::el7 atomic-openshift-service-idler
atomic-openshift-template-service-broker affected Red Hat:openshift:3.11::el7 atomic-openshift-template-service-broker
atomic-openshift-tests affected Red Hat:openshift:3.11::el7 atomic-openshift-tests
atomic-openshift-web-console affected Red Hat:openshift:3.11::el7 atomic-openshift-web-console
golang-github-openshift-oauth-proxy affected Red Hat:openshift:3.11::el7 golang-github-openshift-oauth-proxy
golang-github-prometheus-alertmanager affected Red Hat:openshift:3.11::el7 golang-github-prometheus-alertmanager
golang-github-prometheus-node_exporter affected Red Hat:openshift:3.11::el7 golang-github-prometheus-node_exporter
golang-github-prometheus-prometheus affected Red Hat:openshift:3.11::el7 golang-github-prometheus-prometheus
openshift-enterprise-autoheal affected Red Hat:openshift:3.11::el7 openshift-enterprise-autoheal
openshift-enterprise-autoheal-0:3.11.374-1.git.218.9cf7939.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11 affected Red Hat
openshift-enterprise-cluster-capacity affected Red Hat:openshift:3.11::el7 openshift-enterprise-cluster-capacity
prometheus affected Red Hat:openshift:3.11::el7 prometheus
prometheus-alertmanager affected Red Hat:openshift:3.11::el7 prometheus-alertmanager
prometheus-node-exporter affected Red Hat:openshift:3.11::el7 prometheus-node-exporter
python2-urllib3 affected Red Hat:openshift:3.11::el7 python2-urllib3
python-urllib3 affected Red Hat:openshift:3.11::el7 python-urllib3
Upstream advisory

CVE-2021-21126

Open SourcePoC exploitCRITICAL2021-01-20

Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension.

CVEs:CVE-2021-21126

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

CVE-2021-21125

Open SourcePoC exploitCRITICAL2021-01-20

Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

CVEs:CVE-2021-21125

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

CVE-2021-21124

Open SourcePoC exploitCRITICAL2021-01-20

Potential user after free in Speech Recognizer in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-21124

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

CVE-2021-21131

Open SourcePoC exploitCRITICAL2021-01-20

Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

CVEs:CVE-2021-21131

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

CVE-2021-21122

Open SourcePoC exploitCRITICAL2021-01-20

Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-21122

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

CVE-2021-21120

Open SourcePoC exploitCRITICAL2021-01-20

Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-21120

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

CVE-2021-21119

Open SourcePoC exploitCRITICAL2021-01-20

Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-21119

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

CVE-2021-21128

Open SourcePoC exploitCRITICAL2021-01-20

Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-21128

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2021-3115

Open SourcePoC exploitCRITICAL2021-01-26

DEBIAN-CVE-2021-3115

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

CVE-2021-3115

GooglePoC exploitCRITICAL2021-01-26

Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an untrusted downl...

CVEs:CVE-2021-3115

Affected products

ProductStatusVendorPackageEcosystem
cloud_insights_telegraf_agent affected netapp
fedora affected fedoraproject
go affected golang
storagegrid affected netapp
Upstream advisory

CVE-2021-21121

Open SourcePoC exploitCRITICAL2021-01-20

Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-21121

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

CVE-2021-21137

Open SourcePoC exploitHIGH2021-01-20

Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.

CVEs:CVE-2021-21137

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

CVE-2021-21127

Open SourcePoC exploitCRITICAL2021-01-20

Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass content security policy via a crafted Chrome Extension.

CVEs:CVE-2021-21127

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

CVE-2021-21129

Open SourcePoC exploitCRITICAL2021-01-20

Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

CVEs:CVE-2021-21129

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

CVE-2021-21130

Open SourcePoC exploitCRITICAL2021-01-20

Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

CVEs:CVE-2021-21130

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

CVE-2021-21141

GooglePoC exploitCRITICAL2021-01-20

Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass file extension policy via a crafted HTML page.

CVEs:CVE-2021-21141

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge affected microsoft
Upstream advisory

CVE-2021-21134

Open SourcePoC exploitMEDIUM2021-01-20

Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remote attacker to spoof security UI via a crafted HTML page.

CVEs:CVE-2021-21134

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

CVE-2021-21139

Open SourcePoC exploitMEDIUM2021-01-20

Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2021-21139

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

CVE-2021-21136

Open SourcePoC exploitCRITICAL2021-01-20

Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2021-21136

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

GHSA-cghx-9gcr-r42x

Open SourcePoC exploitHIGH2021-01-29

Path Traversal in the Java Kubernetes Client

Affected products

ProductStatusVendorPackageEcosystem
io.kubernetes:client-java affected Maven io.kubernetes:client-java
Upstream advisory

GHSA-cghx-9gcr-r42x

Open SourcePoC exploitHIGH2021-01-29

Path Traversal in the Java Kubernetes Client

Affected products

ProductStatusVendorPackageEcosystem
io.kubernetes:client-java affected Maven io.kubernetes:client-java
Upstream advisory

CVE-2020-8570

Open SourcePoC exploitHIGH2021-01-21

Path Traversal in the Java Kubernetes Client

CVEs:CVE-2020-8570

Affected products

ProductStatusVendorPackageEcosystem
io.kubernetes:client-java affected Maven io.kubernetes:client-java
Upstream advisory

CVE-2020-8570

GooglePoC exploitCRITICAL2021-01-21

Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrit...

CVEs:CVE-2020-8570

Affected products

ProductStatusVendorPackageEcosystem
java affected kubernetes
Upstream advisory

DSA-4832-1

Open SourcePoC exploit2021-01-16

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:10 chromium
Upstream advisory

openSUSE-SU-2021:0048-1

Open SourcePoC exploitCRITICAL2021-01-11

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP2 chromium
Upstream advisory

openSUSE-SU-2021:0047-1

Open SourcePoC exploitCRITICAL2021-01-11

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2021:0041-1

Open SourcePoC exploitCRITICAL2021-01-10

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

openSUSE-SU-2021:0040-1

Open SourcePoC exploitCRITICAL2021-01-10

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

DEBIAN-CVE-2021-21110

Open SourcePoC exploitCRITICAL2021-01-08

DEBIAN-CVE-2021-21110

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2021-21110

GooglePoC exploitCRITICAL2021-01-07

Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-21110

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-0316

Open SourcePoC exploitHIGH2021-01-04

In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2021-0316

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-21133

Open SourcePoC exploitCRITICAL2021-01-20

Insufficient policy enforcement in Downloads in Google Chrome prior to 88.0.4324.96 allowed an attacker who convinced a user to download files to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2021-21133

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
Upstream advisory

AZL-79110

Open SourcePoC exploitMEDIUM2021-01-26

CVE-2021-3114 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2021-3114

Open SourcePoC exploitMEDIUM2021-01-26

DEBIAN-CVE-2021-3114

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

CVE-2021-3114

GooglePoC exploitMEDIUM2021-01-26

In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect outputs, related to an underflow of the lowest limb during the final complete reduction in the P-224 field.

CVEs:CVE-2021-3114

Affected products

ProductStatusVendorPackageEcosystem
cloud_insights_telegraf_agent affected netapp
debian_linux affected debian
fedora affected fedoraproject
go affected golang
storagegrid affected netapp
Upstream advisory

DEBIAN-CVE-2020-16012

Open SourcePoC exploitHIGH2021-01-08

DEBIAN-CVE-2020-16012

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
firefox-esr affected Debian:14 firefox-esr
firefox-esr affected Debian:11 firefox-esr
firefox-esr affected Debian:12 firefox-esr
firefox-esr affected Debian:13 firefox-esr
thunderbird affected Debian:14 thunderbird
thunderbird affected Debian:11 thunderbird
thunderbird affected Debian:13 thunderbird
thunderbird affected Debian:12 thunderbird
Upstream advisory

CVE-2020-8569

Open SourcePoC exploitMEDIUM2021-01-21

NULL Pointer Dereference in Kubernetes CSI snapshot-controller

CVEs:CVE-2020-8569

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-csi/external-snapshotter/v2 affected github.com github.com/kubernetes-csi/external-snapshotter/v2
kubernetes-csi/external-snapshotter/v3 affected github.com github.com/kubernetes-csi/external-snapshotter/v3
Upstream advisory

CVE-2020-8569

GooglePoC exploitCRITICAL2021-01-21

Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resource when: - The VolumeSnapshot referenced a non-existing PersistentVolumeClaim and the VolumeSnapshot did not reference any VolumeSna...

CVEs:CVE-2020-8569

Affected products

ProductStatusVendorPackageEcosystem
container_storage_interface_snapshotter affected kubernetes
Upstream advisory

CVE-2021-0313

Open SourcePoC exploitHIGH2021-01-04

In isWordBreakAfter of LayoutUtils.cpp, there is a possible way to slow or crash a TextView due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2021-0313

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0471

Open SourcePoC exploitCRITICAL2021-01-04

In reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into an encrypted Bluetooth connection due to improper input validation. This could lead to remote escalation of privilege between two Bluetooth devices by a ...

CVEs:CVE-2020-0471

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-16044

GooglePoC exploitCRITICAL2021-01-07

Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.

CVEs:CVE-2020-16044

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2021-0312

Open SourcePoC exploitHIGH2021-01-04

In WAVSource::read of WAVExtractor.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Pr...

CVEs:CVE-2021-0312

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-21140

GooglePoC exploitMEDIUM2021-01-20

Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of bounds memory access via via a USB device.

CVEs:CVE-2021-21140

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge affected microsoft
Upstream advisory

ASB-A-170658976

GooglePoC exploitMEDIUM2021-01-01

ASB-A-170658976

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

ASB-A-169505740

GooglePoC exploitMEDIUM2021-01-01

ASB-A-169505740

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-0308

Open SourcePoC exploitHIGH2021-01-04

In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2021-0308

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
Upstream advisory

CVE-2021-0315

Open SourcePoC exploitHIGH2021-01-04

In onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user to grant an app access to an account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privilege...

CVEs:CVE-2021-0315

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0306

Open SourcePoC exploitHIGH2021-01-04

In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Android versions which allows an app to gain the android.permission.ACTIVITY_RECOGNITION permission without user confirmation. This could...

CVEs:CVE-2021-0306

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0318

Open SourcePoC exploitHIGH2021-01-04

In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2021-0318

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0319

Open SourcePoC exploitHIGH2021-01-04

In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device's MAC address without appropriate permissions due to a permissions bypass. This could lead to local escalation of privilege that gr...

CVEs:CVE-2021-0319

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-168722551

GooglePoC exploit2021-01-01

ASB-A-168722551

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2021-0317

Open SourcePoC exploitHIGH2021-01-04

In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploit...

CVEs:CVE-2021-0317

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0342

Open SourcePoC exploitHIGH2021-01-04

In tun_get_user of tun.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges required. User interaction is not required for exploitation. Product: Android; Vers...

CVEs:CVE-2021-0342

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0304

Open SourcePoC exploitMEDIUM2021-01-04

In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of the user's contacts with User execution privileges needed. User interaction is not n...

CVEs:CVE-2021-0304

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0307

Open SourcePoC exploitHIGH2021-01-04

In updatePermissionSourcePackage of PermissionManagerService.java, there is a possible automatic runtime permission grant due to a confused deputy. This could lead to local escalation of privilege allowing a malicious app to silently gain access to a d...

CVEs:CVE-2021-0307

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0310

Open SourcePoC exploitHIGH2021-01-04

In LazyServiceRegistrar of LazyServiceRegistrar.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2021-0310

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0309

Open SourcePoC exploitMEDIUM2021-01-04

In onCreate of grantCredentialsPermissionActivity, there is a confused deputy. This could lead to local information disclosure and account access with no additional execution privileges needed. User interaction is needed for exploitation. Product: Andr...

CVEs:CVE-2021-0309

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0322

Open SourcePoC exploitMEDIUM2021-01-04

In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploit...

CVEs:CVE-2021-0322

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-170138526

GooglePoC exploit2021-01-01

ASB-A-170138526

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2021-0301

Open SourcePoC exploitHIGH2021-01-04

In ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Androi...

CVEs:CVE-2021-0301

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-172514667

GooglePoC exploitHIGH2021-01-01

ASB-A-172514667

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0321

Open SourcePoC exploitHIGH2021-01-04

In enforceDumpPermissionForPackage of ActivityManagerService.java, there is a possible way to determine if a package is installed due to side channel information disclosure. This could lead to local information disclosure with no additional execution p...

CVEs:CVE-2021-0321

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0303

Open SourcePoC exploitHIGH2021-01-04

In dispatchGraphTerminationMessage() of packages/services/Car/computepipe/runner/graph/StreamSetObserver.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with User execution privileges ne...

CVEs:CVE-2021-0303

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-170139097

GooglePoC exploit2021-01-01

ASB-A-170139097

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2021-0320

Open SourcePoC exploitHIGH2021-01-04

In is_device_locked and set_device_locked of keystore_keymaster_enforcement.h, there is a possible bypass of lockscreen requirements for keyguard bound keys due to a race condition. This could lead to local information disclosure with no additional exe...

CVEs:CVE-2021-0320

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-170138789

GooglePoC exploit2021-01-01

ASB-A-170138789

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

DEBIAN-CVE-2021-21112

Open SourceCoalition ESS 30-63%CRITICAL2021-01-08

DEBIAN-CVE-2021-21112

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21112

GoogleCoalition ESS 30-63%CRITICAL2021-01-07

Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-21112

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

ALPINE-CVE-2021-3121

Open SourceCoalition ESS < 30%HIGH2021-01-11

ALPINE-CVE-2021-3121

Affected products

ProductStatusVendorPackageEcosystem
protobuf-c affected Alpine:v3.14 protobuf-c
protobuf-c affected Alpine:v3.15 protobuf-c
protobuf-c affected Alpine:v3.16 protobuf-c
protobuf-c affected Alpine:v3.17 protobuf-c
protobuf-c affected Alpine:v3.18 protobuf-c
protobuf-c affected Alpine:v3.19 protobuf-c
protobuf-c affected Alpine:v3.20 protobuf-c
protobuf-c affected Alpine:v3.21 protobuf-c
protobuf-c affected Alpine:v3.22 protobuf-c
protobuf-c affected Alpine:v3.23 protobuf-c
protobuf-c affected Alpine:v3.24 protobuf-c
Upstream advisory

DEBIAN-CVE-2021-3121

Open SourceCoalition ESS < 30%HIGH2021-01-11

DEBIAN-CVE-2021-3121

Affected products

ProductStatusVendorPackageEcosystem
golang-gogoprotobuf affected Debian:11 golang-gogoprotobuf
golang-gogoprotobuf affected Debian:12 golang-gogoprotobuf
golang-gogoprotobuf affected Debian:13 golang-gogoprotobuf
golang-gogoprotobuf affected Debian:14 golang-gogoprotobuf
Upstream advisory

CVE-2021-3121

Open SourceCoalition ESS < 30%HIGH2021-01-11

An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue.

CVEs:CVE-2021-3121

Affected products

ProductStatusVendorPackageEcosystem
consul affected hashicorp
protobuf affected golang
Upstream advisory

CVE-2021-3121

Open SourceCoalition ESS < 30%HIGH2021-01-11

Improper Input Validation in GoGo Protobuf

CVEs:CVE-2021-3121

Affected products

ProductStatusVendorPackageEcosystem
gogo/protobuf affected github.com github.com/gogo/protobuf
Upstream advisory

MGASA-2021-0018

Open SourceCoalition ESS < 30%CRITICAL2021-01-10

Updated golang packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:7 golang
Upstream advisory

DEBIAN-CVE-2020-28851

Open SourceCoalition ESS < 30%HIGH2021-01-02

DEBIAN-CVE-2020-28851

Affected products

ProductStatusVendorPackageEcosystem
golang-golang-x-text affected Debian:11 golang-golang-x-text
golang-golang-x-text affected Debian:12 golang-golang-x-text
golang-golang-x-text affected Debian:13 golang-golang-x-text
golang-golang-x-text affected Debian:14 golang-golang-x-text
Upstream advisory

CVE-2020-28851

GoogleCoalition ESS < 30%HIGH2021-01-02

In x/text in Go 1.15.4, an "index out of range" panic occurs in language.ParseAcceptLanguage while parsing the -u- extension. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)

CVEs:CVE-2020-28851

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

DEBIAN-CVE-2020-16025

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2020-16025

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-21106

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2021-21106

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21106

GoogleCoalition ESS < 30%CRITICAL2021-01-07

Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-21106

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DLA-2520-1

Open SourceCoalition ESS < 30%NONE2021-01-07

golang-websocket - security update

Affected products

ProductStatusVendorPackageEcosystem
golang-websocket affected Debian:9 golang-websocket
Upstream advisory

DEBIAN-CVE-2020-16041

Open SourceCoalition ESS < 30%HIGH2021-01-08

DEBIAN-CVE-2020-16041

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16024

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2020-16024

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-36066

Open SourceCoalition ESS < 30%HIGH2021-01-05

DEBIAN-CVE-2020-36066

Affected products

ProductStatusVendorPackageEcosystem
golang-github-tidwall-gjson affected Debian:11 golang-github-tidwall-gjson
golang-github-tidwall-gjson affected Debian:12 golang-github-tidwall-gjson
golang-github-tidwall-gjson affected Debian:13 golang-github-tidwall-gjson
golang-github-tidwall-gjson affected Debian:14 golang-github-tidwall-gjson
Upstream advisory

DEBIAN-CVE-2020-28852

Open SourceCoalition ESS < 30%HIGH2021-01-02

DEBIAN-CVE-2020-28852

Affected products

ProductStatusVendorPackageEcosystem
golang-golang-x-text affected Debian:11 golang-golang-x-text
golang-golang-x-text affected Debian:12 golang-golang-x-text
golang-golang-x-text affected Debian:13 golang-golang-x-text
golang-golang-x-text affected Debian:14 golang-golang-x-text
Upstream advisory

CVE-2020-28852

GoogleCoalition ESS < 30%HIGH2021-01-02

In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)

CVEs:CVE-2020-28852

Affected products

ProductStatusVendorPackageEcosystem
text affected golang
Upstream advisory

DEBIAN-CVE-2021-21113

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2021-21113

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21113

GoogleCoalition ESS < 30%CRITICAL2021-01-07

Heap buffer overflow in Skia in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-21113

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-21116

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2021-21116

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21116

GoogleCoalition ESS < 30%CRITICAL2021-01-07

Heap buffer overflow in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-21116

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2019-25014

Open SourceCoalition ESS < 30%CRITICAL2021-01-29

A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha.0. If a particular HTTP GET request is made to the pilot API endpoint, it is possible to cause the Go runtime to panic (resulting i...

CVEs:CVE-2019-25014

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio
openshift_service_mesh affected redhat
Upstream advisory

DEBIAN-CVE-2021-21115

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2021-21115

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21115

GoogleCoalition ESS < 30%CRITICAL2021-01-07

User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-21115

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2020-36067

Open SourceCoalition ESS < 30%HIGH2021-01-05

DEBIAN-CVE-2020-36067

Affected products

ProductStatusVendorPackageEcosystem
golang-github-tidwall-gjson affected Debian:13 golang-github-tidwall-gjson
golang-github-tidwall-gjson affected Debian:14 golang-github-tidwall-gjson
golang-github-tidwall-gjson affected Debian
golang-github-tidwall-gjson affected Debian:11 golang-github-tidwall-gjson
golang-github-tidwall-gjson affected Debian:12 golang-github-tidwall-gjson
Upstream advisory

CVE-2020-8567

GoogleCoalition ESS < 30%MEDIUM2021-01-21

Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host ...

CVEs:CVE-2020-8567

Affected products

ProductStatusVendorPackageEcosystem
azure_key_vault_provider_for_secrets_store_csi_driver affected microsoft
secret_manager_provider_for_secret_store_csi_driver affected google
vault_provider_for_secrets_store_csi_driver affected hashicorp
Upstream advisory

CVE-2020-8567

Open SourceCoalition ESS < 30%LOW2021-01-21

Kubernetes Secrets Store CSI Driver plugins arbitrary file write

CVEs:CVE-2020-8567

Affected products

ProductStatusVendorPackageEcosystem
Azure/secrets-store-csi-driver-provider-azure affected github.com github.com/Azure/secrets-store-csi-driver-provider-azure
GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp affected github.com github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp
hashicorp/vault-csi-provider affected github.com github.com/hashicorp/vault-csi-provider
Upstream advisory

CVE-2020-8567

Open SourceCoalition ESS < 30%MEDIUM2021-01-21

Kubernetes Secrets Store CSI Driver plugins arbitrary file write

CVEs:CVE-2020-8567

Affected products

ProductStatusVendorPackageEcosystem
Azure/secrets-store-csi-driver-provider-azure affected github.com github.com/Azure/secrets-store-csi-driver-provider-azure
GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp affected github.com github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp
hashicorp/vault-csi-provider affected github.com github.com/hashicorp/vault-csi-provider
Upstream advisory

DEBIAN-CVE-2021-21114

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2021-21114

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21114

GoogleCoalition ESS < 30%CRITICAL2021-01-07

Use after free in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-21114

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-21109

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2021-21109

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-21108

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2021-21108

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21108

GoogleCoalition ESS < 30%CRITICAL2021-01-07

Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-21108

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-21109

GoogleCoalition ESS < 30%CRITICAL2021-01-07

Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-21109

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2020-28483

Open SourceCoalition ESS < 30%HIGH2021-01-20

DEBIAN-CVE-2020-28483

Affected products

ProductStatusVendorPackageEcosystem
golang-github-gin-gonic-gin affected Debian:11 golang-github-gin-gonic-gin
golang-github-gin-gonic-gin affected Debian:12 golang-github-gin-gonic-gin
golang-github-gin-gonic-gin affected Debian:13 golang-github-gin-gonic-gin
golang-github-gin-gonic-gin affected Debian:14 golang-github-gin-gonic-gin
Upstream advisory

CVE-2020-8568

Open SourceCoalition ESS < 30%MEDIUM2021-01-21

Directory traversal in Kubernetes Secrets Store CSI Driver

CVEs:CVE-2020-8568

Affected products

ProductStatusVendorPackageEcosystem
secrets-store-csi-driver affected sigs.k8s.io sigs.k8s.io/secrets-store-csi-driver
Upstream advisory

CVE-2020-8568

Open SourceCoalition ESS < 30%MEDIUM2021-01-21

Directory traversal in Kubernetes Secrets Store CSI Driver

CVEs:CVE-2020-8568

Affected products

ProductStatusVendorPackageEcosystem
secrets-store-csi-driver affected sigs.k8s.io sigs.k8s.io/secrets-store-csi-driver
Upstream advisory

CVE-2020-8568

GoogleCoalition ESS < 30%CRITICAL2021-01-21

Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the ability to write content to the host filesystem and sync file contents to Kubernetes Secrets. This incl...

CVEs:CVE-2020-8568

Affected products

ProductStatusVendorPackageEcosystem
secrets_store_csi_driver affected kubernetes
Upstream advisory

DEBIAN-CVE-2020-16039

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2020-16039

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16037

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2020-16037

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16038

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2020-16038

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-1677

Open SourceCoalition ESS < 30%MEDIUM2021-01-12

Azure Active Directory Pod Identity Spoofing Vulnerability

CVEs:CVE-2021-1677

Affected products

ProductStatusVendorPackageEcosystem
azure_kubernetes_service affected microsoft
Upstream advisory

DEBIAN-CVE-2021-21107

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2021-21107

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21107

GoogleCoalition ESS < 30%CRITICAL2021-01-07

Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-21107

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2020-16043

Open SourceCoalition ESS < 30%HIGH2021-01-08

DEBIAN-CVE-2020-16043

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-16043

GoogleCoalition ESS < 30%HIGH2021-01-07

Insufficient data validation in networking in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to bypass discretionary access control via malicious network traffic.

CVEs:CVE-2020-16043

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-21111

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2021-21111

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21111

GoogleCoalition ESS < 30%CRITICAL2021-01-07

Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

CVEs:CVE-2021-21111

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2020-16045

GoogleCoalition ESS < 30%CRITICAL2021-01-14

Use after Free in Payments in Google Chrome on Android prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-16045

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-16035

Open SourceCoalition ESS < 30%HIGH2021-01-08

DEBIAN-CVE-2020-16035

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16026

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2020-16026

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16014

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2020-16014

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16015

Open SourceCoalition ESS < 30%HIGH2021-01-08

DEBIAN-CVE-2020-16015

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16018

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2020-16018

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16029

Open SourceCoalition ESS < 30%HIGH2021-01-08

DEBIAN-CVE-2020-16029

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16027

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2020-16027

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16028

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2020-16028

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16023

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2020-16023

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16042

Open SourceCoalition ESS < 30%HIGH2021-01-08

DEBIAN-CVE-2020-16042

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
firefox-esr affected Debian:11 firefox-esr
firefox-esr affected Debian:12 firefox-esr
firefox-esr affected Debian:13 firefox-esr
firefox-esr affected Debian:14 firefox-esr
thunderbird affected Debian:11 thunderbird
thunderbird affected Debian:12 thunderbird
thunderbird affected Debian:13 thunderbird
thunderbird affected Debian:14 thunderbird
Upstream advisory

DEBIAN-CVE-2020-16019

Open SourceCoalition ESS < 30%HIGH2021-01-08

DEBIAN-CVE-2020-16019

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16020

Open SourceCoalition ESS < 30%HIGH2021-01-08

DEBIAN-CVE-2020-16020

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16016

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2020-16016

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16022

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2020-16022

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-0236

Open SourceCoalition ESS < 30%HIGH2021-01-25

In A2DP_GetCodecType of a2dp_codec_config, there is a possible out-of-bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2020-0236

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-16046

GoogleCoalition ESS < 30%CRITICAL2021-01-14

Script injection in iOSWeb in Google Chrome on iOS prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

CVEs:CVE-2020-16046

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-16036

Open SourceCoalition ESS < 30%MEDIUM2021-01-08

DEBIAN-CVE-2020-16036

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16033

Open SourceCoalition ESS < 30%MEDIUM2021-01-08

DEBIAN-CVE-2020-16033

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16031

Open SourceCoalition ESS < 30%MEDIUM2021-01-08

DEBIAN-CVE-2020-16031

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16032

Open SourceCoalition ESS < 30%MEDIUM2021-01-08

DEBIAN-CVE-2020-16032

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16030

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2020-16030

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-16021

Open SourceCoalition ESS < 30%CRITICAL2021-01-08

DEBIAN-CVE-2020-16021

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21138

GoogleCoalition ESS < 30%HIGH2021-01-20

Use after free in DevTools in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform a sandbox escape via a crafted file.

CVEs:CVE-2021-21138

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-16034

Open SourceCoalition ESS < 30%MEDIUM2021-01-08

DEBIAN-CVE-2020-16034

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

ASB-A-156766097

GoogleCoalition ESS < 30%MEDIUM2021-01-01

ASB-A-156766097

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-22494

Open SourceCoalition ESS < 30%MEDIUM2021-01-05

An issue was discovered in the fingerprint scanner on Samsung Note20 mobile devices with Q(10.0) software. When a screen protector is used, the required image compensation is not present. Consequently, inversion can occur during fingerprint enrollment,...

CVEs:CVE-2021-22494

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-22495

Open SourceCoalition ESS < 30%HIGH2021-01-05

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) (Exynos chipsets) software. The Mali GPU driver allows out-of-bounds access and a device reset. The Samsung ID is SVE-2020-19174 (January 2021).

CVEs:CVE-2021-22495

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-22492

Open SourceCoalition ESS < 30%CRITICAL2021-01-05

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Broadcom Bluetooth chipsets) software. The Bluetooth UART driver has a buffer overflow. The Samsung ID is SVE-2020-18731 (January 2021).

CVEs:CVE-2021-22492

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-21117

GoogleCoalition ESS < 30%HIGH2021-01-20

Insufficient policy enforcement in Cryptohome in Google Chrome prior to 88.0.4324.96 allowed a local attacker to perform OS-level privilege escalation via a crafted file.

CVEs:CVE-2021-21117

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-27059

Open SourceCoalition ESS < 30%HIGH2021-01-04

In onAuthenticated of AuthenticationClient.java, there is a possible tapjacking attack when requesting the user's fingerprint due to an overlaid window. This could lead to local escalation of privilege with no additional execution privileges needed. Us...

CVEs:CVE-2020-27059

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-3011

GoogleCoalition ESS < 30%MEDIUM2021-01-07

An electromagnetic-wave side-channel issue was discovered on NXP SmartMX / P5x security microcontrollers and A7x secure authentication microcontrollers, with CryptoLib through v2.9. It allows attackers to extract the ECDSA private key after extensive p...

CVEs:CVE-2021-3011

Affected products

ProductStatusVendorPackageEcosystem
3a081 affected nxp
a7005a affected nxp
j2a081 affected nxp
j2d081_m59 affected nxp
j2d081_m61 affected nxp
j2d082_m60 affected nxp
j2d120_m60 affected nxp
j2d145_m59 affected nxp
j2e081_m64 affected nxp
j2e082_m65 affected nxp
j2e120_m65 affected nxp
j2e145_m64 affected nxp
j3a041 affected nxp
j3d081_m59 affected nxp
j3d081_m59_df affected nxp
j3d081_m61 affected nxp
j3d081_m61_df affected nxp
j3d082_m60 affected nxp
j3d120_m60 affected nxp
j3d145_m59 affected nxp
j3e016_m64 affected nxp
j3e016_m64_df affected nxp
j3e016_m66 affected nxp
j3e016_m66_df affected nxp
j3e041_m64 affected nxp
j3e041_m64_df affected nxp
j3e041_m66 affected nxp
j3e041_m66_df affected nxp
j3e081_m64 affected nxp
j3e081_m64_df affected nxp
j3e081_m66 affected nxp
j3e081_m66_df affected nxp
j3e082_m65 affected nxp
j3e120_m65 affected nxp
j3e145_m64 affected nxp
k13 affected ftsafe
k21 affected ftsafe
k40 affected ftsafe
k9 affected ftsafe
p5010 affected nxp
p5020 affected nxp
p5021 affected nxp
p5040 affected nxp
titan_security_key affected google
yubikey_neo affected yubico
Upstream advisory

CVE-2020-27097

Open SourceCoalition ESS < 30%MEDIUM2021-01-26

In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:...

CVEs:CVE-2020-27097

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-27098

Open SourceCoalition ESS < 30%MEDIUM2021-01-26

In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible way to access contacts due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ...

CVEs:CVE-2020-27098

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-3022

Open SourceCoalition ESS < 30%MEDIUM2021-01-05

An issue was discovered on LG mobile devices with Android OS 10 software. There was no write protection for the MTK protect2 partition. The LG ID is LVE-SMP-200028 (January 2021).

CVEs:CVE-2021-3022

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MGASA-2021-0044

Open SourceAll remaining2021-01-17

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:7 chromium-browser-stable
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.