Google Security Advisories · February 2021 — Google Security Advisories
238 advisories 145 CVEs 19 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2021-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 19 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2021-21017

GoogleExploitedCISA KEV listedHIGH2021-02-10

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to...

CVEs:CVE-2021-21017

Affected products

ProductStatusVendorPackageEcosystem
acrobat affected adobe
acrobat_dc affected adobe
acrobat_reader affected adobe
acrobat_reader_dc affected adobe
Upstream advisory

CVE-2021-1732

GoogleExploitedCISA KEV listedCRITICAL2021-02-10

Windows Win32k Elevation of Privilege Vulnerability

CVEs:CVE-2021-1732

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1803 affected microsoft
windows_10_1809 affected microsoft
windows_10_1909 affected microsoft
windows_10_2004 affected microsoft
windows_10_20h2 affected microsoft
windows_server_1909 affected microsoft
windows_server_2004 affected microsoft
windows_server_2019 affected microsoft
windows_server_20h2 affected microsoft
Upstream advisory

DSA-4858-1

Open SourceExploitedCISA KEV listed2021-02-19

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:10 chromium
Upstream advisory

openSUSE-SU-2021:0276-1

Open SourceExploitedCISA KEV listedCRITICAL2021-02-11

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP2 chromium
Upstream advisory

openSUSE-SU-2021:0267-1

Open SourceExploitedCISA KEV listedCRITICAL2021-02-09

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

DEBIAN-CVE-2021-21148

Open SourceExploitedCISA KEV listedCRITICAL2021-02-09

DEBIAN-CVE-2021-21148

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21148

Project ZeroExploitedCISA KEV listed2021-02-05

Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-21148

Upstream advisory

CVE-2021-21148

GoogleExploitedCISA KEV listedCRITICAL2021-02-05

Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-21148

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-1870

GoogleExploitedCISA KEV listedCRITICAL2021-02-02

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execu...

CVEs:CVE-2021-1870

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
webkitgtk affected webkitgtk
Upstream advisory

CVE-2021-1870

Project ZeroExploitedCISA KEV listed2021-02-02

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

CVEs:CVE-2021-1870

Upstream advisory

CVE-2021-1871

GoogleExploitedCISA KEV listedCRITICAL2021-02-02

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execu...

CVEs:CVE-2021-1871

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
fedora affected fedoraproject
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
Upstream advisory

CVE-2021-1871

Project ZeroExploitedCISA KEV listed2021-02-02

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

CVEs:CVE-2021-1871

Upstream advisory

openSUSE-SU-2021:0278-1

Open SourceActive exploitation (sightings)CRITICAL2021-02-12

Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork

Affected products

ProductStatusVendorPackageEcosystem
containerd affected openSUSE:Leap 15.2 containerd
docker affected openSUSE:Leap 15.2 docker
docker-runc affected openSUSE:Leap 15.2 docker-runc
fish affected openSUSE:Leap 15.2 fish
golang-github-docker-libnetwork affected openSUSE:Leap 15.2 golang-github-docker-libnetwork
Upstream advisory

SUSE-SU-2021:0435-1

Open SourceActive exploitation (sightings)CRITICAL2021-02-11

Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork

Affected products

ProductStatusVendorPackageEcosystem
containerd affected SUSE:Manager Server 4.0 containerd
containerd affected SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOS containerd
containerd affected SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS containerd
containerd affected SUSE:Linux Enterprise Server 15 SP1-BCL containerd
containerd affected SUSE:Linux Enterprise Server 15 SP1-LTSS containerd
containerd affected SUSE:Linux Enterprise Server for SAP Applications 15 SP1 containerd
containerd affected SUSE:Manager Proxy 4.0 containerd
containerd affected SUSE:Manager Retail Branch Server 4.0 containerd
containerd affected SUSE:Enterprise Storage 6 containerd
containerd affected SUSE:Linux Enterprise Module for Containers 15 SP2 containerd
docker affected SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS docker
docker affected SUSE:Linux Enterprise Server 15 SP1-BCL docker
docker affected SUSE:Linux Enterprise Server 15 SP1-LTSS docker
docker affected SUSE:Linux Enterprise Server for SAP Applications 15 SP1 docker
docker affected SUSE:Enterprise Storage 6 docker
docker affected SUSE:Manager Proxy 4.0 docker
docker affected SUSE:Manager Retail Branch Server 4.0 docker
docker affected SUSE:Linux Enterprise Module for Containers 15 SP2 docker
docker affected SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOS docker
docker affected SUSE:Manager Server 4.0 docker
docker-runc affected SUSE:Manager Retail Branch Server 4.0 docker-runc
docker-runc affected SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS docker-runc
docker-runc affected SUSE:Manager Server 4.0 docker-runc
docker-runc affected SUSE:Manager Proxy 4.0 docker-runc
docker-runc affected SUSE:Linux Enterprise Server 15 SP1-BCL docker-runc
docker-runc affected SUSE:Linux Enterprise Server for SAP Applications 15 SP1 docker-runc
docker-runc affected SUSE:Enterprise Storage 6 docker-runc
docker-runc affected SUSE:Linux Enterprise Module for Containers 15 SP2 docker-runc
docker-runc affected SUSE:Linux Enterprise Server 15 SP1-LTSS docker-runc
docker-runc affected SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOS docker-runc
golang-github-docker-libnetwork affected SUSE:Linux Enterprise Server 15 SP1-LTSS golang-github-docker-libnetwork
golang-github-docker-libnetwork affected SUSE:Linux Enterprise Module for Containers 15 SP2 golang-github-docker-libnetwork
golang-github-docker-libnetwork affected SUSE:Linux Enterprise Server for SAP Applications 15 SP1 golang-github-docker-libnetwork
golang-github-docker-libnetwork affected SUSE:Manager Retail Branch Server 4.0 golang-github-docker-libnetwork
golang-github-docker-libnetwork affected SUSE:Manager Proxy 4.0 golang-github-docker-libnetwork
golang-github-docker-libnetwork affected SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS golang-github-docker-libnetwork
golang-github-docker-libnetwork affected SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOS golang-github-docker-libnetwork
golang-github-docker-libnetwork affected SUSE:Linux Enterprise Server 15 SP1-BCL golang-github-docker-libnetwork
golang-github-docker-libnetwork affected SUSE:Manager Server 4.0 golang-github-docker-libnetwork
golang-github-docker-libnetwork affected SUSE:Enterprise Storage 6 golang-github-docker-libnetwork
Upstream advisory

DEBIAN-CVE-2021-21132

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21132

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DSA-4846-1

Open SourcePoC exploit2021-02-07

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:10 chromium
Upstream advisory

DEBIAN-CVE-2021-21135

Open SourcePoC exploitMEDIUM2021-02-09

DEBIAN-CVE-2021-21135

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-21118

Open SourcePoC exploitHIGH2021-02-09

DEBIAN-CVE-2021-21118

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-21123

Open SourcePoC exploitMEDIUM2021-02-09

DEBIAN-CVE-2021-21123

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-21157

Open SourcePoC exploitCRITICAL2021-02-22

DEBIAN-CVE-2021-21157

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21157

Open SourcePoC exploitCRITICAL2021-02-17

Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-21157

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-21126

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21126

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

DEBIAN-CVE-2021-21125

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21125

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-21124

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21124

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-21131

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21131

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

DEBIAN-CVE-2021-21122

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21122

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-21120

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21120

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-21119

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21119

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-21128

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21128

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-21121

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21121

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-21137

Open SourcePoC exploitHIGH2021-02-09

DEBIAN-CVE-2021-21137

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-21127

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21127

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-21129

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21129

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-21130

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21130

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-21141

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21141

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-21134

Open SourcePoC exploitMEDIUM2021-02-09

DEBIAN-CVE-2021-21134

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-0326

Open SourcePoC exploitHIGH2021-02-01

In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no additional execution privileges needed. ...

CVEs:CVE-2021-0326

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-21139

Open SourcePoC exploitMEDIUM2021-02-09

DEBIAN-CVE-2021-21139

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DSA-4848-1

Open SourcePoC exploit2021-02-08

golang-1.11 - security update

Affected products

ProductStatusVendorPackageEcosystem
golang-1.11 affected Debian:10 golang-1.11
Upstream advisory

DEBIAN-CVE-2021-21136

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21136

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

SUSE-SU-2021:0445-1

Open SourcePoC exploitCRITICAL2021-02-12

Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork

Affected products

ProductStatusVendorPackageEcosystem
containerd affected SUSE:Linux Enterprise Module for Containers 12 containerd
docker affected SUSE:Linux Enterprise Module for Containers 12 docker
docker-runc affected SUSE:Linux Enterprise Module for Containers 12 docker-runc
golang-github-docker-libnetwork affected SUSE:Linux Enterprise Module for Containers 12 golang-github-docker-libnetwork
Upstream advisory

DEBIAN-CVE-2021-21133

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21133

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-21156

Open SourcePoC exploitCRITICAL2021-02-22

DEBIAN-CVE-2021-21156

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21156

GooglePoC exploitCRITICAL2021-02-17

Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted script.

CVEs:CVE-2021-21156

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2020-29582

Open SourcePoC exploitMEDIUM2021-02-03

Incorrect Default Permissions in JetBrains Kotlin

CVEs:CVE-2020-29582

Affected products

ProductStatusVendorPackageEcosystem
org.jetbrains.kotlin:kotlin-stdlib affected Maven org.jetbrains.kotlin:kotlin-stdlib
Upstream advisory

CVE-2020-29582

GooglePoC exploitMEDIUM2021-02-03

In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.

CVEs:CVE-2020-29582

Affected products

ProductStatusVendorPackageEcosystem
communications_cloud_native_core_network_slice_selection_function affected oracle
communications_cloud_native_core_policy affected oracle
communications_cloud_native_core_service_communication_proxy affected oracle
kotlin affected jetbrains
Upstream advisory

CVE-2021-0325

Open SourcePoC exploitHIGH2021-02-01

In ih264d_parse_pslice of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation...

CVEs:CVE-2021-0325

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

OESA-2021-1011

Open SourcePoC exploit2021-02-04

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS golang
golang affected openEuler:20.03-LTS-SP1 golang
Upstream advisory

CVE-2021-0340

Open SourcePoC exploitHIGH2021-02-01

In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is nee...

CVEs:CVE-2021-0340

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-24113

Open SourcePoC exploitMEDIUM2021-02-05

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVEs:CVE-2021-24113

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2021-21149

Open SourcePoC exploitCRITICAL2021-02-22

DEBIAN-CVE-2021-21149

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21149

GooglePoC exploitCRITICAL2021-02-17

Stack buffer overflow in Data Transfer in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.

CVEs:CVE-2021-21149

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-21154

Open SourcePoC exploitCRITICAL2021-02-22

DEBIAN-CVE-2021-21154

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

CVE-2021-21154

GooglePoC exploitCRITICAL2021-02-17

Heap buffer overflow in Tab Strip in Google Chrome prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-21154

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-21155

Open SourcePoC exploitCRITICAL2021-02-22

DEBIAN-CVE-2021-21155

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21155

GooglePoC exploitCRITICAL2021-02-17

Heap buffer overflow in Tab Strip in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-21155

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-21152

Open SourcePoC exploitCRITICAL2021-02-22

DEBIAN-CVE-2021-21152

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-21153

Open SourcePoC exploitCRITICAL2021-02-22

DEBIAN-CVE-2021-21153

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21152

GooglePoC exploitCRITICAL2021-02-17

Heap buffer overflow in Media in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-21152

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-21153

GooglePoC exploitCRITICAL2021-02-17

Stack buffer overflow in GPU Process in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVEs:CVE-2021-21153

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-21150

Open SourcePoC exploitCRITICAL2021-02-22

DEBIAN-CVE-2021-21150

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21150

GooglePoC exploitCRITICAL2021-02-17

Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-21150

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-21151

Open SourcePoC exploitCRITICAL2021-02-22

DEBIAN-CVE-2021-21151

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21151

GooglePoC exploitCRITICAL2021-02-17

Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-21151

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

openSUSE-SU-2021:0268-1

Open SourcePoC exploitCRITICAL2021-02-10

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP2 chromium
Upstream advisory

DEBIAN-CVE-2021-21146

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21146

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

openSUSE-SU-2021:0259-1

Open SourcePoC exploitCRITICAL2021-02-07

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

CVE-2021-21146

GooglePoC exploitCRITICAL2021-02-03

Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-21146

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-21142

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21142

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21142

GooglePoC exploitCRITICAL2021-02-03

Use after free in Payments in Google Chrome on Mac prior to 88.0.4324.146 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-21142

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-21145

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21145

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21145

GooglePoC exploitCRITICAL2021-02-03

Use after free in Fonts in Google Chrome prior to 88.0.4324.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-21145

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-0341

Open SourcePoC exploitHIGH2021-02-01

In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User inte...

CVEs:CVE-2021-0341

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0341

GooglePoC exploitHIGH2021-02-01

Square OkHttp can accept the wrong certificate

CVEs:CVE-2021-0341

Affected products

ProductStatusVendorPackageEcosystem
com.squareup.okhttp3:okhttp affected Maven com.squareup.okhttp3:okhttp
Upstream advisory

DEBIAN-CVE-2021-21144

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21144

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21144

GooglePoC exploitCRITICAL2021-02-03

Heap buffer overflow in Tab Groups in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

CVEs:CVE-2021-21144

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-21147

Open SourcePoC exploitMEDIUM2021-02-09

DEBIAN-CVE-2021-21147

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21147

GooglePoC exploitMEDIUM2021-02-03

Inappropriate implementation in Skia in Google Chrome prior to 88.0.4324.146 allowed a local attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2021-21147

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-21143

Open SourcePoC exploitCRITICAL2021-02-09

DEBIAN-CVE-2021-21143

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-21143

GooglePoC exploitCRITICAL2021-02-03

Heap buffer overflow in Extensions in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

CVEs:CVE-2021-21143

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-21140

Open SourcePoC exploitMEDIUM2021-02-09

DEBIAN-CVE-2021-21140

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-0339

Open SourcePoC exploitHIGH2021-02-01

In loadAnimation of WindowContainer.java, there is a possible way to keep displaying a malicious app while a target app is brought to the foreground. This could lead to local escalation of privilege with no additional execution privileges needed. User ...

CVEs:CVE-2021-0339

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0302

Open SourcePoC exploitHIGH2021-02-01

In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Pr...

CVEs:CVE-2021-0302

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0333

Open SourcePoC exploitHIGH2021-02-01

In onCreate of BluetoothPermissionActivity.java, there is a possible permissions bypass due to a tapjacking overlay that obscures the phonebook permissions dialog when a Bluetooth device is connecting. This could lead to local escalation of privilege w...

CVEs:CVE-2021-0333

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0334

Open SourcePoC exploitHIGH2021-02-01

In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges needed. User interact...

CVEs:CVE-2021-0334

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0331

Open SourcePoC exploitHIGH2021-02-01

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible overlay attack due to an insecure default value. This could lead to local escalation of privilege and notification access with User execution privileges needed. User intera...

CVEs:CVE-2021-0331

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0314

Open SourcePoC exploitHIGH2021-02-01

In onCreate of UninstallerActivity, there is a possible way to uninstall an all without informed user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction i...

CVEs:CVE-2021-0314

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0327

Open SourcePoC exploitHIGH2021-02-01

In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored binder identities. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is ...

CVEs:CVE-2021-0327

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0336

Open SourcePoC exploitHIGH2021-02-01

In onReceive of BluetoothPermissionRequest.java, there is a possible permissions bypass due to a mutable PendingIntent. This could lead to local escalation of privilege that bypasses a permission check, with User execution privileges needed. User inter...

CVEs:CVE-2021-0336

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0329

Open SourcePoC exploitHIGH2021-02-01

In several native functions called by AdvertiseManager.java, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the Bluetooth server with User execution privileges needed. User int...

CVEs:CVE-2021-0329

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0330

Open SourcePoC exploitHIGH2021-02-01

In add_user_ce and remove_user_ce of storaged.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in storaged with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2021-0330

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0332

Open SourcePoC exploitHIGH2021-02-01

In bootFinished of SurfaceFlinger.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: Andro...

CVEs:CVE-2021-0332

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0328

Open SourcePoC exploitHIGH2021-02-01

In onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve Bluetooth scan results without permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execut...

CVEs:CVE-2021-0328

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0337

Open SourcePoC exploitHIGH2021-02-01

In moveInMediaStore of FileSystemProvider.java, there is a possible file exposure due to stale metadata. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: An...

CVEs:CVE-2021-0337

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1721

Open SourceCoalition ESS < 30%MEDIUM2021-02-10

Denial of service in .NET core

CVEs:CVE-2021-1721

Affected products

ProductStatusVendorPackageEcosystem
Microsoft.NETCore.App affected NuGet Microsoft.NETCore.App
Microsoft.NETCore.App.Host.linux-arm affected NuGet Microsoft.NETCore.App.Host.linux-arm
Microsoft.NETCore.App.Host.linux-arm64 affected NuGet Microsoft.NETCore.App.Host.linux-arm64
Microsoft.NETCore.App.Host.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Host.linux-musl-arm64
Microsoft.NETCore.App.Host.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Host.linux-musl-x64
Microsoft.NETCore.App.Host.linux-x64 affected NuGet Microsoft.NETCore.App.Host.linux-x64
Microsoft.NETCore.App.Host.osx-x64 affected NuGet Microsoft.NETCore.App.Host.osx-x64
Microsoft.NETCore.App.Host.rhel.6-x64 affected NuGet Microsoft.NETCore.App.Host.rhel.6-x64
Microsoft.NETCore.App.Host.win-arm affected NuGet Microsoft.NETCore.App.Host.win-arm
Microsoft.NETCore.App.Host.win-arm64 affected NuGet Microsoft.NETCore.App.Host.win-arm64
Microsoft.NETCore.App.Host.win-x64 affected NuGet Microsoft.NETCore.App.Host.win-x64
Microsoft.NETCore.App.Host.win-x86 affected NuGet Microsoft.NETCore.App.Host.win-x86
Microsoft.NETCore.App.Runtime.android-arm affected NuGet Microsoft.NETCore.App.Runtime.android-arm
Microsoft.NETCore.App.Runtime.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.android-arm64
Microsoft.NETCore.App.Runtime.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.android-x64
Microsoft.NETCore.App.Runtime.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.android-x86
Microsoft.NETCore.App.Runtime.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.browser-wasm
Microsoft.NETCore.App.Runtime.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.ios-arm
Microsoft.NETCore.App.Runtime.ios-x64 affected NuGet Microsoft.NETCore.App.Runtime.ios-x64
Microsoft.NETCore.App.Runtime.ios-x86 affected NuGet Microsoft.NETCore.App.Runtime.ios-x86
Microsoft.NETCore.App.Runtime.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-arm
Microsoft.NETCore.App.Runtime.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-arm64
Microsoft.NETCore.App.Runtime.linux-musl-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm
Microsoft.NETCore.App.Runtime.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm64
Microsoft.NETCore.App.Runtime.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-x64
Microsoft.NETCore.App.Runtime.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-x64
Microsoft.NETCore.App.Runtime.Mono.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm
Microsoft.NETCore.App.Runtime.Mono.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64
Microsoft.NETCore.App.Runtime.Mono.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64
Microsoft.NETCore.App.Runtime.Mono.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-x64
Microsoft.NETCore.App.Runtime.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.osx-x64
Microsoft.NETCore.App.Runtime.rhel.6-x64 affected NuGet Microsoft.NETCore.App.Runtime.rhel.6-x64
Microsoft.NETCore.App.Runtime.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.tvos-arm64
Microsoft.NETCore.App.Runtime.tvos-x64 affected NuGet Microsoft.NETCore.App.Runtime.tvos-x64
Microsoft.NETCore.App.Runtime.win-arm affected NuGet Microsoft.NETCore.App.Runtime.win-arm
Microsoft.NETCore.App.Runtime.win-arm64 affected NuGet Microsoft.NETCore.App.Runtime.win-arm64
Microsoft.NETCore.App.Runtime.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.win-x64
Microsoft.NETCore.App.Runtime.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.win-x86
Upstream advisory

CVE-2021-1721

GoogleCoalition ESS < 30%HIGH2021-02-09

.NET Core and Visual Studio Denial of Service Vulnerability

CVEs:CVE-2021-1721

Affected products

ProductStatusVendorPackageEcosystem
.net affected microsoft
.net_core affected microsoft
powershell_core affected microsoft
visual_studio_2017 affected microsoft
visual_studio_2019 affected microsoft
Upstream advisory

CVE-2021-21277

Open SourceCoalition ESS < 30%CRITICAL2021-02-01

angular-expressions is "angular's nicest part extracted as a standalone module for the browser and node". In angular-expressions before version 1.1.2 there is a vulnerability which allows Remote Code Execution if you call "expressions.compile(userContr...

CVEs:CVE-2021-21277

Affected products

ProductStatusVendorPackageEcosystem
angular-expressions affected peerigon
Upstream advisory

CVE-2021-21277

Open SourceCoalition ESS < 30%HIGH2021-02-01

Angular Expressions - Remote Code Execution

CVEs:CVE-2021-21277

Affected products

ProductStatusVendorPackageEcosystem
angular-expressions affected npm angular-expressions
Upstream advisory

CVE-2021-21277

Open SourceCoalition ESS < 30%HIGH2021-02-01

Angular Expressions - Remote Code Execution

CVEs:CVE-2021-21277

Affected products

ProductStatusVendorPackageEcosystem
angular-expressions affected npm angular-expressions
Upstream advisory

GHSA-j6px-jwvv-vpwq

Open SourceCoalition ESS < 30%HIGH2021-02-01

Angular Expressions - Remote Code Execution

Affected products

ProductStatusVendorPackageEcosystem
angular-expressions affected npm angular-expressions
Upstream advisory

GHSA-j6px-jwvv-vpwq

Open SourceCoalition ESS < 30%HIGH2021-02-01

Angular Expressions - Remote Code Execution

Affected products

ProductStatusVendorPackageEcosystem
angular-expressions affected npm angular-expressions
Upstream advisory

CVE-2021-24109

Open SourceCoalition ESS < 30%CRITICAL2021-02-10

Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

CVEs:CVE-2021-24109

Affected products

ProductStatusVendorPackageEcosystem
azure_kubernetes_service affected microsoft
Upstream advisory

SUSE-SU-2021:0263-1

Open SourceCoalition ESS < 30%HIGH2021-02-01

Security update for terraform

Affected products

ProductStatusVendorPackageEcosystem
terraform affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 terraform
terraform-provider-aws affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 terraform-provider-aws
terraform-provider-azurerm affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 terraform-provider-azurerm
terraform-provider-external affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 terraform-provider-external
terraform-provider-google affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 terraform-provider-google
terraform-provider-helm affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 terraform-provider-helm
terraform-provider-kubernetes affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 terraform-provider-kubernetes
terraform-provider-local affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 terraform-provider-local
terraform-provider-null affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 terraform-provider-null
terraform-provider-random affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 terraform-provider-random
terraform-provider-tls affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 terraform-provider-tls
Upstream advisory

CVE-2021-0351

Open SourceCoalition ESS < 30%HIGH2021-02-04

In wlan driver, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: And...

CVEs:CVE-2021-0351

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0335

Open SourceCoalition ESS < 30%HIGH2021-02-01

In process of C2SoftHevcDec.cpp, there is a possible out of bounds write due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: Andr...

CVEs:CVE-2021-0335

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-26687

Open SourceCoalition ESS < 30%CRITICAL2021-02-04

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. In preloaded applications, the HostnameVerified default is mishandled. The LG ID is LVE-SMP-200029 (February 2021).

CVEs:CVE-2021-26687

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-26689

Open SourceCoalition ESS < 30%CRITICAL2021-02-04

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. The USB laf gadget has a use-after-free. The LG ID is LVE-SMP-200031 (February 2021).

CVEs:CVE-2021-26689

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-3189

GoogleCoalition ESS < 30%MEDIUM2021-02-19

The slashify package 1.0.0 for Node.js allows open-redirect attacks, as demonstrated by a localhost:3000///example.com/ substring.

CVEs:CVE-2021-3189

Affected products

ProductStatusVendorPackageEcosystem
slashify affected google
Upstream advisory

CVE-2021-0305

Open SourceCoalition ESS < 30%HIGH2021-02-01

In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Pr...

CVEs:CVE-2021-0305

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2021-21138

Open SourceCoalition ESS < 30%HIGH2021-02-09

DEBIAN-CVE-2021-21138

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-26688

Open SourceCoalition ESS < 30%CRITICAL2021-02-04

An issue was discovered on LG Wing mobile devices with Android OS 10 software. The biometric sensor has weak security properties. The LG ID is LVE-SMP-200030 (February 2021).

CVEs:CVE-2021-26688

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-22553

GoogleCoalition ESS < 30%HIGH2021-02-17

Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We re...

CVEs:CVE-2021-22553

Affected products

ProductStatusVendorPackageEcosystem
gerrit affected google
Upstream advisory

CVE-2021-0364

Open SourceCoalition ESS < 30%HIGH2021-02-03

In mobile_log_d, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versio...

CVEs:CVE-2021-0364

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-8902

GoogleCoalition ESS < 30%CRITICAL2021-02-23

Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force a rendertron headless chrome process to render internal sites it has access to, and display ...

CVEs:CVE-2020-8902

Affected products

ProductStatusVendorPackageEcosystem
rendertron affected google
Upstream advisory

CVE-2021-0356

Open SourceCoalition ESS < 30%HIGH2021-02-03

In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: A...

CVEs:CVE-2021-0356

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0358

Open SourceCoalition ESS < 30%HIGH2021-02-03

In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: A...

CVEs:CVE-2021-0358

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0363

Open SourceCoalition ESS < 30%HIGH2021-02-03

In mobile_log_d, there is a possible command injection due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions:...

CVEs:CVE-2021-0363

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0402

Open SourceCoalition ESS < 30%HIGH2021-02-26

In jpeg, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: An...

CVEs:CVE-2021-0402

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0405

Open SourceCoalition ESS < 30%HIGH2021-02-26

In performance driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; V...

CVEs:CVE-2021-0405

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0406

Open SourceCoalition ESS < 30%HIGH2021-02-26

In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: ...

CVEs:CVE-2021-0406

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2021-21117

Open SourceCoalition ESS < 30%HIGH2021-02-09

DEBIAN-CVE-2021-21117

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
chromium affected Debian:13 chromium
Upstream advisory

ASB-A-161374239

GoogleCoalition ESS < 30%2021-02-01

ASB-A-161374239

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-172348954

GoogleCoalition ESS < 30%2021-02-01

ASB-A-172348954

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-172348990

GoogleCoalition ESS < 30%2021-02-01

ASB-A-172348990

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2021-0366

Open SourceCoalition ESS < 30%HIGH2021-02-26

In vpu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, An...

CVEs:CVE-2021-0366

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0367

Open SourceCoalition ESS < 30%HIGH2021-02-26

In vpu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, An...

CVEs:CVE-2021-0367

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0401

Open SourceCoalition ESS < 30%HIGH2021-02-26

In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-10, Androi...

CVEs:CVE-2021-0401

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0345

Open SourceCoalition ESS < 30%HIGH2021-02-04

In mobile_log_d, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; ...

CVEs:CVE-2021-0345

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0346

Open SourceCoalition ESS < 30%HIGH2021-02-04

In vpu, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: And...

CVEs:CVE-2021-0346

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0348

Open SourceCoalition ESS < 30%HIGH2021-02-04

In vpu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Androi...

CVEs:CVE-2021-0348

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0344

Open SourceCoalition ESS < 30%HIGH2021-02-04

In mtkpower, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: And...

CVEs:CVE-2021-0344

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0349

Open SourceCoalition ESS < 30%HIGH2021-02-04

In display driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: And...

CVEs:CVE-2021-0349

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39648

Open SourceCoalition ESS < 30%MEDIUM2021-02-17

In gadget_dev_desc_UDC_show of configfs.c, there is a possible disclosure of kernel heap memory due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2021-39648

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0343

Open SourceCoalition ESS < 30%HIGH2021-02-04

In kisd, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Andro...

CVEs:CVE-2021-0343

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0353

Open SourceCoalition ESS < 30%HIGH2021-02-03

In kisd, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android...

CVEs:CVE-2021-0353

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0347

Open SourceCoalition ESS < 30%MEDIUM2021-02-04

In ccu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.1,...

CVEs:CVE-2021-0347

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0359

Open SourceCoalition ESS < 30%HIGH2021-02-03

In netdiag, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: An...

CVEs:CVE-2021-0359

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0360

Open SourceCoalition ESS < 30%HIGH2021-02-03

In netdiag, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions:...

CVEs:CVE-2021-0360

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0354

Open SourceCoalition ESS < 30%HIGH2021-02-03

In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-8...

CVEs:CVE-2021-0354

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0357

Open SourceCoalition ESS < 30%HIGH2021-02-03

In netdiag, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: An...

CVEs:CVE-2021-0357

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0362

Open SourceCoalition ESS < 30%HIGH2021-02-03

In aee, there is a possible memory corruption due to a stack buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android...

CVEs:CVE-2021-0362

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0365

Open SourceCoalition ESS < 30%HIGH2021-02-03

In display driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: And...

CVEs:CVE-2021-0365

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0355

Open SourceCoalition ESS < 30%HIGH2021-02-03

In kisd, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-...

CVEs:CVE-2021-0355

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-11836

Open SourceCoalition ESS < 30%HIGH2021-02-05

OPPO Android Phone with MTK chipset and Android 8.1/9/10/11 versions have an information leak vulnerability. The “adb shell getprop ro.vendor.aee.enforcing” or “adb shell getprop ro.vendor.aee.enforcing” return no.

CVEs:CVE-2020-11836

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0361

Open SourceCoalition ESS < 30%MEDIUM2021-02-03

In kisd, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: And...

CVEs:CVE-2021-0361

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0350

Open SourceCoalition ESS < 30%MEDIUM2021-02-04

In ged, there is a possible system crash due to an improper input validation. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-8.1, ...

CVEs:CVE-2021-0350

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0338

Open SourceCoalition ESS < 30%MEDIUM2021-02-01

In SystemSettingsValidators, there is a possible permanent denial of service due to missing bounds checks on UI settings. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2021-0338

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0352

Open SourceCoalition ESS < 30%HIGH2021-02-03

In RT regmap driver, there is a possible memory corruption due to type confusion. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-1...

CVEs:CVE-2021-0352

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0404

Open SourceCoalition ESS < 30%MEDIUM2021-02-26

In mobile_log_d, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Ve...

CVEs:CVE-2021-0404

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0403

Open SourceCoalition ESS < 30%MEDIUM2021-02-26

In netdiag, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versio...

CVEs:CVE-2021-0403

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-172349048

GoogleCoalition ESS < 30%2021-02-01

ASB-A-172349048

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-172999675

GoogleEPSS <= 49%HIGH2021-02-01

ASB-A-172999675

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

OSV-2021-449

Open SourceAll remainingHIGH2021-02-27

UNKNOWN READ in std::pair<absl::lts_NUMBER_02_25::container_internal::raw_hash_set<absl::lts_NUM

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI
Upstream advisory

MGASA-2021-0083

Open SourceAll remaining2021-02-15

Updated chromium-browser packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:7 chromium-browser-stable
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.