CVE-2021-21017
CVEs:CVE-2021-21017
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 19 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
CVEs:CVE-2021-21017
Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution
CVEs:CVE-2021-21017
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to...
CVEs:CVE-2021-21017
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| acrobat | affected | adobe | — | — |
| acrobat_dc | affected | adobe | — | — |
| acrobat_reader | affected | adobe | — | — |
| acrobat_reader_dc | affected | adobe | — | — |
CVEs:CVE-2021-1732
Windows Win32k Elevation of Privilege Vulnerability
CVEs:CVE-2021-1732
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1803 | affected | microsoft | — | — |
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_1909 | affected | microsoft | — | — |
| windows_10_2004 | affected | microsoft | — | — |
| windows_10_20h2 | affected | microsoft | — | — |
| windows_server_1909 | affected | microsoft | — | — |
| windows_server_2004 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
| windows_server_20h2 | affected | microsoft | — | — |
Windows Win32k Elevation of Privilege Vulnerability
CVEs:CVE-2021-1732
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:10 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP2 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Leap 15.2 | chromium | — |
DEBIAN-CVE-2021-21148
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-21148
CVEs:CVE-2021-21148
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-21148
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execu...
CVEs:CVE-2021-1870
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| fedora | affected | fedoraproject | — | — |
| ipados | affected | apple | — | — |
| iphone_os | affected | apple | — | — |
| macos | affected | apple | — | — |
| mac_os_x | affected | apple | — | — |
| webkitgtk | affected | webkitgtk | — | — |
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
CVEs:CVE-2021-1870
CVEs:CVE-2021-1870
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execu...
CVEs:CVE-2021-1871
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| ipados | affected | apple | — | — |
| iphone_os | affected | apple | — | — |
| macos | affected | apple | — | — |
| mac_os_x | affected | apple | — | — |
CVEs:CVE-2021-1871
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
CVEs:CVE-2021-1871
Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| containerd | affected | openSUSE:Leap 15.2 | containerd | — |
| docker | affected | openSUSE:Leap 15.2 | docker | — |
| docker-runc | affected | openSUSE:Leap 15.2 | docker-runc | — |
| fish | affected | openSUSE:Leap 15.2 | fish | — |
| golang-github-docker-libnetwork | affected | openSUSE:Leap 15.2 | golang-github-docker-libnetwork | — |
Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| containerd | affected | SUSE:Manager Server 4.0 | containerd | — |
| containerd | affected | SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOS | containerd | — |
| containerd | affected | SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS | containerd | — |
| containerd | affected | SUSE:Linux Enterprise Server 15 SP1-BCL | containerd | — |
| containerd | affected | SUSE:Linux Enterprise Server 15 SP1-LTSS | containerd | — |
| containerd | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP1 | containerd | — |
| containerd | affected | SUSE:Manager Proxy 4.0 | containerd | — |
| containerd | affected | SUSE:Manager Retail Branch Server 4.0 | containerd | — |
| containerd | affected | SUSE:Enterprise Storage 6 | containerd | — |
| containerd | affected | SUSE:Linux Enterprise Module for Containers 15 SP2 | containerd | — |
| docker | affected | SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS | docker | — |
| docker | affected | SUSE:Linux Enterprise Server 15 SP1-BCL | docker | — |
| docker | affected | SUSE:Linux Enterprise Server 15 SP1-LTSS | docker | — |
| docker | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP1 | docker | — |
| docker | affected | SUSE:Enterprise Storage 6 | docker | — |
| docker | affected | SUSE:Manager Proxy 4.0 | docker | — |
| docker | affected | SUSE:Manager Retail Branch Server 4.0 | docker | — |
| docker | affected | SUSE:Linux Enterprise Module for Containers 15 SP2 | docker | — |
| docker | affected | SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOS | docker | — |
| docker | affected | SUSE:Manager Server 4.0 | docker | — |
| docker-runc | affected | SUSE:Manager Retail Branch Server 4.0 | docker-runc | — |
| docker-runc | affected | SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS | docker-runc | — |
| docker-runc | affected | SUSE:Manager Server 4.0 | docker-runc | — |
| docker-runc | affected | SUSE:Manager Proxy 4.0 | docker-runc | — |
| docker-runc | affected | SUSE:Linux Enterprise Server 15 SP1-BCL | docker-runc | — |
| docker-runc | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP1 | docker-runc | — |
| docker-runc | affected | SUSE:Enterprise Storage 6 | docker-runc | — |
| docker-runc | affected | SUSE:Linux Enterprise Module for Containers 15 SP2 | docker-runc | — |
| docker-runc | affected | SUSE:Linux Enterprise Server 15 SP1-LTSS | docker-runc | — |
| docker-runc | affected | SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOS | docker-runc | — |
| golang-github-docker-libnetwork | affected | SUSE:Linux Enterprise Server 15 SP1-LTSS | golang-github-docker-libnetwork | — |
| golang-github-docker-libnetwork | affected | SUSE:Linux Enterprise Module for Containers 15 SP2 | golang-github-docker-libnetwork | — |
| golang-github-docker-libnetwork | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP1 | golang-github-docker-libnetwork | — |
| golang-github-docker-libnetwork | affected | SUSE:Manager Retail Branch Server 4.0 | golang-github-docker-libnetwork | — |
| golang-github-docker-libnetwork | affected | SUSE:Manager Proxy 4.0 | golang-github-docker-libnetwork | — |
| golang-github-docker-libnetwork | affected | SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS | golang-github-docker-libnetwork | — |
| golang-github-docker-libnetwork | affected | SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOS | golang-github-docker-libnetwork | — |
| golang-github-docker-libnetwork | affected | SUSE:Linux Enterprise Server 15 SP1-BCL | golang-github-docker-libnetwork | — |
| golang-github-docker-libnetwork | affected | SUSE:Manager Server 4.0 | golang-github-docker-libnetwork | — |
| golang-github-docker-libnetwork | affected | SUSE:Enterprise Storage 6 | golang-github-docker-libnetwork | — |
DEBIAN-CVE-2021-21132
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:10 | chromium | — |
DEBIAN-CVE-2021-21135
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-21118
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-21123
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-21157
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-21157
Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-21157
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2021-21126
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
DEBIAN-CVE-2021-21125
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-21124
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-21131
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
DEBIAN-CVE-2021-21122
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-21120
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-21119
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-21128
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-21121
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-21137
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-21127
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-21129
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-21130
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-21141
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-21134
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-0326
In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no additional execution privileges needed. ...
CVEs:CVE-2021-0326
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2021-21139
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
golang-1.11 - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.11 | affected | Debian:10 | golang-1.11 | — |
DEBIAN-CVE-2021-21136
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| containerd | affected | SUSE:Linux Enterprise Module for Containers 12 | containerd | — |
| docker | affected | SUSE:Linux Enterprise Module for Containers 12 | docker | — |
| docker-runc | affected | SUSE:Linux Enterprise Module for Containers 12 | docker-runc | — |
| golang-github-docker-libnetwork | affected | SUSE:Linux Enterprise Module for Containers 12 | golang-github-docker-libnetwork | — |
DEBIAN-CVE-2021-21133
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-21156
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-21156
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted script.
CVEs:CVE-2021-21156
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Incorrect Default Permissions in JetBrains Kotlin
CVEs:CVE-2020-29582
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jetbrains.kotlin:kotlin-stdlib | affected | Maven | org.jetbrains.kotlin:kotlin-stdlib | — |
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
CVEs:CVE-2020-29582
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| communications_cloud_native_core_network_slice_selection_function | affected | oracle | — | — |
| communications_cloud_native_core_policy | affected | oracle | — | — |
| communications_cloud_native_core_service_communication_proxy | affected | oracle | — | — |
| kotlin | affected | jetbrains | — | — |
In ih264d_parse_pslice of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation...
CVEs:CVE-2021-0325
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0325
golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | openEuler:20.03-LTS | golang | — |
| golang | affected | openEuler:20.03-LTS-SP1 | golang | — |
CVEs:CVE-2021-0340
In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is nee...
CVEs:CVE-2021-0340
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-24113
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVEs:CVE-2021-24113
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
DEBIAN-CVE-2021-21149
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-21149
Stack buffer overflow in Data Transfer in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
CVEs:CVE-2021-21149
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2021-21154
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
CVEs:CVE-2021-21154
Heap buffer overflow in Tab Strip in Google Chrome prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2021-21154
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2021-21155
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Heap buffer overflow in Tab Strip in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2021-21155
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-21155
DEBIAN-CVE-2021-21152
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-21153
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Heap buffer overflow in Media in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-21152
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-21152
CVEs:CVE-2021-21153
Stack buffer overflow in GPU Process in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVEs:CVE-2021-21153
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2021-21150
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2021-21150
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-21150
DEBIAN-CVE-2021-21151
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2021-21151
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-21151
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP2 | chromium | — |
DEBIAN-CVE-2021-21146
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Leap 15.2 | chromium | — |
Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2021-21146
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-21146
DEBIAN-CVE-2021-21142
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-21142
Use after free in Payments in Google Chrome on Mac prior to 88.0.4324.146 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2021-21142
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2021-21145
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-21145
Use after free in Fonts in Google Chrome prior to 88.0.4324.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-21145
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User inte...
CVEs:CVE-2021-0341
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Square OkHttp can accept the wrong certificate
CVEs:CVE-2021-0341
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.squareup.okhttp3:okhttp | affected | Maven | com.squareup.okhttp3:okhttp | — |
DEBIAN-CVE-2021-21144
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-21144
Heap buffer overflow in Tab Groups in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
CVEs:CVE-2021-21144
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2021-21147
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Inappropriate implementation in Skia in Google Chrome prior to 88.0.4324.146 allowed a local attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2021-21147
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-21147
DEBIAN-CVE-2021-21143
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Heap buffer overflow in Extensions in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
CVEs:CVE-2021-21143
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-21143
DEBIAN-CVE-2021-21140
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
In loadAnimation of WindowContainer.java, there is a possible way to keep displaying a malicious app while a target app is brought to the foreground. This could lead to local escalation of privilege with no additional execution privileges needed. User ...
CVEs:CVE-2021-0339
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0339
CVEs:CVE-2021-0302
In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Pr...
CVEs:CVE-2021-0302
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In onCreate of BluetoothPermissionActivity.java, there is a possible permissions bypass due to a tapjacking overlay that obscures the phonebook permissions dialog when a Bluetooth device is connecting. This could lead to local escalation of privilege w...
CVEs:CVE-2021-0333
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0333
In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges needed. User interact...
CVEs:CVE-2021-0334
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0334
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible overlay attack due to an insecure default value. This could lead to local escalation of privilege and notification access with User execution privileges needed. User intera...
CVEs:CVE-2021-0331
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0331
CVEs:CVE-2021-0314
In onCreate of UninstallerActivity, there is a possible way to uninstall an all without informed user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction i...
CVEs:CVE-2021-0314
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0327
In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored binder identities. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is ...
CVEs:CVE-2021-0327
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In onReceive of BluetoothPermissionRequest.java, there is a possible permissions bypass due to a mutable PendingIntent. This could lead to local escalation of privilege that bypasses a permission check, with User execution privileges needed. User inter...
CVEs:CVE-2021-0336
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0336
CVEs:CVE-2021-0329
In several native functions called by AdvertiseManager.java, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the Bluetooth server with User execution privileges needed. User int...
CVEs:CVE-2021-0329
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In add_user_ce and remove_user_ce of storaged.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in storaged with no additional execution privileges needed. User interaction is not needed f...
CVEs:CVE-2021-0330
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0330
In bootFinished of SurfaceFlinger.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: Andro...
CVEs:CVE-2021-0332
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0332
CVEs:CVE-2021-0328
In onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve Bluetooth scan results without permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execut...
CVEs:CVE-2021-0328
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0337
In moveInMediaStore of FileSystemProvider.java, there is a possible file exposure due to stale metadata. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: An...
CVEs:CVE-2021-0337
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Denial of service in .NET core
CVEs:CVE-2021-1721
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| Microsoft.NETCore.App | affected | NuGet | Microsoft.NETCore.App | — |
| Microsoft.NETCore.App.Host.linux-arm | affected | NuGet | Microsoft.NETCore.App.Host.linux-arm | — |
| Microsoft.NETCore.App.Host.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Host.linux-arm64 | — |
| Microsoft.NETCore.App.Host.linux-musl-arm64 | affected | NuGet | Microsoft.NETCore.App.Host.linux-musl-arm64 | — |
| Microsoft.NETCore.App.Host.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Host.linux-musl-x64 | — |
| Microsoft.NETCore.App.Host.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Host.linux-x64 | — |
| Microsoft.NETCore.App.Host.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Host.osx-x64 | — |
| Microsoft.NETCore.App.Host.rhel.6-x64 | affected | NuGet | Microsoft.NETCore.App.Host.rhel.6-x64 | — |
| Microsoft.NETCore.App.Host.win-arm | affected | NuGet | Microsoft.NETCore.App.Host.win-arm | — |
| Microsoft.NETCore.App.Host.win-arm64 | affected | NuGet | Microsoft.NETCore.App.Host.win-arm64 | — |
| Microsoft.NETCore.App.Host.win-x64 | affected | NuGet | Microsoft.NETCore.App.Host.win-x64 | — |
| Microsoft.NETCore.App.Host.win-x86 | affected | NuGet | Microsoft.NETCore.App.Host.win-x86 | — |
| Microsoft.NETCore.App.Runtime.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.android-arm | — |
| Microsoft.NETCore.App.Runtime.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.android-x64 | — |
| Microsoft.NETCore.App.Runtime.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.android-x86 | — |
| Microsoft.NETCore.App.Runtime.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.ios-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.ios-arm | — |
| Microsoft.NETCore.App.Runtime.ios-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.ios-x64 | — |
| Microsoft.NETCore.App.Runtime.ios-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.ios-x86 | — |
| Microsoft.NETCore.App.Runtime.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm | — |
| Microsoft.NETCore.App.Runtime.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.rhel.6-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.rhel.6-x64 | — |
| Microsoft.NETCore.App.Runtime.tvos-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.tvos-arm64 | — |
| Microsoft.NETCore.App.Runtime.tvos-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.tvos-x64 | — |
| Microsoft.NETCore.App.Runtime.win-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm | — |
| Microsoft.NETCore.App.Runtime.win-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm64 | — |
| Microsoft.NETCore.App.Runtime.win-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x64 | — |
| Microsoft.NETCore.App.Runtime.win-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x86 | — |
.NET Core and Visual Studio Denial of Service Vulnerability
CVEs:CVE-2021-1721
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| .net | affected | microsoft | — | — |
| .net_core | affected | microsoft | — | — |
| powershell_core | affected | microsoft | — | — |
| visual_studio_2017 | affected | microsoft | — | — |
| visual_studio_2019 | affected | microsoft | — | — |
angular-expressions is "angular's nicest part extracted as a standalone module for the browser and node". In angular-expressions before version 1.1.2 there is a vulnerability which allows Remote Code Execution if you call "expressions.compile(userContr...
CVEs:CVE-2021-21277
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-expressions | affected | peerigon | — | — |
Angular Expressions - Remote Code Execution
CVEs:CVE-2021-21277
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-expressions | affected | npm | angular-expressions | — |
Angular Expressions - Remote Code Execution
CVEs:CVE-2021-21277
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-expressions | affected | npm | angular-expressions | — |
Angular Expressions - Remote Code Execution
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-expressions | affected | npm | angular-expressions | — |
Angular Expressions - Remote Code Execution
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-expressions | affected | npm | angular-expressions | — |
CVEs:CVE-2021-24109
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CVEs:CVE-2021-24109
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| azure_kubernetes_service | affected | microsoft | — | — |
Security update for terraform
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| terraform | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | terraform | — |
| terraform-provider-aws | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | terraform-provider-aws | — |
| terraform-provider-azurerm | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | terraform-provider-azurerm | — |
| terraform-provider-external | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | terraform-provider-external | — |
| terraform-provider-google | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | terraform-provider-google | — |
| terraform-provider-helm | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | terraform-provider-helm | — |
| terraform-provider-kubernetes | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | terraform-provider-kubernetes | — |
| terraform-provider-local | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | terraform-provider-local | — |
| terraform-provider-null | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | terraform-provider-null | — |
| terraform-provider-random | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | terraform-provider-random | — |
| terraform-provider-tls | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | terraform-provider-tls | — |
In wlan driver, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: And...
CVEs:CVE-2021-0351
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0351
CVEs:CVE-2021-0335
In process of C2SoftHevcDec.cpp, there is a possible out of bounds write due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: Andr...
CVEs:CVE-2021-0335
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-26687
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. In preloaded applications, the HostnameVerified default is mishandled. The LG ID is LVE-SMP-200029 (February 2021).
CVEs:CVE-2021-26687
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-26689
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. The USB laf gadget has a use-after-free. The LG ID is LVE-SMP-200031 (February 2021).
CVEs:CVE-2021-26689
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
The slashify package 1.0.0 for Node.js allows open-redirect attacks, as demonstrated by a localhost:3000///example.com/ substring.
CVEs:CVE-2021-3189
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| slashify | affected | — | — |
Open redirect in Slashify
CVEs:CVE-2021-3189
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| slashify | affected | npm | slashify | — |
Open redirect in Slashify
CVEs:CVE-2021-3189
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| slashify | affected | npm | slashify | — |
In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Pr...
CVEs:CVE-2021-0305
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0305
DEBIAN-CVE-2021-21138
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-26688
An issue was discovered on LG Wing mobile devices with Android OS 10 software. The biometric sensor has weak security properties. The LG ID is LVE-SMP-200030 (February 2021).
CVEs:CVE-2021-26688
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-22553
Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We re...
CVEs:CVE-2021-22553
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| gerrit | affected | — | — |
CVEs:CVE-2021-0364
In mobile_log_d, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versio...
CVEs:CVE-2021-0364
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
SSRF in Rendertron
CVEs:CVE-2020-8902
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| rendertron | affected | npm | rendertron | — |
Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force a rendertron headless chrome process to render internal sites it has access to, and display ...
CVEs:CVE-2020-8902
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| rendertron | affected | — | — |
SSRF in Rendertron
CVEs:CVE-2020-8902
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| rendertron | affected | npm | rendertron | — |
In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: A...
CVEs:CVE-2021-0356
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0356
In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: A...
CVEs:CVE-2021-0358
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0358
CVEs:CVE-2021-0363
In mobile_log_d, there is a possible command injection due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions:...
CVEs:CVE-2021-0363
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In jpeg, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: An...
CVEs:CVE-2021-0402
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0402
CVEs:CVE-2021-0405
In performance driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; V...
CVEs:CVE-2021-0405
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: ...
CVEs:CVE-2021-0406
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0406
DEBIAN-CVE-2021-21117
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
ASB-A-161374239
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
ASB-A-172348954
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
ASB-A-172348990
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
CVEs:CVE-2021-0366
In vpu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, An...
CVEs:CVE-2021-0366
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0367
In vpu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, An...
CVEs:CVE-2021-0367
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-10, Androi...
CVEs:CVE-2021-0401
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0401
In mobile_log_d, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; ...
CVEs:CVE-2021-0345
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0345
CVEs:CVE-2021-0346
In vpu, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: And...
CVEs:CVE-2021-0346
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0348
In vpu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Androi...
CVEs:CVE-2021-0348
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In mtkpower, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: And...
CVEs:CVE-2021-0344
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0344
In display driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: And...
CVEs:CVE-2021-0349
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0349
CVEs:CVE-2021-39648
In gadget_dev_desc_UDC_show of configfs.c, there is a possible disclosure of kernel heap memory due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2021-39648
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In kisd, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Andro...
CVEs:CVE-2021-0343
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0343
CVEs:CVE-2021-0353
In kisd, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android...
CVEs:CVE-2021-0353
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In ccu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.1,...
CVEs:CVE-2021-0347
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0347
In netdiag, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: An...
CVEs:CVE-2021-0359
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0359
In netdiag, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions:...
CVEs:CVE-2021-0360
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0360
CVEs:CVE-2021-0354
In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-8...
CVEs:CVE-2021-0354
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In netdiag, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: An...
CVEs:CVE-2021-0357
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0357
In aee, there is a possible memory corruption due to a stack buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android...
CVEs:CVE-2021-0362
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0362
CVEs:CVE-2021-0365
In display driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: And...
CVEs:CVE-2021-0365
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In kisd, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-...
CVEs:CVE-2021-0355
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0355
CVEs:CVE-2020-11836
OPPO Android Phone with MTK chipset and Android 8.1/9/10/11 versions have an information leak vulnerability. The “adb shell getprop ro.vendor.aee.enforcing” or “adb shell getprop ro.vendor.aee.enforcing” return no.
CVEs:CVE-2020-11836
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In kisd, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: And...
CVEs:CVE-2021-0361
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0361
CVEs:CVE-2021-0350
In ged, there is a possible system crash due to an improper input validation. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-8.1, ...
CVEs:CVE-2021-0350
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In SystemSettingsValidators, there is a possible permanent denial of service due to missing bounds checks on UI settings. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2021-0338
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0338
CVEs:CVE-2021-0352
In RT regmap driver, there is a possible memory corruption due to type confusion. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-1...
CVEs:CVE-2021-0352
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0404
In mobile_log_d, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Ve...
CVEs:CVE-2021-0404
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0403
In netdiag, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versio...
CVEs:CVE-2021-0403
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-172349048
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-172999675
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
UNKNOWN READ in std::pair<absl::lts_NUMBER_02_25::container_internal::raw_hash_set<absl::lts_NUM
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | — | — |
Updated chromium-browser packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:7 | chromium-browser-stable | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.