CVE-2021-31955
CVEs:CVE-2021-31955
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 35 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
CVEs:CVE-2021-31955
Windows Kernel Information Disclosure Vulnerability
CVEs:CVE-2021-31955
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_1909 | affected | microsoft | — | — |
| windows_10_2004 | affected | microsoft | — | — |
| windows_10_20h2 | affected | microsoft | — | — |
| windows_10_21h1 | affected | microsoft | — | — |
| windows_server_2004 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
| windows_server_20h2 | affected | microsoft | — | — |
Windows Kernel Information Disclosure Vulnerability
CVEs:CVE-2021-31955
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP3 | chromium | — |
| chromium | affected | openSUSE:Leap 15.3 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Leap 15.2 | chromium | — |
DEBIAN-CVE-2021-30551
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30551
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30551
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30551
Windows MSHTML Platform Remote Code Execution Vulnerability
CVEs:CVE-2021-33742
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1507 | affected | microsoft | — | — |
| windows_10_1607 | affected | microsoft | — | — |
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_1909 | affected | microsoft | — | — |
| windows_10_2004 | affected | microsoft | — | — |
| windows_10_20h2 | affected | microsoft | — | — |
| windows_10_21h1 | affected | microsoft | — | — |
| windows_7 | affected | microsoft | — | — |
| windows_8.1 | affected | microsoft | — | — |
| windows_rt_8.1 | affected | microsoft | — | — |
| windows_server_2008 | affected | microsoft | — | — |
| windows_server_2012 | affected | microsoft | — | — |
| windows_server_2016 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
CVEs:CVE-2021-33742
Windows MSHTML Platform Remote Code Execution Vulnerability
CVEs:CVE-2021-33742
Windows NTFS Elevation of Privilege Vulnerability
CVEs:CVE-2021-31956
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1507 | affected | microsoft | — | — |
| windows_10_1607 | affected | microsoft | — | — |
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_1909 | affected | microsoft | — | — |
| windows_10_2004 | affected | microsoft | — | — |
| windows_10_20h2 | affected | microsoft | — | — |
| windows_10_21h1 | affected | microsoft | — | — |
| windows_7 | affected | microsoft | — | — |
| windows_8.1 | affected | microsoft | — | — |
| windows_rt_8.1 | affected | microsoft | — | — |
| windows_server_2004 | affected | microsoft | — | — |
| windows_server_2008 | affected | microsoft | — | — |
| windows_server_2012 | affected | microsoft | — | — |
| windows_server_2016 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
| windows_server_20h2 | affected | microsoft | — | — |
CVEs:CVE-2021-31956
Windows NTFS Elevation of Privilege Vulnerability
CVEs:CVE-2021-31956
DEBIAN-CVE-2021-30533
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP3 | chromium | — |
| chromium | affected | openSUSE:Leap 15.3 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Leap 15.2 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Leap 15.2 | chromium | — |
Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30554
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30554
Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30554
CVEs:CVE-2021-31199
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
CVEs:CVE-2021-31199
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1507 | affected | microsoft | — | — |
| windows_10_1607 | affected | microsoft | — | — |
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_1909 | affected | microsoft | — | — |
| windows_10_2004 | affected | microsoft | — | — |
| windows_10_20h2 | affected | microsoft | — | — |
| windows_10_21h1 | affected | microsoft | — | — |
| windows_7 | affected | microsoft | — | — |
| windows_8.1 | affected | microsoft | — | — |
| windows_rt_8.1 | affected | microsoft | — | — |
| windows_server_2004 | affected | microsoft | — | — |
| windows_server_2008 | affected | microsoft | — | — |
| windows_server_2012 | affected | microsoft | — | — |
| windows_server_2016 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
| windows_server_20h2 | affected | microsoft | — | — |
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
CVEs:CVE-2021-31199
CVEs:CVE-2021-31201
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
CVEs:CVE-2021-31201
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1507 | affected | microsoft | — | — |
| windows_10_1607 | affected | microsoft | — | — |
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_1909 | affected | microsoft | — | — |
| windows_10_2004 | affected | microsoft | — | — |
| windows_10_20h2 | affected | microsoft | — | — |
| windows_10_21h1 | affected | microsoft | — | — |
| windows_7 | affected | microsoft | — | — |
| windows_8.1 | affected | microsoft | — | — |
| windows_rt_8.1 | affected | microsoft | — | — |
| windows_server_2004 | affected | microsoft | — | — |
| windows_server_2008 | affected | microsoft | — | — |
| windows_server_2012 | affected | microsoft | — | — |
| windows_server_2016 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
| windows_server_20h2 | affected | microsoft | — | — |
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
CVEs:CVE-2021-31201
CVEs:CVE-2021-25394
A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.
CVEs:CVE-2021-25394
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.
CVEs:CVE-2021-25394
CVEs:CVE-2021-25395
A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.
CVEs:CVE-2021-25395
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.
CVEs:CVE-2021-25395
DEBIAN-CVE-2021-30538
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
In memory management driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2021-0527
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0527
ASB-A-185193931
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Security update for SUSE Manager Client Tools
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-wrouesnel-postgres_exporter | affected | SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS | golang-github-wrouesnel-postgres_exporter | — |
| golang-github-wrouesnel-postgres_exporter | affected | SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS | golang-github-wrouesnel-postgres_exporter | — |
| mgr-cfg | affected | SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS | mgr-cfg | — |
| mgr-cfg | affected | SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS | mgr-cfg | — |
| mgr-custom-info | affected | SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS | mgr-custom-info | — |
| mgr-custom-info | affected | SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS | mgr-custom-info | — |
| mgr-daemon | affected | SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS | mgr-daemon | — |
| mgr-daemon | affected | SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS | mgr-daemon | — |
| mgr-osad | affected | SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS | mgr-osad | — |
| mgr-osad | affected | SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS | mgr-osad | — |
| mgr-push | affected | SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS | mgr-push | — |
| mgr-push | affected | SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS | mgr-push | — |
| mgr-virtualization | affected | SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS | mgr-virtualization | — |
| mgr-virtualization | affected | SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS | mgr-virtualization | — |
| rhnlib | affected | SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS | rhnlib | — |
| rhnlib | affected | SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS | rhnlib | — |
| salt | affected | SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS | salt | — |
| salt | affected | SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS | salt | — |
| spacecmd | affected | SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS | spacecmd | — |
| spacecmd | affected | SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS | spacecmd | — |
| spacewalk-client-tools | affected | SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS | spacewalk-client-tools | — |
| spacewalk-client-tools | affected | SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS | spacewalk-client-tools | — |
| spacewalk-koan | affected | SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS | spacewalk-koan | — |
| spacewalk-koan | affected | SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS | spacewalk-koan | — |
| spacewalk-oscap | affected | SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS | spacewalk-oscap | — |
| spacewalk-oscap | affected | SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS | spacewalk-oscap | — |
| spacewalk-remote-utils | affected | SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS | spacewalk-remote-utils | — |
| spacewalk-remote-utils | affected | SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS | spacewalk-remote-utils | — |
| supportutils-plugin-susemanager-client | affected | SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS | supportutils-plugin-susemanager-client | — |
| supportutils-plugin-susemanager-client | affected | SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS | supportutils-plugin-susemanager-client | — |
| suseRegisterInfo | affected | SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS | suseRegisterInfo | — |
| suseRegisterInfo | affected | SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS | suseRegisterInfo | — |
| uyuni-common-libs | affected | SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS | uyuni-common-libs | — |
| uyuni-common-libs | affected | SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS | uyuni-common-libs | — |
Security update for SUSE Manager Server 4.1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cobbler | affected | SUSE:Manager Server Module 4.1 | cobbler | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Manager Server Module 4.1 | golang-github-prometheus-node_exporter | — |
| grafana-formula | affected | SUSE:Manager Server Module 4.1 | grafana-formula | — |
| patterns-suse-manager | affected | SUSE:Manager Server Module 4.1 | patterns-suse-manager | — |
| prometheus-exporters-formula | affected | SUSE:Manager Server Module 4.1 | prometheus-exporters-formula | — |
| py26-compat-salt | affected | SUSE:Manager Server Module 4.1 | py26-compat-salt | — |
| py27-compat-salt | affected | SUSE:Manager Server Module 4.1 | py27-compat-salt | — |
| spacewalk-admin | affected | SUSE:Manager Server Module 4.1 | spacewalk-admin | — |
| spacewalk-backend | affected | SUSE:Manager Server Module 4.1 | spacewalk-backend | — |
| spacewalk-branding | affected | SUSE:Manager Server Module 4.1 | spacewalk-branding | — |
| spacewalk-certs-tools | affected | SUSE:Manager Server Module 4.1 | spacewalk-certs-tools | — |
| spacewalk-java | affected | SUSE:Manager Server Module 4.1 | spacewalk-java | — |
| spacewalk-utils | affected | SUSE:Manager Server Module 4.1 | spacewalk-utils | — |
| spacewalk-web | affected | SUSE:Manager Server Module 4.1 | spacewalk-web | — |
| susemanager | affected | SUSE:Manager Server Module 4.1 | susemanager | — |
| susemanager-build-keys | affected | SUSE:Manager Server Module 4.1 | susemanager-build-keys | — |
| susemanager-doc-indexes | affected | SUSE:Manager Server Module 4.1 | susemanager-doc-indexes | — |
| susemanager-docs_en | affected | SUSE:Manager Server Module 4.1 | susemanager-docs_en | — |
| susemanager-schema | affected | SUSE:Manager Server Module 4.1 | susemanager-schema | — |
| susemanager-sls | affected | SUSE:Manager Server Module 4.1 | susemanager-sls | — |
| susemanager-sync-data | affected | SUSE:Manager Server Module 4.1 | susemanager-sync-data | — |
| tika-core | affected | SUSE:Manager Server Module 4.1 | tika-core | — |
| uyuni-common-libs | affected | SUSE:Manager Server Module 4.1 | uyuni-common-libs | — |
ASB-A-174904512
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
DEBIAN-CVE-2021-30547
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| firefox-esr | affected | Debian:11 | firefox-esr | — |
| firefox-esr | affected | Debian:12 | firefox-esr | — |
| firefox-esr | affected | Debian:13 | firefox-esr | — |
| firefox-esr | affected | Debian:14 | firefox-esr | — |
| thunderbird | affected | Debian:11 | thunderbird | — |
| thunderbird | affected | Debian:12 | thunderbird | — |
| thunderbird | affected | Debian:13 | thunderbird | — |
| thunderbird | affected | Debian:14 | thunderbird | — |
CVEs:CVE-2021-30547
Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVEs:CVE-2021-30547
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| firefox | affected | mozilla | — | — |
CVEs:CVE-2021-33196
In archive/zip in Go before 1.15.13 and 1.16.x before 1.16.5, a crafted file count (in an archive's header) can cause a NewReader or OpenReader panic.
CVEs:CVE-2021-33196
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| debian_linux | affected | debian | — | — |
| go | affected | golang | — | — |
Recommended update for the Azure and AWS SDKs
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aws-cli | affected | SUSE:OpenStack Cloud 8 | aws-cli | — |
| aws-cli | affected | SUSE:OpenStack Cloud Crowbar 8 | aws-cli | — |
| aws-cli | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | aws-cli | — |
| aws-cli | affected | SUSE:HPE Helion OpenStack 8 | aws-cli | — |
| azure-cli | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | azure-cli | — |
| azure-cli-command-modules-nspkg | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | azure-cli-command-modules-nspkg | — |
| azure-cli-core | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | azure-cli-core | — |
| azure-cli-nspkg | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | azure-cli-nspkg | — |
| azure-cli-telemetry | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | azure-cli-telemetry | — |
| azure-cli-test | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | azure-cli-test | — |
| libsodium | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | libsodium | — |
| libsodium | affected | SUSE:Linux Enterprise Module for Web and Scripting 12 | libsodium | — |
| python3-requests | affected | SUSE:HPE Helion OpenStack 8 | python3-requests | — |
| python3-requests | affected | SUSE:OpenStack Cloud 9 | python3-requests | — |
| python3-requests | affected | SUSE:OpenStack Cloud Crowbar 9 | python3-requests | — |
| python3-requests | affected | SUSE:OpenStack Cloud Crowbar 8 | python3-requests | — |
| python3-requests | affected | SUSE:OpenStack Cloud 8 | python3-requests | — |
| python3-requests | affected | SUSE:Linux Enterprise Workstation Extension 12 SP5 | python3-requests | — |
| python3-requests | affected | SUSE:Linux Enterprise Server for SAP Applications 12 SP5 | python3-requests | — |
| python3-requests | affected | SUSE:Linux Enterprise Server 12 SP5 | python3-requests | — |
| python3-requests | affected | SUSE:Linux Enterprise Server 12 SP4-LTSS | python3-requests | — |
| python3-requests | affected | SUSE:Linux Enterprise Server 12 SP3-BCL | python3-requests | — |
| python3-requests | affected | SUSE:Linux Enterprise Server 12 SP3-LTSS | python3-requests | — |
| python3-requests | affected | SUSE:Linux Enterprise Server 12 SP2-BCL | python3-requests | — |
| python3-requests | affected | SUSE:Linux Enterprise Software Development Kit 12 SP5 | python3-requests | — |
| python3-requests | affected | SUSE:Linux Enterprise Server for SAP Applications 12 SP4 | python3-requests | — |
| python3-requests | affected | SUSE:Linux Enterprise Server for SAP Applications 12 SP3 | python3-requests | — |
| python-adal | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-adal | — |
| python-antlr4-python3-runtime | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-antlr4-python3-runtime | — |
| python-applicationinsights | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-applicationinsights | — |
| python-atomicwrites | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-atomicwrites | — |
| python-attrs | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-attrs | — |
| python-azure-ai-anomalydetector | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-ai-anomalydetector | — |
| python-azure-ai-metricsadvisor | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-ai-metricsadvisor | — |
| python-azure-ai-nspkg | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-ai-nspkg | — |
| python-azure-ai-textanalytics | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-ai-textanalytics | — |
| python-azure-appconfiguration | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-appconfiguration | — |
| python-azure-applicationinsights | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-applicationinsights | — |
| python-azure-batch | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-batch | — |
| python-azure-cognitiveservices-anomalydetector | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-anomalydetector | — |
| python-azure-cognitiveservices-formrecognizer | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-formrecognizer | — |
| python-azure-cognitiveservices-inkrecognizer | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-inkrecognizer | — |
| python-azure-cognitiveservices-knowledge-nspkg | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-knowledge-nspkg | — |
| python-azure-cognitiveservices-knowledge-qnamaker | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-knowledge-qnamaker | — |
| python-azure-cognitiveservices-language-luis | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-language-luis | — |
| python-azure-cognitiveservices-language-nspkg | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-language-nspkg | — |
| python-azure-cognitiveservices-language-spellcheck | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-language-spellcheck | — |
| python-azure-cognitiveservices-language-textanalytics | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-language-textanalytics | — |
| python-azure-cognitiveservices-nspkg | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-nspkg | — |
| python-azure-cognitiveservices-personalizer | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-personalizer | — |
| python-azure-cognitiveservices-search-autosuggest | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-search-autosuggest | — |
| python-azure-cognitiveservices-search-customimagesearch | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-search-customimagesearch | — |
| python-azure-cognitiveservices-search-customsearch | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-search-customsearch | — |
| python-azure-cognitiveservices-search-entitysearch | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-search-entitysearch | — |
| python-azure-cognitiveservices-search-imagesearch | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-search-imagesearch | — |
| python-azure-cognitiveservices-search-newssearch | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-search-newssearch | — |
| python-azure-cognitiveservices-search-nspkg | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-search-nspkg | — |
| python-azure-cognitiveservices-search-videosearch | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-search-videosearch | — |
| python-azure-cognitiveservices-search-visualsearch | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-search-visualsearch | — |
| python-azure-cognitiveservices-search-websearch | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-search-websearch | — |
| python-azure-cognitiveservices-vision-computervision | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-vision-computervision | — |
| python-azure-cognitiveservices-vision-contentmoderator | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-vision-contentmoderator | — |
| python-azure-cognitiveservices-vision-customvision | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-vision-customvision | — |
| python-azure-cognitiveservices-vision-face | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-vision-face | — |
| python-azure-cognitiveservices-vision-nspkg | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cognitiveservices-vision-nspkg | — |
| python-azure-common | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-common | — |
| python-azure-communication-administration | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-communication-administration | — |
| python-azure-communication-chat | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-communication-chat | — |
| python-azure-communication-nspkg | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-communication-nspkg | — |
| python-azure-communication-sms | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-communication-sms | — |
| python-azure-core | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-core | — |
| python-azure-cosmos | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-cosmos | — |
| python-azure-datalake-store | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-datalake-store | — |
| python-azure-data-nspkg | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-data-nspkg | — |
| python-azure-data-tables | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-data-tables | — |
| python-azure-devops | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-devops | — |
| python-azure-eventgrid | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-eventgrid | — |
| python-azure-eventhub | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-eventhub | — |
| python-azure-eventhub-checkpointstoreblob | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-eventhub-checkpointstoreblob | — |
| python-azure-functions-devops-build | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-functions-devops-build | — |
| python-azure-graphrbac | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-graphrbac | — |
| python-azure-identity | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-identity | — |
| python-azure-keyvault | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-keyvault | — |
| python-azure-keyvault-administration | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-keyvault-administration | — |
| python-azure-keyvault-certificates | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-keyvault-certificates | — |
| python-azure-keyvault-keys | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-keyvault-keys | — |
| python-azure-keyvault-nspkg | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-keyvault-nspkg | — |
| python-azure-keyvault-secrets | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-keyvault-secrets | — |
| python-azure-loganalytics | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-loganalytics | — |
| python-azure-mgmt | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt | — |
| python-azure-mgmt-advisor | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-advisor | — |
| python-azure-mgmt-alertsmanagement | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-alertsmanagement | — |
| python-azure-mgmt-apimanagement | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-apimanagement | — |
| python-azure-mgmt-appconfiguration | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-appconfiguration | — |
| python-azure-mgmt-applicationinsights | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-applicationinsights | — |
| python-azure-mgmt-appplatform | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-appplatform | — |
| python-azure-mgmt-attestation | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-attestation | — |
| python-azure-mgmt-authorization | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-authorization | — |
| python-azure-mgmt-automanage | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-automanage | — |
| python-azure-mgmt-automation | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-automation | — |
| python-azure-mgmt-azurestack | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-azurestack | — |
| python-azure-mgmt-azurestackhci | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-azurestackhci | — |
| python-azure-mgmt-baremetalinfrastructure | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-baremetalinfrastructure | — |
| python-azure-mgmt-batch | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-batch | — |
| python-azure-mgmt-batchai | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-batchai | — |
| python-azure-mgmt-billing | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-billing | — |
| python-azure-mgmt-botservice | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-botservice | — |
| python-azure-mgmt-cdn | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-cdn | — |
| python-azure-mgmt-cognitiveservices | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-cognitiveservices | — |
| python-azure-mgmt-commerce | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-commerce | — |
| python-azure-mgmt-communication | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-communication | — |
| python-azure-mgmt-compute | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-compute | — |
| python-azure-mgmt-consumption | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-consumption | — |
| python-azure-mgmt-containerinstance | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-containerinstance | — |
| python-azure-mgmt-containerregistry | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-containerregistry | — |
| python-azure-mgmt-containerservice | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-containerservice | — |
| python-azure-mgmt-core | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-core | — |
| python-azure-mgmt-cosmosdb | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-cosmosdb | — |
| python-azure-mgmt-costmanagement | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-costmanagement | — |
| python-azure-mgmt-databoxedge | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-databoxedge | — |
| python-azure-mgmt-databricks | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-databricks | — |
| python-azure-mgmt-datafactory | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-datafactory | — |
| python-azure-mgmt-datalake-analytics | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-datalake-analytics | — |
| python-azure-mgmt-datalake-nspkg | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-datalake-nspkg | — |
| python-azure-mgmt-datalake-store | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-datalake-store | — |
| python-azure-mgmt-datamigration | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-datamigration | — |
| python-azure-mgmt-datashare | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-datashare | — |
| python-azure-mgmt-deploymentmanager | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-deploymentmanager | — |
| python-azure-mgmt-devspaces | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-devspaces | — |
| python-azure-mgmt-devtestlabs | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-devtestlabs | — |
| python-azure-mgmt-dns | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-dns | — |
| python-azure-mgmt-documentdb | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-documentdb | — |
| python-azure-mgmt-edgegateway | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-edgegateway | — |
| python-azure-mgmt-eventgrid | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-eventgrid | — |
| python-azure-mgmt-eventhub | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-eventhub | — |
| python-azure-mgmt-frontdoor | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-frontdoor | — |
| python-azure-mgmt-hanaonazure | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-hanaonazure | — |
| python-azure-mgmt-hdinsight | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-hdinsight | — |
| python-azure-mgmt-healthcareapis | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-healthcareapis | — |
| python-azure-mgmt-hybridcompute | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-hybridcompute | — |
| python-azure-mgmt-imagebuilder | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-imagebuilder | — |
| python-azure-mgmt-iotcentral | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-iotcentral | — |
| python-azure-mgmt-iothub | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-iothub | — |
| python-azure-mgmt-iothubprovisioningservices | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-iothubprovisioningservices | — |
| python-azure-mgmt-keyvault | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-keyvault | — |
| python-azure-mgmt-kubernetesconfiguration | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-kubernetesconfiguration | — |
| python-azure-mgmt-kusto | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-kusto | — |
| python-azure-mgmt-labservices | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-labservices | — |
| python-azure-mgmt-loganalytics | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-loganalytics | — |
| python-azure-mgmt-logic | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-logic | — |
| python-azure-mgmt-machinelearningcompute | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-machinelearningcompute | — |
| python-azure-mgmt-machinelearningservices | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-machinelearningservices | — |
| python-azure-mgmt-managedservices | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-managedservices | — |
| python-azure-mgmt-managementgroups | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-managementgroups | — |
| python-azure-mgmt-managementpartner | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-managementpartner | — |
| python-azure-mgmt-maps | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-maps | — |
| python-azure-mgmt-marketplaceordering | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-marketplaceordering | — |
| python-azure-mgmt-media | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-media | — |
| python-azure-mgmt-mixedreality | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-mixedreality | — |
| python-azure-mgmt-monitor | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-monitor | — |
| python-azure-mgmt-msi | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-msi | — |
| python-azure-mgmt-netapp | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-netapp | — |
| python-azure-mgmt-network | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-network | — |
| python-azure-mgmt-notificationhubs | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-notificationhubs | — |
| python-azure-mgmt-nspkg | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-nspkg | — |
| python-azure-mgmt-peering | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-peering | — |
| python-azure-mgmt-policyinsights | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-policyinsights | — |
| python-azure-mgmt-powerbiembedded | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-powerbiembedded | — |
| python-azure-mgmt-privatedns | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-privatedns | — |
| python-azure-mgmt-rdbms | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-rdbms | — |
| python-azure-mgmt-recoveryservices | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-recoveryservices | — |
| python-azure-mgmt-recoveryservicesbackup | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-recoveryservicesbackup | — |
| python-azure-mgmt-redhatopenshift | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-redhatopenshift | — |
| python-azure-mgmt-redis | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-redis | — |
| python-azure-mgmt-regionmove | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-regionmove | — |
| python-azure-mgmt-relay | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-relay | — |
| python-azure-mgmt-reservations | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-reservations | — |
| python-azure-mgmt-resource | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-resource | — |
| python-azure-mgmt-resourcegraph | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-resourcegraph | — |
| python-azure-mgmt-resourcemover | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-resourcemover | — |
| python-azure-mgmt-scheduler | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-scheduler | — |
| python-azure-mgmt-search | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-search | — |
| python-azure-mgmt-security | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-security | — |
| python-azure-mgmt-serialconsole | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-serialconsole | — |
| python-azure-mgmt-servermanager | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-servermanager | — |
| python-azure-mgmt-servicebus | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-servicebus | — |
| python-azure-mgmt-servicefabric | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-servicefabric | — |
| python-azure-mgmt-signalr | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-signalr | — |
| python-azure-mgmt-sql | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-sql | — |
| python-azure-mgmt-sqlvirtualmachine | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-sqlvirtualmachine | — |
| python-azure-mgmt-storage | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-storage | — |
| python-azure-mgmt-storagecache | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-storagecache | — |
| python-azure-mgmt-storageimportexport | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-storageimportexport | — |
| python-azure-mgmt-storagesync | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-storagesync | — |
| python-azure-mgmt-streamanalytics | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-streamanalytics | — |
| python-azure-mgmt-subscription | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-subscription | — |
| python-azure-mgmt-synapse | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-synapse | — |
| python-azure-mgmt-trafficmanager | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-trafficmanager | — |
| python-azure-mgmt-vmwarecloudsimple | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-vmwarecloudsimple | — |
| python-azure-mgmt-web | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-mgmt-web | — |
| python-azure-monitor | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-monitor | — |
| python-azure-multiapi-storage | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-multiapi-storage | — |
| python-azure-nspkg | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-nspkg | — |
| python-azure-sdk | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-sdk | — |
| python-azure-search-documents | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-search-documents | — |
| python-azure-search-nspkg | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-search-nspkg | — |
| python-azure-servicebus | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-servicebus | — |
| python-azure-servicefabric | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-servicefabric | — |
| python-azure-servicemanagement-legacy | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-servicemanagement-legacy | — |
| python-azure-storage-blob | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-storage-blob | — |
| python-azure-storage-common | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-storage-common | — |
| python-azure-storage-file | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-storage-file | — |
| python-azure-storage-file-datalake | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-storage-file-datalake | — |
| python-azure-storage-file-share | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-storage-file-share | — |
| python-azure-storage-nspkg | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-storage-nspkg | — |
| python-azure-storage-queue | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-storage-queue | — |
| python-azure-synapse-accesscontrol | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-synapse-accesscontrol | — |
| python-azure-synapse-artifacts | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-synapse-artifacts | — |
| python-azure-synapse-nspkg | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-synapse-nspkg | — |
| python-azure-synapse-spark | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-azure-synapse-spark | — |
| python-bcrypt | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-bcrypt | — |
| python-boto3 | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-boto3 | — |
| python-botocore | affected | SUSE:OpenStack Cloud Crowbar 8 | python-botocore | — |
| python-botocore | affected | SUSE:OpenStack Cloud 8 | python-botocore | — |
| python-botocore | affected | SUSE:HPE Helion OpenStack 8 | python-botocore | — |
| python-botocore | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-botocore | — |
| python-brotlipy | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-brotlipy | — |
| python-colorama | affected | SUSE:OpenStack Cloud 7 | python-colorama | — |
| python-colorama | affected | SUSE:OpenStack Cloud Crowbar 8 | python-colorama | — |
| python-colorama | affected | SUSE:HPE Helion OpenStack 8 | python-colorama | — |
| python-colorama | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-colorama | — |
| python-colorama | affected | SUSE:OpenStack Cloud 8 | python-colorama | — |
| python-configparser | affected | SUSE:OpenStack Cloud 7 | python-configparser | — |
| python-configparser | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-configparser | — |
| python-contextlib2 | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-contextlib2 | — |
| python-Fabric | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-Fabric | — |
| python-fluidity-sm | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-fluidity-sm | — |
| python-importlib-metadata | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-importlib-metadata | — |
| python-importlib_resources | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-importlib_resources | — |
| python-invoke | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-invoke | — |
| python-javaproperties | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-javaproperties | — |
| python-jsmin | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-jsmin | — |
| python-jsondiff | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-jsondiff | — |
| python-knack | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-knack | — |
| python-lexicon | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-lexicon | — |
| python-more-itertools | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-more-itertools | — |
| python-msal | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-msal | — |
| python-msal-extensions | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-msal-extensions | — |
| python-msrest | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-msrest | — |
| python-msrestazure | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-msrestazure | — |
| python-multidict | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-multidict | — |
| python-nose | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-nose | — |
| python-paramiko | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-paramiko | — |
| python-pathlib2 | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-pathlib2 | — |
| python-pexpect | affected | SUSE:OpenStack Cloud 7 | python-pexpect | — |
| python-pexpect | affected | SUSE:OpenStack Cloud Crowbar 8 | python-pexpect | — |
| python-pexpect | affected | SUSE:HPE Helion OpenStack 8 | python-pexpect | — |
| python-pexpect | affected | SUSE:Linux Enterprise High Availability Extension 12 SP4 | python-pexpect | — |
| python-pexpect | affected | SUSE:Linux Enterprise High Availability Extension 12 SP3 | python-pexpect | — |
| python-pexpect | affected | SUSE:OpenStack Cloud 8 | python-pexpect | — |
| python-pexpect | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-pexpect | — |
| python-pexpect | affected | SUSE:Linux Enterprise Workstation Extension 12 SP5 | python-pexpect | — |
| python-pexpect | affected | SUSE:Linux Enterprise High Availability Extension 12 SP5 | python-pexpect | — |
| python-pkginfo | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-pkginfo | — |
| python-pluggy | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-pluggy | — |
| python-portalocker | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-portalocker | — |
| python-ptyprocess | affected | SUSE:OpenStack Cloud 7 | python-ptyprocess | — |
| python-ptyprocess | affected | SUSE:Linux Enterprise High Availability Extension 12 SP5 | python-ptyprocess | — |
| python-ptyprocess | affected | SUSE:Linux Enterprise High Availability Extension 12 SP4 | python-ptyprocess | — |
| python-ptyprocess | affected | SUSE:Linux Enterprise High Availability Extension 12 SP3 | python-ptyprocess | — |
| python-ptyprocess | affected | SUSE:HPE Helion OpenStack 8 | python-ptyprocess | — |
| python-ptyprocess | affected | SUSE:OpenStack Cloud Crowbar 8 | python-ptyprocess | — |
| python-ptyprocess | affected | SUSE:OpenStack Cloud 8 | python-ptyprocess | — |
| python-ptyprocess | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-ptyprocess | — |
| python-ptyprocess | affected | SUSE:Linux Enterprise Workstation Extension 12 SP5 | python-ptyprocess | — |
| python-pydocumentdb | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-pydocumentdb | — |
| python-pyfakefs | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-pyfakefs | — |
| python-Pygments | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-Pygments | — |
| python-PyNaCl | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-PyNaCl | — |
| python-pytest | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-pytest | — |
| python-pytest-mock | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-pytest-mock | — |
| python-pytest-relaxed | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-pytest-relaxed | — |
| python-pytz | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-pytz | — |
| python-PyYAML | affected | SUSE:OpenStack Cloud 8 | python-PyYAML | — |
| python-PyYAML | affected | SUSE:OpenStack Cloud 7 | python-PyYAML | — |
| python-PyYAML | affected | SUSE:OpenStack Cloud Crowbar 8 | python-PyYAML | — |
| python-PyYAML | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-PyYAML | — |
| python-PyYAML | affected | SUSE:HPE Helion OpenStack 8 | python-PyYAML | — |
| python-requests | affected | SUSE:Linux Enterprise Server for SAP Applications 12 SP5 | python-requests | — |
| python-requests | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-requests | — |
| python-requests | affected | SUSE:Linux Enterprise High Availability Extension 12 SP5 | python-requests | — |
| python-requests | affected | SUSE:Linux Enterprise Server 12 SP5 | python-requests | — |
| python-scandir | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-scandir | — |
| python-scandir | affected | SUSE:OpenStack Cloud 7 | python-scandir | — |
| python-scp | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-scp | — |
| python-six | affected | SUSE:OpenStack Cloud 8 | python-six | — |
| python-six | affected | SUSE:Linux Enterprise Server 12 SP3-BCL | python-six | — |
| python-six | affected | SUSE:OpenStack Cloud Crowbar 8 | python-six | — |
| python-six | affected | SUSE:Linux Enterprise Server 12 SP3-LTSS | python-six | — |
| python-six | affected | SUSE:HPE Helion OpenStack 8 | python-six | — |
| python-six | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-six | — |
| python-six | affected | SUSE:Linux Enterprise Server for SAP Applications 12 SP3 | python-six | — |
| python-six | affected | SUSE:Linux Enterprise Server 12 SP2-BCL | python-six | — |
| python-spec | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-spec | — |
| python-uamqp | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-uamqp | — |
| python-urllib3 | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-urllib3 | — |
| python-urllib3 | affected | SUSE:Linux Enterprise Software Development Kit 12 SP5 | python-urllib3 | — |
| python-urllib3 | affected | SUSE:Linux Enterprise Server for SAP Applications 12 SP4 | python-urllib3 | — |
| python-urllib3 | affected | SUSE:Linux Enterprise Server for SAP Applications 12 SP3 | python-urllib3 | — |
| python-urllib3 | affected | SUSE:Linux Enterprise Server 12 SP2-BCL | python-urllib3 | — |
| python-urllib3 | affected | SUSE:OpenStack Cloud Crowbar 9 | python-urllib3 | — |
| python-urllib3 | affected | SUSE:Linux Enterprise Workstation Extension 12 SP5 | python-urllib3 | — |
| python-urllib3 | affected | SUSE:Linux Enterprise Server 12 SP5 | python-urllib3 | — |
| python-urllib3 | affected | SUSE:OpenStack Cloud Crowbar 8 | python-urllib3 | — |
| python-urllib3 | affected | SUSE:Linux Enterprise Server for SAP Applications 12 SP5 | python-urllib3 | — |
| python-urllib3 | affected | SUSE:OpenStack Cloud 9 | python-urllib3 | — |
| python-urllib3 | affected | SUSE:OpenStack Cloud 8 | python-urllib3 | — |
| python-urllib3 | affected | SUSE:HPE Helion OpenStack 8 | python-urllib3 | — |
| python-urllib3 | affected | SUSE:Linux Enterprise Server 12 SP3-LTSS | python-urllib3 | — |
| python-urllib3 | affected | SUSE:Linux Enterprise Server 12 SP3-BCL | python-urllib3 | — |
| python-urllib3 | affected | SUSE:Linux Enterprise Server 12 SP4-LTSS | python-urllib3 | — |
| python-vcrpy | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-vcrpy | — |
| python-vsts | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-vsts | — |
| python-websocket-client | affected | SUSE:OpenStack Cloud 7 | python-websocket-client | — |
| python-websocket-client | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-websocket-client | — |
| python-wrapt | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-wrapt | — |
| python-xmltodict | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-xmltodict | — |
| python-yarl | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-yarl | — |
| python-zipp | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | python-zipp | — |
CVEs:CVE-2021-33195
Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC1035 format.
CVEs:CVE-2021-33195
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cloud_insights_telegraf_agent | affected | netapp | — | — |
| go | affected | golang | — | — |
DEBIAN-CVE-2021-30517
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-33197
In Go before 1.15.13 and 1.16.x before 1.16.5, some configurations of ReverseProxy (from net/http/httputil) result in a situation where an attacker is able to drop arbitrary headers.
CVEs:CVE-2021-33197
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go | affected | golang | — | — |
CVEs:CVE-2021-34506
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVEs:CVE-2021-34506
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
DEBIAN-CVE-2021-30513
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-34824
Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.
CVEs:CVE-2021-34824
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio | affected | istio | — | — |
CVEs:CVE-2021-35958
TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives
CVEs:CVE-2021-35958
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2021-0516
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0516
In ConnectionHandler::SdpCb of connection_handler.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2021-0522
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0522
DEBIAN-CVE-2021-30516
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30518
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
DEBIAN-CVE-2021-30544
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in BFCache in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30544
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30544
DEBIAN-CVE-2021-30512
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30510
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30515
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30553
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30548
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Loader in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30548
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30548
Use after free in Network service in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30553
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30553
DEBIAN-CVE-2021-30507
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30514
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30545
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30546
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-30545
Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30545
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30546
Use after free in Autofill in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30546
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
In handle_rc_metamsg_cmd of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2021-0507
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0507
DEBIAN-CVE-2021-30552
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30552
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30552
DEBIAN-CVE-2021-30508
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30549
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-30549
Use after free in Spell check in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30549
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2021-30519
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30511
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30520
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30550
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Accessibility in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30550
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30550
DEBIAN-CVE-2021-30509
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30506
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
In ActivityPicker.java, there is a possible bypass of user interaction in intent resolution due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for explo...
CVEs:CVE-2021-0506
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0506
CVEs:CVE-2021-0478
In updateDrawable of StatusBarIconView.java, there is a possible permission bypass due to an uncaught exception. This could lead to local escalation of privilege by running foreground services without notifying the user, with User execution privileges ...
CVEs:CVE-2021-0478
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...
CVEs:CVE-2021-0510
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0510
CVEs:CVE-2021-0511
In Dex2oat of dex2oat.cc, there is a possible way to inject bytecode into an app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2021-0511
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0513
In deleteNotificationChannel and related functions of NotificationManagerService.java, there is a possible permission bypass due to improper state validation. This could lead to local escalation of privilege via hidden services with no additional execu...
CVEs:CVE-2021-0513
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0508
In various functions of DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:...
CVEs:CVE-2021-0508
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0520
In several functions of MemoryFileSystem.cpp and related files, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...
CVEs:CVE-2021-0520
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0509
In various functions of CryptoPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2021-0509
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
DEBIAN-CVE-2021-30522
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in TabGroups in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30557
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30557
CVEs:CVE-2021-33198
In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.
CVEs:CVE-2021-33198
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go | affected | golang | — | — |
CVEs:CVE-2021-33741
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2021-33741
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
Helm uses crypto package vulnerable to panic from malformed X.509 certificate
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| dex-k8s-authenticator | affected | chainguard | dex-k8s-authenticator | — |
| helm/helm | affected | github.com | github.com/helm/helm | — |
| helm/v3 | affected | helm.sh | helm.sh/helm/v3 | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
Helm uses crypto package vulnerable to panic from malformed X.509 certificate
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| helm/helm | affected | github.com | github.com/helm/helm | — |
| helm/v3 | affected | helm.sh | helm.sh/helm/v3 | — |
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
Microsoft VsCode Kubernetes Tools Extension Elevation of Privilege Vulnerability
CVEs:CVE-2021-31938
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes_tools | affected | microsoft | — | — |
CVEs:CVE-2021-31938
Use after free in WebAudio in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30556
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30556
DEBIAN-CVE-2021-30531
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Missing Authorization in Jenkins Kubernetes CLI Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:kubernetes-cli | affected | Maven | org.jenkins-ci.plugins:kubernetes-cli | — |
Missing Authorization in Jenkins Kubernetes CLI Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:kubernetes-cli | affected | Maven | org.jenkins-ci.plugins:kubernetes-cli | — |
Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CVEs:CVE-2021-21661
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | jenkins | — | — |
Missing Authorization in Jenkins Kubernetes CLI Plugin
CVEs:CVE-2021-21661
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:kubernetes-cli | affected | Maven | org.jenkins-ci.plugins:kubernetes-cli | — |
Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in the cluster, bypassing authorization checks, when a gateway is configured with AUTO_PASSTHROUGH routing c...
CVEs:CVE-2021-31921
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio | affected | istio | — | — |
CVEs:CVE-2021-31921
DEBIAN-CVE-2021-30540
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Sharing in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page and user gesture.
CVEs:CVE-2021-30555
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2021-30555
DEBIAN-CVE-2021-30528
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30521
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30539
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30534
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30536
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30530
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30532
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30537
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30535
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| icu | affected | Debian:11 | icu | — |
| icu | affected | Debian:12 | icu | — |
| icu | affected | Debian:13 | icu | — |
| icu | affected | Debian:14 | icu | — |
DEBIAN-CVE-2021-30523
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30529
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30526
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30524
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30527
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30525
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
CVEs:CVE-2021-0517
In updateCapabilities of ConnectivityService.java, there is a possible incorrect network state determination due to a logic error in the code. This could lead to biasing of networking tasks to occur on non-VPN networks, which could lead to remote infor...
CVEs:CVE-2021-0517
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Improper Input Validation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ovn-org/ovn-kubernetes | affected | github.com | github.com/ovn-org/ovn-kubernetes | — |
Improper Input Validation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ovn-org/ovn-kubernetes | affected | github.com | github.com/ovn-org/ovn-kubernetes | — |
A vulnerability was found in OVN Kubernetes in versions up to and including 0.3.0 where the Egress Firewall does not reliably apply firewall rules when there is multiple DNS rules. It could lead to potentially lose of confidentiality, integrity or avai...
CVEs:CVE-2021-3499
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ovn-kubernetes | affected | ovn | — | — |
Improper Input Validation
CVEs:CVE-2021-3499
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ovn-org/ovn-kubernetes | affected | github.com | github.com/ovn-org/ovn-kubernetes | — |
Improper Input Validation
CVEs:CVE-2021-3499
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ovn-org/ovn-kubernetes | affected | github.com | github.com/ovn-org/ovn-kubernetes | — |
Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30542
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30542
Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30543
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30543
DEBIAN-CVE-2021-30542
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30543
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-0555
In RenderStruct of protostream_objectsource.cc, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: ...
CVEs:CVE-2021-0555
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-179161711
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| external/protobuf | affected | platform | platform/external/protobuf | — |
In fillMainDataBuf of pvmp3_framedecoder.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploita...
CVEs:CVE-2021-0558
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0558
CVEs:CVE-2021-0557
In setRange of ABuffer.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersion...
CVEs:CVE-2021-0557
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0559
In Lag_max of p_ol_wgh.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: Andr...
CVEs:CVE-2021-0559
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An improper input validation vulnerability in sdfffd_parse_chunk_PROP() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
CVEs:CVE-2021-25385
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-25385
CVEs:CVE-2021-25386
An improper input validation vulnerability in sdfffd_parse_chunk_FVER() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
CVEs:CVE-2021-25386
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Privilege Escalation in fscrypt
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google/fscrypt | affected | github.com | github.com/google/fscrypt | — |
Privilege Escalation in fscrypt
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google/fscrypt | affected | github.com | github.com/google/fscrypt | — |
In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media file due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interact...
CVEs:CVE-2021-0551
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0551
CVEs:CVE-2021-25387
An improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
CVEs:CVE-2021-25387
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-34475
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2021-34475
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
An improper input validation vulnerability in scmn_mfal_read() in libsapeextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
CVEs:CVE-2021-25383
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-25383
CVEs:CVE-2021-25384
An improper input validation vulnerability in sdfffd_parse_chunk_PROP() with Sample Rate Chunk in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
CVEs:CVE-2021-25384
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0561
In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ne...
CVEs:CVE-2021-0561
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-25417
Improper authorization in SDP SDK prior to SMR JUN-2021 Release 1 allows access to internal storage.
CVEs:CVE-2021-25417
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ...
CVEs:CVE-2021-0512
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0512
ASB-A-173843328
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2021-0504
In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not ne...
CVEs:CVE-2021-0504
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-n...
CVEs:CVE-2020-1742
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes-nmstate | affected | nmstate | — | — |
| openshift_virtualization | affected | redhat | — | — |
Withdrawn Advisory: kubernetes-nmstate Insecure Privilege Management
CVEs:CVE-2020-1742
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| nmstate/kubernetes-nmstate | affected | github.com | github.com/nmstate/kubernetes-nmstate | — |
CVEs:CVE-2021-22545
An attacker can craft a specific IdaPro *.i64 file that will cause the BinDiff plugin to load an invalid memory offset. This can allow the attacker to control the instruction pointer and execute arbitrary code. It is recommended to upgrade BinDiff 7
CVEs:CVE-2021-22545
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| bindiff | affected | — | — |
PUB-A-110373476
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
ASB-A-168918351
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kernel/linux-msm | affected | oss | oss/kernel/linux-msm | — |
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
CVEs:CVE-2021-25414
Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to copy or overwrite arbitrary files with Samsung Contacts privilege.
CVEs:CVE-2021-25414
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to get permissions to access arbitrary data with Samsung Contacts privilege.
CVEs:CVE-2021-25413
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-25413
A possible out of bounds write vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write.
CVEs:CVE-2021-25407
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-25407
CVEs:CVE-2021-25410
Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files with an escalated privilege.
CVEs:CVE-2021-25410
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Intent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.
CVEs:CVE-2021-25391
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-25391
CVEs:CVE-2021-25390
Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.
CVEs:CVE-2021-25390
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0606
In drm_syncobj_handle_to_fd of drm_syncobj.c, there is a possible use after free due to incorrect refcounting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Pro...
CVEs:CVE-2021-0606
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-168034487
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2021-25415
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writable.
CVEs:CVE-2021-25415
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation...
CVEs:CVE-2021-0553
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0553
CVEs:CVE-2021-25393
Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system uid data.
CVEs:CVE-2021-25393
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0567
In isRestricted of RemoteViews.java, there is a possible way to inject font files due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2021-0567
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
A possible buffer overflow vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write and code execution.
CVEs:CVE-2021-25408
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-25408
An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted applications.
CVEs:CVE-2021-25397
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-25397
CVEs:CVE-2021-25396
An improper input validation vulnerability in NPU firmware prior to SMR MAY-2021 Release 1 allows arbitrary memory write and code execution.
CVEs:CVE-2021-25396
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In /proc/net of the kernel filesystem, there is a possible information leak due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...
CVEs:CVE-2019-9475
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2019-9475
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel page outside code area.
CVEs:CVE-2021-25416
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-25416
In getBlockSum of fastcodemb.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...
CVEs:CVE-2021-0556
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0556
In ih264e_fmt_conv_422i_to_420sp of ih264e_fmt_conv.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed ...
CVEs:CVE-2021-0563
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0563
CVEs:CVE-2021-22548
An attacker can change the pointer to untrusted memory to point to trusted memory region which causes copying trusted memory to trusted memory, if the latter is later copied out, it allows for reading of memory regions from the trusted region. It is re...
CVEs:CVE-2021-22548
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| asylo | affected | — | — |
CVEs:CVE-2021-22549
An attacker can modify the address to point to trusted memory to overwrite arbitrary trusted memory. It is recommended to update past 0.6.2 or git commit https://github.com/google/asylo/commit/53ed5d8fd8118ced1466e509606dd2f473707a5c
CVEs:CVE-2021-22549
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| asylo | affected | — | — |
In onCreate of WifiScanModeActivity.java, there is a possible way to enable Wi-Fi scanning without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction...
CVEs:CVE-2021-0523
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0523
In memory management driver, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andr...
CVEs:CVE-2021-0525
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0525
CVEs:CVE-2021-0526
In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An...
CVEs:CVE-2021-0526
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An...
CVEs:CVE-2021-0530
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0530
ASB-A-185193929
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-185195264
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-185196175
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In permission declarations of DeviceAdminReceiver.java, there is a possible lack of broadcast protection due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...
CVEs:CVE-2021-0534
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0534
CVEs:CVE-2021-0536
In dropFile of WiFiInstaller, there is a way to delete files accessible to CertInstaller due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2021-0536
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In halWrapperDataCallback of hal_wrapper.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2021-0540
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0540
In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interac...
CVEs:CVE-2021-0541
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0541
CVEs:CVE-2021-0543
In phNxpNciHal_process_ext_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2021-0543
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0544
In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2021-0544
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC server with System execution privileges needed. User interaction is no...
CVEs:CVE-2021-0545
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0545
In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2021-0546
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0546
CVEs:CVE-2021-0548
In rw_i93_send_to_lower of rw_i93.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2021-0548
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0549
In sspRequestCallback of BondStateMachine.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not need...
CVEs:CVE-2021-0549
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0550
In onLoadFailed of AnnotateActivity.java, there is a possible way to gain WRITE_EXTERNAL_STORAGE permissions without user consent due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed....
CVEs:CVE-2021-0550
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In accessAudioHalPidscpp of TimeCheck.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Pr...
CVEs:CVE-2021-0566
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0566
CVEs:CVE-2021-0607
In iaxxx_calc_i2s_div of iaxxx-codec.c, there is a possible hardware port write with user controlled data due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i...
CVEs:CVE-2021-0607
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In handleAppLaunch of AppLaunchActivity.java, there is a possible arbitrary activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2021-0608
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0608
PUB-A-174870704
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-179688673
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| vendor/unbundled_google/packages/MarkupGoogle | affected | platform | platform/vendor/unbundled_google/packages/MarkupGoogle | — |
PUB-A-180950209
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In memory management driver, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...
CVEs:CVE-2021-0528
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0528
In memory management driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2021-0531
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0531
ASB-A-185195266
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-185195272
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2021-0521
In getAllPackages of PackageManagerService, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of cross-user permissions with no additional execution privileges needed. User int...
CVEs:CVE-2021-0521
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In onCreate of WiFiInstaller.java, there is a possible way to install a malicious Hotspot 2.0 configuration due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is ...
CVEs:CVE-2021-0537
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0537
CVEs:CVE-2021-0538
In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible exit of emergency callback mode due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is nee...
CVEs:CVE-2021-0538
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0542
In updateNotification of BeamTransferManager.java, there is a missing permission check. This could lead to local information disclosure of paired Bluetooth addresses with no additional execution privileges needed. User interaction is needed for exploit...
CVEs:CVE-2021-0542
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In RasterIntraUpdate of motion_est.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2021-0562
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0562
In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation...
CVEs:CVE-2021-0505
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0505
In wpas_ctrl_msg_queue_timeout of ctrl_iface_unix.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2021-0535
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0535
In onStart of ContactsDumpActivity.java, there is possible access to contacts due to a tapjacking/overlay attack. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product...
CVEs:CVE-2021-0569
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0569
CVEs:CVE-2021-25389
Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authentication.
CVEs:CVE-2021-25389
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0552
In getEndItemSliceAction of MediaOutputSlice.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2021-0552
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0570
In sendBugreportNotification of BugreportProgressService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed ...
CVEs:CVE-2021-0570
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In ActivityTaskManagerService.startActivity() and AppTaskImpl.startActivity() of ActivityTaskManagerService.java and AppTaskImpl.java, there is possible access to restricted activities due to a permissions bypass. This could lead to local escalation of...
CVEs:CVE-2021-0571
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0571
CVEs:CVE-2021-0572
In doNotification of AccountManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2021-0572
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In onReceive of NetInitiatedActivity.java, there is a possible way to supply an attacker-controlled value to a GPS HAL handler due to a missing permission check. This could lead to local escalation of privilege that may result in undefined behavior in ...
CVEs:CVE-2021-0547
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0547
CVEs:CVE-2021-0554
In isBackupServiceActive of BackupManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android...
CVEs:CVE-2021-0554
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to execute protected activity with system privilege via untrusted applications.
CVEs:CVE-2021-25412
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-25412
In archiveStoredConversation of MmsService.java, there is a possible way to archive message conversation without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges ne...
CVEs:CVE-2021-0539
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0539
CVEs:CVE-2021-0568
In onReceive of DevicePolicyManagerService.java, there is a possible enabling of disabled profiles due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n...
CVEs:CVE-2021-0568
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-25409
Improper access in Notification setting prior to SMR JUN-2021 Release 1 allows physically proximate attackers to set arbitrary notification via physically configuring device.
CVEs:CVE-2021-25409
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root privileged local attackers to write read-only kernel memory.
CVEs:CVE-2021-25411
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-25411
CVEs:CVE-2021-25392
Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to get sensitive information via changing the path.
CVEs:CVE-2021-25392
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-22550
An attacker can modify the pointers in enclave memory to overwrite arbitrary memory addresses within the secure enclave. It is recommended to update past 0.6.3 or git commit https://github.com/google/asylo/commit/a47ef55db2337d29de19c50cd29b0deb2871d31c
CVEs:CVE-2021-22550
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| asylo | affected | — | — |
CVEs:CVE-2021-0565
In wrapUserThread of AudioStream.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: ...
CVEs:CVE-2021-0565
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In memory management driver, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2021-0529
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0529
ASB-A-185195268
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary app.
CVEs:CVE-2021-25388
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-25388
CVEs:CVE-2021-0564
In decrypt of CryptoPlugin.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...
CVEs:CVE-2021-0564
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0532
In memory management driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2021-0532
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0533
In memory management driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2021-0533
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-185193932
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-185196177
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.