Google Security Advisories · June 2021 — Google Security Advisories
357 advisories 210 CVEs 35 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2021-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 35 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2021-31955

GoogleExploitedCISA KEV listedHIGH2021-06-08

Windows Kernel Information Disclosure Vulnerability

CVEs:CVE-2021-31955

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1809 affected microsoft
windows_10_1909 affected microsoft
windows_10_2004 affected microsoft
windows_10_20h2 affected microsoft
windows_10_21h1 affected microsoft
windows_server_2004 affected microsoft
windows_server_2019 affected microsoft
windows_server_20h2 affected microsoft
Upstream advisory

openSUSE-SU-2021:0938-1

Open SourceExploitedCISA KEV listedCRITICAL2021-06-28

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

openSUSE-SU-2021:0881-1

Open SourceExploitedCISA KEV listedCRITICAL2021-06-16

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

DEBIAN-CVE-2021-30551

Open SourceExploitedCISA KEV listedHIGH2021-06-15

DEBIAN-CVE-2021-30551

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30551

GoogleExploitedCISA KEV listedHIGH2021-06-10

Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30551

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30551

Project ZeroExploitedCISA KEV listed2021-06-10

Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30551

Upstream advisory

CVE-2021-33742

GoogleExploitedCISA KEV listedCRITICAL2021-06-08

Windows MSHTML Platform Remote Code Execution Vulnerability

CVEs:CVE-2021-33742

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_1909 affected microsoft
windows_10_2004 affected microsoft
windows_10_20h2 affected microsoft
windows_10_21h1 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
Upstream advisory

CVE-2021-31956

GoogleExploitedCISA KEV listedCRITICAL2021-06-08

Windows NTFS Elevation of Privilege Vulnerability

CVEs:CVE-2021-31956

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_1909 affected microsoft
windows_10_2004 affected microsoft
windows_10_20h2 affected microsoft
windows_10_21h1 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2004 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_20h2 affected microsoft
Upstream advisory

DEBIAN-CVE-2021-30533

Open SourceExploitedCISA KEV listedCRITICAL2021-06-07

DEBIAN-CVE-2021-30533

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

openSUSE-SU-2021:0840-1

Open SourceExploitedCISA KEV listedCRITICAL2021-06-04

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

openSUSE-SU-2021:0825-1

Open SourceExploitedCISA KEV listedCRITICAL2021-06-02

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

openSUSE-SU-2021:0898-1

Open SourceExploitedCISA KEV listedCRITICAL2021-06-21

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

CVE-2021-30554

GoogleExploitedCISA KEV listedCRITICAL2021-06-18

Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30554

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30554

Project ZeroExploitedCISA KEV listed2021-06-18

Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30554

Upstream advisory

CVE-2021-31199

GoogleExploitedCISA KEV listedCRITICAL2021-06-08

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

CVEs:CVE-2021-31199

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_1909 affected microsoft
windows_10_2004 affected microsoft
windows_10_20h2 affected microsoft
windows_10_21h1 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2004 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_20h2 affected microsoft
Upstream advisory

CVE-2021-31201

GoogleExploitedCISA KEV listedCRITICAL2021-06-08

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

CVEs:CVE-2021-31201

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_1909 affected microsoft
windows_10_2004 affected microsoft
windows_10_20h2 affected microsoft
windows_10_21h1 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2004 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_20h2 affected microsoft
Upstream advisory

CVE-2021-25394

Open SourceExploitedCISA KEV listedCRITICAL2021-06-11

A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.

CVEs:CVE-2021-25394

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2021-25394

Project ZeroExploitedCISA KEV listed2021-06-11

A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.

CVEs:CVE-2021-25394

Upstream advisory

CVE-2021-25395

Open SourceExploitedCISA KEV listedMEDIUM2021-06-11

A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.

CVEs:CVE-2021-25395

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2021-25395

Project ZeroExploitedCISA KEV listed2021-06-11

A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.

CVEs:CVE-2021-25395

Upstream advisory

DEBIAN-CVE-2021-30538

Open SourceExploitedVulnCheck KEV listedCRITICAL2021-06-07

DEBIAN-CVE-2021-30538

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-0527

Open SourceWeaponized exploitHIGH2021-06-08

In memory management driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2021-0527

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-185193931

GoogleWeaponized exploitHIGH2021-06-01

ASB-A-185193931

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

SUSE-SU-2021:14753-1

Open SourcePoC exploitCRITICAL2021-06-21

Security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
golang-github-wrouesnel-postgres_exporter affected SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS golang-github-wrouesnel-postgres_exporter
golang-github-wrouesnel-postgres_exporter affected SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS golang-github-wrouesnel-postgres_exporter
mgr-cfg affected SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS mgr-cfg
mgr-cfg affected SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS mgr-cfg
mgr-custom-info affected SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS mgr-custom-info
mgr-custom-info affected SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS mgr-custom-info
mgr-daemon affected SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS mgr-daemon
mgr-daemon affected SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS mgr-daemon
mgr-osad affected SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS mgr-osad
mgr-osad affected SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS mgr-osad
mgr-push affected SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS mgr-push
mgr-push affected SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS mgr-push
mgr-virtualization affected SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS mgr-virtualization
mgr-virtualization affected SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS mgr-virtualization
rhnlib affected SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS rhnlib
rhnlib affected SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS rhnlib
salt affected SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS salt
salt affected SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS salt
spacecmd affected SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS spacecmd
spacecmd affected SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS spacecmd
spacewalk-client-tools affected SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS spacewalk-client-tools
spacewalk-client-tools affected SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS spacewalk-client-tools
spacewalk-koan affected SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS spacewalk-koan
spacewalk-koan affected SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS spacewalk-koan
spacewalk-oscap affected SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS spacewalk-oscap
spacewalk-oscap affected SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS spacewalk-oscap
spacewalk-remote-utils affected SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS spacewalk-remote-utils
spacewalk-remote-utils affected SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS spacewalk-remote-utils
supportutils-plugin-susemanager-client affected SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS supportutils-plugin-susemanager-client
supportutils-plugin-susemanager-client affected SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS supportutils-plugin-susemanager-client
suseRegisterInfo affected SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS suseRegisterInfo
suseRegisterInfo affected SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS suseRegisterInfo
uyuni-common-libs affected SUSE:Linux Enterprise Server 11 SP3-CLIENT-TOOLS uyuni-common-libs
uyuni-common-libs affected SUSE:Linux Enterprise Server 11 SP4-CLIENT-TOOLS uyuni-common-libs
Upstream advisory

SUSE-SU-2021:2098-1

Open SourcePoC exploitHIGH2021-06-21

Security update for SUSE Manager Server 4.1

Affected products

ProductStatusVendorPackageEcosystem
cobbler affected SUSE:Manager Server Module 4.1 cobbler
golang-github-prometheus-node_exporter affected SUSE:Manager Server Module 4.1 golang-github-prometheus-node_exporter
grafana-formula affected SUSE:Manager Server Module 4.1 grafana-formula
patterns-suse-manager affected SUSE:Manager Server Module 4.1 patterns-suse-manager
prometheus-exporters-formula affected SUSE:Manager Server Module 4.1 prometheus-exporters-formula
py26-compat-salt affected SUSE:Manager Server Module 4.1 py26-compat-salt
py27-compat-salt affected SUSE:Manager Server Module 4.1 py27-compat-salt
spacewalk-admin affected SUSE:Manager Server Module 4.1 spacewalk-admin
spacewalk-backend affected SUSE:Manager Server Module 4.1 spacewalk-backend
spacewalk-branding affected SUSE:Manager Server Module 4.1 spacewalk-branding
spacewalk-certs-tools affected SUSE:Manager Server Module 4.1 spacewalk-certs-tools
spacewalk-java affected SUSE:Manager Server Module 4.1 spacewalk-java
spacewalk-utils affected SUSE:Manager Server Module 4.1 spacewalk-utils
spacewalk-web affected SUSE:Manager Server Module 4.1 spacewalk-web
susemanager affected SUSE:Manager Server Module 4.1 susemanager
susemanager-build-keys affected SUSE:Manager Server Module 4.1 susemanager-build-keys
susemanager-doc-indexes affected SUSE:Manager Server Module 4.1 susemanager-doc-indexes
susemanager-docs_en affected SUSE:Manager Server Module 4.1 susemanager-docs_en
susemanager-schema affected SUSE:Manager Server Module 4.1 susemanager-schema
susemanager-sls affected SUSE:Manager Server Module 4.1 susemanager-sls
susemanager-sync-data affected SUSE:Manager Server Module 4.1 susemanager-sync-data
tika-core affected SUSE:Manager Server Module 4.1 tika-core
uyuni-common-libs affected SUSE:Manager Server Module 4.1 uyuni-common-libs
Upstream advisory

ASB-A-174904512

GooglePoC exploitHIGH2021-06-01

ASB-A-174904512

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

DEBIAN-CVE-2021-30547

Open SourcePoC exploitCRITICAL2021-06-15

DEBIAN-CVE-2021-30547

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
firefox-esr affected Debian:11 firefox-esr
firefox-esr affected Debian:12 firefox-esr
firefox-esr affected Debian:13 firefox-esr
firefox-esr affected Debian:14 firefox-esr
thunderbird affected Debian:11 thunderbird
thunderbird affected Debian:12 thunderbird
thunderbird affected Debian:13 thunderbird
thunderbird affected Debian:14 thunderbird
Upstream advisory

CVE-2021-30547

GooglePoC exploitCRITICAL2021-06-10

Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVEs:CVE-2021-30547

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
firefox affected mozilla
Upstream advisory

CVE-2021-33196

GooglePoC exploitHIGH2021-06-28

In archive/zip in Go before 1.15.13 and 1.16.x before 1.16.5, a crafted file count (in an archive's header) can cause a NewReader or OpenReader panic.

CVEs:CVE-2021-33196

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
go affected golang
Upstream advisory

SUSE-RU-2021:2194-1

Open SourcePoC exploit2021-06-28

Recommended update for the Azure and AWS SDKs

Affected products

ProductStatusVendorPackageEcosystem
aws-cli affected SUSE:OpenStack Cloud 8 aws-cli
aws-cli affected SUSE:OpenStack Cloud Crowbar 8 aws-cli
aws-cli affected SUSE:Linux Enterprise Module for Public Cloud 12 aws-cli
aws-cli affected SUSE:HPE Helion OpenStack 8 aws-cli
azure-cli affected SUSE:Linux Enterprise Module for Public Cloud 12 azure-cli
azure-cli-command-modules-nspkg affected SUSE:Linux Enterprise Module for Public Cloud 12 azure-cli-command-modules-nspkg
azure-cli-core affected SUSE:Linux Enterprise Module for Public Cloud 12 azure-cli-core
azure-cli-nspkg affected SUSE:Linux Enterprise Module for Public Cloud 12 azure-cli-nspkg
azure-cli-telemetry affected SUSE:Linux Enterprise Module for Public Cloud 12 azure-cli-telemetry
azure-cli-test affected SUSE:Linux Enterprise Module for Public Cloud 12 azure-cli-test
libsodium affected SUSE:Linux Enterprise Module for Public Cloud 12 libsodium
libsodium affected SUSE:Linux Enterprise Module for Web and Scripting 12 libsodium
python3-requests affected SUSE:HPE Helion OpenStack 8 python3-requests
python3-requests affected SUSE:OpenStack Cloud 9 python3-requests
python3-requests affected SUSE:OpenStack Cloud Crowbar 9 python3-requests
python3-requests affected SUSE:OpenStack Cloud Crowbar 8 python3-requests
python3-requests affected SUSE:OpenStack Cloud 8 python3-requests
python3-requests affected SUSE:Linux Enterprise Workstation Extension 12 SP5 python3-requests
python3-requests affected SUSE:Linux Enterprise Server for SAP Applications 12 SP5 python3-requests
python3-requests affected SUSE:Linux Enterprise Server 12 SP5 python3-requests
python3-requests affected SUSE:Linux Enterprise Server 12 SP4-LTSS python3-requests
python3-requests affected SUSE:Linux Enterprise Server 12 SP3-BCL python3-requests
python3-requests affected SUSE:Linux Enterprise Server 12 SP3-LTSS python3-requests
python3-requests affected SUSE:Linux Enterprise Server 12 SP2-BCL python3-requests
python3-requests affected SUSE:Linux Enterprise Software Development Kit 12 SP5 python3-requests
python3-requests affected SUSE:Linux Enterprise Server for SAP Applications 12 SP4 python3-requests
python3-requests affected SUSE:Linux Enterprise Server for SAP Applications 12 SP3 python3-requests
python-adal affected SUSE:Linux Enterprise Module for Public Cloud 12 python-adal
python-antlr4-python3-runtime affected SUSE:Linux Enterprise Module for Public Cloud 12 python-antlr4-python3-runtime
python-applicationinsights affected SUSE:Linux Enterprise Module for Public Cloud 12 python-applicationinsights
python-atomicwrites affected SUSE:Linux Enterprise Module for Public Cloud 12 python-atomicwrites
python-attrs affected SUSE:Linux Enterprise Module for Public Cloud 12 python-attrs
python-azure-ai-anomalydetector affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-ai-anomalydetector
python-azure-ai-metricsadvisor affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-ai-metricsadvisor
python-azure-ai-nspkg affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-ai-nspkg
python-azure-ai-textanalytics affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-ai-textanalytics
python-azure-appconfiguration affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-appconfiguration
python-azure-applicationinsights affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-applicationinsights
python-azure-batch affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-batch
python-azure-cognitiveservices-anomalydetector affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-anomalydetector
python-azure-cognitiveservices-formrecognizer affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-formrecognizer
python-azure-cognitiveservices-inkrecognizer affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-inkrecognizer
python-azure-cognitiveservices-knowledge-nspkg affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-knowledge-nspkg
python-azure-cognitiveservices-knowledge-qnamaker affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-knowledge-qnamaker
python-azure-cognitiveservices-language-luis affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-language-luis
python-azure-cognitiveservices-language-nspkg affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-language-nspkg
python-azure-cognitiveservices-language-spellcheck affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-language-spellcheck
python-azure-cognitiveservices-language-textanalytics affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-language-textanalytics
python-azure-cognitiveservices-nspkg affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-nspkg
python-azure-cognitiveservices-personalizer affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-personalizer
python-azure-cognitiveservices-search-autosuggest affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-search-autosuggest
python-azure-cognitiveservices-search-customimagesearch affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-search-customimagesearch
python-azure-cognitiveservices-search-customsearch affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-search-customsearch
python-azure-cognitiveservices-search-entitysearch affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-search-entitysearch
python-azure-cognitiveservices-search-imagesearch affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-search-imagesearch
python-azure-cognitiveservices-search-newssearch affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-search-newssearch
python-azure-cognitiveservices-search-nspkg affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-search-nspkg
python-azure-cognitiveservices-search-videosearch affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-search-videosearch
python-azure-cognitiveservices-search-visualsearch affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-search-visualsearch
python-azure-cognitiveservices-search-websearch affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-search-websearch
python-azure-cognitiveservices-vision-computervision affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-vision-computervision
python-azure-cognitiveservices-vision-contentmoderator affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-vision-contentmoderator
python-azure-cognitiveservices-vision-customvision affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-vision-customvision
python-azure-cognitiveservices-vision-face affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-vision-face
python-azure-cognitiveservices-vision-nspkg affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cognitiveservices-vision-nspkg
python-azure-common affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-common
python-azure-communication-administration affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-communication-administration
python-azure-communication-chat affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-communication-chat
python-azure-communication-nspkg affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-communication-nspkg
python-azure-communication-sms affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-communication-sms
python-azure-core affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-core
python-azure-cosmos affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-cosmos
python-azure-datalake-store affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-datalake-store
python-azure-data-nspkg affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-data-nspkg
python-azure-data-tables affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-data-tables
python-azure-devops affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-devops
python-azure-eventgrid affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-eventgrid
python-azure-eventhub affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-eventhub
python-azure-eventhub-checkpointstoreblob affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-eventhub-checkpointstoreblob
python-azure-functions-devops-build affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-functions-devops-build
python-azure-graphrbac affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-graphrbac
python-azure-identity affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-identity
python-azure-keyvault affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-keyvault
python-azure-keyvault-administration affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-keyvault-administration
python-azure-keyvault-certificates affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-keyvault-certificates
python-azure-keyvault-keys affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-keyvault-keys
python-azure-keyvault-nspkg affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-keyvault-nspkg
python-azure-keyvault-secrets affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-keyvault-secrets
python-azure-loganalytics affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-loganalytics
python-azure-mgmt affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt
python-azure-mgmt-advisor affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-advisor
python-azure-mgmt-alertsmanagement affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-alertsmanagement
python-azure-mgmt-apimanagement affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-apimanagement
python-azure-mgmt-appconfiguration affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-appconfiguration
python-azure-mgmt-applicationinsights affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-applicationinsights
python-azure-mgmt-appplatform affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-appplatform
python-azure-mgmt-attestation affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-attestation
python-azure-mgmt-authorization affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-authorization
python-azure-mgmt-automanage affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-automanage
python-azure-mgmt-automation affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-automation
python-azure-mgmt-azurestack affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-azurestack
python-azure-mgmt-azurestackhci affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-azurestackhci
python-azure-mgmt-baremetalinfrastructure affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-baremetalinfrastructure
python-azure-mgmt-batch affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-batch
python-azure-mgmt-batchai affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-batchai
python-azure-mgmt-billing affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-billing
python-azure-mgmt-botservice affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-botservice
python-azure-mgmt-cdn affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-cdn
python-azure-mgmt-cognitiveservices affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-cognitiveservices
python-azure-mgmt-commerce affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-commerce
python-azure-mgmt-communication affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-communication
python-azure-mgmt-compute affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-compute
python-azure-mgmt-consumption affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-consumption
python-azure-mgmt-containerinstance affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-containerinstance
python-azure-mgmt-containerregistry affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-containerregistry
python-azure-mgmt-containerservice affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-containerservice
python-azure-mgmt-core affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-core
python-azure-mgmt-cosmosdb affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-cosmosdb
python-azure-mgmt-costmanagement affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-costmanagement
python-azure-mgmt-databoxedge affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-databoxedge
python-azure-mgmt-databricks affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-databricks
python-azure-mgmt-datafactory affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-datafactory
python-azure-mgmt-datalake-analytics affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-datalake-analytics
python-azure-mgmt-datalake-nspkg affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-datalake-nspkg
python-azure-mgmt-datalake-store affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-datalake-store
python-azure-mgmt-datamigration affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-datamigration
python-azure-mgmt-datashare affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-datashare
python-azure-mgmt-deploymentmanager affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-deploymentmanager
python-azure-mgmt-devspaces affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-devspaces
python-azure-mgmt-devtestlabs affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-devtestlabs
python-azure-mgmt-dns affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-dns
python-azure-mgmt-documentdb affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-documentdb
python-azure-mgmt-edgegateway affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-edgegateway
python-azure-mgmt-eventgrid affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-eventgrid
python-azure-mgmt-eventhub affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-eventhub
python-azure-mgmt-frontdoor affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-frontdoor
python-azure-mgmt-hanaonazure affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-hanaonazure
python-azure-mgmt-hdinsight affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-hdinsight
python-azure-mgmt-healthcareapis affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-healthcareapis
python-azure-mgmt-hybridcompute affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-hybridcompute
python-azure-mgmt-imagebuilder affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-imagebuilder
python-azure-mgmt-iotcentral affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-iotcentral
python-azure-mgmt-iothub affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-iothub
python-azure-mgmt-iothubprovisioningservices affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-iothubprovisioningservices
python-azure-mgmt-keyvault affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-keyvault
python-azure-mgmt-kubernetesconfiguration affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-kubernetesconfiguration
python-azure-mgmt-kusto affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-kusto
python-azure-mgmt-labservices affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-labservices
python-azure-mgmt-loganalytics affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-loganalytics
python-azure-mgmt-logic affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-logic
python-azure-mgmt-machinelearningcompute affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-machinelearningcompute
python-azure-mgmt-machinelearningservices affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-machinelearningservices
python-azure-mgmt-managedservices affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-managedservices
python-azure-mgmt-managementgroups affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-managementgroups
python-azure-mgmt-managementpartner affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-managementpartner
python-azure-mgmt-maps affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-maps
python-azure-mgmt-marketplaceordering affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-marketplaceordering
python-azure-mgmt-media affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-media
python-azure-mgmt-mixedreality affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-mixedreality
python-azure-mgmt-monitor affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-monitor
python-azure-mgmt-msi affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-msi
python-azure-mgmt-netapp affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-netapp
python-azure-mgmt-network affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-network
python-azure-mgmt-notificationhubs affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-notificationhubs
python-azure-mgmt-nspkg affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-nspkg
python-azure-mgmt-peering affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-peering
python-azure-mgmt-policyinsights affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-policyinsights
python-azure-mgmt-powerbiembedded affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-powerbiembedded
python-azure-mgmt-privatedns affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-privatedns
python-azure-mgmt-rdbms affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-rdbms
python-azure-mgmt-recoveryservices affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-recoveryservices
python-azure-mgmt-recoveryservicesbackup affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-recoveryservicesbackup
python-azure-mgmt-redhatopenshift affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-redhatopenshift
python-azure-mgmt-redis affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-redis
python-azure-mgmt-regionmove affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-regionmove
python-azure-mgmt-relay affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-relay
python-azure-mgmt-reservations affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-reservations
python-azure-mgmt-resource affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-resource
python-azure-mgmt-resourcegraph affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-resourcegraph
python-azure-mgmt-resourcemover affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-resourcemover
python-azure-mgmt-scheduler affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-scheduler
python-azure-mgmt-search affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-search
python-azure-mgmt-security affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-security
python-azure-mgmt-serialconsole affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-serialconsole
python-azure-mgmt-servermanager affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-servermanager
python-azure-mgmt-servicebus affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-servicebus
python-azure-mgmt-servicefabric affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-servicefabric
python-azure-mgmt-signalr affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-signalr
python-azure-mgmt-sql affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-sql
python-azure-mgmt-sqlvirtualmachine affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-sqlvirtualmachine
python-azure-mgmt-storage affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-storage
python-azure-mgmt-storagecache affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-storagecache
python-azure-mgmt-storageimportexport affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-storageimportexport
python-azure-mgmt-storagesync affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-storagesync
python-azure-mgmt-streamanalytics affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-streamanalytics
python-azure-mgmt-subscription affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-subscription
python-azure-mgmt-synapse affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-synapse
python-azure-mgmt-trafficmanager affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-trafficmanager
python-azure-mgmt-vmwarecloudsimple affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-vmwarecloudsimple
python-azure-mgmt-web affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-mgmt-web
python-azure-monitor affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-monitor
python-azure-multiapi-storage affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-multiapi-storage
python-azure-nspkg affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-nspkg
python-azure-sdk affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-sdk
python-azure-search-documents affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-search-documents
python-azure-search-nspkg affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-search-nspkg
python-azure-servicebus affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-servicebus
python-azure-servicefabric affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-servicefabric
python-azure-servicemanagement-legacy affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-servicemanagement-legacy
python-azure-storage-blob affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-storage-blob
python-azure-storage-common affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-storage-common
python-azure-storage-file affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-storage-file
python-azure-storage-file-datalake affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-storage-file-datalake
python-azure-storage-file-share affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-storage-file-share
python-azure-storage-nspkg affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-storage-nspkg
python-azure-storage-queue affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-storage-queue
python-azure-synapse-accesscontrol affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-synapse-accesscontrol
python-azure-synapse-artifacts affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-synapse-artifacts
python-azure-synapse-nspkg affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-synapse-nspkg
python-azure-synapse-spark affected SUSE:Linux Enterprise Module for Public Cloud 12 python-azure-synapse-spark
python-bcrypt affected SUSE:Linux Enterprise Module for Public Cloud 12 python-bcrypt
python-boto3 affected SUSE:Linux Enterprise Module for Public Cloud 12 python-boto3
python-botocore affected SUSE:OpenStack Cloud Crowbar 8 python-botocore
python-botocore affected SUSE:OpenStack Cloud 8 python-botocore
python-botocore affected SUSE:HPE Helion OpenStack 8 python-botocore
python-botocore affected SUSE:Linux Enterprise Module for Public Cloud 12 python-botocore
python-brotlipy affected SUSE:Linux Enterprise Module for Public Cloud 12 python-brotlipy
python-colorama affected SUSE:OpenStack Cloud 7 python-colorama
python-colorama affected SUSE:OpenStack Cloud Crowbar 8 python-colorama
python-colorama affected SUSE:HPE Helion OpenStack 8 python-colorama
python-colorama affected SUSE:Linux Enterprise Module for Public Cloud 12 python-colorama
python-colorama affected SUSE:OpenStack Cloud 8 python-colorama
python-configparser affected SUSE:OpenStack Cloud 7 python-configparser
python-configparser affected SUSE:Linux Enterprise Module for Public Cloud 12 python-configparser
python-contextlib2 affected SUSE:Linux Enterprise Module for Public Cloud 12 python-contextlib2
python-Fabric affected SUSE:Linux Enterprise Module for Public Cloud 12 python-Fabric
python-fluidity-sm affected SUSE:Linux Enterprise Module for Public Cloud 12 python-fluidity-sm
python-importlib-metadata affected SUSE:Linux Enterprise Module for Public Cloud 12 python-importlib-metadata
python-importlib_resources affected SUSE:Linux Enterprise Module for Public Cloud 12 python-importlib_resources
python-invoke affected SUSE:Linux Enterprise Module for Public Cloud 12 python-invoke
python-javaproperties affected SUSE:Linux Enterprise Module for Public Cloud 12 python-javaproperties
python-jsmin affected SUSE:Linux Enterprise Module for Public Cloud 12 python-jsmin
python-jsondiff affected SUSE:Linux Enterprise Module for Public Cloud 12 python-jsondiff
python-knack affected SUSE:Linux Enterprise Module for Public Cloud 12 python-knack
python-lexicon affected SUSE:Linux Enterprise Module for Public Cloud 12 python-lexicon
python-more-itertools affected SUSE:Linux Enterprise Module for Public Cloud 12 python-more-itertools
python-msal affected SUSE:Linux Enterprise Module for Public Cloud 12 python-msal
python-msal-extensions affected SUSE:Linux Enterprise Module for Public Cloud 12 python-msal-extensions
python-msrest affected SUSE:Linux Enterprise Module for Public Cloud 12 python-msrest
python-msrestazure affected SUSE:Linux Enterprise Module for Public Cloud 12 python-msrestazure
python-multidict affected SUSE:Linux Enterprise Module for Public Cloud 12 python-multidict
python-nose affected SUSE:Linux Enterprise Module for Public Cloud 12 python-nose
python-paramiko affected SUSE:Linux Enterprise Module for Public Cloud 12 python-paramiko
python-pathlib2 affected SUSE:Linux Enterprise Module for Public Cloud 12 python-pathlib2
python-pexpect affected SUSE:OpenStack Cloud 7 python-pexpect
python-pexpect affected SUSE:OpenStack Cloud Crowbar 8 python-pexpect
python-pexpect affected SUSE:HPE Helion OpenStack 8 python-pexpect
python-pexpect affected SUSE:Linux Enterprise High Availability Extension 12 SP4 python-pexpect
python-pexpect affected SUSE:Linux Enterprise High Availability Extension 12 SP3 python-pexpect
python-pexpect affected SUSE:OpenStack Cloud 8 python-pexpect
python-pexpect affected SUSE:Linux Enterprise Module for Public Cloud 12 python-pexpect
python-pexpect affected SUSE:Linux Enterprise Workstation Extension 12 SP5 python-pexpect
python-pexpect affected SUSE:Linux Enterprise High Availability Extension 12 SP5 python-pexpect
python-pkginfo affected SUSE:Linux Enterprise Module for Public Cloud 12 python-pkginfo
python-pluggy affected SUSE:Linux Enterprise Module for Public Cloud 12 python-pluggy
python-portalocker affected SUSE:Linux Enterprise Module for Public Cloud 12 python-portalocker
python-ptyprocess affected SUSE:OpenStack Cloud 7 python-ptyprocess
python-ptyprocess affected SUSE:Linux Enterprise High Availability Extension 12 SP5 python-ptyprocess
python-ptyprocess affected SUSE:Linux Enterprise High Availability Extension 12 SP4 python-ptyprocess
python-ptyprocess affected SUSE:Linux Enterprise High Availability Extension 12 SP3 python-ptyprocess
python-ptyprocess affected SUSE:HPE Helion OpenStack 8 python-ptyprocess
python-ptyprocess affected SUSE:OpenStack Cloud Crowbar 8 python-ptyprocess
python-ptyprocess affected SUSE:OpenStack Cloud 8 python-ptyprocess
python-ptyprocess affected SUSE:Linux Enterprise Module for Public Cloud 12 python-ptyprocess
python-ptyprocess affected SUSE:Linux Enterprise Workstation Extension 12 SP5 python-ptyprocess
python-pydocumentdb affected SUSE:Linux Enterprise Module for Public Cloud 12 python-pydocumentdb
python-pyfakefs affected SUSE:Linux Enterprise Module for Public Cloud 12 python-pyfakefs
python-Pygments affected SUSE:Linux Enterprise Module for Public Cloud 12 python-Pygments
python-PyNaCl affected SUSE:Linux Enterprise Module for Public Cloud 12 python-PyNaCl
python-pytest affected SUSE:Linux Enterprise Module for Public Cloud 12 python-pytest
python-pytest-mock affected SUSE:Linux Enterprise Module for Public Cloud 12 python-pytest-mock
python-pytest-relaxed affected SUSE:Linux Enterprise Module for Public Cloud 12 python-pytest-relaxed
python-pytz affected SUSE:Linux Enterprise Module for Public Cloud 12 python-pytz
python-PyYAML affected SUSE:OpenStack Cloud 8 python-PyYAML
python-PyYAML affected SUSE:OpenStack Cloud 7 python-PyYAML
python-PyYAML affected SUSE:OpenStack Cloud Crowbar 8 python-PyYAML
python-PyYAML affected SUSE:Linux Enterprise Module for Public Cloud 12 python-PyYAML
python-PyYAML affected SUSE:HPE Helion OpenStack 8 python-PyYAML
python-requests affected SUSE:Linux Enterprise Server for SAP Applications 12 SP5 python-requests
python-requests affected SUSE:Linux Enterprise Module for Public Cloud 12 python-requests
python-requests affected SUSE:Linux Enterprise High Availability Extension 12 SP5 python-requests
python-requests affected SUSE:Linux Enterprise Server 12 SP5 python-requests
python-scandir affected SUSE:Linux Enterprise Module for Public Cloud 12 python-scandir
python-scandir affected SUSE:OpenStack Cloud 7 python-scandir
python-scp affected SUSE:Linux Enterprise Module for Public Cloud 12 python-scp
python-six affected SUSE:OpenStack Cloud 8 python-six
python-six affected SUSE:Linux Enterprise Server 12 SP3-BCL python-six
python-six affected SUSE:OpenStack Cloud Crowbar 8 python-six
python-six affected SUSE:Linux Enterprise Server 12 SP3-LTSS python-six
python-six affected SUSE:HPE Helion OpenStack 8 python-six
python-six affected SUSE:Linux Enterprise Module for Public Cloud 12 python-six
python-six affected SUSE:Linux Enterprise Server for SAP Applications 12 SP3 python-six
python-six affected SUSE:Linux Enterprise Server 12 SP2-BCL python-six
python-spec affected SUSE:Linux Enterprise Module for Public Cloud 12 python-spec
python-uamqp affected SUSE:Linux Enterprise Module for Public Cloud 12 python-uamqp
python-urllib3 affected SUSE:Linux Enterprise Module for Public Cloud 12 python-urllib3
python-urllib3 affected SUSE:Linux Enterprise Software Development Kit 12 SP5 python-urllib3
python-urllib3 affected SUSE:Linux Enterprise Server for SAP Applications 12 SP4 python-urllib3
python-urllib3 affected SUSE:Linux Enterprise Server for SAP Applications 12 SP3 python-urllib3
python-urllib3 affected SUSE:Linux Enterprise Server 12 SP2-BCL python-urllib3
python-urllib3 affected SUSE:OpenStack Cloud Crowbar 9 python-urllib3
python-urllib3 affected SUSE:Linux Enterprise Workstation Extension 12 SP5 python-urllib3
python-urllib3 affected SUSE:Linux Enterprise Server 12 SP5 python-urllib3
python-urllib3 affected SUSE:OpenStack Cloud Crowbar 8 python-urllib3
python-urllib3 affected SUSE:Linux Enterprise Server for SAP Applications 12 SP5 python-urllib3
python-urllib3 affected SUSE:OpenStack Cloud 9 python-urllib3
python-urllib3 affected SUSE:OpenStack Cloud 8 python-urllib3
python-urllib3 affected SUSE:HPE Helion OpenStack 8 python-urllib3
python-urllib3 affected SUSE:Linux Enterprise Server 12 SP3-LTSS python-urllib3
python-urllib3 affected SUSE:Linux Enterprise Server 12 SP3-BCL python-urllib3
python-urllib3 affected SUSE:Linux Enterprise Server 12 SP4-LTSS python-urllib3
python-vcrpy affected SUSE:Linux Enterprise Module for Public Cloud 12 python-vcrpy
python-vsts affected SUSE:Linux Enterprise Module for Public Cloud 12 python-vsts
python-websocket-client affected SUSE:OpenStack Cloud 7 python-websocket-client
python-websocket-client affected SUSE:Linux Enterprise Module for Public Cloud 12 python-websocket-client
python-wrapt affected SUSE:Linux Enterprise Module for Public Cloud 12 python-wrapt
python-xmltodict affected SUSE:Linux Enterprise Module for Public Cloud 12 python-xmltodict
python-yarl affected SUSE:Linux Enterprise Module for Public Cloud 12 python-yarl
python-zipp affected SUSE:Linux Enterprise Module for Public Cloud 12 python-zipp
Upstream advisory

CVE-2021-33195

GooglePoC exploitCRITICAL2021-06-28

Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC1035 format.

CVEs:CVE-2021-33195

Affected products

ProductStatusVendorPackageEcosystem
cloud_insights_telegraf_agent affected netapp
go affected golang
Upstream advisory

DEBIAN-CVE-2021-30517

Open SourcePoC exploitHIGH2021-06-04

DEBIAN-CVE-2021-30517

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-33197

GooglePoC exploitMEDIUM2021-06-28

In Go before 1.15.13 and 1.16.x before 1.16.5, some configurations of ReverseProxy (from net/http/httputil) result in a situation where an attacker is able to drop arbitrary headers.

CVEs:CVE-2021-33197

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

CVE-2021-34506

Open SourcePoC exploitMEDIUM2021-06-25

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVEs:CVE-2021-34506

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2021-30513

Open SourcePoC exploitHIGH2021-06-04

DEBIAN-CVE-2021-30513

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-34824

Open SourcePoC exploitHIGH2021-06-29

Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.

CVEs:CVE-2021-34824

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio
Upstream advisory

CVE-2021-35958

Open SourcePoC exploitCRITICAL2021-06-30

TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives

CVEs:CVE-2021-35958

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-0516

Open SourcePoC exploitCRITICAL2021-06-08

In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2021-0516

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0522

Open SourcePoC exploitHIGH2021-06-08

In ConnectionHandler::SdpCb of connection_handler.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2021-0522

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2021-30516

Open SourcePoC exploitCRITICAL2021-06-04

DEBIAN-CVE-2021-30516

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30518

Open SourcePoC exploitCRITICAL2021-06-04

DEBIAN-CVE-2021-30518

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

DEBIAN-CVE-2021-30544

Open SourcePoC exploitCRITICAL2021-06-15

DEBIAN-CVE-2021-30544

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30544

GooglePoC exploitCRITICAL2021-06-10

Use after free in BFCache in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30544

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30512

Open SourcePoC exploitCRITICAL2021-06-04

DEBIAN-CVE-2021-30512

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30510

Open SourcePoC exploitCRITICAL2021-06-04

DEBIAN-CVE-2021-30510

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30515

Open SourcePoC exploitCRITICAL2021-06-04

DEBIAN-CVE-2021-30515

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30553

Open SourcePoC exploitCRITICAL2021-06-15

DEBIAN-CVE-2021-30553

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30548

Open SourcePoC exploitCRITICAL2021-06-15

DEBIAN-CVE-2021-30548

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30548

GooglePoC exploitCRITICAL2021-06-10

Use after free in Loader in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30548

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30553

GooglePoC exploitCRITICAL2021-06-10

Use after free in Network service in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30553

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30507

Open SourcePoC exploitHIGH2021-06-04

DEBIAN-CVE-2021-30507

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30514

Open SourcePoC exploitCRITICAL2021-06-04

DEBIAN-CVE-2021-30514

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30545

Open SourcePoC exploitCRITICAL2021-06-15

DEBIAN-CVE-2021-30545

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30546

Open SourcePoC exploitCRITICAL2021-06-15

DEBIAN-CVE-2021-30546

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30545

GooglePoC exploitCRITICAL2021-06-10

Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30545

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30546

GooglePoC exploitCRITICAL2021-06-10

Use after free in Autofill in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30546

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-0507

Open SourcePoC exploitHIGH2021-06-08

In handle_rc_metamsg_cmd of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2021-0507

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2021-30552

Open SourcePoC exploitCRITICAL2021-06-15

DEBIAN-CVE-2021-30552

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30552

GooglePoC exploitCRITICAL2021-06-10

Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30552

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30508

Open SourcePoC exploitCRITICAL2021-06-04

DEBIAN-CVE-2021-30508

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30549

Open SourcePoC exploitCRITICAL2021-06-15

DEBIAN-CVE-2021-30549

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30549

GooglePoC exploitCRITICAL2021-06-10

Use after free in Spell check in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30549

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30519

Open SourcePoC exploitCRITICAL2021-06-04

DEBIAN-CVE-2021-30519

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30511

Open SourcePoC exploitHIGH2021-06-04

DEBIAN-CVE-2021-30511

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30520

Open SourcePoC exploitCRITICAL2021-06-04

DEBIAN-CVE-2021-30520

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30550

Open SourcePoC exploitCRITICAL2021-06-15

DEBIAN-CVE-2021-30550

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30550

GooglePoC exploitCRITICAL2021-06-10

Use after free in Accessibility in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30550

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30509

Open SourcePoC exploitCRITICAL2021-06-04

DEBIAN-CVE-2021-30509

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30506

Open SourcePoC exploitHIGH2021-06-04

DEBIAN-CVE-2021-30506

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-0506

Open SourcePoC exploitHIGH2021-06-08

In ActivityPicker.java, there is a possible bypass of user interaction in intent resolution due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for explo...

CVEs:CVE-2021-0506

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0478

Open SourcePoC exploitHIGH2021-06-08

In updateDrawable of StatusBarIconView.java, there is a possible permission bypass due to an uncaught exception. This could lead to local escalation of privilege by running foreground services without notifying the user, with User execution privileges ...

CVEs:CVE-2021-0478

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0510

Open SourcePoC exploitHIGH2021-06-08

In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2021-0510

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0511

Open SourcePoC exploitHIGH2021-06-08

In Dex2oat of dex2oat.cc, there is a possible way to inject bytecode into an app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2021-0511

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0513

Open SourcePoC exploitHIGH2021-06-08

In deleteNotificationChannel and related functions of NotificationManagerService.java, there is a possible permission bypass due to improper state validation. This could lead to local escalation of privilege via hidden services with no additional execu...

CVEs:CVE-2021-0513

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0508

Open SourcePoC exploitHIGH2021-06-08

In various functions of DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:...

CVEs:CVE-2021-0508

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0520

Open SourcePoC exploitHIGH2021-06-08

In several functions of MemoryFileSystem.cpp and related files, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2021-0520

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0509

Open SourcePoC exploitHIGH2021-06-08

In various functions of CryptoPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2021-0509

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2021-30522

Open SourceCoalition ESS 30-63%CRITICAL2021-06-07

DEBIAN-CVE-2021-30522

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30557

GoogleCoalition ESS < 30%CRITICAL2021-06-18

Use after free in TabGroups in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30557

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-33198

GoogleCoalition ESS < 30%HIGH2021-06-28

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVEs:CVE-2021-33198

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

CVE-2021-33741

Open SourceCoalition ESS < 30%CRITICAL2021-06-07

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2021-33741

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

GHSA-cjjc-xp8v-855w

Open SourceCoalition ESS < 30%HIGH2021-06-23

Helm uses crypto package vulnerable to panic from malformed X.509 certificate

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
helm/helm affected github.com github.com/helm/helm
helm/v3 affected helm.sh helm.sh/helm/v3
k3d affected chainguard k3d
k3d affected wolfi k3d
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

GHSA-cjjc-xp8v-855w

Open SourceCoalition ESS < 30%HIGH2021-06-23

Helm uses crypto package vulnerable to panic from malformed X.509 certificate

Affected products

ProductStatusVendorPackageEcosystem
helm/helm affected github.com github.com/helm/helm
helm/v3 affected helm.sh helm.sh/helm/v3
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

CVE-2021-31938

Open SourceCoalition ESS < 30%CRITICAL2021-06-08

Microsoft VsCode Kubernetes Tools Extension Elevation of Privilege Vulnerability

CVEs:CVE-2021-31938

Affected products

ProductStatusVendorPackageEcosystem
kubernetes_tools affected microsoft
Upstream advisory

CVE-2021-30556

GoogleCoalition ESS < 30%CRITICAL2021-06-18

Use after free in WebAudio in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30556

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30531

Open SourceCoalition ESS < 30%CRITICAL2021-06-07

DEBIAN-CVE-2021-30531

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-xrg9-wwrq-xmx9

Open SourceCoalition ESS < 30%MEDIUM2021-06-16

Missing Authorization in Jenkins Kubernetes CLI Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:kubernetes-cli affected Maven org.jenkins-ci.plugins:kubernetes-cli
Upstream advisory

GHSA-xrg9-wwrq-xmx9

Open SourceCoalition ESS < 30%MEDIUM2021-06-16

Missing Authorization in Jenkins Kubernetes CLI Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:kubernetes-cli affected Maven org.jenkins-ci.plugins:kubernetes-cli
Upstream advisory

CVE-2021-21661

Open SourceCoalition ESS < 30%MEDIUM2021-06-10

Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

CVEs:CVE-2021-21661

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected jenkins
Upstream advisory

CVE-2021-21661

Open SourceCoalition ESS < 30%MEDIUM2021-06-10

Missing Authorization in Jenkins Kubernetes CLI Plugin

CVEs:CVE-2021-21661

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:kubernetes-cli affected Maven org.jenkins-ci.plugins:kubernetes-cli
Upstream advisory

CVE-2021-31921

Open SourceCoalition ESS < 30%CRITICAL2021-06-02

Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in the cluster, bypassing authorization checks, when a gateway is configured with AUTO_PASSTHROUGH routing c...

CVEs:CVE-2021-31921

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio
Upstream advisory

DEBIAN-CVE-2021-30540

Open SourceCoalition ESS < 30%MEDIUM2021-06-07

DEBIAN-CVE-2021-30540

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30555

GoogleCoalition ESS < 30%CRITICAL2021-06-18

Use after free in Sharing in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page and user gesture.

CVEs:CVE-2021-30555

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2021-30528

Open SourceCoalition ESS < 30%CRITICAL2021-06-07

DEBIAN-CVE-2021-30528

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30521

Open SourceCoalition ESS < 30%CRITICAL2021-06-07

DEBIAN-CVE-2021-30521

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30539

Open SourceCoalition ESS < 30%CRITICAL2021-06-07

DEBIAN-CVE-2021-30539

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30534

Open SourceCoalition ESS < 30%CRITICAL2021-06-07

DEBIAN-CVE-2021-30534

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30536

Open SourceCoalition ESS < 30%HIGH2021-06-07

DEBIAN-CVE-2021-30536

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30530

Open SourceCoalition ESS < 30%HIGH2021-06-07

DEBIAN-CVE-2021-30530

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30532

Open SourceCoalition ESS < 30%CRITICAL2021-06-07

DEBIAN-CVE-2021-30532

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30537

Open SourceCoalition ESS < 30%CRITICAL2021-06-07

DEBIAN-CVE-2021-30537

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30535

Open SourceCoalition ESS < 30%CRITICAL2021-06-07

DEBIAN-CVE-2021-30535

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
icu affected Debian:11 icu
icu affected Debian:12 icu
icu affected Debian:13 icu
icu affected Debian:14 icu
Upstream advisory

DEBIAN-CVE-2021-30523

Open SourceCoalition ESS < 30%CRITICAL2021-06-07

DEBIAN-CVE-2021-30523

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30529

Open SourceCoalition ESS < 30%CRITICAL2021-06-07

DEBIAN-CVE-2021-30529

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30526

Open SourceCoalition ESS < 30%CRITICAL2021-06-07

DEBIAN-CVE-2021-30526

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30524

Open SourceCoalition ESS < 30%CRITICAL2021-06-07

DEBIAN-CVE-2021-30524

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30527

Open SourceCoalition ESS < 30%CRITICAL2021-06-07

DEBIAN-CVE-2021-30527

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30525

Open SourceCoalition ESS < 30%CRITICAL2021-06-07

DEBIAN-CVE-2021-30525

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2021-0517

Open SourceCoalition ESS < 30%HIGH2021-06-08

In updateCapabilities of ConnectivityService.java, there is a possible incorrect network state determination due to a logic error in the code. This could lead to biasing of networking tasks to occur on non-VPN networks, which could lead to remote infor...

CVEs:CVE-2021-0517

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-57v4-m9jx-mh8r

Open SourceCoalition ESS < 30%MEDIUM2021-06-08

Improper Input Validation

Affected products

ProductStatusVendorPackageEcosystem
ovn-org/ovn-kubernetes affected github.com github.com/ovn-org/ovn-kubernetes
Upstream advisory

GHSA-57v4-m9jx-mh8r

Open SourceCoalition ESS < 30%MEDIUM2021-06-08

Improper Input Validation

Affected products

ProductStatusVendorPackageEcosystem
ovn-org/ovn-kubernetes affected github.com github.com/ovn-org/ovn-kubernetes
Upstream advisory

CVE-2021-3499

Open SourceCoalition ESS < 30%MEDIUM2021-06-02

A vulnerability was found in OVN Kubernetes in versions up to and including 0.3.0 where the Egress Firewall does not reliably apply firewall rules when there is multiple DNS rules. It could lead to potentially lose of confidentiality, integrity or avai...

CVEs:CVE-2021-3499

Affected products

ProductStatusVendorPackageEcosystem
ovn-kubernetes affected ovn
Upstream advisory

CVE-2021-3499

Open SourceCoalition ESS < 30%MEDIUM2021-06-02

Improper Input Validation

CVEs:CVE-2021-3499

Affected products

ProductStatusVendorPackageEcosystem
ovn-org/ovn-kubernetes affected github.com github.com/ovn-org/ovn-kubernetes
Upstream advisory

CVE-2021-3499

Open SourceCoalition ESS < 30%MEDIUM2021-06-02

Improper Input Validation

CVEs:CVE-2021-3499

Affected products

ProductStatusVendorPackageEcosystem
ovn-org/ovn-kubernetes affected github.com github.com/ovn-org/ovn-kubernetes
Upstream advisory

CVE-2021-30542

GoogleCoalition ESS < 30%CRITICAL2021-06-07

Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30542

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30543

GoogleCoalition ESS < 30%CRITICAL2021-06-07

Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30543

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30542

Open SourceCoalition ESS < 30%CRITICAL2021-06-07

DEBIAN-CVE-2021-30542

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30543

Open SourceCoalition ESS < 30%CRITICAL2021-06-07

DEBIAN-CVE-2021-30543

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-0555

Open SourceCoalition ESS < 30%HIGH2021-06-08

In RenderStruct of protostream_objectsource.cc, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: ...

CVEs:CVE-2021-0555

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-179161711

Open SourceCoalition ESS < 30%HIGH2021-06-01

PUB-A-179161711

Affected products

ProductStatusVendorPackageEcosystem
external/protobuf affected platform platform/external/protobuf
Upstream advisory

CVE-2021-0558

Open SourceCoalition ESS < 30%HIGH2021-06-08

In fillMainDataBuf of pvmp3_framedecoder.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploita...

CVEs:CVE-2021-0558

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0557

Open SourceCoalition ESS < 30%HIGH2021-06-08

In setRange of ABuffer.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersion...

CVEs:CVE-2021-0557

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0559

Open SourceCoalition ESS < 30%MEDIUM2021-06-08

In Lag_max of p_ol_wgh.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: Andr...

CVEs:CVE-2021-0559

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25385

Open SourceCoalition ESS < 30%CRITICAL2021-06-11

An improper input validation vulnerability in sdfffd_parse_chunk_PROP() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

CVEs:CVE-2021-25385

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25386

Open SourceCoalition ESS < 30%CRITICAL2021-06-11

An improper input validation vulnerability in sdfffd_parse_chunk_FVER() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

CVEs:CVE-2021-25386

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-qj26-7grj-whg3

GoogleCoalition ESS < 30%CRITICAL2021-06-23

Privilege Escalation in fscrypt

Affected products

ProductStatusVendorPackageEcosystem
google/fscrypt affected github.com github.com/google/fscrypt
Upstream advisory

GHSA-qj26-7grj-whg3

GoogleCoalition ESS < 30%CRITICAL2021-06-23

Privilege Escalation in fscrypt

Affected products

ProductStatusVendorPackageEcosystem
google/fscrypt affected github.com github.com/google/fscrypt
Upstream advisory

CVE-2021-0551

Open SourceCoalition ESS < 30%MEDIUM2021-06-08

In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media file due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interact...

CVEs:CVE-2021-0551

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25387

Open SourceCoalition ESS < 30%CRITICAL2021-06-11

An improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

CVEs:CVE-2021-25387

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-34475

Open SourceCoalition ESS < 30%CRITICAL2021-06-25

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2021-34475

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2021-25383

Open SourceCoalition ESS < 30%CRITICAL2021-06-11

An improper input validation vulnerability in scmn_mfal_read() in libsapeextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

CVEs:CVE-2021-25383

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25384

Open SourceCoalition ESS < 30%CRITICAL2021-06-11

An improper input validation vulnerability in sdfffd_parse_chunk_PROP() with Sample Rate Chunk in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

CVEs:CVE-2021-25384

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0561

Open SourceCoalition ESS < 30%HIGH2021-06-08

In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ne...

CVEs:CVE-2021-0561

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-25417

Open SourceCoalition ESS < 30%HIGH2021-06-11

Improper authorization in SDP SDK prior to SMR JUN-2021 Release 1 allows access to internal storage.

CVEs:CVE-2021-25417

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0512

Open SourceCoalition ESS < 30%HIGH2021-06-08

In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ...

CVEs:CVE-2021-0512

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-173843328

GoogleCoalition ESS < 30%HIGH2021-06-01

ASB-A-173843328

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-0504

Open SourceCoalition ESS < 30%MEDIUM2021-06-08

In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not ne...

CVEs:CVE-2021-0504

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-1742

Open SourceCoalition ESS < 30%HIGH2021-06-07

An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-n...

CVEs:CVE-2020-1742

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-nmstate affected nmstate
openshift_virtualization affected redhat
Upstream advisory

CVE-2020-1742

Open SourceCoalition ESS < 30%HIGH2021-06-07

Withdrawn Advisory: kubernetes-nmstate Insecure Privilege Management

CVEs:CVE-2020-1742

Affected products

ProductStatusVendorPackageEcosystem
nmstate/kubernetes-nmstate affected github.com github.com/nmstate/kubernetes-nmstate
Upstream advisory

CVE-2021-22545

GoogleCoalition ESS < 30%CRITICAL2021-06-29

An attacker can craft a specific IdaPro *.i64 file that will cause the BinDiff plugin to load an invalid memory offset. This can allow the attacker to control the instruction pointer and execute arbitrary code. It is recommended to upgrade BinDiff 7

CVEs:CVE-2021-22545

Affected products

ProductStatusVendorPackageEcosystem
bindiff affected google
Upstream advisory

PUB-A-110373476

GoogleCoalition ESS < 30%MEDIUM2021-06-01

PUB-A-110373476

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

ASB-A-168918351

GoogleCoalition ESS < 30%2021-06-01

ASB-A-168918351

Affected products

ProductStatusVendorPackageEcosystem
kernel/linux-msm affected oss oss/kernel/linux-msm
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2021-25414

Open SourceCoalition ESS < 30%HIGH2021-06-11

Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to copy or overwrite arbitrary files with Samsung Contacts privilege.

CVEs:CVE-2021-25414

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25413

Open SourceCoalition ESS < 30%MEDIUM2021-06-11

Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to get permissions to access arbitrary data with Samsung Contacts privilege.

CVEs:CVE-2021-25413

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25407

Open SourceCoalition ESS < 30%CRITICAL2021-06-11

A possible out of bounds write vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write.

CVEs:CVE-2021-25407

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25410

Open SourceCoalition ESS < 30%HIGH2021-06-11

Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files with an escalated privilege.

CVEs:CVE-2021-25410

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25391

Open SourceCoalition ESS < 30%MEDIUM2021-06-11

Intent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.

CVEs:CVE-2021-25391

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25390

Open SourceCoalition ESS < 30%MEDIUM2021-06-11

Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.

CVEs:CVE-2021-25390

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0606

Open SourceCoalition ESS < 30%HIGH2021-06-08

In drm_syncobj_handle_to_fd of drm_syncobj.c, there is a possible use after free due to incorrect refcounting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2021-0606

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-168034487

GoogleCoalition ESS < 30%HIGH2021-06-01

PUB-A-168034487

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-25415

Open SourceCoalition ESS < 30%MEDIUM2021-06-11

Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writable.

CVEs:CVE-2021-25415

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0553

Open SourceCoalition ESS < 30%HIGH2021-06-08

In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation...

CVEs:CVE-2021-0553

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25393

Open SourceCoalition ESS < 30%MEDIUM2021-06-11

Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system uid data.

CVEs:CVE-2021-25393

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0567

Open SourceCoalition ESS < 30%HIGH2021-06-08

In isRestricted of RemoteViews.java, there is a possible way to inject font files due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2021-0567

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25408

Open SourceCoalition ESS < 30%CRITICAL2021-06-11

A possible buffer overflow vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write and code execution.

CVEs:CVE-2021-25408

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25397

Open SourceCoalition ESS < 30%MEDIUM2021-06-11

An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted applications.

CVEs:CVE-2021-25397

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25396

Open SourceCoalition ESS < 30%CRITICAL2021-06-11

An improper input validation vulnerability in NPU firmware prior to SMR MAY-2021 Release 1 allows arbitrary memory write and code execution.

CVEs:CVE-2021-25396

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9475

Open SourceCoalition ESS < 30%MEDIUM2021-06-11

In /proc/net of the kernel filesystem, there is a possible information leak due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2019-9475

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25416

Open SourceCoalition ESS < 30%MEDIUM2021-06-11

Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel page outside code area.

CVEs:CVE-2021-25416

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0556

Open SourceCoalition ESS < 30%HIGH2021-06-08

In getBlockSum of fastcodemb.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...

CVEs:CVE-2021-0556

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0563

Open SourceCoalition ESS < 30%HIGH2021-06-08

In ih264e_fmt_conv_422i_to_420sp of ih264e_fmt_conv.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2021-0563

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-22548

GoogleCoalition ESS < 30%HIGH2021-06-08

An attacker can change the pointer to untrusted memory to point to trusted memory region which causes copying trusted memory to trusted memory, if the latter is later copied out, it allows for reading of memory regions from the trusted region. It is re...

CVEs:CVE-2021-22548

Affected products

ProductStatusVendorPackageEcosystem
asylo affected google
Upstream advisory

CVE-2021-22549

GoogleCoalition ESS < 30%HIGH2021-06-08

An attacker can modify the address to point to trusted memory to overwrite arbitrary trusted memory. It is recommended to update past 0.6.2 or git commit https://github.com/google/asylo/commit/53ed5d8fd8118ced1466e509606dd2f473707a5c

CVEs:CVE-2021-22549

Affected products

ProductStatusVendorPackageEcosystem
asylo affected google
Upstream advisory

CVE-2021-0523

Open SourceCoalition ESS < 30%HIGH2021-06-08

In onCreate of WifiScanModeActivity.java, there is a possible way to enable Wi-Fi scanning without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction...

CVEs:CVE-2021-0523

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0525

Open SourceCoalition ESS < 30%HIGH2021-06-08

In memory management driver, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andr...

CVEs:CVE-2021-0525

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0526

Open SourceCoalition ESS < 30%HIGH2021-06-08

In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An...

CVEs:CVE-2021-0526

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0530

Open SourceCoalition ESS < 30%HIGH2021-06-08

In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An...

CVEs:CVE-2021-0530

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-185193929

GoogleCoalition ESS < 30%HIGH2021-06-01

ASB-A-185193929

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-185195264

GoogleCoalition ESS < 30%HIGH2021-06-01

ASB-A-185195264

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-185196175

GoogleCoalition ESS < 30%HIGH2021-06-01

ASB-A-185196175

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0534

Open SourceCoalition ESS < 30%HIGH2021-06-08

In permission declarations of DeviceAdminReceiver.java, there is a possible lack of broadcast protection due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...

CVEs:CVE-2021-0534

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0536

Open SourceCoalition ESS < 30%HIGH2021-06-08

In dropFile of WiFiInstaller, there is a way to delete files accessible to CertInstaller due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2021-0536

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0540

Open SourceCoalition ESS < 30%HIGH2021-06-08

In halWrapperDataCallback of hal_wrapper.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2021-0540

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0541

Open SourceCoalition ESS < 30%MEDIUM2021-06-08

In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interac...

CVEs:CVE-2021-0541

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0543

Open SourceCoalition ESS < 30%HIGH2021-06-08

In phNxpNciHal_process_ext_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2021-0543

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0544

Open SourceCoalition ESS < 30%HIGH2021-06-08

In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2021-0544

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0545

Open SourceCoalition ESS < 30%HIGH2021-06-08

In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC server with System execution privileges needed. User interaction is no...

CVEs:CVE-2021-0545

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0546

Open SourceCoalition ESS < 30%HIGH2021-06-08

In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2021-0546

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0548

Open SourceCoalition ESS < 30%HIGH2021-06-08

In rw_i93_send_to_lower of rw_i93.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2021-0548

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0549

Open SourceCoalition ESS < 30%MEDIUM2021-06-08

In sspRequestCallback of BondStateMachine.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not need...

CVEs:CVE-2021-0549

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0550

Open SourceCoalition ESS < 30%HIGH2021-06-08

In onLoadFailed of AnnotateActivity.java, there is a possible way to gain WRITE_EXTERNAL_STORAGE permissions without user consent due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed....

CVEs:CVE-2021-0550

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0566

Open SourceCoalition ESS < 30%MEDIUM2021-06-08

In accessAudioHalPidscpp of TimeCheck.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Pr...

CVEs:CVE-2021-0566

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0607

Open SourceCoalition ESS < 30%HIGH2021-06-08

In iaxxx_calc_i2s_div of iaxxx-codec.c, there is a possible hardware port write with user controlled data due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i...

CVEs:CVE-2021-0607

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0608

Open SourceCoalition ESS < 30%HIGH2021-06-08

In handleAppLaunch of AppLaunchActivity.java, there is a possible arbitrary activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2021-0608

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-174870704

GoogleCoalition ESS < 30%NONE2021-06-01

PUB-A-174870704

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-179688673

GoogleCoalition ESS < 30%NONE2021-06-01

PUB-A-179688673

Affected products

ProductStatusVendorPackageEcosystem
vendor/unbundled_google/packages/MarkupGoogle affected platform platform/vendor/unbundled_google/packages/MarkupGoogle
Upstream advisory

PUB-A-180950209

GoogleCoalition ESS < 30%NONE2021-06-01

PUB-A-180950209

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0528

Open SourceCoalition ESS < 30%HIGH2021-06-08

In memory management driver, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...

CVEs:CVE-2021-0528

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0531

Open SourceCoalition ESS < 30%HIGH2021-06-08

In memory management driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2021-0531

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-185195266

GoogleCoalition ESS < 30%HIGH2021-06-01

ASB-A-185195266

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-185195272

GoogleCoalition ESS < 30%HIGH2021-06-01

ASB-A-185195272

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0521

Open SourceCoalition ESS < 30%MEDIUM2021-06-08

In getAllPackages of PackageManagerService, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of cross-user permissions with no additional execution privileges needed. User int...

CVEs:CVE-2021-0521

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0537

Open SourceCoalition ESS < 30%HIGH2021-06-08

In onCreate of WiFiInstaller.java, there is a possible way to install a malicious Hotspot 2.0 configuration due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is ...

CVEs:CVE-2021-0537

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0538

Open SourceCoalition ESS < 30%HIGH2021-06-08

In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible exit of emergency callback mode due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is nee...

CVEs:CVE-2021-0538

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0542

Open SourceCoalition ESS < 30%MEDIUM2021-06-08

In updateNotification of BeamTransferManager.java, there is a missing permission check. This could lead to local information disclosure of paired Bluetooth addresses with no additional execution privileges needed. User interaction is needed for exploit...

CVEs:CVE-2021-0542

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0562

Open SourceCoalition ESS < 30%MEDIUM2021-06-08

In RasterIntraUpdate of motion_est.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2021-0562

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0505

Open SourceCoalition ESS < 30%HIGH2021-06-08

In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation...

CVEs:CVE-2021-0505

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0535

Open SourceCoalition ESS < 30%HIGH2021-06-08

In wpas_ctrl_msg_queue_timeout of ctrl_iface_unix.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2021-0535

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0569

Open SourceCoalition ESS < 30%MEDIUM2021-06-08

In onStart of ContactsDumpActivity.java, there is possible access to contacts due to a tapjacking/overlay attack. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product...

CVEs:CVE-2021-0569

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25389

Open SourceCoalition ESS < 30%MEDIUM2021-06-11

Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authentication.

CVEs:CVE-2021-25389

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0552

Open SourceCoalition ESS < 30%MEDIUM2021-06-08

In getEndItemSliceAction of MediaOutputSlice.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2021-0552

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0570

Open SourceCoalition ESS < 30%HIGH2021-06-08

In sendBugreportNotification of BugreportProgressService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed ...

CVEs:CVE-2021-0570

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0571

Open SourceCoalition ESS < 30%HIGH2021-06-08

In ActivityTaskManagerService.startActivity() and AppTaskImpl.startActivity() of ActivityTaskManagerService.java and AppTaskImpl.java, there is possible access to restricted activities due to a permissions bypass. This could lead to local escalation of...

CVEs:CVE-2021-0571

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0572

Open SourceCoalition ESS < 30%MEDIUM2021-06-08

In doNotification of AccountManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2021-0572

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0547

Open SourceCoalition ESS < 30%HIGH2021-06-08

In onReceive of NetInitiatedActivity.java, there is a possible way to supply an attacker-controlled value to a GPS HAL handler due to a missing permission check. This could lead to local escalation of privilege that may result in undefined behavior in ...

CVEs:CVE-2021-0547

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0554

Open SourceCoalition ESS < 30%MEDIUM2021-06-08

In isBackupServiceActive of BackupManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android...

CVEs:CVE-2021-0554

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25412

Open SourceCoalition ESS < 30%HIGH2021-06-11

An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to execute protected activity with system privilege via untrusted applications.

CVEs:CVE-2021-25412

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0539

Open SourceCoalition ESS < 30%HIGH2021-06-08

In archiveStoredConversation of MmsService.java, there is a possible way to archive message conversation without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges ne...

CVEs:CVE-2021-0539

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0568

Open SourceCoalition ESS < 30%HIGH2021-06-08

In onReceive of DevicePolicyManagerService.java, there is a possible enabling of disabled profiles due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n...

CVEs:CVE-2021-0568

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25409

Open SourceCoalition ESS < 30%LOW2021-06-11

Improper access in Notification setting prior to SMR JUN-2021 Release 1 allows physically proximate attackers to set arbitrary notification via physically configuring device.

CVEs:CVE-2021-25409

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25411

Open SourceCoalition ESS < 30%MEDIUM2021-06-11

Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root privileged local attackers to write read-only kernel memory.

CVEs:CVE-2021-25411

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25392

Open SourceCoalition ESS < 30%HIGH2021-06-11

Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to get sensitive information via changing the path.

CVEs:CVE-2021-25392

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-22550

GoogleCoalition ESS < 30%HIGH2021-06-08

An attacker can modify the pointers in enclave memory to overwrite arbitrary memory addresses within the secure enclave. It is recommended to update past 0.6.3 or git commit https://github.com/google/asylo/commit/a47ef55db2337d29de19c50cd29b0deb2871d31c

CVEs:CVE-2021-22550

Affected products

ProductStatusVendorPackageEcosystem
asylo affected google
Upstream advisory

CVE-2021-0565

Open SourceCoalition ESS < 30%HIGH2021-06-08

In wrapUserThread of AudioStream.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: ...

CVEs:CVE-2021-0565

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0529

Open SourceCoalition ESS < 30%HIGH2021-06-08

In memory management driver, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2021-0529

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-185195268

GoogleCoalition ESS < 30%HIGH2021-06-01

ASB-A-185195268

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-25388

Open SourceCoalition ESS < 30%HIGH2021-06-11

Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary app.

CVEs:CVE-2021-25388

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0564

Open SourceCoalition ESS < 30%HIGH2021-06-08

In decrypt of CryptoPlugin.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...

CVEs:CVE-2021-0564

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0532

Open SourceCoalition ESS < 30%HIGH2021-06-08

In memory management driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2021-0532

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0533

Open SourceCoalition ESS < 30%HIGH2021-06-08

In memory management driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2021-0533

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-185193932

GoogleCoalition ESS < 30%HIGH2021-06-01

ASB-A-185193932

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-185196177

GoogleCoalition ESS < 30%HIGH2021-06-01

ASB-A-185196177

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.