Google Security Advisories · September 2021 — Google Security Advisories
265 advisories 154 CVEs 17 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2021-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 17 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2021-41773

GoogleExploitedCISA KEV listedCRITICAL2021-09-29

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories ...

CVEs:CVE-2021-41773

Affected products

ProductStatusVendorPackageEcosystem
cloud_backup affected netapp
fedora affected fedoraproject
http_server affected apache
instantis_enterprisetrack affected oracle
Upstream advisory

CVE-2021-40444

GoogleExploitedCISA KEV listedCRITICAL2021-09-08

Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office document...

CVEs:CVE-2021-40444

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_1909 affected microsoft
windows_10_2004 affected microsoft
windows_10_20h2 affected microsoft
windows_10_21h1 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2004 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
windows_server_20h2 affected microsoft
Upstream advisory

openSUSE-SU-2021:1303-1

Open SourceExploitedCISA KEV listedCRITICAL2021-09-22

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

openSUSE-SU-2021:1300-1

Open SourceExploitedCISA KEV listedCRITICAL2021-09-21

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

CVE-2021-30632

GoogleExploitedCISA KEV listedCRITICAL2021-09-14

Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30632

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30632

Project ZeroExploitedCISA KEV listed2021-09-14

Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30632

Upstream advisory

CVE-2021-30633

GoogleExploitedCISA KEV listedCRITICAL2021-09-14

Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-30633

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-30633

Project ZeroExploitedCISA KEV listed2021-09-14

Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-30633

Upstream advisory

CVE-2021-37973

GoogleExploitedCISA KEV listedCRITICAL2021-09-27

Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-37973

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-37973

Project ZeroExploitedCISA KEV listed2021-09-27

Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-37973

Upstream advisory

GHSA-74j8-88mm-7496

Open SourceActive exploitation (sightings)MEDIUM2021-09-21

Confused Deputy in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-74j8-88mm-7496

Open SourceActive exploitation (sightings)MEDIUM2021-09-21

Confused Deputy in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
spark-operator affected chainguard spark-operator
spark-operator affected wolfi spark-operator
Upstream advisory

DEBIAN-CVE-2020-8561

Open SourceActive exploitation (sightings)MEDIUM2021-09-20

DEBIAN-CVE-2020-8561

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2020-8561

Open SourceActive exploitation (sightings)MEDIUM2021-09-15

A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that ...

CVEs:CVE-2020-8561

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2020-8561

Open SourceActive exploitation (sightings)MEDIUM2021-09-15

Confused Deputy in Kubernetes

CVEs:CVE-2020-8561

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-vw47-mr44-3jf9

Open SourceActive exploitation (sightings)LOW2021-09-21

Confused Deputy in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-1.28 affected wolfi kubernetes-1.28
kubernetes-1.28 affected chainguard kubernetes-1.28
kubernetes-1.29 affected chainguard kubernetes-1.29
kubernetes-1.29 affected wolfi kubernetes-1.29
kubernetes-1.30 affected wolfi kubernetes-1.30
kubernetes-1.30 affected chainguard kubernetes-1.30
kubernetes-1.31 affected wolfi kubernetes-1.31
kubernetes-1.31 affected chainguard kubernetes-1.31
kubernetes-1.32 affected wolfi kubernetes-1.32
kubernetes-1.32 affected chainguard kubernetes-1.32
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
nodetaint affected chainguard nodetaint
nodetaint affected wolfi nodetaint
spark-operator affected chainguard spark-operator
spark-operator affected wolfi spark-operator
Upstream advisory

GHSA-vw47-mr44-3jf9

Open SourceActive exploitation (sightings)LOW2021-09-21

Confused Deputy in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

DEBIAN-CVE-2021-25740

Open SourceActive exploitation (sightings)LOW2021-09-20

DEBIAN-CVE-2021-25740

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

DEBIAN-CVE-2021-25741

Open SourcePoC exploitHIGH2021-09-20

DEBIAN-CVE-2021-25741

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2021-25741

Open SourcePoC exploitHIGH2021-09-15

Files or Directories Accessible to External Parties in kubernetes

CVEs:CVE-2021-25741

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2021-25741

Open SourcePoC exploitHIGH2021-09-15

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

CVEs:CVE-2021-25741

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

OESA-2021-1373

Open SourcePoC exploitNONE2021-09-30

kubernetes security update

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected openEuler:20.03-LTS-SP1 kubernetes
kubernetes affected openEuler:20.03-LTS-SP2 kubernetes
Upstream advisory

DEBIAN-CVE-2021-25735

Open SourcePoC exploitMEDIUM2021-09-06

DEBIAN-CVE-2021-25735

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

RLSA-2021:3585

Open SourcePoC exploitHIGH2021-09-21

Moderate: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Rocky Linux:8 delve
golang affected Rocky Linux:8 golang
go-toolset affected Rocky Linux:8 go-toolset
Upstream advisory

MGASA-2021-0416

Open SourcePoC exploitNONE2021-09-04

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:8 golang
Upstream advisory

CVE-2021-37972

GooglePoC exploitHIGH2021-09-21

Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-37972

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

GHSA-f263-c949-w85g

GooglePoC exploitCRITICAL2021-09-28

Improper Authorization in Google OAuth Client

Affected products

ProductStatusVendorPackageEcosystem
com.google.oauth-client:google-oauth-client affected Maven com.google.oauth-client:google-oauth-client
Upstream advisory

GHSA-f263-c949-w85g

GooglePoC exploitCRITICAL2021-09-28

Improper Authorization in Google OAuth Client

Affected products

ProductStatusVendorPackageEcosystem
com.google.oauth-client:google-oauth-client affected Maven com.google.oauth-client:google-oauth-client
Upstream advisory

GHSA-mfv7-gq43-w965

Open SourcePoC exploitMEDIUM2021-09-07

Incomplete List of Disallowed Inputs in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-mfv7-gq43-w965

Open SourcePoC exploitMEDIUM2021-09-07

Incomplete List of Disallowed Inputs in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

DEBIAN-CVE-2021-25737

Open SourcePoC exploitMEDIUM2021-09-06

DEBIAN-CVE-2021-25737

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2021-25737

Open SourcePoC exploitMEDIUM2021-09-06

Incomplete List of Disallowed Inputs in Kubernetes

CVEs:CVE-2021-25737

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2021-25737

Open SourcePoC exploitMEDIUM2021-09-06

A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not per...

CVEs:CVE-2021-25737

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

PUB-A-190877100

GooglePoC exploitHIGH2021-09-01

PUB-A-190877100

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-172378366

GooglePoC exploit2021-09-01

PUB-A-172378366

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2021-0683

Open SourcePoC exploitHIGH2021-09-08

In runTraceIpcStop of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...

CVEs:CVE-2021-0683

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0595

Open SourcePoC exploitHIGH2021-09-08

In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after logging in. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...

CVEs:CVE-2021-0595

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25461

Open SourcePoC exploitCRITICAL2021-09-09

An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.

CVEs:CVE-2021-25461

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0688

Open SourcePoC exploitHIGH2021-09-08

In lockNow of PhoneWindowManager.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: Andr...

CVEs:CVE-2021-0688

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-30625

GoogleCoalition ESS < 30%HIGH2021-09-14

Use after free in Selection API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who convinced the user the visit a malicious website to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30625

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30615

Open SourceCoalition ESS < 30%HIGH2021-09-03

DEBIAN-CVE-2021-30615

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30615

Open SourceCoalition ESS < 30%HIGH2021-09-01

Chromium: CVE-2021-30615 Cross-origin data leak in Navigation

CVEs:CVE-2021-30615

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30614

Open SourceCoalition ESS < 30%CRITICAL2021-09-03

DEBIAN-CVE-2021-30614

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30614

Open SourceCoalition ESS < 30%CRITICAL2021-09-01

Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip

CVEs:CVE-2021-30614

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30609

Open SourceCoalition ESS < 30%CRITICAL2021-09-03

DEBIAN-CVE-2021-30609

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30609

Open SourceCoalition ESS < 30%CRITICAL2021-09-01

Chromium: CVE-2021-30609 Use after free in Sign-In

CVEs:CVE-2021-30609

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30616

Open SourceCoalition ESS < 30%CRITICAL2021-09-03

DEBIAN-CVE-2021-30616

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30616

Open SourceCoalition ESS < 30%CRITICAL2021-09-01

Chromium: CVE-2021-30616 Use after free in Media

CVEs:CVE-2021-30616

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30610

Open SourceCoalition ESS < 30%CRITICAL2021-09-03

DEBIAN-CVE-2021-30610

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30610

Open SourceCoalition ESS < 30%CRITICAL2021-09-01

Chromium: CVE-2021-30610 Use after free in Extensions API

CVEs:CVE-2021-30610

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30624

Open SourceCoalition ESS < 30%CRITICAL2021-09-03

DEBIAN-CVE-2021-30624

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30606

Open SourceCoalition ESS < 30%CRITICAL2021-09-03

DEBIAN-CVE-2021-30606

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30607

Open SourceCoalition ESS < 30%CRITICAL2021-09-03

DEBIAN-CVE-2021-30607

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2021-30613

Open SourceCoalition ESS < 30%CRITICAL2021-09-03

DEBIAN-CVE-2021-30613

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30618

Open SourceCoalition ESS < 30%HIGH2021-09-03

DEBIAN-CVE-2021-30618

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30620

Open SourceCoalition ESS < 30%CRITICAL2021-09-03

DEBIAN-CVE-2021-30620

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30606

Open SourceCoalition ESS < 30%CRITICAL2021-09-01

Chromium: CVE-2021-30606 Use after free in Blink

CVEs:CVE-2021-30606

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

CVE-2021-30607

Open SourceCoalition ESS < 30%CRITICAL2021-09-01

Chromium: CVE-2021-30607 Use after free in Permissions

CVEs:CVE-2021-30607

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

CVE-2021-30613

Open SourceCoalition ESS < 30%CRITICAL2021-09-01

Chromium: CVE-2021-30613 Use after free in Base internals

CVEs:CVE-2021-30613

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

CVE-2021-30618

Open SourceCoalition ESS < 30%HIGH2021-09-01

Chromium: CVE-2021-30618 Inappropriate implementation in DevTools

CVEs:CVE-2021-30618

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

CVE-2021-30620

Open SourceCoalition ESS < 30%CRITICAL2021-09-01

Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink

CVEs:CVE-2021-30620

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

CVE-2021-30624

Open SourceCoalition ESS < 30%CRITICAL2021-09-01

Chromium: CVE-2021-30624 Use after free in Autofill

CVEs:CVE-2021-30624

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30608

Open SourceCoalition ESS < 30%CRITICAL2021-09-03

DEBIAN-CVE-2021-30608

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30622

Open SourceCoalition ESS < 30%CRITICAL2021-09-03

DEBIAN-CVE-2021-30622

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30608

Open SourceCoalition ESS < 30%CRITICAL2021-09-01

Chromium: CVE-2021-30608 Use after free in Web Share

CVEs:CVE-2021-30608

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

CVE-2021-30622

Open SourceCoalition ESS < 30%CRITICAL2021-09-01

Chromium: CVE-2021-30622 Use after free in WebApp Installs

CVEs:CVE-2021-30622

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30623

Open SourceCoalition ESS < 30%CRITICAL2021-09-03

DEBIAN-CVE-2021-30623

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2021-30623

Open SourceCoalition ESS < 30%CRITICAL2021-09-01

Chromium: CVE-2021-30623 Use after free in Bookmarks

CVEs:CVE-2021-30623

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30617

Open SourceCoalition ESS < 30%MEDIUM2021-09-03

DEBIAN-CVE-2021-30617

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30617

Open SourceCoalition ESS < 30%MEDIUM2021-09-01

Chromium: CVE-2021-30617 Policy bypass in Blink

CVEs:CVE-2021-30617

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30619

Open SourceCoalition ESS < 30%MEDIUM2021-09-03

DEBIAN-CVE-2021-30619

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-30621

Open SourceCoalition ESS < 30%MEDIUM2021-09-03

DEBIAN-CVE-2021-30621

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30619

Open SourceCoalition ESS < 30%MEDIUM2021-09-01

Chromium: CVE-2021-30619 UI Spoofing in Autofill

CVEs:CVE-2021-30619

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

CVE-2021-30621

Open SourceCoalition ESS < 30%MEDIUM2021-09-01

Chromium: CVE-2021-30621 UI Spoofing in Autofill

CVEs:CVE-2021-30621

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

CVE-2021-40448

Open SourceCoalition ESS < 30%HIGH2021-09-15

Microsoft Accessibility Insights for Android Information Disclosure Vulnerability

CVEs:CVE-2021-40448

Affected products

ProductStatusVendorPackageEcosystem
accessibility_insights_for_android affected microsoft
Upstream advisory

CVE-2021-38669

Open SourceCoalition ESS < 30%HIGH2021-09-10

Microsoft Edge (Chromium-based) Tampering Vulnerability

CVEs:CVE-2021-38669

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2021-30611

Open SourceCoalition ESS < 30%CRITICAL2021-09-03

DEBIAN-CVE-2021-30611

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30611

Open SourceCoalition ESS < 30%CRITICAL2021-09-01

Chromium: CVE-2021-30611 Use after free in WebRTC

CVEs:CVE-2021-30611

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-30612

Open SourceCoalition ESS < 30%CRITICAL2021-09-03

DEBIAN-CVE-2021-30612

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-30612

Open SourceCoalition ESS < 30%CRITICAL2021-09-01

Chromium: CVE-2021-30612 Use after free in WebRTC

CVEs:CVE-2021-30612

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

CVE-2021-40864

GoogleCoalition ESS < 30%CRITICAL2021-09-10

The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields.

CVEs:CVE-2021-40864

Affected products

ProductStatusVendorPackageEcosystem
google_translate affected onlyoffice
Upstream advisory

CVE-2021-37970

GoogleCoalition ESS < 30%CRITICAL2021-09-21

Use after free in File System API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-37970

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-37961

GoogleCoalition ESS < 30%CRITICAL2021-09-21

Use after free in Tab Strip in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-37961

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-37962

GoogleCoalition ESS < 30%CRITICAL2021-09-21

Use after free in Performance Manager in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-37962

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-37968

GoogleCoalition ESS < 30%MEDIUM2021-09-21

Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2021-37968

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-37971

GoogleCoalition ESS < 30%MEDIUM2021-09-21

Incorrect security UI in Web Browser UI in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2021-37971

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-37956

GoogleCoalition ESS < 30%CRITICAL2021-09-21

Use after free in Offline use in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-37956

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-37957

GoogleCoalition ESS < 30%CRITICAL2021-09-21

Use after free in WebGPU in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-37957

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-37965

GoogleCoalition ESS < 30%MEDIUM2021-09-21

Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2021-37965

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-37963

GoogleCoalition ESS < 30%HIGH2021-09-21

Side-channel information leakage in DevTools in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to bypass site isolation via a crafted HTML page.

CVEs:CVE-2021-37963

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-30626

GoogleCoalition ESS < 30%HIGH2021-09-14

Out of bounds memory access in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30626

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-37958

GoogleCoalition ESS < 30%MEDIUM2021-09-21

Inappropriate implementation in Navigation in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to inject scripts or HTML into a privileged page via a crafted HTML page.

CVEs:CVE-2021-37958

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-30628

GoogleCoalition ESS < 30%CRITICAL2021-09-14

Stack buffer overflow in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page.

CVEs:CVE-2021-30628

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-37969

GoogleCoalition ESS < 30%HIGH2021-09-21

Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege escalation via a crafted file.

CVEs:CVE-2021-37969

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-37959

GoogleCoalition ESS < 30%CRITICAL2021-09-21

Use after free in Task Manager in Google Chrome prior to 94.0.4606.54 allowed an attacker who convinced a user to enage in a series of user gestures to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-37959

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-30627

GoogleCoalition ESS < 30%HIGH2021-09-14

Type confusion in Blink layout in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30627

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-38319

GoogleCoalition ESS < 30%CRITICAL2021-09-09

The More From Google WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/morefromgoogle.php file which allows attackers to inject arbitrary web scripts, in versions up to and including...

CVEs:CVE-2021-38319

Affected products

ProductStatusVendorPackageEcosystem
more_from_google affected windyroad
Upstream advisory

CVE-2021-30629

GoogleCoalition ESS < 30%CRITICAL2021-09-14

Use after free in Permissions in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-30629

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-0869

Open SourceCoalition ESS < 30%CRITICAL2021-09-08

In GetTimeStampAndPkt of DumpstateDevice.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2021-0869

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-179620905

GoogleCoalition ESS < 30%HIGH2021-09-01

PUB-A-179620905

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0690

Open SourceCoalition ESS < 30%HIGH2021-09-08

In ih264d_mark_err_slice_skip of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed f...

CVEs:CVE-2021-0690

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-37967

GoogleCoalition ESS < 30%MEDIUM2021-09-21

Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2021-37967

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-30630

GoogleCoalition ESS < 30%MEDIUM2021-09-14

Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2021-30630

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2021-37966

GoogleCoalition ESS < 30%MEDIUM2021-09-21

Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2021-37966

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-40824

Open SourceCoalition ESS < 30%MEDIUM2021-09-13

A logic error in the room key sharing functionality of Element Android before 1.2.2 and matrix-android-sdk2 (aka Matrix SDK for Android) before 1.2.2 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via c...

CVEs:CVE-2021-40824

Affected products

ProductStatusVendorPackageEcosystem
element affected matrix
matrix-android-sdk2 affected matrix
Upstream advisory

CVE-2021-40824

Open SourceCoalition ESS < 30%MEDIUM2021-09-13

Logic error in Matrix SDK for Android

CVEs:CVE-2021-40824

Affected products

ProductStatusVendorPackageEcosystem
org.matrix.android:matrix-android-sdk2 affected Maven org.matrix.android:matrix-android-sdk2
Upstream advisory

CVE-2021-37964

GoogleCoalition ESS < 30%MEDIUM2021-09-21

Inappropriate implementation in ChromeOS Networking in Google Chrome on ChromeOS prior to 94.0.4606.54 allowed an attacker with a rogue wireless access point to to potentially carryout a wifi impersonation attack via a crafted ONC file.

CVEs:CVE-2021-37964

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-0660

Open SourceCoalition ESS < 30%MEDIUM2021-09-27

In ccu, there is a possible out of bounds read due to incorrect error handling. This could lead to information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05827145; Issue ID: ALPS05...

CVEs:CVE-2021-0660

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-vrxp-mg9f-hwf3

Open SourceCoalition ESS < 30%MEDIUM2021-09-22

Improperly Implemented path matching for in-toto-golang

Affected products

ProductStatusVendorPackageEcosystem
in-toto/in-toto-golang affected github.com github.com/in-toto/in-toto-golang
Upstream advisory

GHSA-vrxp-mg9f-hwf3

Open SourceCoalition ESS < 30%MEDIUM2021-09-22

Improperly Implemented path matching for in-toto-golang

Affected products

ProductStatusVendorPackageEcosystem
in-toto/in-toto-golang affected github.com github.com/in-toto/in-toto-golang
Upstream advisory

CVE-2021-41087

Open SourceCoalition ESS < 30%MEDIUM2021-09-21

Improperly Implemented path matching for in-toto-golang

CVEs:CVE-2021-41087

Affected products

ProductStatusVendorPackageEcosystem
in-toto/in-toto-golang affected github.com github.com/in-toto/in-toto-golang
Upstream advisory

CVE-2021-41087

Open SourceCoalition ESS < 30%MEDIUM2021-09-21

in-toto-golang is a go implementation of the in-toto framework to protect software supply chain integrity. In affected versions authenticated attackers posing as functionaries (i.e., within a trusted set of users for a layout) are able to create attest...

CVEs:CVE-2021-41087

Affected products

ProductStatusVendorPackageEcosystem
in-toto-golang affected in-toto
Upstream advisory

CVE-2021-25449

Open SourceCoalition ESS < 30%CRITICAL2021-09-09

An improper input validation vulnerability in libsapeextractor library prior to SMR Sep-2021 Release 1 allows attackers to execute arbitrary code in mediaextractor process.

CVEs:CVE-2021-25449

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0635

Open SourceCoalition ESS < 30%HIGH2021-09-08

When extracting the incorrectly formatted flv file, the memory is damaged, the playback interface shows that the video cannot be played, and the log is found to be crashed. This problem may lead to hacker malicious code attacks, resulting in the loss o...

CVEs:CVE-2021-0635

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0636

Open SourceCoalition ESS < 30%HIGH2021-09-08

When extracting the incorrectly formatted avi file, the memory is damaged, the playback interface shows that the video cannot be played, and the log is found to be crashed. This problem may lead to hacker malicious code attacks, resulting in the loss o...

CVEs:CVE-2021-0636

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-189392423

GoogleCoalition ESS < 30%2021-09-01

ASB-A-189392423

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-189402477

GoogleCoalition ESS < 30%2021-09-01

ASB-A-189402477

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-25456

Open SourceCoalition ESS < 30%MEDIUM2021-09-09

OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute memcpy at arbitrary address via forged wmf file.

CVEs:CVE-2021-25456

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25451

Open SourceCoalition ESS < 30%MEDIUM2021-09-09

A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.

CVEs:CVE-2021-25451

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25454

Open SourceCoalition ESS < 30%HIGH2021-09-09

OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote DoS via forged aac file.

CVEs:CVE-2021-25454

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0685

Open SourceCoalition ESS < 30%HIGH2021-09-08

In ParsedIntentInfo of ParsedIntentInfo.java, there is a possible parcel serialization/deserialization mismatch due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...

CVEs:CVE-2021-0685

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25455

Open SourceCoalition ESS < 30%MEDIUM2021-09-09

OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitrary address through pointer via forged avi file.

CVEs:CVE-2021-25455

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25450

Open SourceCoalition ESS < 30%HIGH2021-09-09

Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote socket.

CVEs:CVE-2021-25450

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-181677125

GoogleCoalition ESS < 30%2021-09-01

PUB-A-181677125

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

PUB-A-181677179

GoogleCoalition ESS < 30%2021-09-01

PUB-A-181677179

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-190404324

GoogleCoalition ESS < 30%2021-09-01

ASB-A-190404324

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2021-0684

Open SourceCoalition ESS < 30%HIGH2021-09-08

In TouchInputMapper::sync of TouchInputMapper.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2021-0684

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0598

Open SourceCoalition ESS < 30%HIGH2021-09-08

In onCreate of ConfirmConnectActivity.java, there is a possible pairing of untrusted Bluetooth devices due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is neede...

CVEs:CVE-2021-0598

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0695

Open SourceCoalition ESS < 30%HIGH2021-09-08

In get_sock_stat of xt_qtaguid.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVer...

CVEs:CVE-2021-0695

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-184018316

GoogleCoalition ESS < 30%HIGH2021-09-01

ASB-A-184018316

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-0687

Open SourceCoalition ESS < 30%MEDIUM2021-09-08

In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Andr...

CVEs:CVE-2021-0687

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-30605

GoogleCoalition ESS < 30%HIGH2021-09-08

Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.

CVEs:CVE-2021-30605

Affected products

ProductStatusVendorPackageEcosystem
chrome_os_readiness_tool affected google
Upstream advisory

CVE-2021-0689

Open SourceCoalition ESS < 30%MEDIUM2021-09-08

In RGB_to_BGR1_portable of SkSwizzler_opts.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2021-0689

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-190188264

Open SourceCoalition ESS < 30%MEDIUM2021-09-01

ASB-A-190188264

Affected products

ProductStatusVendorPackageEcosystem
external/skia affected platform platform/external/skia
Upstream advisory

CVE-2021-25462

Open SourceCoalition ESS < 30%CRITICAL2021-09-09

NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.

CVEs:CVE-2021-25462

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25458

Open SourceCoalition ESS < 30%CRITICAL2021-09-09

NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.

CVEs:CVE-2021-25458

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0682

Open SourceCoalition ESS < 30%MEDIUM2021-09-08

In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction...

CVEs:CVE-2021-0682

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25452

Open SourceCoalition ESS < 30%HIGH2021-09-09

An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform permanent denial of service on the device.

CVEs:CVE-2021-25452

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0610

Open SourceCoalition ESS < 30%HIGH2021-09-27

In memory management driver, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A...

CVEs:CVE-2021-0610

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0611

Open SourceCoalition ESS < 30%HIGH2021-09-27

In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS0542...

CVEs:CVE-2021-0611

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0612

Open SourceCoalition ESS < 30%HIGH2021-09-27

In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS0542...

CVEs:CVE-2021-0612

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25459

Open SourceCoalition ESS < 30%MEDIUM2021-09-09

An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZService.

CVEs:CVE-2021-25459

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0421

Open SourceCoalition ESS < 30%MEDIUM2021-09-27

In memory management driver, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patc...

CVEs:CVE-2021-0421

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0423

Open SourceCoalition ESS < 30%MEDIUM2021-09-27

In memory management driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID...

CVEs:CVE-2021-0423

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0425

Open SourceCoalition ESS < 30%MEDIUM2021-09-27

In memory management driver, there is a possible side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0540349...

CVEs:CVE-2021-0425

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0644

Open SourceCoalition ESS < 30%MEDIUM2021-09-08

In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User ...

CVEs:CVE-2021-0644

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0693

Open SourceCoalition ESS < 30%MEDIUM2021-09-08

In openFile of HeapDumpProvider.java, there is a possible way to retrieve generated heap dumps from debuggable apps due to an unprotected provider. This could lead to local information disclosure with no additional execution privileges needed. User int...

CVEs:CVE-2021-0693

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0691

Open SourceCoalition ESS < 30%HIGH2021-09-08

In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in other processes due to an overly-permissive SELinux policy. This could lead to local escalation of privilege with System execution privi...

CVEs:CVE-2021-0691

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0692

Open SourceCoalition ESS < 30%HIGH2021-09-08

In sendBroadcastToInstaller of FirstScreenBroadcast.java, there is a possible activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede...

CVEs:CVE-2021-0692

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-23243

Open SourceCoalition ESS < 30%CRITICAL2021-09-27

In Oppo's battery application, the third-party SDK provides the function of loading a third-party Provider, which can be used.

CVEs:CVE-2021-23243

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0422

Open SourceCoalition ESS < 30%MEDIUM2021-09-27

In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403...

CVEs:CVE-2021-0422

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0424

Open SourceCoalition ESS < 30%MEDIUM2021-09-27

In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403...

CVEs:CVE-2021-0424

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0680

Open SourceCoalition ESS < 30%MEDIUM2021-09-08

In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:...

CVEs:CVE-2021-0680

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0681

Open SourceCoalition ESS < 30%MEDIUM2021-09-08

In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:...

CVEs:CVE-2021-0681

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0686

Open SourceCoalition ESS < 30%MEDIUM2021-09-08

In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app of a different device user due to a missing permission check. This could lead to local information disclosure with no additional ex...

CVEs:CVE-2021-0686

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-192535337

GoogleCoalition ESS < 30%MEDIUM2021-09-01

ASB-A-192535337

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-192535676

GoogleCoalition ESS < 30%MEDIUM2021-09-01

ASB-A-192535676

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-25453

Open SourceCoalition ESS < 30%MEDIUM2021-09-09

Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.

CVEs:CVE-2021-25453

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-190403706

GoogleCoalition ESS < 30%2021-09-01

ASB-A-190403706

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

PUB-A-181676968

GoogleCoalition ESS < 30%2021-09-01

PUB-A-181676968

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2021-25457

Open SourceCoalition ESS < 30%MEDIUM2021-09-09

An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a limited kernel memory information.

CVEs:CVE-2021-25457

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25460

Open SourceCoalition ESS < 30%MEDIUM2021-09-09

An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BlockchainTZService.

CVEs:CVE-2021-25460

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

OSV-2021-1347

Open SourceAll remainingHIGH2021-09-22

Invalid-free in generic specialization <Swift.Int> of Swift.Array.subscript.getter :

Affected products

ProductStatusVendorPackageEcosystem
swift-protobuf affected OSS-Fuzz swift-protobuf
Upstream advisory

OSV-2021-1332

Open SourceAll remainingHIGH2021-09-20

Invalid-free in swift_unexpectedError

Affected products

ProductStatusVendorPackageEcosystem
swift-protobuf affected OSS-Fuzz swift-protobuf
Upstream advisory

OSV-2021-1222

Open SourceAll remainingHIGH2021-09-11

Invalid-free in swift_unexpectedError

Affected products

ProductStatusVendorPackageEcosystem
swift-protobuf affected OSS-Fuzz swift-protobuf
Upstream advisory

OSV-2021-1215

Open SourceAll remainingHIGH2021-09-10

Invalid-free in swift_unexpectedError

Affected products

ProductStatusVendorPackageEcosystem
swift-protobuf affected OSS-Fuzz swift-protobuf
Upstream advisory

OSV-2021-1214

Open SourceAll remainingHIGH2021-09-10

Invalid-free in swift_unexpectedError

Affected products

ProductStatusVendorPackageEcosystem
swift-protobuf affected OSS-Fuzz swift-protobuf
swift-protobuf affected
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.