Google Security Advisories · December 2021 — Google Security Advisories
405 advisories 243 CVEs 6 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2021-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 6 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

openSUSE-SU-2021:1632-1

Open SourceExploitedCISA KEV listedCRITICAL2021-12-28

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

openSUSE-SU-2021:1600-1

Open SourceExploitedCISA KEV listedCRITICAL2021-12-20

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.3 chromium
chromium affected SUSE:Package Hub 15 SP3 chromium
Upstream advisory

MGASA-2021-0565

Open SourceExploitedCISA KEV listedCRITICAL2021-12-19

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

CVE-2021-4102

GoogleExploitedCISA KEV listedCRITICAL2021-12-14

Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-4102

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2021-4102

Project ZeroExploitedCISA KEV listed2021-12-14

Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-4102

Upstream advisory

ASB-A-195082750

GooglePoC exploitHIGH2021-12-01

ASB-A-195082750

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

MGASA-2021-0578

Open SourcePoC exploitHIGH2021-12-23

Updated thrift/golang-github-apache-thrift packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang-github-apache-thrift affected Mageia:8 golang-github-apache-thrift
thrift affected Mageia:8 thrift
Upstream advisory

MGASA-2021-0537

Open SourcePoC exploit2021-12-03

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:8 golang
Upstream advisory

MGASA-2021-0587

Open SourcePoC exploit2021-12-26

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:8 golang
Upstream advisory

RHSA-2021:5176

Open SourcePoC exploitHIGH2021-12-16

Red Hat Security Advisory: go-toolset-1.16 and go-toolset-1.16-golang security and bug fix update

Affected products

ProductStatusVendorPackageEcosystem
go-toolset-1.16 affected Red Hat:devtools:2021 go-toolset-1.16
go-toolset-1.16-build affected Red Hat:devtools:2021 go-toolset-1.16-build
go-toolset-1.16-golang affected Red Hat:devtools:2021 go-toolset-1.16-golang
go-toolset-1.16-golang-bin affected Red Hat:devtools:2021 go-toolset-1.16-golang-bin
go-toolset-1.16-golang-docs affected Red Hat:devtools:2021 go-toolset-1.16-golang-docs
go-toolset-1.16-golang-misc affected Red Hat:devtools:2021 go-toolset-1.16-golang-misc
go-toolset-1.16-golang-race affected Red Hat:devtools:2021 go-toolset-1.16-golang-race
go-toolset-1.16-golang-src affected Red Hat:devtools:2021 go-toolset-1.16-golang-src
go-toolset-1.16-golang-tests affected Red Hat:devtools:2021 go-toolset-1.16-golang-tests
go-toolset-1.16-runtime affected Red Hat:devtools:2021 go-toolset-1.16-runtime
go-toolset-1.16-scldevel affected Red Hat:devtools:2021 go-toolset-1.16-scldevel
Upstream advisory

ALSA-2021:5160

Open SourcePoC exploit2021-12-15

Important: go-toolset:rhel8 security and bug fix update

Affected products

ProductStatusVendorPackageEcosystem
delve affected AlmaLinux:8 delve
golang affected AlmaLinux:8 golang
golang-bin affected AlmaLinux:8 golang-bin
golang-docs affected AlmaLinux:8 golang-docs
golang-misc affected AlmaLinux:8 golang-misc
golang-race affected AlmaLinux:8 golang-race
golang-src affected AlmaLinux:8 golang-src
golang-tests affected AlmaLinux:8 golang-tests
go-toolset affected AlmaLinux:8 go-toolset
Upstream advisory

RLSA-2021:5160

Open SourcePoC exploitHIGH2021-12-15

Important: go-toolset:rhel8 security and bug fix update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Rocky Linux:8 delve
golang affected Rocky Linux:8 golang
go-toolset affected Rocky Linux:8 go-toolset
Upstream advisory

CVE-2021-44716

Open SourcePoC exploitHIGH2021-12-15

golang.org/x/net/http2 allows uncontrolled memory consumption

CVEs:CVE-2021-44716

Affected products

ProductStatusVendorPackageEcosystem
x/net/http2 affected golang.org golang.org/x/net/http2
Upstream advisory

CVE-2021-44716

GooglePoC exploitHIGH2021-12-15

net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.

CVEs:CVE-2021-44716

Affected products

ProductStatusVendorPackageEcosystem
cloud_insights_telegraf affected netapp
debian_linux affected debian
go affected golang
Upstream advisory

GHSA-wxc4-f4m6-wwqv

GooglePoC exploitCRITICAL2021-12-20

Excessive Platform Resource Consumption within a Loop in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
go-yaml/yaml affected github.com github.com/go-yaml/yaml
yaml.v2 affected gopkg.in gopkg.in/yaml.v2
Upstream advisory

GHSA-wxc4-f4m6-wwqv

Open SourcePoC exploitCRITICAL2021-12-20

Excessive Platform Resource Consumption within a Loop in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
go-yaml/yaml affected github.com github.com/go-yaml/yaml
k3d affected wolfi k3d
k3d affected chainguard k3d
yaml.v2 affected gopkg.in gopkg.in/yaml.v2
Upstream advisory

openSUSE-SU-2021:1582-1

Open SourcePoC exploitCRITICAL2021-12-13

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

CLSA-2021-1638804072

Open SourcePoC exploitHIGH2021-12-06

Fix CVE(s): CVE-2021-3426

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.5 affected TuxCare:Ubuntu:16.04 idle-python3.5
libpython3.5 affected TuxCare:Ubuntu:16.04 libpython3.5
libpython3.5-dev affected TuxCare:Ubuntu:16.04 libpython3.5-dev
libpython3.5-minimal affected TuxCare:Ubuntu:16.04 libpython3.5-minimal
libpython3.5-stdlib affected TuxCare:Ubuntu:16.04 libpython3.5-stdlib
libpython3.5-testsuite affected TuxCare:Ubuntu:16.04 libpython3.5-testsuite
python3.5 affected TuxCare:Ubuntu:16.04 python3.5
python3.5-dev affected TuxCare:Ubuntu:16.04 python3.5-dev
python3.5-doc affected TuxCare:Ubuntu:16.04 python3.5-doc
python3.5-examples affected TuxCare:Ubuntu:16.04 python3.5-examples
python3.5-minimal affected TuxCare:Ubuntu:16.04 python3.5-minimal
python3.5-venv affected TuxCare:Ubuntu:16.04 python3.5-venv
Upstream advisory

DEBIAN-CVE-2021-38008

Open SourcePoC exploitCRITICAL2021-12-23

DEBIAN-CVE-2021-38008

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

PUB-A-190228658

GooglePoC exploitHIGH2021-12-01

PUB-A-190228658

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

DEBIAN-CVE-2021-38013

Open SourcePoC exploitCRITICAL2021-12-23

DEBIAN-CVE-2021-38013

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-38005

Open SourcePoC exploitCRITICAL2021-12-23

DEBIAN-CVE-2021-38005

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-38006

Open SourcePoC exploitCRITICAL2021-12-23

DEBIAN-CVE-2021-38006

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-38012

Open SourcePoC exploitHIGH2021-12-23

DEBIAN-CVE-2021-38012

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-38007

Open SourcePoC exploitHIGH2021-12-23

DEBIAN-CVE-2021-38007

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-38010

Open SourcePoC exploitMEDIUM2021-12-23

DEBIAN-CVE-2021-38010

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-38022

Open SourcePoC exploitMEDIUM2021-12-23

DEBIAN-CVE-2021-38022

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-38014

Open SourcePoC exploitCRITICAL2021-12-23

DEBIAN-CVE-2021-38014

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-38009

Open SourcePoC exploitMEDIUM2021-12-23

DEBIAN-CVE-2021-38009

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-38019

Open SourcePoC exploitCRITICAL2021-12-23

DEBIAN-CVE-2021-38019

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2021-38011

Open SourcePoC exploitCRITICAL2021-12-23

DEBIAN-CVE-2021-38011

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-38016

Open SourcePoC exploitCRITICAL2021-12-23

DEBIAN-CVE-2021-38016

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-38017

Open SourcePoC exploitCRITICAL2021-12-23

DEBIAN-CVE-2021-38017

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-38021

Open SourcePoC exploitMEDIUM2021-12-23

DEBIAN-CVE-2021-38021

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-38018

Open SourcePoC exploitMEDIUM2021-12-23

DEBIAN-CVE-2021-38018

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

DEBIAN-CVE-2021-38020

Open SourcePoC exploitCRITICAL2021-12-23

DEBIAN-CVE-2021-38020

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-38015

Open SourcePoC exploitHIGH2021-12-23

DEBIAN-CVE-2021-38015

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

PUB-A-188883590

GooglePoC exploitHIGH2021-12-01

PUB-A-188883590

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-0954

Open SourcePoC exploitHIGH2021-12-07

In ResolverActivity, there is a possible user interaction bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVer...

CVEs:CVE-2021-0954

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0963

Open SourcePoC exploitHIGH2021-12-07

In onCreate of KeyChainActivity.java, there is a possible way to use an app certificate stored in keychain due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...

CVEs:CVE-2021-0963

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-190011721

GoogleCoalition ESS 30-63%HIGH2021-12-01

PUB-A-190011721

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

DEBIAN-CVE-2021-4057

Open SourceCoalition ESS < 30%CRITICAL2021-12-23

DEBIAN-CVE-2021-4057

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

MGASA-2021-0555

Open SourceCoalition ESS < 30%CRITICAL2021-12-10

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

CVE-2021-4057

GoogleCoalition ESS < 30%CRITICAL2021-12-07

Use after free in file API in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-4057

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-44717

GoogleCoalition ESS < 30%MEDIUM2021-12-13

Go before 1.16.12 and 1.17.x before 1.17.5 on UNIX allows write operations to an unintended file or unintended network connection as a consequence of erroneous closing of file descriptor 0 after file-descriptor exhaustion.

CVEs:CVE-2021-44717

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
go affected golang
Upstream advisory

DEBIAN-CVE-2021-4062

Open SourceCoalition ESS < 30%CRITICAL2021-12-23

DEBIAN-CVE-2021-4062

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-4062

GoogleCoalition ESS < 30%CRITICAL2021-12-07

Heap buffer overflow in BFCache in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-4062

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-4056

Open SourceCoalition ESS < 30%HIGH2021-12-23

DEBIAN-CVE-2021-4056

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-4061

Open SourceCoalition ESS < 30%HIGH2021-12-23

DEBIAN-CVE-2021-4061

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-4056

GoogleCoalition ESS < 30%HIGH2021-12-07

Type confusion in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-4056

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-4061

GoogleCoalition ESS < 30%HIGH2021-12-07

Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-4061

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-4058

Open SourceCoalition ESS < 30%CRITICAL2021-12-23

DEBIAN-CVE-2021-4058

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-4058

GoogleCoalition ESS < 30%CRITICAL2021-12-07

Heap buffer overflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-4058

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-4063

Open SourceCoalition ESS < 30%CRITICAL2021-12-23

DEBIAN-CVE-2021-4063

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-4063

GoogleCoalition ESS < 30%CRITICAL2021-12-07

Use after free in developer tools in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-4063

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-4068

Open SourceCoalition ESS < 30%MEDIUM2021-12-23

DEBIAN-CVE-2021-4068

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2021-4068

GoogleCoalition ESS < 30%MEDIUM2021-12-07

Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2021-4068

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-4064

Open SourceCoalition ESS < 30%CRITICAL2021-12-23

DEBIAN-CVE-2021-4064

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-4064

GoogleCoalition ESS < 30%CRITICAL2021-12-07

Use after free in screen capture in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-4064

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-4066

Open SourceCoalition ESS < 30%HIGH2021-12-23

DEBIAN-CVE-2021-4066

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-4066

GoogleCoalition ESS < 30%HIGH2021-12-07

Integer underflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-4066

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-4059

Open SourceCoalition ESS < 30%MEDIUM2021-12-23

DEBIAN-CVE-2021-4059

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-4059

GoogleCoalition ESS < 30%MEDIUM2021-12-07

Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2021-4059

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-4065

Open SourceCoalition ESS < 30%CRITICAL2021-12-23

DEBIAN-CVE-2021-4065

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-4067

Open SourceCoalition ESS < 30%CRITICAL2021-12-23

DEBIAN-CVE-2021-4067

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-4053

Open SourceCoalition ESS < 30%CRITICAL2021-12-23

DEBIAN-CVE-2021-4053

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-4053

GoogleCoalition ESS < 30%CRITICAL2021-12-07

Use after free in UI in Google Chrome on Linux prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-4053

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-4065

GoogleCoalition ESS < 30%CRITICAL2021-12-07

Use after free in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-4065

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-4067

GoogleCoalition ESS < 30%CRITICAL2021-12-07

Use after free in window manager in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-4067

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-0956

Open SourceCoalition ESS < 30%HIGH2021-12-07

In NfcTag::discoverTechnologies (activation) of NfcTag.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additionalSystem execution privileges needed. User interacti...

CVEs:CVE-2021-0956

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2021-4054

Open SourceCoalition ESS < 30%MEDIUM2021-12-23

DEBIAN-CVE-2021-4054

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-4054

GoogleCoalition ESS < 30%MEDIUM2021-12-07

Incorrect security UI in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVEs:CVE-2021-4054

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2021-4055

Open SourceCoalition ESS < 30%CRITICAL2021-12-23

DEBIAN-CVE-2021-4055

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-4055

GoogleCoalition ESS < 30%CRITICAL2021-12-07

Heap buffer overflow in extensions in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

CVEs:CVE-2021-4055

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-4101

GoogleCoalition ESS < 30%CRITICAL2021-12-14

Heap buffer overflow in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-4101

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2021-0967

Open SourceCoalition ESS < 30%HIGH2021-12-15

In vorbis_book_decodev_set of codebook.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitatio...

CVEs:CVE-2021-0967

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2021-4078

Open SourceCoalition ESS < 30%HIGH2021-12-23

DEBIAN-CVE-2021-4078

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-4078

GoogleCoalition ESS < 30%HIGH2021-12-13

Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-4078

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2021-4052

Open SourceCoalition ESS < 30%CRITICAL2021-12-23

DEBIAN-CVE-2021-4052

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-4052

GoogleCoalition ESS < 30%CRITICAL2021-12-07

Use after free in web apps in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

CVEs:CVE-2021-4052

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2021-22568

Open SourceCoalition ESS < 30%HIGH2021-12-09

When using the dart pub publish command to publish a package to a third-party package server, the request would be authenticated with an oauth2 access_token that is valid for publishing on pub.dev. Using these obtained credentials, an attacker can impe...

CVEs:CVE-2021-22568

Affected products

ProductStatusVendorPackageEcosystem
dart_software_development_kit affected dart
Upstream advisory

CVE-2021-0964

Open SourceCoalition ESS < 30%HIGH2021-12-07

In C2SoftMP3::process() of C2SoftMp3Dec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploita...

CVEs:CVE-2021-0964

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-193363621

GoogleCoalition ESS < 30%HIGH2021-12-01

ASB-A-193363621

Affected products

ProductStatusVendorPackageEcosystem
frameworks/av affected platform platform/frameworks/av
hardware/google/av affected platform platform/hardware/google/av
Upstream advisory

CVE-2021-24935

GoogleCoalition ESS < 30%HIGH2021-12-06

The WP Google Fonts WordPress plugin before 3.1.5 does not escape the googlefont_ajax_name and googlefont_ajax_family parameter of the googlefont_action AJAx action (available to any authenticated user) before outputing them in attributes, leading Refl...

CVEs:CVE-2021-24935

Affected products

ProductStatusVendorPackageEcosystem
wp_google_fonts affected wp_google_fonts_project
Upstream advisory

DEBIAN-CVE-2021-4079

Open SourceCoalition ESS < 30%CRITICAL2021-12-23

DEBIAN-CVE-2021-4079

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
chromium affected Debian:13 chromium
Upstream advisory

CVE-2021-4079

GoogleCoalition ESS < 30%CRITICAL2021-12-13

Out of bounds write in WebRTC in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via crafted WebRTC packets.

CVEs:CVE-2021-4079

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2021-1002

Open SourceCoalition ESS < 30%HIGH2021-12-07

In WT_Interpolate of eas_wtengine.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2021-1002

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-4099

GoogleCoalition ESS < 30%CRITICAL2021-12-14

Use after free in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-4099

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2021-4100

GoogleCoalition ESS < 30%HIGH2021-12-14

Object lifecycle issue in ANGLE in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2021-4100

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2021-1022

Open SourceCoalition ESS < 30%HIGH2021-12-07

In btif_in_hf_client_generic_evt of btif_hf_client.cc, there is a possible Bluetooth service crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2021-1022

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0673

Open SourceCoalition ESS < 30%HIGH2021-12-17

In Audio Aurisys HAL, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A...

CVEs:CVE-2021-0673

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0968

Open SourceCoalition ESS < 30%HIGH2021-12-07

In osi_malloc and osi_calloc of allocator.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2021-0968

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0971

Open SourceCoalition ESS < 30%HIGH2021-12-15

In MPEG4Source::read of MPEG4Extractor.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitat...

CVEs:CVE-2021-0971

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0976

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In toBARK of floor0.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVe...

CVEs:CVE-2021-0976

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-4098

GoogleCoalition ESS < 30%HIGH2021-12-14

Insufficient data validation in Mojo in Google Chrome prior to 96.0.4664.110 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2021-4098

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-36846

Open SourceCoalition ESS < 30%CRITICAL2021-12-20

Integer overflow in the bundled Brotli C library

CVEs:CVE-2020-36846

Affected products

ProductStatusVendorPackageEcosystem
brotli affected PyPI brotli
compu-brotli-sys affected crates.io compu-brotli-sys
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.browser-wasm
Microsoft.NETCore.App.Runtime.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-arm
Microsoft.NETCore.App.Runtime.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-arm64
Microsoft.NETCore.App.Runtime.linux-musl-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm
Microsoft.NETCore.App.Runtime.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm64
Microsoft.NETCore.App.Runtime.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-x64
Microsoft.NETCore.App.Runtime.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-x64
Microsoft.NETCore.App.Runtime.Mono.android-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm
Microsoft.NETCore.App.Runtime.Mono.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm
Microsoft.NETCore.App.Runtime.Mono.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm
Microsoft.NETCore.App.Runtime.Mono.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64
Microsoft.NETCore.App.Runtime.Mono.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-arm64
Microsoft.NETCore.App.Runtime.Mono.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x64
Microsoft.NETCore.App.Runtime.Mono.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x86
Microsoft.NETCore.App.Runtime.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.osx-arm64
Microsoft.NETCore.App.Runtime.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.osx-x64
Microsoft.NETCore.App.Runtime.win-arm affected NuGet Microsoft.NETCore.App.Runtime.win-arm
Microsoft.NETCore.App.Runtime.win-arm64 affected NuGet Microsoft.NETCore.App.Runtime.win-arm64
Microsoft.NETCore.App.Runtime.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.win-x64
Microsoft.NETCore.App.Runtime.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.win-x86
Upstream advisory

CVE-2020-36846

GoogleCoalition ESS < 30%CRITICAL2020-09-15

A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library.  Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length o...

CVEs:CVE-2020-36846

Upstream advisory

CVE-2020-36846

Open SourceCoalition ESS < 30%MEDIUM2020-09-15

PYSEC-2020-29

CVEs:CVE-2020-36846

Affected products

ProductStatusVendorPackageEcosystem
brotli affected PyPI brotli
compu-brotli-sys affected crates.io compu-brotli-sys
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.browser-wasm
Microsoft.NETCore.App.Runtime.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-arm
Microsoft.NETCore.App.Runtime.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-arm64
Microsoft.NETCore.App.Runtime.linux-musl-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm
Microsoft.NETCore.App.Runtime.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm64
Microsoft.NETCore.App.Runtime.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-x64
Microsoft.NETCore.App.Runtime.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-x64
Microsoft.NETCore.App.Runtime.Mono.android-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm
Microsoft.NETCore.App.Runtime.Mono.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm
Microsoft.NETCore.App.Runtime.Mono.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm
Microsoft.NETCore.App.Runtime.Mono.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64
Microsoft.NETCore.App.Runtime.Mono.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-arm64
Microsoft.NETCore.App.Runtime.Mono.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x64
Microsoft.NETCore.App.Runtime.Mono.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x86
Microsoft.NETCore.App.Runtime.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.osx-arm64
Microsoft.NETCore.App.Runtime.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.osx-x64
Microsoft.NETCore.App.Runtime.win-arm affected NuGet Microsoft.NETCore.App.Runtime.win-arm
Microsoft.NETCore.App.Runtime.win-arm64 affected NuGet Microsoft.NETCore.App.Runtime.win-arm64
Microsoft.NETCore.App.Runtime.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.win-x64
Microsoft.NETCore.App.Runtime.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.win-x86
Upstream advisory

CVE-2021-0969

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In getTitle of AccessPoint.java, there is a possible unhandled exception due to a missing null check. This could lead to remote denial of service if a proximal Wi-Fi AP provides invalid information with no additional execution privileges needed. User i...

CVEs:CVE-2021-0969

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0993

Open SourceCoalition ESS < 30%HIGH2021-12-07

In getOffsetBeforeAfter of TextLine.java, there is a possible denial of service due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product:...

CVEs:CVE-2021-0993

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39645

Open SourceCoalition ESS < 30%HIGH2021-12-07

Product: AndroidVersions: Android kernelAndroid ID: A-199805112References: N/A

CVEs:CVE-2021-39645

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-199805112

GoogleCoalition ESS < 30%2021-12-01

PUB-A-199805112

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0675

Open SourceCoalition ESS < 30%HIGH2021-12-07

In alac decoder, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0...

CVEs:CVE-2021-0675

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-201895896

GoogleCoalition ESS < 30%HIGH2021-12-01

ASB-A-201895896

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-4273

Open SourceCoalition ESS < 30%CRITICAL2021-12-20

A vulnerability classified as problematic was found in studygolang. This vulnerability affects the function Search of the file http/controller/search.go. The manipulation of the argument q leads to cross site scripting. The attack can be initiated remo...

CVEs:CVE-2021-4273

Affected products

ProductStatusVendorPackageEcosystem
studygolang affected studygolang
Upstream advisory

CVE-2021-0674

Open SourceCoalition ESS < 30%MEDIUM2021-12-17

In alac decoder, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS060...

CVEs:CVE-2021-0674

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39641

Open SourceCoalition ESS < 30%CRITICAL2021-12-07

Product: AndroidVersions: Android kernelAndroid ID: A-126949257References: N/A

CVEs:CVE-2021-39641

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39644

Open SourceCoalition ESS < 30%CRITICAL2021-12-07

Product: AndroidVersions: Android kernelAndroid ID: A-199809304References: N/A

CVEs:CVE-2021-39644

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39655

Open SourceCoalition ESS < 30%CRITICAL2021-12-07

Product: AndroidVersions: Android kernelAndroid ID: A-192641593References: N/A

CVEs:CVE-2021-39655

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-126949257

GoogleCoalition ESS < 30%2021-12-01

PUB-A-126949257

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-192641593

GoogleCoalition ESS < 30%2021-12-01

PUB-A-192641593

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-199809304

GoogleCoalition ESS < 30%2021-12-01

PUB-A-199809304

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-39646

Open SourceCoalition ESS < 30%HIGH2021-12-07

Product: AndroidVersions: Android kernelAndroid ID: A-201537251References: N/A

CVEs:CVE-2021-39646

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-201537251

GoogleCoalition ESS < 30%2021-12-01

PUB-A-201537251

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-196448784

GoogleCoalition ESS < 30%HIGH2021-12-01

ASB-A-196448784

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-25516

Open SourceCoalition ESS < 30%HIGH2021-12-08

An improper check or handling of exceptional conditions in Exynos baseband prior to SMR Dec-2021 Release 1 allows attackers to track locations.

CVEs:CVE-2021-25516

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25514

Open SourceCoalition ESS < 30%HIGH2021-12-08

An improper intent redirection handling in Tags prior to SMR Dec-2021 Release 1 allows attackers to access sensitive information.

CVEs:CVE-2021-25514

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39636

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed f...

CVEs:CVE-2021-39636

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-120612905

GoogleCoalition ESS < 30%MEDIUM2021-12-01

PUB-A-120612905

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-0965

Open SourceCoalition ESS < 30%HIGH2021-12-07

In AndroidManifest.xml of Settings, there is a possible pairing of a Bluetooth device without user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...

CVEs:CVE-2021-0965

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0970

Open SourceCoalition ESS < 30%HIGH2021-12-07

In createFromParcel of GpsNavigationMessage.java, there is a possible Parcel serialization/deserialization mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2021-0970

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0996

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In nfaHciCallback of HciEventManager.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure over NFC with System execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2021-0996

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-160822094

GoogleCoalition ESS < 30%MEDIUM2021-12-01

PUB-A-160822094

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-0991

Open SourceCoalition ESS < 30%HIGH2021-12-07

In OnMetadataChangedListener of AdvancedBluetoothDetailsHeaderController.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges neede...

CVEs:CVE-2021-0991

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39657

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2021-39657

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-199190644

GoogleCoalition ESS < 30%2021-12-01

ASB-A-199190644

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

PUB-A-194696049

GoogleCoalition ESS < 30%MEDIUM2021-12-01

PUB-A-194696049

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-0961

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In quota_proc_write of xt_quota2.c, there is a possible way to read kernel memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produc...

CVEs:CVE-2021-0961

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-190402578

GoogleCoalition ESS < 30%2021-12-01

ASB-A-190402578

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-196046570

GoogleCoalition ESS < 30%MEDIUM2021-12-01

ASB-A-196046570

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-190408641

GoogleCoalition ESS < 30%2021-12-01

PUB-A-190408641

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2021-0952

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In doCropPhoto of PhotoSelectionHandler.java, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure of user's contacts with no additional execution privileges needed. User interaction is needed ...

CVEs:CVE-2021-0952

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0904

Open SourceCoalition ESS < 30%HIGH2021-12-07

In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06076938; ...

CVEs:CVE-2021-0904

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-201779035

GoogleCoalition ESS < 30%NONE2021-12-01

ASB-A-201779035

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-1039

Open SourceCoalition ESS < 30%HIGH2021-12-15

In NotificationAccessActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitati...

CVEs:CVE-2021-1039

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0973

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In isFileUri of UriUtil.java, there is a possible way to bypass ignoring file://URI attachment due to improper handling of case sensitivity. This could lead to local information disclosure with no additional execution privileges needed. User interactio...

CVEs:CVE-2021-0973

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0984

Open SourceCoalition ESS < 30%HIGH2021-12-07

In onNullBinding of ManagedServices.java, there is a possible permission bypass due to an incorrectly unbound service. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2021-0984

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0704

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In createNoCredentialsPermissionNotification and related functions of AccountManagerService.java, there is a possible way to retrieve accounts from the device without permissions due to a permissions bypass. This could lead to local information disclos...

CVEs:CVE-2021-0704

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1044

Open SourceCoalition ESS < 30%HIGH2021-12-15

In eicOpsDecryptAes128Gcm of acropora/app/identity/identity_support.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interact...

CVEs:CVE-2021-1044

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39639

Open SourceCoalition ESS < 30%HIGH2021-12-07

In TBD of fvp.c, there is a possible way to glitch CPU behavior due to a missing permission check. This could lead to local escalation of privilege with physical access to device internals with no additional execution privileges needed. User interactio...

CVEs:CVE-2021-39639

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-198291476

GoogleCoalition ESS < 30%NONE2021-12-01

PUB-A-198291476

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-39652

Open SourceCoalition ESS < 30%HIGH2021-12-07

In sec_ts_parsing_cmds of (TBD), there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2021-39652

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-194499021

GoogleCoalition ESS < 30%HIGH2021-12-01

PUB-A-194499021

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0769

Open SourceCoalition ESS < 30%HIGH2021-12-07

In onCreate of AllowBindAppWidgetActivity.java, there is a possible bypass of user interaction requirements due to unclear UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed f...

CVEs:CVE-2021-0769

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1047

Open SourceCoalition ESS < 30%HIGH2021-12-07

In valid_ipc_dram_addr of cm_access_control.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2021-1047

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-197966306

GoogleCoalition ESS < 30%HIGH2021-12-01

PUB-A-197966306

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-1019

Open SourceCoalition ESS < 30%HIGH2021-12-07

In snoozeNotification of NotificationListenerService.java, there is a possible permission confusion due to a misleading user consent dialog. This could lead to local escalation of privilege with User execution privileges needed. User interaction is nee...

CVEs:CVE-2021-1019

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1020

Open SourceCoalition ESS < 30%HIGH2021-12-07

In snoozeNotification of NotificationListenerService.java, there is a possible way to disable notification for an arbitrary user due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. U...

CVEs:CVE-2021-1020

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1021

Open SourceCoalition ESS < 30%HIGH2021-12-07

In snoozeNotificationInt of NotificationManagerService.java, there is a possible way to disable notification for an arbitrary user due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed....

CVEs:CVE-2021-1021

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39656

Open SourceCoalition ESS < 30%HIGH2021-12-15

In __configfs_open_file of file.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2021-39656

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1017

Open SourceCoalition ESS < 30%HIGH2021-12-07

In AdapterService and GattService definition of AndroidManifest.xml, there is a possible way to disable bluetooth connection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges nee...

CVEs:CVE-2021-1017

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-174049066

GoogleCoalition ESS < 30%HIGH2021-12-01

PUB-A-174049066

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-1046

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In lwis_dpm_update_clock of lwis_device_dpm.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2021-1046

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39637

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In CreateDeviceInfo of trusty_remote_provisioning_context.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed...

CVEs:CVE-2021-39637

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39643

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In ic_startRetrieveEntryValue of acropora/app/identity/ic.c, there is a possible bypass of defense-in-depth due to missing validation of the return value. This could lead to local escalation of privilege with System execution privileges needed. User in...

CVEs:CVE-2021-39643

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39653

Open SourceCoalition ESS < 30%HIGH2021-12-07

In (TBD) of (TBD), there is a possible way to boot with a hidden debug policy due to a missing warning to the user. This could lead to local escalation of privilege after preparing the device, hiding the warning, and passing the phone to a new user, wi...

CVEs:CVE-2021-39653

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-193579873

GoogleCoalition ESS < 30%MEDIUM2021-12-01

PUB-A-193579873

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-195573629

GoogleCoalition ESS < 30%NONE2021-12-01

PUB-A-195573629

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-195609074

GoogleCoalition ESS < 30%MEDIUM2021-12-01

PUB-A-195609074

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-39638

Open SourceCoalition ESS < 30%HIGH2021-12-07

In periodic_io_work_func of lwis_periodic_io.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2021-39638

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39650

Open SourceCoalition ESS < 30%HIGH2021-12-07

In (TBD) of (TBD), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions...

CVEs:CVE-2021-39650

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-169763055

GoogleCoalition ESS < 30%HIGH2021-12-01

PUB-A-169763055

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-195607566

GoogleCoalition ESS < 30%HIGH2021-12-01

PUB-A-195607566

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-1023

Open SourceCoalition ESS < 30%MEDIUM2021-12-15

In onCreate of RequestIgnoreBatteryOptimizations.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no addi...

CVEs:CVE-2021-1023

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0998

Open SourceCoalition ESS < 30%HIGH2021-12-07

In 'ih264e_find_bskip_params()' of ih264e_me.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2021-0998

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1001

Open SourceCoalition ESS < 30%HIGH2021-12-07

In PVInitVideoEncoder of mp4enc_api.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2021-1001

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0900

Open SourceCoalition ESS < 30%MEDIUM2021-12-17

In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ...

CVEs:CVE-2021-0900

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0902

Open SourceCoalition ESS < 30%MEDIUM2021-12-17

In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ...

CVEs:CVE-2021-0902

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0676

Open SourceCoalition ESS < 30%MEDIUM2021-12-17

In geniezone driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS058630...

CVEs:CVE-2021-0676

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0677

Open SourceCoalition ESS < 30%HIGH2021-12-17

In ccu driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05827154; Issue ID...

CVEs:CVE-2021-0677

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1040

Open SourceCoalition ESS < 30%HIGH2021-12-15

In onCreate of BluetoothPairingSelectionFragment.java, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitat...

CVEs:CVE-2021-1040

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25517

Open SourceCoalition ESS < 30%CRITICAL2021-12-08

An improper input validation vulnerability in LDFW prior to SMR Dec-2021 Release 1 allows attackers to perform arbitrary code execution.

CVEs:CVE-2021-25517

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0981

Open SourceCoalition ESS < 30%HIGH2021-12-07

In enqueueNotificationInternal of NotificationManagerService.java, there is a possible way to run a foreground service without showing a notification due to improper input validation. This could lead to local escalation of privilege with no additional ...

CVEs:CVE-2021-0981

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1003

Open SourceCoalition ESS < 30%HIGH2021-12-07

In adjustStreamVolume of AudioService.java, there is a possible way for unprivileged app to change audio stream volume due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User inter...

CVEs:CVE-2021-1003

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0678

Open SourceCoalition ESS < 30%HIGH2021-12-17

In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue I...

CVEs:CVE-2021-0678

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0894

Open SourceCoalition ESS < 30%HIGH2021-12-17

In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue I...

CVEs:CVE-2021-0894

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0895

Open SourceCoalition ESS < 30%HIGH2021-12-17

In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue I...

CVEs:CVE-2021-0895

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0896

Open SourceCoalition ESS < 30%HIGH2021-12-17

In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue I...

CVEs:CVE-2021-0896

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0903

Open SourceCoalition ESS < 30%HIGH2021-12-17

In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue I...

CVEs:CVE-2021-0903

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0679

Open SourceCoalition ESS < 30%HIGH2021-12-17

In apusys, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID:...

CVEs:CVE-2021-0679

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0893

Open SourceCoalition ESS < 30%HIGH2021-12-17

In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS0...

CVEs:CVE-2021-0893

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0898

Open SourceCoalition ESS < 30%HIGH2021-12-17

In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS0...

CVEs:CVE-2021-0898

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0899

Open SourceCoalition ESS < 30%HIGH2021-12-17

In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS0...

CVEs:CVE-2021-0899

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0901

Open SourceCoalition ESS < 30%HIGH2021-12-17

In apusys, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID:...

CVEs:CVE-2021-0901

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1029

Open SourceCoalition ESS < 30%HIGH2021-12-15

In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2021-1029

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0977

Open SourceCoalition ESS < 30%HIGH2021-12-07

In phNxpNHal_DtaUpdate of phNxpNciHal_dta.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2021-0977

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0992

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In onCreate of PaymentDefaultDialog.java, there is a possible way to change a default payment app without user consent due to tapjack overlay. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...

CVEs:CVE-2021-0992

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1007

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In btu_hcif_process_event of btu_hcif.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2021-1007

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1024

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In onEventReceived of EventResultPersister.java, there is a possible intent redirection due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2021-1024

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1027

Open SourceCoalition ESS < 30%HIGH2021-12-07

In setTransactionState of SurfaceFlinger, there is possible arbitrary code execution in a privileged process due to improper casting. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n...

CVEs:CVE-2021-1027

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1028

Open SourceCoalition ESS < 30%HIGH2021-12-07

In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2021-1028

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25511

Open SourceCoalition ESS < 30%CRITICAL2021-12-08

An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal vulnerability.

CVEs:CVE-2021-25511

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1038

Open SourceCoalition ESS < 30%MEDIUM2021-12-15

In UserDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/overlay attack. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: A...

CVEs:CVE-2021-1038

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25518

Open SourceCoalition ESS < 30%CRITICAL2021-12-08

An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write and code execution.

CVEs:CVE-2021-25518

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25510

Open SourceCoalition ESS < 30%CRITICAL2021-12-08

An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execution.

CVEs:CVE-2021-25510

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0966

Open SourceCoalition ESS < 30%HIGH2021-12-07

In code generated by BuildParcelFields of generate_cpp.cpp, there is a possible way for a crafted parcelable to reveal uninitialized memory of a target process due to uninitialized data. This could lead to local information disclosure across Binder tra...

CVEs:CVE-2021-0966

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0997

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In handleUpdateNetworkState of GnssNetworkConnectivityHandler.java , there is a possible APN disclosure due to log information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction ...

CVEs:CVE-2021-0997

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1005

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In getDeviceIdWithFeature of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no ad...

CVEs:CVE-2021-1005

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1009

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In setApplicationCategoryHint of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with n...

CVEs:CVE-2021-1009

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1012

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In onResume of NotificationAccessDetails.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional e...

CVEs:CVE-2021-1012

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1013

Open SourceCoalition ESS < 30%HIGH2021-12-07

In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead...

CVEs:CVE-2021-1013

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1014

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In getNetworkTypeForSubscriber of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with ...

CVEs:CVE-2021-1014

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1016

Open SourceCoalition ESS < 30%HIGH2021-12-07

In onCreate of UsbPermissionActivity.java, there is a possible way to grant an app access to USB without informed user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. U...

CVEs:CVE-2021-1016

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1026

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In startRanging of RttServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional executio...

CVEs:CVE-2021-1026

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1030

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In setNotificationsShownFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information discl...

CVEs:CVE-2021-1030

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39651

Open SourceCoalition ESS < 30%HIGH2021-12-15

In TBD of TBD, there is a possible way to access PIN protected settings bypassing PIN confirmation due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n...

CVEs:CVE-2021-39651

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1015

Open SourceCoalition ESS < 30%MEDIUM2021-12-15

In getMeidForSlot of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional...

CVEs:CVE-2021-1015

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0988

Open SourceCoalition ESS < 30%MEDIUM2021-12-15

In getLaunchedFromUid and getLaunchedFromPackage of ActivityClientController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local informa...

CVEs:CVE-2021-0988

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0953

Open SourceCoalition ESS < 30%HIGH2021-12-07

In setOnClickActivityIntent of SearchWidgetProvider.java, there is a possible way to access contacts and history bookmarks without permission due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privilege...

CVEs:CVE-2021-0953

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0983

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In createAdminSupportIntent of DevicePolicyManagerService.java, there is a possible disclosure of information about installed device/profile owner package name due to side channel information disclosure. This could lead to local information disclosure ...

CVEs:CVE-2021-0983

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0986

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In hasGrantedPolicy of DevicePolicyManagerService.java, there is a possible information disclosure about the device owner, profile owner, or device admin due to a logic error in the code. This could lead to local information disclosure with no addition...

CVEs:CVE-2021-0986

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0987

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In getNeighboringCellInfo of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no ad...

CVEs:CVE-2021-0987

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0989

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In hasManageOngoingCallsPermission of TelecomServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with...

CVEs:CVE-2021-0989

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0990

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In getDeviceId of PhoneSubInfoController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional e...

CVEs:CVE-2021-0990

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0995

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In registerSuggestionConnectionStatusListener of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclos...

CVEs:CVE-2021-0995

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1018

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In adjustStreamVolume of AudioService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional exec...

CVEs:CVE-2021-1018

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1031

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In cancelNotificationsFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclos...

CVEs:CVE-2021-1031

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1032

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In getMimeGroup of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional e...

CVEs:CVE-2021-1032

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-193438173

GoogleCoalition ESS < 30%NONE2021-12-01

PUB-A-193438173

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-1006

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In several functions of DatabaseManager.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed...

CVEs:CVE-2021-1006

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1034

Open SourceCoalition ESS < 30%HIGH2021-12-07

In getLine1NumberForDisplay of PhoneInterfaceManager.java, there is apossible way to determine whether an app is installed, without querypermissions due to a missing permission check. This could lead to localinformation disclosure with no additional ex...

CVEs:CVE-2021-1034

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0958

Open SourceCoalition ESS < 30%HIGH2021-12-07

In update of km_compat.cpp, there is a possible loss of potentially sensitive data due to a logic error in the code. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2021-0958

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1008

Open SourceCoalition ESS < 30%HIGH2021-12-07

In addSubInfo of SubscriptionController.java, there is a possible way to force the user to make a factory reset due to a logic error in the code. This could lead to local denial of service with System execution privileges needed. User interaction is no...

CVEs:CVE-2021-1008

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25513

Open SourceCoalition ESS < 30%LOW2021-12-08

An improper privilege management vulnerability in Apps Edge application prior to SMR Dec-2021 Release 1 allows unauthorized access to some device data on the lockscreen.

CVEs:CVE-2021-25513

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0979

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In isRequestPinItemSupported of ShortcutService.java, there is a possible cross-user leak of packages in which the default launcher supports requests to create pinned shortcuts due to a permissions bypass. This could lead to local information disclosur...

CVEs:CVE-2021-0979

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1011

Open SourceCoalition ESS < 30%MEDIUM2021-12-15

In setPackageStoppedState of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andro...

CVEs:CVE-2021-1011

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0978

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In getSerialForPackage of DeviceIdentifiersPolicyService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with...

CVEs:CVE-2021-0978

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0982

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In getOrganizationNameForUser of DevicePolicyManagerService.java, there is a possible organization name disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User i...

CVEs:CVE-2021-0982

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0985

Open SourceCoalition ESS < 30%HIGH2021-12-07

In onReceive of AlertReceiver.java, there is a possible way to dismiss system dialog due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2021-0985

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0994

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In requestRouteToHostAddress of ConnectivityService.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional...

CVEs:CVE-2021-0994

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0999

Open SourceCoalition ESS < 30%HIGH2021-12-07

In the broadcast definition in AndroidManifest.xml, there is a possible way to set the A2DP bluetooth device connection state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges ne...

CVEs:CVE-2021-0999

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1004

Open SourceCoalition ESS < 30%HIGH2021-12-07

In getConfiguredNetworks of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local escalation of privilege with no additional execut...

CVEs:CVE-2021-1004

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1010

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In getSigningKeySet of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVers...

CVEs:CVE-2021-1010

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1025

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In hasNamedWallpaper of WallpaperManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional exe...

CVEs:CVE-2021-1025

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-25512

Open SourceCoalition ESS < 30%HIGH2021-12-08

An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain activities.

CVEs:CVE-2021-25512

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39640

Open SourceCoalition ESS < 30%HIGH2021-12-07

In __dwc3_gadget_ep0_queue of ep0.c, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2021-39640

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-157294279

GoogleCoalition ESS < 30%HIGH2021-12-01

PUB-A-157294279

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-25515

Open SourceCoalition ESS < 30%MEDIUM2021-12-08

An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.

CVEs:CVE-2021-25515

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39647

Open SourceCoalition ESS < 30%MEDIUM2021-12-07

In mon_smc_load_sp of gs101-sc/plat/samsung/exynos/soc/exynos9845/smc_booting.S, there is a possible reinitialization of TEE due to improper locking. This could lead to local information disclosure with System execution privileges needed. User interact...

CVEs:CVE-2021-39647

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39649

Open SourceCoalition ESS < 30%HIGH2021-12-07

In regmap_exit of regmap.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: And...

CVEs:CVE-2021-39649

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-174049006

GoogleCoalition ESS < 30%HIGH2021-12-01

PUB-A-174049006

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-198713939

GoogleCoalition ESS < 30%MEDIUM2021-12-01

PUB-A-198713939

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-25519

Open SourceCoalition ESS < 30%MEDIUM2021-12-08

An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC information without permission.

CVEs:CVE-2021-25519

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0897

Open SourceCoalition ESS < 30%HIGH2021-12-17

In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue I...

CVEs:CVE-2021-0897

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0955

Open SourceCoalition ESS < 30%HIGH2021-12-07

In pf_write_buf of FuseDaemon.cpp, there is possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An...

CVEs:CVE-2021-0955

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39642

Open SourceCoalition ESS < 30%HIGH2021-12-07

In synchronous_process_io_entries of lwis_ioctl.c, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2021-39642

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-195731663

GoogleCoalition ESS < 30%HIGH2021-12-01

PUB-A-195731663

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-m3fm-h5jp-q79p

Open SourceEPSS <= 49%CRITICAL2021-12-20

Authorization bypass in Openshift

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-1.19 affected chainguard kubernetes-1.19
kubernetes-1.20 affected chainguard kubernetes-1.20
kubernetes-1.21 affected chainguard kubernetes-1.21
kubernetes-1.22 affected chainguard kubernetes-1.22
kubernetes-1.23 affected chainguard kubernetes-1.23
kubernetes-1.24 affected wolfi kubernetes-1.24
kubernetes-1.24 affected chainguard kubernetes-1.24
kubernetes-1.25 affected chainguard kubernetes-1.25
kubernetes-1.25 affected wolfi kubernetes-1.25
kubernetes-1.26 affected chainguard kubernetes-1.26
kubernetes-1.26 affected wolfi kubernetes-1.26
kubernetes-1.27 affected wolfi kubernetes-1.27
kubernetes-1.27 affected chainguard kubernetes-1.27
kubernetes-1.28 affected wolfi kubernetes-1.28
kubernetes-1.28 affected chainguard kubernetes-1.28
kubernetes-1.29 affected chainguard kubernetes-1.29
kubernetes-1.29 affected wolfi kubernetes-1.29
kubernetes-1.30 affected wolfi kubernetes-1.30
kubernetes-1.30 affected chainguard kubernetes-1.30
kubernetes-1.31 affected wolfi kubernetes-1.31
kubernetes-1.31 affected chainguard kubernetes-1.31
kubernetes-1.32 affected chainguard kubernetes-1.32
kubernetes-1.32 affected wolfi kubernetes-1.32
openshift/origin affected github.com github.com/openshift/origin
Upstream advisory

GHSA-m3fm-h5jp-q79p

GoogleEPSS <= 49%CRITICAL2021-12-20

Authorization bypass in Openshift

Affected products

ProductStatusVendorPackageEcosystem
openshift/origin affected github.com github.com/openshift/origin
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.