Google Security Advisories · February 2022 — Google Security Advisories
768 advisories 461 CVEs 16 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2022-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 16 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2022-24682

GoogleExploitedCISA KEV listedMEDIUM2022-02-09

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attr...

CVEs:CVE-2022-24682

Affected products

ProductStatusVendorPackageEcosystem
zimbra_collaboration_suite affected synacor
Upstream advisory

CVE-2022-24682

Project ZeroExploitedCISA KEV listed2022-02-09

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.

CVEs:CVE-2022-24682

Upstream advisory

openSUSE-SU-2022:0042-1

Open SourceExploitedCISA KEV listedCRITICAL2022-02-17

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

DSA-5079-1

Open SourceExploitedCISA KEV listed2022-02-17

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-0609

Project ZeroExploitedCISA KEV listed2022-02-15

Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0609

Upstream advisory

CVE-2022-0609

GoogleExploitedCISA KEV listedCRITICAL2022-02-15

Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0609

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0609

GoogleExploitedCISA KEV listedHIGH2022-02-15

Use after free in Animation

CVEs:CVE-2022-0609

Affected products

ProductStatusVendorPackageEcosystem
CefSharp.Common affected NuGet CefSharp.Common
CefSharp.Common.NETCore affected NuGet CefSharp.Common.NETCore
CefSharp.OffScreen affected NuGet CefSharp.OffScreen
CefSharp.OffScreen.NETCore affected NuGet CefSharp.OffScreen.NETCore
CefSharp.WinForms affected NuGet CefSharp.WinForms
CefSharp.WinForms.NETCore affected NuGet CefSharp.WinForms.NETCore
CefSharp.Wpf affected NuGet CefSharp.Wpf
CefSharp.Wpf.HwndHost affected NuGet CefSharp.Wpf.HwndHost
CefSharp.Wpf.NETCore affected NuGet CefSharp.Wpf.NETCore
Upstream advisory

CVE-2022-22620

Project ZeroExploitedCISA KEV listed2022-02-11

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

CVEs:CVE-2022-22620

Upstream advisory

CVE-2022-22620

GoogleExploitedCISA KEV listedCRITICAL2022-02-11

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to a...

CVEs:CVE-2022-22620

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
Upstream advisory

DEBIAN-CVE-2021-4102

Open SourceExploitedCISA KEV listedCRITICAL2022-02-11

DEBIAN-CVE-2021-4102

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

openSUSE-SU-2022:0030-1

Open SourceExploitedVulnCheck KEV listedCRITICAL2022-02-07

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

DSA-5068-1

Open SourceExploitedVulnCheck KEV listed2022-02-07

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-0456

GoogleExploitedVulnCheck KEV listedCRITICAL2022-02-02

Use after free in Web Search in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via profile destruction.

CVEs:CVE-2022-0456

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-579h-mv94-g4gp

Open SourceWeaponized exploitCRITICAL2022-02-15

Privilege Escalation in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

GHSA-579h-mv94-g4gp

Open SourceWeaponized exploitCRITICAL2022-02-15

Privilege Escalation in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

MGASA-2022-0043

Open SourceActive exploitation (sightings)CRITICAL2022-02-02

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

GHSA-82mm-ffjr-h86c

Open SourceActive exploitation (sightings)CRITICAL2022-02-15

Authorization bypass in Istio

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio.io istio.io/istio
Upstream advisory

GHSA-82mm-ffjr-h86c

Open SourceActive exploitation (sightings)CRITICAL2022-02-15

Authorization bypass in Istio

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio.io istio.io/istio
Upstream advisory

DEBIAN-CVE-2022-0293

Open SourceActive exploitation (sightings)CRITICAL2022-02-12

DEBIAN-CVE-2022-0293

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0295

Open SourceActive exploitation (sightings)HIGH2022-02-12

DEBIAN-CVE-2022-0295

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0296

Open SourceActive exploitation (sightings)HIGH2022-02-12

DEBIAN-CVE-2022-0296

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0297

Open SourceActive exploitation (sightings)CRITICAL2022-02-12

DEBIAN-CVE-2022-0297

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0298

Open SourceActive exploitation (sightings)CRITICAL2022-02-12

DEBIAN-CVE-2022-0298

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0307

Open SourceActive exploitation (sightings)HIGH2022-02-12

DEBIAN-CVE-2022-0307

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0308

Open SourceActive exploitation (sightings)HIGH2022-02-12

DEBIAN-CVE-2022-0308

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0291

Open SourceActive exploitation (sightings)MEDIUM2022-02-12

DEBIAN-CVE-2022-0291

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0294

Open SourceActive exploitation (sightings)MEDIUM2022-02-12

DEBIAN-CVE-2022-0294

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0305

Open SourceActive exploitation (sightings)MEDIUM2022-02-12

DEBIAN-CVE-2022-0305

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-2575-pghm-6qqx

Open SourceActive exploitation (sightings)MEDIUM2022-02-15

Kubernetes Unsafe Cacheing

Affected products

ProductStatusVendorPackageEcosystem
client-go affected k8s.io k8s.io/client-go
Upstream advisory

GHSA-2575-pghm-6qqx

Open SourceActive exploitation (sightings)MEDIUM2022-02-15

Kubernetes Unsafe Cacheing

Affected products

ProductStatusVendorPackageEcosystem
client-go affected k8s.io k8s.io/client-go
Upstream advisory

GHSA-wxjg-p59j-6c92

GoogleActive exploitation (sightings)HIGH2022-02-26

Command injection in github.com/google/fscrypt

Affected products

ProductStatusVendorPackageEcosystem
google/fscrypt affected github.com github.com/google/fscrypt
Upstream advisory

GHSA-wxjg-p59j-6c92

GoogleActive exploitation (sightings)HIGH2022-02-26

Command injection in github.com/google/fscrypt

Affected products

ProductStatusVendorPackageEcosystem
google/fscrypt affected github.com github.com/google/fscrypt
Upstream advisory

CVE-2022-25328

GoogleActive exploitation (sightings)MEDIUM2022-02-25

Command injection in github.com/google/fscrypt

CVEs:CVE-2022-25328

Affected products

ProductStatusVendorPackageEcosystem
google/fscrypt affected github.com github.com/google/fscrypt
Upstream advisory

CVE-2022-25328

GoogleActive exploitation (sightings)HIGH2022-02-25

The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their p...

CVEs:CVE-2022-25328

Affected products

ProductStatusVendorPackageEcosystem
fscrypt affected google
Upstream advisory

GHSA-34jx-wx69-9x8v

Open SourcePoC exploitMEDIUM2022-02-15

Symlink Attack in kubectl cp

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-34jx-wx69-9x8v

Open SourcePoC exploitMEDIUM2022-02-15

Symlink Attack in kubectl cp

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-j9wf-vvm6-4r9w

Open SourcePoC exploitHIGH2022-02-08

Unverified Ownership in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-j9wf-vvm6-4r9w

Open SourcePoC exploitHIGH2022-02-08

Unverified Ownership in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-1.21 affected chainguard kubernetes-1.21
kubernetes-1.22 affected chainguard kubernetes-1.22
kubernetes-1.23 affected chainguard kubernetes-1.23
kubernetes-1.24 affected chainguard kubernetes-1.24
kubernetes-1.24 affected wolfi kubernetes-1.24
kubernetes-1.26 affected chainguard kubernetes-1.26
kubernetes-1.26 affected wolfi kubernetes-1.26
kubernetes-1.27 affected chainguard kubernetes-1.27
kubernetes-1.27 affected wolfi kubernetes-1.27
kubernetes-1.28 affected wolfi kubernetes-1.28
kubernetes-1.28 affected chainguard kubernetes-1.28
kubernetes-1.29 affected chainguard kubernetes-1.29
kubernetes-1.29 affected wolfi kubernetes-1.29
kubernetes-1.30 affected chainguard kubernetes-1.30
kubernetes-1.30 affected wolfi kubernetes-1.30
kubernetes-1.31 affected wolfi kubernetes-1.31
kubernetes-1.31 affected chainguard kubernetes-1.31
kubernetes-1.32 affected chainguard kubernetes-1.32
kubernetes-1.32 affected wolfi kubernetes-1.32
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
spark-operator affected wolfi spark-operator
spark-operator affected chainguard spark-operator
Upstream advisory

GO-2021-0238

Open SourcePoC exploitHIGH2022-02-17

Infinite loop when parsing inputs in golang.org/x/net/html

Affected products

ProductStatusVendorPackageEcosystem
grpcurl affected wolfi grpcurl
grpcurl affected chainguard grpcurl
hey affected chainguard hey
hey affected wolfi hey
k3d affected wolfi k3d
k3d affected chainguard k3d
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
x/net affected golang.org golang.org/x/net
Upstream advisory

GO-2021-0243

Open SourcePoC exploit2022-02-17

Panic on certain certificates in crypto/tls

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

OESA-2022-1518

Open SourcePoC exploit2022-02-11

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS-SP1 golang
golang affected openEuler:20.03-LTS-SP2 golang
golang affected openEuler:20.03-LTS-SP3 golang
Upstream advisory

GHSA-cg3q-j54f-5p7p

Open SourcePoC exploitHIGH2022-02-16

Uncontrolled Resource Consumption in promhttp

Affected products

ProductStatusVendorPackageEcosystem
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
prometheus/client_golang affected github.com github.com/prometheus/client_golang
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
Upstream advisory

GHSA-cg3q-j54f-5p7p

Open SourcePoC exploitHIGH2022-02-16

Uncontrolled Resource Consumption in promhttp

Affected products

ProductStatusVendorPackageEcosystem
prometheus/client_golang affected github.com github.com/prometheus/client_golang
Upstream advisory

AZL-33567

Open SourcePoC exploitHIGH2022-02-15

CVE-2022-21698 affecting package application-gateway-kubernetes-ingress for versions less than 1.4.0-17

Affected products

ProductStatusVendorPackageEcosystem
application-gateway-kubernetes-ingress affected Azure Linux:2 application-gateway-kubernetes-ingress
Upstream advisory

AZL-34541

Open SourcePoC exploitHIGH2022-02-15

CVE-2022-21698 affecting package application-gateway-kubernetes-ingress for versions less than 1.7.2-2

Affected products

ProductStatusVendorPackageEcosystem
application-gateway-kubernetes-ingress affected Azure Linux:3 application-gateway-kubernetes-ingress
Upstream advisory

DEBIAN-CVE-2022-21698

Open SourcePoC exploitHIGH2022-02-15

DEBIAN-CVE-2022-21698

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-client-golang affected Debian:14 golang-github-prometheus-client-golang
golang-github-prometheus-client-golang affected Debian:11 golang-github-prometheus-client-golang
golang-github-prometheus-client-golang affected Debian:12 golang-github-prometheus-client-golang
golang-github-prometheus-client-golang affected Debian:13 golang-github-prometheus-client-golang
Upstream advisory

CVE-2022-21698

Open SourcePoC exploitHIGH2022-02-15

Uncontrolled Resource Consumption in promhttp

CVEs:CVE-2022-21698

Affected products

ProductStatusVendorPackageEcosystem
prometheus/client_golang affected github.com github.com/prometheus/client_golang
Upstream advisory

CVE-2022-21698

Open SourcePoC exploitHIGH2022-02-15

client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial...

CVEs:CVE-2022-21698

Affected products

ProductStatusVendorPackageEcosystem
client_golang affected prometheus
extra_packages_for_enterprise_linux affected fedoraproject
fedora affected fedoraproject
rdo affected rdo_project
Upstream advisory

GHSA-x6mj-w4jf-jmgw

Open SourcePoC exploitHIGH2022-02-15

Server Side Request Forgery (SSRF) in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
Upstream advisory

GHSA-x6mj-w4jf-jmgw

Open SourcePoC exploitHIGH2022-02-15

Server Side Request Forgery (SSRF) in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-wqv3-8cm6-h6wg

Open SourcePoC exploitHIGH2022-02-15

Improper Authentication in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
Upstream advisory

GHSA-wqv3-8cm6-h6wg

Open SourcePoC exploitHIGH2022-02-15

Improper Authentication in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GO-2021-0240

Open SourcePoC exploit2022-02-17

Panic when reading certain archives in archive/zip

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

GO-2021-0227

Open SourcePoC exploit2022-02-17

Panic on crafted authentication request message in golang.org/x/crypto/ssh

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
k3d affected chainguard k3d
k3d affected wolfi k3d
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

GO-2021-0239

Open SourcePoC exploit2022-02-17

Improper sanitization when resolving values from DNS in net

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

GO-2021-0245

Open SourcePoC exploit2022-02-17

Panic in ReverseProxy in net/http/httputil

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

AZL-79100

Open SourcePoC exploitCRITICAL2022-02-11

CVE-2022-23806 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-8524

Open SourcePoC exploitCRITICAL2022-02-11

CVE-2022-23806 affecting package golang for versions less than 1.18.8-3

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

CVE-2022-23806

Open SourcePoC exploitCRITICAL2022-02-11

Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.

CVEs:CVE-2022-23806

Affected products

ProductStatusVendorPackageEcosystem
beegfs_csi_driver affected netapp
cloud_insights_telegraf_agent affected netapp
debian_linux affected debian
go affected golang
kubernetes_monitoring_operator affected netapp
storagegrid affected netapp
Upstream advisory

DEBIAN-CVE-2022-23806

Open SourcePoC exploitCRITICAL2022-02-11

DEBIAN-CVE-2022-23806

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

AZL-8512

Open SourcePoC exploitHIGH2022-02-11

CVE-2022-23772 affecting package golang for versions less than 1.17.8-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

CVE-2022-23772

Open SourcePoC exploitHIGH2022-02-11

Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.

CVEs:CVE-2022-23772

Affected products

ProductStatusVendorPackageEcosystem
beegfs_csi_driver affected netapp
cloud_insights_telegraf_agent affected netapp
debian_linux affected debian
go affected golang
kubernetes_monitoring_operator affected netapp
storagegrid affected netapp
Upstream advisory

DEBIAN-CVE-2022-23772

Open SourcePoC exploitHIGH2022-02-11

DEBIAN-CVE-2022-23772

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

GO-2021-0235

Open SourcePoC exploit2022-02-17

Incorrect operations on the P-224 curve in crypto/elliptic

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

AZL-8513

Open SourcePoC exploitHIGH2022-02-11

CVE-2022-23773 affecting package golang for versions less than 1.17.8-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

CVE-2022-23773

Open SourcePoC exploitHIGH2022-02-11

cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.

CVEs:CVE-2022-23773

Affected products

ProductStatusVendorPackageEcosystem
beegfs_csi_driver affected netapp
cloud_insights_telegraf_agent affected netapp
go affected golang
kubernetes_monitoring_operator affected netapp
storagegrid affected netapp
Upstream advisory

DEBIAN-CVE-2022-23773

Open SourcePoC exploitHIGH2022-02-11

DEBIAN-CVE-2022-23773

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

GHSA-82hx-w2r5-c2wq

Open SourcePoC exploitHIGH2022-02-15

Kubernetes API Server DoS Via API Requests

Affected products

ProductStatusVendorPackageEcosystem
apiserver affected k8s.io k8s.io/apiserver
Upstream advisory

GHSA-82hx-w2r5-c2wq

Open SourcePoC exploitHIGH2022-02-15

Kubernetes API Server DoS Via API Requests

Affected products

ProductStatusVendorPackageEcosystem
apiserver affected k8s.io k8s.io/apiserver
argo-cd-2.7 affected wolfi argo-cd-2.7
argo-cd-2.7 affected chainguard argo-cd-2.7
argo-cd-2.8 affected chainguard argo-cd-2.8
argo-cd-2.8 affected wolfi argo-cd-2.8
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-ebs-csi-driver affected wolfi aws-ebs-csi-driver
aws-ebs-csi-driver-1.18 affected chainguard aws-ebs-csi-driver-1.18
aws-ebs-csi-driver-1.19 affected chainguard aws-ebs-csi-driver-1.19
calico affected chainguard calico
calico affected wolfi calico
cert-manager-1.11 affected chainguard cert-manager-1.11
cert-manager-1.11 affected wolfi cert-manager-1.11
cert-manager-1.12 affected chainguard cert-manager-1.12
cert-manager-1.12 affected wolfi cert-manager-1.12
flux-helm-controller affected chainguard flux-helm-controller
flux-helm-controller affected wolfi flux-helm-controller
flux-helm-controller-0 affected chainguard flux-helm-controller-0
flux-helm-controller-0.37 affected chainguard flux-helm-controller-0.37
gatekeeper-3.12 affected chainguard gatekeeper-3.12
gatekeeper-3.12 affected wolfi gatekeeper-3.12
gatekeeper-3.13 affected wolfi gatekeeper-3.13
gatekeeper-3.13 affected chainguard gatekeeper-3.13
haproxy-ingress affected chainguard haproxy-ingress
haproxy-ingress affected wolfi haproxy-ingress
helm affected chainguard helm
helm affected wolfi helm
helm-3 affected wolfi helm-3
helm-3 affected chainguard helm-3
helm-4 affected chainguard helm-4
helm-4 affected wolfi helm-4
istio-pilot-agent-1.18 affected wolfi istio-pilot-agent-1.18
istio-pilot-agent-1.18 affected chainguard istio-pilot-agent-1.18
istio-pilot-agent-fips-1.19 affected chainguard istio-pilot-agent-fips-1.19
istio-pilot-discovery-1.19 affected wolfi istio-pilot-discovery-1.19
istio-pilot-discovery-1.19 affected chainguard istio-pilot-discovery-1.19
istio-pilot-discovery-fips-1.19 affected chainguard istio-pilot-discovery-fips-1.19
k8sgpt affected chainguard k8sgpt
k8sgpt affected wolfi k8sgpt
kargo affected chainguard kargo
kargo affected wolfi kargo
keda affected wolfi keda
keda affected chainguard keda
keda-2.10 affected wolfi keda-2.10
keda-2.10 affected chainguard keda-2.10
keda-2.8 affected chainguard keda-2.8
keda-2.9 affected chainguard keda-2.9
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines affected wolfi kubeflow-pipelines
kube-oidc-proxy affected chainguard kube-oidc-proxy
kubernetes-csi-external-provisioner affected chainguard kubernetes-csi-external-provisioner
kubernetes-csi-external-provisioner affected wolfi kubernetes-csi-external-provisioner
kubernetes-csi-external-resizer affected chainguard kubernetes-csi-external-resizer
kubernetes-csi-external-resizer affected wolfi kubernetes-csi-external-resizer
kubevela affected chainguard kubevela
kubevela affected wolfi kubevela
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
Upstream advisory

GO-2021-0241

Open SourcePoC exploit2022-02-17

Attacker can drop certain headers in net/http/httputil

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

GHSA-hwrr-rhmm-vcvf

Open SourcePoC exploitCRITICAL2022-02-15

NULL Pointer Dereference in Kubernetes CSI snapshot-controller

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-csi/external-snapshotter/v2 affected github.com github.com/kubernetes-csi/external-snapshotter/v2
kubernetes-csi/external-snapshotter/v3 affected github.com github.com/kubernetes-csi/external-snapshotter/v3
Upstream advisory

GHSA-hwrr-rhmm-vcvf

Open SourcePoC exploitCRITICAL2022-02-15

NULL Pointer Dereference in Kubernetes CSI snapshot-controller

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-csi/external-snapshotter/v2 affected github.com github.com/kubernetes-csi/external-snapshotter/v2
kubernetes-csi/external-snapshotter/v3 affected github.com github.com/kubernetes-csi/external-snapshotter/v3
Upstream advisory

GHSA-2qp4-g3q3-f92w

Open SourcePoC exploitMEDIUM2022-02-26

Improper Locking in JetBrains Kotlin

Affected products

ProductStatusVendorPackageEcosystem
org.jetbrains.kotlin:kotlin-stdlib affected Maven org.jetbrains.kotlin:kotlin-stdlib
Upstream advisory

GHSA-2qp4-g3q3-f92w

Open SourcePoC exploitMEDIUM2022-02-26

Improper Locking in JetBrains Kotlin

Affected products

ProductStatusVendorPackageEcosystem
org.jetbrains.kotlin:kotlin-stdlib affected Maven org.jetbrains.kotlin:kotlin-stdlib
thingsboard affected wolfi thingsboard
thingsboard affected chainguard thingsboard
Upstream advisory

CVE-2022-24329

GooglePoC exploitMEDIUM2022-02-25

In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.

CVEs:CVE-2022-24329

Affected products

ProductStatusVendorPackageEcosystem
communications_cloud_native_core_binding_support_function affected oracle
communications_pricing_design_center affected oracle
kotlin affected jetbrains
Upstream advisory

CVE-2022-24329

Open SourcePoC exploitMEDIUM2022-02-25

Improper Locking in JetBrains Kotlin

CVEs:CVE-2022-24329

Affected products

ProductStatusVendorPackageEcosystem
org.jetbrains.kotlin:kotlin-stdlib affected Maven org.jetbrains.kotlin:kotlin-stdlib
Upstream advisory

GHSA-xx8c-m748-xr4j

Open SourcePoC exploitHIGH2022-02-15

Access Restriction Bypass in kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

GHSA-xx8c-m748-xr4j

Open SourcePoC exploitHIGH2022-02-15

Access Restriction Bypass in kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-1.19 affected chainguard kubernetes-1.19
kubernetes-1.20 affected chainguard kubernetes-1.20
kubernetes-1.21 affected chainguard kubernetes-1.21
kubernetes-1.22 affected chainguard kubernetes-1.22
kubernetes-1.23 affected chainguard kubernetes-1.23
kubernetes-1.24 affected wolfi kubernetes-1.24
kubernetes-1.24 affected chainguard kubernetes-1.24
kubernetes-1.25 affected chainguard kubernetes-1.25
kubernetes-1.25 affected wolfi kubernetes-1.25
kubernetes-1.26 affected chainguard kubernetes-1.26
kubernetes-1.26 affected wolfi kubernetes-1.26
kubernetes-1.27 affected wolfi kubernetes-1.27
kubernetes-1.27 affected chainguard kubernetes-1.27
kubernetes-1.28 affected chainguard kubernetes-1.28
kubernetes-1.28 affected wolfi kubernetes-1.28
kubernetes-1.29 affected chainguard kubernetes-1.29
kubernetes-1.29 affected wolfi kubernetes-1.29
kubernetes-1.30 affected wolfi kubernetes-1.30
kubernetes-1.30 affected chainguard kubernetes-1.30
kubernetes-1.31 affected chainguard kubernetes-1.31
kubernetes-1.31 affected wolfi kubernetes-1.31
kubernetes-1.32 affected wolfi kubernetes-1.32
kubernetes-1.32 affected chainguard kubernetes-1.32
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

GHSA-qhm4-jxv7-j9pq

Open SourcePoC exploitHIGH2022-02-15

Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
Upstream advisory

GHSA-qhm4-jxv7-j9pq

Open SourcePoC exploitHIGH2022-02-15

Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

DEBIAN-CVE-2022-0108

Open SourcePoC exploitMEDIUM2022-02-12

DEBIAN-CVE-2022-0108

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
webkit2gtk affected Debian:11 webkit2gtk
webkit2gtk affected Debian:12 webkit2gtk
webkit2gtk affected Debian:13 webkit2gtk
webkit2gtk affected Debian:14 webkit2gtk
wpewebkit affected Debian:11 wpewebkit
wpewebkit affected Debian:12 wpewebkit
wpewebkit affected Debian:13 wpewebkit
wpewebkit affected Debian:14 wpewebkit
Upstream advisory

GHSA-6gmv-pjp9-p8w8

Open SourcePoC exploitHIGH2022-02-09

Out of bounds read in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6gmv-pjp9-p8w8

Open SourcePoC exploitHIGH2022-02-09

Out of bounds read in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-107

Open SourcePoC exploitCRITICAL2022-02-03

PYSEC-2022-107

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-52

Open SourcePoC exploitCRITICAL2022-02-03

PYSEC-2022-52

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-21728

Open SourcePoC exploitCRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `ReverseSequence` does not fully validate the value of `batch_dim` and can result in a heap OOB read. There is a check to make sure the value of `batch_d...

CVEs:CVE-2022-21728

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-21728

Open SourcePoC exploitHIGH2022-02-03

Out of bounds read in Tensorflow

CVEs:CVE-2022-21728

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21728

Open SourcePoC exploitHIGH2022-02-03

PYSEC-2022-52

CVEs:CVE-2022-21728

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qh36-44jv-c8xj

Open SourcePoC exploitLOW2022-02-02

Potential proxy IP restriction bypass in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-qh36-44jv-c8xj

Open SourcePoC exploitLOW2022-02-02

Potential proxy IP restriction bypass in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
Upstream advisory

DEBIAN-CVE-2020-8562

Open SourcePoC exploitLOW2022-02-01

DEBIAN-CVE-2020-8562

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2020-8562

Open SourcePoC exploitLOW2022-02-01

Potential proxy IP restriction bypass in Kubernetes

CVEs:CVE-2020-8562

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2020-8562

Open SourcePoC exploitLOW2022-02-01

As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers. ...

CVEs:CVE-2020-8562

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
kubernetes affected kubernetes
Kubernetes affected Kubernetes
Upstream advisory

GHSA-4hvf-hxvg-f67v

Open SourcePoC exploitHIGH2022-02-09

Read and Write outside of bounds in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4hvf-hxvg-f67v

Open SourcePoC exploitHIGH2022-02-09

Read and Write outside of bounds in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-124

Open SourcePoC exploitCRITICAL2022-02-04

PYSEC-2022-124

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-69

Open SourcePoC exploitCRITICAL2022-02-04

PYSEC-2022-69

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23560

Open SourcePoC exploitHIGH2022-02-04

Read and Write outside of bounds in TensorFlow

CVEs:CVE-2022-23560

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23560

Open SourcePoC exploitHIGH2022-02-04

PYSEC-2022-69

CVEs:CVE-2022-23560

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23560

Open SourcePoC exploitCRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would allow limited reads and writes outside of arrays in TFLite. This exploits missing validation in the conversion from sparse tensors to dense tensors...

CVEs:CVE-2022-23560

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2021-39635

Open SourcePoC exploitHIGH2022-02-08

ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Product: AndroidV...

CVEs:CVE-2021-39635

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-206492634

GooglePoC exploitHIGH2022-02-01

ASB-A-206492634

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-f5pg-7wfw-84q9

Open SourcePoC exploitCRITICAL2022-02-11

CBC padding oracle issue in AWS S3 Crypto SDK for golang

Affected products

ProductStatusVendorPackageEcosystem
amazon-cloudwatch-agent affected chainguard amazon-cloudwatch-agent
amazon-cloudwatch-agent affected wolfi amazon-cloudwatch-agent
amazon-cloudwatch-agent-fips affected chainguard amazon-cloudwatch-agent-fips
amazon-ecs-agent affected chainguard amazon-ecs-agent
amazon-ecs-agent-fips affected chainguard amazon-ecs-agent-fips
apply-cve-bump affected chainguard apply-cve-bump
argo-cd-3.0 affected wolfi argo-cd-3.0
argo-cd-3.0 affected chainguard argo-cd-3.0
argo-cd-3.1 affected wolfi argo-cd-3.1
argo-cd-3.1 affected chainguard argo-cd-3.1
argo-cd-3.2 affected wolfi argo-cd-3.2
argo-cd-3.2 affected chainguard argo-cd-3.2
argo-cd-3.3 affected chainguard argo-cd-3.3
argo-cd-3.3 affected wolfi argo-cd-3.3
argo-cd-fips-3.0 affected chainguard argo-cd-fips-3.0
argo-cd-fips-3.1 affected chainguard argo-cd-fips-3.1
argo-cd-fips-3.2 affected chainguard argo-cd-fips-3.2
argo-cd-fips-3.3 affected chainguard argo-cd-fips-3.3
argo-events affected wolfi argo-events
argo-events affected chainguard argo-events
argo-events-fips affected chainguard argo-events-fips
argo-rollouts affected wolfi argo-rollouts
argo-rollouts affected chainguard argo-rollouts
argo-rollouts-fips affected chainguard argo-rollouts-fips
atlas-1.0 affected chainguard atlas-1.0
atlas-1.0-fips affected chainguard atlas-1.0-fips
atlas-1.1 affected chainguard atlas-1.1
atlas-1.1-fips affected chainguard atlas-1.1-fips
atlas-1.2 affected chainguard atlas-1.2
aws/aws-sdk-go affected github.com github.com/aws/aws-sdk-go
aws-flb-cloudwatch affected chainguard aws-flb-cloudwatch
aws-flb-cloudwatch affected wolfi aws-flb-cloudwatch
aws-flb-cloudwatch-fips affected chainguard aws-flb-cloudwatch-fips
aws-flb-firehose affected chainguard aws-flb-firehose
aws-flb-firehose affected wolfi aws-flb-firehose
aws-flb-firehose-fips affected chainguard aws-flb-firehose-fips
aws-flb-kinesis affected wolfi aws-flb-kinesis
aws-flb-kinesis affected chainguard aws-flb-kinesis
aws-flb-kinesis-fips affected chainguard aws-flb-kinesis-fips
aws-node-termination-handler affected wolfi aws-node-termination-handler
aws-node-termination-handler affected chainguard aws-node-termination-handler
aws-node-termination-handler-fips affected chainguard aws-node-termination-handler-fips
aws-nuke affected wolfi aws-nuke
aws-nuke affected chainguard aws-nuke
aws-nuke-fips affected chainguard aws-nuke-fips
aws-otel-collector affected chainguard aws-otel-collector
aws-otel-collector affected wolfi aws-otel-collector
aws-otel-collector-fips affected chainguard aws-otel-collector-fips
aws-s3-controller affected chainguard aws-s3-controller
aws-s3-controller affected wolfi aws-s3-controller
aws-sigv4-proxy affected wolfi aws-sigv4-proxy
aws-sigv4-proxy affected chainguard aws-sigv4-proxy
aws-sigv4-proxy-fips affected chainguard aws-sigv4-proxy-fips
bank-vaults affected chainguard bank-vaults
bank-vaults affected wolfi bank-vaults
bank-vaults-fips affected chainguard bank-vaults-fips
bank-vaults-vault-operator affected chainguard bank-vaults-vault-operator
bank-vaults-vault-operator-fips affected chainguard bank-vaults-vault-operator-fips
cadence affected chainguard cadence
cadence-fips affected chainguard cadence-fips
cephcsi affected chainguard cephcsi
cephcsi-fips affected chainguard cephcsi-fips
cert-exporter affected chainguard cert-exporter
cert-exporter affected wolfi cert-exporter
cert-exporter-fips affected chainguard cert-exporter-fips
certificate-transparency affected wolfi certificate-transparency
certificate-transparency affected chainguard certificate-transparency
certificate-transparency-fips affected chainguard certificate-transparency-fips
cg affected chainguard cg
chartmuseum affected wolfi chartmuseum
chartmuseum affected chainguard chartmuseum
chartmuseum-fips affected chainguard chartmuseum-fips
cloudbeat-9.0 affected chainguard cloudbeat-9.0
cloudbeat-fips-8.17 affected chainguard cloudbeat-fips-8.17
cloudbeat-fips-9.0 affected chainguard cloudbeat-fips-9.0
cloud-sql-proxy-2.16 affected chainguard cloud-sql-proxy-2.16
cloud-sql-proxy-2.16 affected wolfi cloud-sql-proxy-2.16
cloud-sql-proxy-2.17 affected wolfi cloud-sql-proxy-2.17
cloud-sql-proxy-2.17 affected chainguard cloud-sql-proxy-2.17
cloud-sql-proxy-2.18 affected chainguard cloud-sql-proxy-2.18
cloud-sql-proxy-2.18 affected wolfi cloud-sql-proxy-2.18
cloud-sql-proxy-2.21 affected wolfi cloud-sql-proxy-2.21
cloud-sql-proxy-2.21 affected chainguard cloud-sql-proxy-2.21
cloud-sql-proxy-2.22 affected chainguard cloud-sql-proxy-2.22
cloud-sql-proxy-2.22 affected wolfi cloud-sql-proxy-2.22
cloud-sql-proxy-fips affected chainguard cloud-sql-proxy-fips
cluster-autoscaler-1.32 affected chainguard cluster-autoscaler-1.32
cluster-autoscaler-1.32 affected wolfi cluster-autoscaler-1.32
cluster-autoscaler-1.33 affected chainguard cluster-autoscaler-1.33
cluster-autoscaler-1.33 affected wolfi cluster-autoscaler-1.33
cluster-autoscaler-1.34 affected wolfi cluster-autoscaler-1.34
cluster-autoscaler-1.34 affected chainguard cluster-autoscaler-1.34
cluster-autoscaler-fips-1.32 affected chainguard cluster-autoscaler-fips-1.32
cluster-autoscaler-fips-1.33 affected chainguard cluster-autoscaler-fips-1.33
cluster-autoscaler-fips-1.34 affected chainguard cluster-autoscaler-fips-1.34
commercial-grafana-11.6 affected chainguard commercial-grafana-11.6
commercial-grafana-12.1 affected chainguard commercial-grafana-12.1
commercial-grafana-12.2 affected chainguard commercial-grafana-12.2
commercial-grafana-12.3 affected chainguard commercial-grafana-12.3
commercial-grafana-12.4 affected chainguard commercial-grafana-12.4
commercial-grafana-13.0 affected chainguard commercial-grafana-13.0
consul-1.18 affected chainguard consul-1.18
consul-1.19 affected chainguard consul-1.19
consul-1.20 affected chainguard consul-1.20
consul-1.21 affected chainguard consul-1.21
consul-fips-1.20 affected chainguard consul-fips-1.20
consul-fips-1.21 affected chainguard consul-fips-1.21
consul-k8s-1.1 affected chainguard consul-k8s-1.1
consul-k8s-1.3 affected chainguard consul-k8s-1.3
consul-k8s-1.4 affected chainguard consul-k8s-1.4
consul-k8s-1.5 affected chainguard consul-k8s-1.5
consul-k8s-1.6 affected wolfi consul-k8s-1.6
consul-k8s-1.6 affected chainguard consul-k8s-1.6
consul-k8s-fips-1.1 affected chainguard consul-k8s-fips-1.1
consul-k8s-fips-1.3 affected chainguard consul-k8s-fips-1.3
consul-k8s-fips-1.4 affected chainguard consul-k8s-fips-1.4
consul-k8s-fips-1.5 affected chainguard consul-k8s-fips-1.5
consul-k8s-fips-1.6 affected chainguard consul-k8s-fips-1.6
crossplane-aws-provider affected chainguard crossplane-aws-provider
crossplane-aws-provider-fips affected chainguard crossplane-aws-provider-fips
dapr-1.14 affected chainguard dapr-1.14
dapr-1.15 affected chainguard dapr-1.15
dapr-1.15 affected wolfi dapr-1.15
dapr-1.16 affected wolfi dapr-1.16
dapr-1.16 affected chainguard dapr-1.16
dapr-fips-1.14 affected chainguard dapr-fips-1.14
dapr-fips-1.15 affected chainguard dapr-fips-1.15
dapr-fips-1.16 affected chainguard dapr-fips-1.16
datadog-agent-7.71 affected chainguard datadog-agent-7.71
datadog-agent-7.77 affected wolfi datadog-agent-7.77
datadog-agent-7.77 affected chainguard datadog-agent-7.77
datadog-agent-7.78 affected chainguard datadog-agent-7.78
datadog-agent-7.78 affected wolfi datadog-agent-7.78
datadog-agent-7.79 affected chainguard datadog-agent-7.79
datadog-agent-7.79 affected wolfi datadog-agent-7.79
datadog-agent-fips-7.71 affected chainguard datadog-agent-fips-7.71
datadog-agent-fips-7.77 affected chainguard datadog-agent-fips-7.77
datadog-agent-fips-7.78 affected chainguard datadog-agent-fips-7.78
datadog-agent-fips-7.79 affected chainguard datadog-agent-fips-7.79
distribution affected chainguard distribution
distribution affected wolfi distribution
distribution-fips affected chainguard distribution-fips
drone affected chainguard drone
drone-fips affected chainguard drone-fips
elastic-agent-8.19 affected chainguard elastic-agent-8.19
elastic-agent-9.1 affected chainguard elastic-agent-9.1
elastic-agent-9.2 affected chainguard elastic-agent-9.2
elastic-agent-9.3 affected chainguard elastic-agent-9.3
elastic-agent-9.4 affected chainguard elastic-agent-9.4
elastic-agent-fips-8.19 affected chainguard elastic-agent-fips-8.19
elastic-agent-fips-9.1 affected chainguard elastic-agent-fips-9.1
elastic-agent-fips-9.2 affected chainguard elastic-agent-fips-9.2
elastic-agent-fips-9.3 affected chainguard elastic-agent-fips-9.3
elastic-agent-fips-9.4 affected chainguard elastic-agent-fips-9.4
external-secrets-fips affected chainguard external-secrets-fips
external-secrets-operator-1.2 affected wolfi external-secrets-operator-1.2
external-secrets-operator-1.2 affected chainguard external-secrets-operator-1.2
external-secrets-operator-1.3 affected chainguard external-secrets-operator-1.3
external-secrets-operator-1.3 affected wolfi external-secrets-operator-1.3
external-secrets-operator-2.0 affected wolfi external-secrets-operator-2.0
external-secrets-operator-2.0 affected chainguard external-secrets-operator-2.0
external-secrets-operator-2.1 affected chainguard external-secrets-operator-2.1
external-secrets-operator-2.1 affected wolfi external-secrets-operator-2.1
external-secrets-operator-2.2 affected chainguard external-secrets-operator-2.2
external-secrets-operator-2.2 affected wolfi external-secrets-operator-2.2
external-secrets-operator-2.3 affected chainguard external-secrets-operator-2.3
external-secrets-operator-2.3 affected wolfi external-secrets-operator-2.3
external-secrets-operator-2.4 affected chainguard external-secrets-operator-2.4
external-secrets-operator-2.4 affected wolfi external-secrets-operator-2.4
external-secrets-operator-2.5 affected wolfi external-secrets-operator-2.5
external-secrets-operator-2.5 affected chainguard external-secrets-operator-2.5
external-secrets-operator-2.6 affected chainguard external-secrets-operator-2.6
external-secrets-operator-2.6 affected wolfi external-secrets-operator-2.6
external-secrets-operator-2.7 affected chainguard external-secrets-operator-2.7
external-secrets-operator-fips-1.2 affected chainguard external-secrets-operator-fips-1.2
external-secrets-operator-fips-1.3 affected chainguard external-secrets-operator-fips-1.3
external-secrets-operator-fips-2.0 affected chainguard external-secrets-operator-fips-2.0
external-secrets-operator-fips-2.1 affected chainguard external-secrets-operator-fips-2.1
external-secrets-operator-fips-2.2 affected chainguard external-secrets-operator-fips-2.2
external-secrets-operator-fips-2.3 affected chainguard external-secrets-operator-fips-2.3
external-secrets-operator-fips-2.4 affected chainguard external-secrets-operator-fips-2.4
external-secrets-operator-fips-2.5 affected chainguard external-secrets-operator-fips-2.5
external-secrets-operator-fips-2.6 affected chainguard external-secrets-operator-fips-2.6
external-secrets-operator-fips-2.7 affected chainguard external-secrets-operator-fips-2.7
flagger affected chainguard flagger
flagger-fips affected chainguard flagger-fips
flyte affected chainguard flyte
flyte affected wolfi flyte
gatekeeper-3.20 affected wolfi gatekeeper-3.20
gatekeeper-3.20 affected chainguard gatekeeper-3.20
gatekeeper-3.21 affected chainguard gatekeeper-3.21
gatekeeper-3.21 affected wolfi gatekeeper-3.21
gatekeeper-3.22 affected chainguard gatekeeper-3.22
gatekeeper-3.22 affected wolfi gatekeeper-3.22
gatekeeper-fips-3.20 affected chainguard gatekeeper-fips-3.20
gatekeeper-fips-3.21 affected chainguard gatekeeper-fips-3.21
gatekeeper-fips-3.22 affected chainguard gatekeeper-fips-3.22
gitlab-cng-18.10 affected chainguard gitlab-cng-18.10
gitlab-cng-18.11 affected chainguard gitlab-cng-18.11
gitlab-cng-19.0 affected chainguard gitlab-cng-19.0
gitlab-cng-19.1 affected chainguard gitlab-cng-19.1
gitlab-cng-fips-18.10 affected chainguard gitlab-cng-fips-18.10
gitlab-cng-fips-18.11 affected chainguard gitlab-cng-fips-18.11
gitlab-cng-fips-19.0 affected chainguard gitlab-cng-fips-19.0
gitlab-cng-fips-19.1 affected chainguard gitlab-cng-fips-19.1
gitlab-runner-18.10 affected wolfi gitlab-runner-18.10
gitlab-runner-18.10 affected chainguard gitlab-runner-18.10
gitlab-runner-18.11 affected chainguard gitlab-runner-18.11
gitlab-runner-18.11 affected wolfi gitlab-runner-18.11
gitlab-runner-19.0 affected chainguard gitlab-runner-19.0
gitlab-runner-19.0 affected wolfi gitlab-runner-19.0
gitlab-runner-19.1 affected chainguard gitlab-runner-19.1
gitlab-runner-19.1 affected wolfi gitlab-runner-19.1
gitlab-runner-fips-18.10 affected chainguard gitlab-runner-fips-18.10
gitlab-runner-fips-18.11 affected chainguard gitlab-runner-fips-18.11
gitlab-runner-fips-19.0 affected chainguard gitlab-runner-fips-19.0
gitlab-runner-fips-19.1 affected chainguard gitlab-runner-fips-19.1
gitness affected wolfi gitness
gitness affected chainguard gitness
gitsign affected chainguard gitsign
gitsign affected wolfi gitsign
go-getter-2 affected chainguard go-getter-2
go-getter-2.1 affected chainguard go-getter-2.1
go-getter-2.2 affected chainguard go-getter-2.2
go-getter-2-fips affected chainguard go-getter-2-fips
gomplate-4 affected chainguard gomplate-4
gomplate-5 affected chainguard gomplate-5
gomplate-5 affected wolfi gomplate-5
gomplate-fips-4 affected chainguard gomplate-fips-4
gomplate-fips-5 affected chainguard gomplate-fips-5
google-cloud-otel-ops-collector affected chainguard google-cloud-otel-ops-collector
gostatsd affected wolfi gostatsd
gostatsd affected chainguard gostatsd
grafana-10.1 affected chainguard grafana-10.1
grafana-11.6 affected chainguard grafana-11.6
grafana-12.0 affected chainguard grafana-12.0
grafana-12.0 affected wolfi grafana-12.0
grafana-12.1 affected chainguard grafana-12.1
grafana-12.1 affected wolfi grafana-12.1
grafana-12.2 affected chainguard grafana-12.2
grafana-12.2 affected wolfi grafana-12.2
grafana-12.3 affected wolfi grafana-12.3
grafana-12.3 affected chainguard grafana-12.3
grafana-12.4 affected wolfi grafana-12.4
grafana-12.4 affected chainguard grafana-12.4
grafana-13.0 affected chainguard grafana-13.0
grafana-13.0 affected wolfi grafana-13.0
grafana-13.1 affected chainguard grafana-13.1
grafana-agent-operator affected chainguard grafana-agent-operator
grafana-agent-operator affected wolfi grafana-agent-operator
grafana-fips-11.6 affected chainguard grafana-fips-11.6
grafana-fips-12.0 affected chainguard grafana-fips-12.0
grafana-fips-12.1 affected chainguard grafana-fips-12.1
grafana-fips-12.2 affected chainguard grafana-fips-12.2
grafana-fips-12.3 affected chainguard grafana-fips-12.3
grafana-fips-12.4 affected chainguard grafana-fips-12.4
grafana-fips-13.0 affected chainguard grafana-fips-13.0
grafana-fips-13.1 affected chainguard grafana-fips-13.1
grafana-mimir-2.17 affected chainguard grafana-mimir-2.17
grafana-mimir-3.0 affected wolfi grafana-mimir-3.0
grafana-mimir-3.0 affected chainguard grafana-mimir-3.0
grafana-mimir-fips-2.17 affected chainguard grafana-mimir-fips-2.17
grafana-mimir-fips-3.0 affected chainguard grafana-mimir-fips-3.0
grafana-pyroscope-1.12 affected chainguard grafana-pyroscope-1.12
grafana-pyroscope-1.13 affected wolfi grafana-pyroscope-1.13
grafana-pyroscope-1.13 affected chainguard grafana-pyroscope-1.13
grafana-pyroscope-1.14 affected chainguard grafana-pyroscope-1.14
grept affected chainguard grept
grept-fips affected chainguard grept-fips
guac affected chainguard guac
guac affected wolfi guac
harbor-2.12 affected chainguard harbor-2.12
harbor-2.13 affected chainguard harbor-2.13
harbor-2.13 affected wolfi harbor-2.13
harbor-2.14 affected chainguard harbor-2.14
harbor-2.14 affected wolfi harbor-2.14
harbor-2.15 affected chainguard harbor-2.15
harbor-fips-2.12 affected chainguard harbor-fips-2.12
harbor-fips-2.13 affected chainguard harbor-fips-2.13
harbor-fips-2.14 affected chainguard harbor-fips-2.14
harbor-fips-2.15 affected chainguard harbor-fips-2.15
harbor-registry affected wolfi harbor-registry
harbor-registry affected chainguard harbor-registry
harbor-registry-fips affected chainguard harbor-registry-fips
harvester affected chainguard harvester
harvester-fips affected chainguard harvester-fips
influxd-2.7 affected chainguard influxd-2.7
juicefs-1.2 affected chainguard juicefs-1.2
k3d affected chainguard k3d
k3d affected wolfi k3d
k8sgpt affected wolfi k8sgpt
k8sgpt affected chainguard k8sgpt
k8s-image-swapper affected chainguard k8s-image-swapper
k8s-image-swapper-fips affected chainguard k8s-image-swapper-fips
karpenter-0.33 affected chainguard karpenter-0.33
karpenter-0.34 affected chainguard karpenter-0.34
karpenter-0.35 affected chainguard karpenter-0.35
karpenter-0.36 affected chainguard karpenter-0.36
karpenter-0.37 affected chainguard karpenter-0.37
karpenter-fips-0.33 affected chainguard karpenter-fips-0.33
karpenter-fips-0.34 affected chainguard karpenter-fips-0.34
karpenter-fips-0.35 affected chainguard karpenter-fips-0.35
karpenter-fips-0.36 affected chainguard karpenter-fips-0.36
karpenter-fips-0.37 affected chainguard karpenter-fips-0.37
kiam affected chainguard kiam
kots affected wolfi kots
kots affected chainguard kots
kserve affected chainguard kserve
kserve affected wolfi kserve
kserve-fips affected chainguard kserve-fips
kserve-localmodelnode-agent affected chainguard kserve-localmodelnode-agent
kserve-localmodelnode-agent-fips affected chainguard kserve-localmodelnode-agent-fips
kserve-modelmesh-serving affected wolfi kserve-modelmesh-serving
kserve-modelmesh-serving affected chainguard kserve-modelmesh-serving
kube-arangodb-1.3 affected wolfi kube-arangodb-1.3
kube-arangodb-1.3 affected chainguard kube-arangodb-1.3
kube-arangodb-1.4 affected wolfi kube-arangodb-1.4
kube-arangodb-1.4 affected chainguard kube-arangodb-1.4
kube-arangodb-fips-1.3 affected chainguard kube-arangodb-fips-1.3
kube-arangodb-fips-1.4 affected chainguard kube-arangodb-fips-1.4
kubeflow affected wolfi kubeflow
kubeflow affected chainguard kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines-driver-fips affected chainguard kubeflow-pipelines-driver-fips
kubeflow-pipelines-fips affected chainguard kubeflow-pipelines-fips
kubernetes-event-exporter affected chainguard kubernetes-event-exporter
kubernetes-event-exporter affected wolfi kubernetes-event-exporter
kubernetes-event-exporter-fips affected chainguard kubernetes-event-exporter-fips
kubescape affected wolfi kubescape
kubescape affected chainguard kubescape
kubescape-operator affected wolfi kubescape-operator
kubescape-operator affected chainguard kubescape-operator
kubescape-operator-fips affected chainguard kubescape-operator-fips
kubescape-server affected chainguard kubescape-server
kubescape-server-fips affected chainguard kubescape-server-fips
kubevirt-cdi-uploadserver-1.5 affected chainguard kubevirt-cdi-uploadserver-1.5
kubevirt-cdi-uploadserver-1.59 affected chainguard kubevirt-cdi-uploadserver-1.59
kubevirt-cdi-uploadserver-1.6 affected chainguard kubevirt-cdi-uploadserver-1.6
kubevirt-cdi-uploadserver-fips-1.5 affected chainguard kubevirt-cdi-uploadserver-fips-1.5
kubevirt-cdi-uploadserver-fips-1.59 affected chainguard kubevirt-cdi-uploadserver-fips-1.59
kubevirt-cdi-uploadserver-fips-1.6 affected chainguard kubevirt-cdi-uploadserver-fips-1.6
loki-2.9 affected chainguard loki-2.9
loki-3.4 affected chainguard loki-3.4
loki-3.5 affected wolfi loki-3.5
loki-3.5 affected chainguard loki-3.5
loki-3.6 affected chainguard loki-3.6
loki-3.6 affected wolfi loki-3.6
loki-3.7 affected chainguard loki-3.7
loki-3.7 affected wolfi loki-3.7
loki-fips-2.9 affected chainguard loki-fips-2.9
loki-fips-3.4 affected chainguard loki-fips-3.4
loki-fips-3.5 affected chainguard loki-fips-3.5
loki-fips-3.6 affected chainguard loki-fips-3.6
loki-fips-3.7 affected chainguard loki-fips-3.7
longhorn-backing-image-manager-1.8 affected chainguard longhorn-backing-image-manager-1.8
longhorn-backing-image-manager-1.9 affected chainguard longhorn-backing-image-manager-1.9
longhorn-backing-image-manager-fips-1.8 affected chainguard longhorn-backing-image-manager-fips-1.8
longhorn-backing-image-manager-fips-1.9 affected chainguard longhorn-backing-image-manager-fips-1.9
longhorn-engine-1.8 affected chainguard longhorn-engine-1.8
longhorn-engine-1.9 affected chainguard longhorn-engine-1.9
longhorn-instance-manager-1.8 affected chainguard longhorn-instance-manager-1.8
longhorn-instance-manager-1.8-fips affected chainguard longhorn-instance-manager-1.8-fips
longhorn-instance-manager-1.9 affected chainguard longhorn-instance-manager-1.9
longhorn-instance-manager-1.9-fips affected chainguard longhorn-instance-manager-1.9-fips
mapotf affected chainguard mapotf
mapotf-fips affected chainguard mapotf-fips
mattermost-10.11 affected chainguard mattermost-10.11
mattermost-11.1 affected chainguard mattermost-11.1
mattermost-11.1 affected wolfi mattermost-11.1
mattermost-11.2 affected chainguard mattermost-11.2
mattermost-11.2 affected wolfi mattermost-11.2
mattermost-fips-10.11 affected chainguard mattermost-fips-10.11
mattermost-fips-11.1 affected chainguard mattermost-fips-11.1
mattermost-fips-11.2 affected chainguard mattermost-fips-11.2
metrics-agent affected wolfi metrics-agent
metrics-agent affected chainguard metrics-agent
metrics-agent-fips affected chainguard metrics-agent-fips
monstache affected chainguard monstache
neuvector affected chainguard neuvector
neuvector-fips affected chainguard neuvector-fips
neuvector-scanner affected chainguard neuvector-scanner
neuvector-scanner affected wolfi neuvector-scanner
neuvector-scanner-fips affected chainguard neuvector-scanner-fips
newrelic-nri-statsd affected chainguard newrelic-nri-statsd
newrelic-nri-statsd affected wolfi newrelic-nri-statsd
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
node-problem-detector-1.34 affected chainguard node-problem-detector-1.34
node-problem-detector-1.35 affected wolfi node-problem-detector-1.35
node-problem-detector-1.35 affected chainguard node-problem-detector-1.35
node-problem-detector-fips-0.8 affected chainguard node-problem-detector-fips-0.8
node-problem-detector-fips-1.34 affected chainguard node-problem-detector-fips-1.34
node-problem-detector-fips-1.35 affected chainguard node-problem-detector-fips-1.35
nrdot-collector affected chainguard nrdot-collector
nrdot-collector-fips affected chainguard nrdot-collector-fips
nrdot-collector-k8s affected chainguard nrdot-collector-k8s
nrdot-collector-k8s-fips affected chainguard nrdot-collector-k8s-fips
openbao affected wolfi openbao
openbao affected chainguard openbao
openbao-fips affected chainguard openbao-fips
opencost affected chainguard opencost
opencost affected wolfi opencost
opencost-fips affected chainguard opencost-fips
opentelemetry-collector affected chainguard opentelemetry-collector
opentelemetry-collector affected wolfi opentelemetry-collector
opentelemetry-collector-contrib affected wolfi opentelemetry-collector-contrib
opentelemetry-collector-contrib affected chainguard opentelemetry-collector-contrib
opentelemetry-collector-contrib-fips affected chainguard opentelemetry-collector-contrib-fips
opentelemetry-collector-fips affected chainguard opentelemetry-collector-fips
opentelemetry-collector-k8s affected chainguard opentelemetry-collector-k8s
opentelemetry-collector-k8s-fips affected chainguard opentelemetry-collector-k8s-fips
opentofu-1.9 affected wolfi opentofu-1.9
opentofu-1.9 affected chainguard opentofu-1.9
opentofu-fips-1.9 affected chainguard opentofu-fips-1.9
packer affected chainguard packer
packer-fips affected chainguard packer-fips
plutono affected chainguard plutono
plutono-fips affected chainguard plutono-fips
porch affected chainguard porch
porch-fips affected chainguard porch-fips
postgres-operator affected wolfi postgres-operator
postgres-operator affected chainguard postgres-operator
postgres-operator-fips affected chainguard postgres-operator-fips
prometheus-2.51 affected chainguard prometheus-2.51
prometheus-3.12 affected chainguard prometheus-3.12
prometheus-3.12 affected wolfi prometheus-3.12
prometheus-3.5 affected chainguard prometheus-3.5
prometheus-fips-3.12 affected chainguard prometheus-fips-3.12
prometheus-fips-3.5 affected chainguard prometheus-fips-3.5
promxy affected chainguard promxy
promxy affected wolfi promxy
promxy-fips affected chainguard promxy-fips
rancher-2.10 affected chainguard rancher-2.10
rancher-2.11 affected chainguard rancher-2.11
rancher-2.12 affected chainguard rancher-2.12
rancher-2.13 affected wolfi rancher-2.13
rancher-2.13 affected chainguard rancher-2.13
rancher-2.14 affected wolfi rancher-2.14
rancher-2.14 affected chainguard rancher-2.14
rancher-agent-2.10 affected chainguard rancher-agent-2.10
rancher-agent-2.11 affected chainguard rancher-agent-2.11
rancher-agent-2.12 affected chainguard rancher-agent-2.12
rancher-agent-2.13 affected chainguard rancher-agent-2.13
rancher-agent-2.13 affected wolfi rancher-agent-2.13
rancher-agent-2.14 affected wolfi rancher-agent-2.14
rancher-agent-2.14 affected chainguard rancher-agent-2.14
rancher-agent-2.9 affected chainguard rancher-agent-2.9
rancher-machine affected chainguard rancher-machine
rancher-machine affected wolfi rancher-machine
redpanda-25.1 affected chainguard redpanda-25.1
redpanda-25.2 affected chainguard redpanda-25.2
redpanda-25.3 affected chainguard redpanda-25.3
rook-1.18 affected chainguard rook-1.18
rook-1.19 affected chainguard rook-1.19
rook-1.19 affected wolfi rook-1.19
rook-fips-1.18 affected chainguard rook-fips-1.18
rook-fips-1.19 affected chainguard rook-fips-1.19
s5cmd affected wolfi s5cmd
s5cmd affected chainguard s5cmd
s5cmd-fips affected chainguard s5cmd-fips
seaweedfs affected chainguard seaweedfs
seaweedfs affected wolfi seaweedfs
seaweedfs-fips affected chainguard seaweedfs-fips
seaweedfs-operator affected chainguard seaweedfs-operator
seaweedfs-operator-fips affected chainguard seaweedfs-operator-fips
seaweedfs-rocksdb affected chainguard seaweedfs-rocksdb
seaweedfs-rocksdb-fips affected chainguard seaweedfs-rocksdb-fips
slsa-verifier affected chainguard slsa-verifier
slsa-verifier affected wolfi slsa-verifier
splunk-otel-collector affected wolfi splunk-otel-collector
splunk-otel-collector affected chainguard splunk-otel-collector
splunk-otel-collector-fips affected chainguard splunk-otel-collector-fips
steampipe affected wolfi steampipe
steampipe affected chainguard steampipe
step-ca affected wolfi step-ca
step-ca affected chainguard step-ca
step-ca-fips affected chainguard step-ca-fips
tekton-chains affected chainguard tekton-chains
tekton-chains affected wolfi tekton-chains
tekton-chains-fips affected chainguard tekton-chains-fips
teleport-17 affected chainguard teleport-17
teleport-operator-fips-16 affected chainguard teleport-operator-fips-16
teleport-operator-fips-17 affected chainguard teleport-operator-fips-17
tempo-2.8 affected chainguard tempo-2.8
tempo-2.9 affected chainguard tempo-2.9
tempo-fips-2.8 affected chainguard tempo-fips-2.8
tempo-fips-2.9 affected chainguard tempo-fips-2.9
terraform affected wolfi terraform
terraform affected chainguard terraform
terraform-1.10 affected chainguard terraform-1.10
terraform-1.11 affected chainguard terraform-1.11
terraform-1.12 affected chainguard terraform-1.12
terraform-1.9 affected chainguard terraform-1.9
terragrunt affected chainguard terragrunt
terragrunt affected wolfi terragrunt
terragrunt-fips affected chainguard terragrunt-fips
tigera-operator-1.28 affected chainguard tigera-operator-1.28
tigera-operator-1.29 affected chainguard tigera-operator-1.29
tigera-operator-1.34 affected chainguard tigera-operator-1.34
tigera-operator-1.36 affected chainguard tigera-operator-1.36
tigera-operator-1.37 affected chainguard tigera-operator-1.37
tigera-operator-1.38 affected chainguard tigera-operator-1.38
tigera-operator-1.40 affected wolfi tigera-operator-1.40
tigera-operator-1.40 affected chainguard tigera-operator-1.40
tigera-operator-1.41 affected wolfi tigera-operator-1.41
tigera-operator-1.41 affected chainguard tigera-operator-1.41
tigera-operator-fips-1.29 affected chainguard tigera-operator-fips-1.29
tigera-operator-fips-1.34 affected chainguard tigera-operator-fips-1.34
tigera-operator-fips-1.36 affected chainguard tigera-operator-fips-1.36
tigera-operator-fips-1.37 affected chainguard tigera-operator-fips-1.37
tigera-operator-fips-1.38 affected chainguard tigera-operator-fips-1.38
tigera-operator-fips-1.40 affected chainguard tigera-operator-fips-1.40
tigera-operator-fips-1.41 affected chainguard tigera-operator-fips-1.41
trillian affected chainguard trillian
trillian affected wolfi trillian
trillian-fips affected chainguard trillian-fips
vault-1.16 affected chainguard vault-1.16
vault-1.17 affected chainguard vault-1.17
vault-1.18 affected chainguard vault-1.18
vault-1.19 affected chainguard vault-1.19
vault-1.20 affected chainguard vault-1.20
vault-1.21 affected chainguard vault-1.21
vault-2.0 affected chainguard vault-2.0
vault-benchmark affected wolfi vault-benchmark
vault-benchmark affected chainguard vault-benchmark
vault-env affected wolfi vault-env
vault-env affected chainguard vault-env
vault-fips-1.21 affected chainguard vault-fips-1.21
vault-fips-2.0 affected chainguard vault-fips-2.0
vault-secrets-operator affected chainguard vault-secrets-operator
vault-secrets-operator-fips affected chainguard vault-secrets-operator-fips
vault-secrets-webhook affected chainguard vault-secrets-webhook
vault-secrets-webhook affected wolfi vault-secrets-webhook
verticadb-operator affected wolfi verticadb-operator
verticadb-operator affected chainguard verticadb-operator
verticadb-operator-fips affected chainguard verticadb-operator-fips
wal-g affected wolfi wal-g
wal-g affected chainguard wal-g
weaviate affected wolfi weaviate
weaviate affected chainguard weaviate
zot affected chainguard zot
zot affected wolfi zot
Upstream advisory

GHSA-f5pg-7wfw-84q9

GooglePoC exploitCRITICAL2022-02-11

CBC padding oracle issue in AWS S3 Crypto SDK for golang

Affected products

ProductStatusVendorPackageEcosystem
aws/aws-sdk-go affected github.com github.com/aws/aws-sdk-go
Upstream advisory

GO-2022-0646

Open SourcePoC exploit2022-02-11

CBC padding oracle issue in AWS S3 Crypto SDK for golang in github.com/aws/aws-sdk-go

Affected products

ProductStatusVendorPackageEcosystem
amazon-cloudwatch-agent affected wolfi amazon-cloudwatch-agent
amazon-cloudwatch-agent affected chainguard amazon-cloudwatch-agent
amazon-cloudwatch-agent-fips affected chainguard amazon-cloudwatch-agent-fips
amazon-ecs-agent affected chainguard amazon-ecs-agent
amazon-ecs-agent-fips affected chainguard amazon-ecs-agent-fips
apply-cve-bump affected chainguard apply-cve-bump
argo-cd-3.0 affected chainguard argo-cd-3.0
argo-cd-3.1 affected chainguard argo-cd-3.1
argo-cd-3.2 affected wolfi argo-cd-3.2
argo-cd-3.2 affected chainguard argo-cd-3.2
argo-cd-3.3 affected chainguard argo-cd-3.3
argo-cd-3.3 affected wolfi argo-cd-3.3
argo-cd-fips-3.0 affected chainguard argo-cd-fips-3.0
argo-cd-fips-3.1 affected chainguard argo-cd-fips-3.1
argo-cd-fips-3.2 affected chainguard argo-cd-fips-3.2
argo-cd-fips-3.3 affected chainguard argo-cd-fips-3.3
argo-events affected chainguard argo-events
argo-events affected wolfi argo-events
argo-events-fips affected chainguard argo-events-fips
argo-rollouts affected wolfi argo-rollouts
argo-rollouts affected chainguard argo-rollouts
argo-rollouts-fips affected chainguard argo-rollouts-fips
atlas-1.0 affected chainguard atlas-1.0
atlas-1.0-fips affected chainguard atlas-1.0-fips
atlas-1.1 affected chainguard atlas-1.1
atlas-1.1-fips affected chainguard atlas-1.1-fips
atlas-1.2 affected chainguard atlas-1.2
aws/aws-sdk-go affected github.com github.com/aws/aws-sdk-go
aws-flb-cloudwatch affected wolfi aws-flb-cloudwatch
aws-flb-cloudwatch affected chainguard aws-flb-cloudwatch
aws-flb-cloudwatch-fips affected chainguard aws-flb-cloudwatch-fips
aws-flb-firehose affected chainguard aws-flb-firehose
aws-flb-firehose affected wolfi aws-flb-firehose
aws-flb-firehose-fips affected chainguard aws-flb-firehose-fips
aws-flb-kinesis affected wolfi aws-flb-kinesis
aws-flb-kinesis affected chainguard aws-flb-kinesis
aws-flb-kinesis-fips affected chainguard aws-flb-kinesis-fips
aws-node-termination-handler affected wolfi aws-node-termination-handler
aws-node-termination-handler affected chainguard aws-node-termination-handler
aws-node-termination-handler-fips affected chainguard aws-node-termination-handler-fips
aws-nuke affected wolfi aws-nuke
aws-nuke affected chainguard aws-nuke
aws-nuke-fips affected chainguard aws-nuke-fips
aws-otel-collector affected chainguard aws-otel-collector
aws-otel-collector affected wolfi aws-otel-collector
aws-otel-collector-fips affected chainguard aws-otel-collector-fips
aws-s3-controller affected wolfi aws-s3-controller
aws-s3-controller affected chainguard aws-s3-controller
aws-sigv4-proxy affected chainguard aws-sigv4-proxy
aws-sigv4-proxy affected wolfi aws-sigv4-proxy
aws-sigv4-proxy-fips affected chainguard aws-sigv4-proxy-fips
bank-vaults affected wolfi bank-vaults
bank-vaults affected chainguard bank-vaults
bank-vaults-fips affected chainguard bank-vaults-fips
bank-vaults-vault-operator affected chainguard bank-vaults-vault-operator
bank-vaults-vault-operator-fips affected chainguard bank-vaults-vault-operator-fips
cadence affected chainguard cadence
cadence-fips affected chainguard cadence-fips
cephcsi affected chainguard cephcsi
cephcsi-fips affected chainguard cephcsi-fips
cert-exporter affected wolfi cert-exporter
cert-exporter affected chainguard cert-exporter
cert-exporter-fips affected chainguard cert-exporter-fips
certificate-transparency affected chainguard certificate-transparency
certificate-transparency affected wolfi certificate-transparency
certificate-transparency-fips affected chainguard certificate-transparency-fips
cg affected chainguard cg
chartmuseum affected chainguard chartmuseum
chartmuseum affected wolfi chartmuseum
chartmuseum-fips affected chainguard chartmuseum-fips
cloudbeat-9.0 affected chainguard cloudbeat-9.0
cloudbeat-fips-8.17 affected chainguard cloudbeat-fips-8.17
cloudbeat-fips-9.0 affected chainguard cloudbeat-fips-9.0
cloud-sql-proxy-2.16 affected wolfi cloud-sql-proxy-2.16
cloud-sql-proxy-2.16 affected chainguard cloud-sql-proxy-2.16
cloud-sql-proxy-2.17 affected chainguard cloud-sql-proxy-2.17
cloud-sql-proxy-2.18 affected chainguard cloud-sql-proxy-2.18
cloud-sql-proxy-2.21 affected wolfi cloud-sql-proxy-2.21
cloud-sql-proxy-2.21 affected chainguard cloud-sql-proxy-2.21
cloud-sql-proxy-2.22 affected wolfi cloud-sql-proxy-2.22
cloud-sql-proxy-2.22 affected chainguard cloud-sql-proxy-2.22
cloud-sql-proxy-fips affected chainguard cloud-sql-proxy-fips
cluster-autoscaler-1.32 affected chainguard cluster-autoscaler-1.32
cluster-autoscaler-1.33 affected chainguard cluster-autoscaler-1.33
cluster-autoscaler-1.34 affected wolfi cluster-autoscaler-1.34
cluster-autoscaler-1.34 affected chainguard cluster-autoscaler-1.34
cluster-autoscaler-fips-1.32 affected chainguard cluster-autoscaler-fips-1.32
cluster-autoscaler-fips-1.33 affected chainguard cluster-autoscaler-fips-1.33
cluster-autoscaler-fips-1.34 affected chainguard cluster-autoscaler-fips-1.34
commercial-grafana-11.6 affected chainguard commercial-grafana-11.6
commercial-grafana-12.1 affected chainguard commercial-grafana-12.1
commercial-grafana-12.2 affected chainguard commercial-grafana-12.2
commercial-grafana-12.3 affected chainguard commercial-grafana-12.3
commercial-grafana-12.4 affected chainguard commercial-grafana-12.4
commercial-grafana-13.0 affected chainguard commercial-grafana-13.0
consul-1.18 affected chainguard consul-1.18
consul-1.19 affected chainguard consul-1.19
consul-1.20 affected chainguard consul-1.20
consul-1.21 affected chainguard consul-1.21
consul-fips-1.20 affected chainguard consul-fips-1.20
consul-fips-1.21 affected chainguard consul-fips-1.21
consul-k8s-1.1 affected chainguard consul-k8s-1.1
consul-k8s-1.3 affected chainguard consul-k8s-1.3
consul-k8s-1.4 affected chainguard consul-k8s-1.4
consul-k8s-1.5 affected chainguard consul-k8s-1.5
consul-k8s-1.6 affected chainguard consul-k8s-1.6
consul-k8s-fips-1.1 affected chainguard consul-k8s-fips-1.1
consul-k8s-fips-1.3 affected chainguard consul-k8s-fips-1.3
consul-k8s-fips-1.4 affected chainguard consul-k8s-fips-1.4
consul-k8s-fips-1.5 affected chainguard consul-k8s-fips-1.5
consul-k8s-fips-1.6 affected chainguard consul-k8s-fips-1.6
crossplane-aws-provider affected chainguard crossplane-aws-provider
crossplane-aws-provider-fips affected chainguard crossplane-aws-provider-fips
dapr-1.14 affected chainguard dapr-1.14
dapr-1.15 affected chainguard dapr-1.15
dapr-1.16 affected chainguard dapr-1.16
dapr-1.16 affected wolfi dapr-1.16
dapr-fips-1.14 affected chainguard dapr-fips-1.14
dapr-fips-1.15 affected chainguard dapr-fips-1.15
dapr-fips-1.16 affected chainguard dapr-fips-1.16
datadog-agent-7.71 affected chainguard datadog-agent-7.71
datadog-agent-7.77 affected wolfi datadog-agent-7.77
datadog-agent-7.77 affected chainguard datadog-agent-7.77
datadog-agent-7.78 affected chainguard datadog-agent-7.78
datadog-agent-7.78 affected wolfi datadog-agent-7.78
datadog-agent-7.79 affected wolfi datadog-agent-7.79
datadog-agent-7.79 affected chainguard datadog-agent-7.79
datadog-agent-fips-7.71 affected chainguard datadog-agent-fips-7.71
datadog-agent-fips-7.77 affected chainguard datadog-agent-fips-7.77
datadog-agent-fips-7.78 affected chainguard datadog-agent-fips-7.78
datadog-agent-fips-7.79 affected chainguard datadog-agent-fips-7.79
distribution affected chainguard distribution
distribution affected wolfi distribution
distribution-fips affected chainguard distribution-fips
drone affected chainguard drone
drone-fips affected chainguard drone-fips
elastic-agent-8.19 affected chainguard elastic-agent-8.19
elastic-agent-9.1 affected chainguard elastic-agent-9.1
elastic-agent-9.2 affected chainguard elastic-agent-9.2
elastic-agent-9.3 affected chainguard elastic-agent-9.3
elastic-agent-9.4 affected chainguard elastic-agent-9.4
elastic-agent-fips-8.19 affected chainguard elastic-agent-fips-8.19
elastic-agent-fips-9.1 affected chainguard elastic-agent-fips-9.1
elastic-agent-fips-9.2 affected chainguard elastic-agent-fips-9.2
elastic-agent-fips-9.3 affected chainguard elastic-agent-fips-9.3
elastic-agent-fips-9.4 affected chainguard elastic-agent-fips-9.4
external-secrets-fips affected chainguard external-secrets-fips
external-secrets-operator-1.2 affected chainguard external-secrets-operator-1.2
external-secrets-operator-1.3 affected chainguard external-secrets-operator-1.3
external-secrets-operator-2.0 affected chainguard external-secrets-operator-2.0
external-secrets-operator-2.0 affected wolfi external-secrets-operator-2.0
external-secrets-operator-2.1 affected chainguard external-secrets-operator-2.1
external-secrets-operator-2.1 affected wolfi external-secrets-operator-2.1
external-secrets-operator-2.2 affected wolfi external-secrets-operator-2.2
external-secrets-operator-2.2 affected chainguard external-secrets-operator-2.2
external-secrets-operator-2.3 affected wolfi external-secrets-operator-2.3
external-secrets-operator-2.3 affected chainguard external-secrets-operator-2.3
external-secrets-operator-2.4 affected wolfi external-secrets-operator-2.4
external-secrets-operator-2.4 affected chainguard external-secrets-operator-2.4
external-secrets-operator-2.5 affected wolfi external-secrets-operator-2.5
external-secrets-operator-2.5 affected chainguard external-secrets-operator-2.5
external-secrets-operator-2.6 affected chainguard external-secrets-operator-2.6
external-secrets-operator-2.6 affected wolfi external-secrets-operator-2.6
external-secrets-operator-2.7 affected chainguard external-secrets-operator-2.7
external-secrets-operator-fips-1.2 affected chainguard external-secrets-operator-fips-1.2
external-secrets-operator-fips-1.3 affected chainguard external-secrets-operator-fips-1.3
external-secrets-operator-fips-2.0 affected chainguard external-secrets-operator-fips-2.0
external-secrets-operator-fips-2.1 affected chainguard external-secrets-operator-fips-2.1
external-secrets-operator-fips-2.2 affected chainguard external-secrets-operator-fips-2.2
external-secrets-operator-fips-2.3 affected chainguard external-secrets-operator-fips-2.3
external-secrets-operator-fips-2.4 affected chainguard external-secrets-operator-fips-2.4
external-secrets-operator-fips-2.5 affected chainguard external-secrets-operator-fips-2.5
external-secrets-operator-fips-2.6 affected chainguard external-secrets-operator-fips-2.6
external-secrets-operator-fips-2.7 affected chainguard external-secrets-operator-fips-2.7
flagger affected chainguard flagger
flagger-fips affected chainguard flagger-fips
flyte affected wolfi flyte
flyte affected chainguard flyte
gatekeeper-3.20 affected chainguard gatekeeper-3.20
gatekeeper-3.21 affected chainguard gatekeeper-3.21
gatekeeper-3.21 affected wolfi gatekeeper-3.21
gatekeeper-3.22 affected wolfi gatekeeper-3.22
gatekeeper-3.22 affected chainguard gatekeeper-3.22
gatekeeper-fips-3.20 affected chainguard gatekeeper-fips-3.20
gatekeeper-fips-3.21 affected chainguard gatekeeper-fips-3.21
gatekeeper-fips-3.22 affected chainguard gatekeeper-fips-3.22
gitlab-cng-18.10 affected chainguard gitlab-cng-18.10
gitlab-cng-18.11 affected chainguard gitlab-cng-18.11
gitlab-cng-19.0 affected chainguard gitlab-cng-19.0
gitlab-cng-19.1 affected chainguard gitlab-cng-19.1
gitlab-cng-fips-18.10 affected chainguard gitlab-cng-fips-18.10
gitlab-cng-fips-18.11 affected chainguard gitlab-cng-fips-18.11
gitlab-cng-fips-19.0 affected chainguard gitlab-cng-fips-19.0
gitlab-cng-fips-19.1 affected chainguard gitlab-cng-fips-19.1
gitlab-runner-18.10 affected chainguard gitlab-runner-18.10
gitlab-runner-18.10 affected wolfi gitlab-runner-18.10
gitlab-runner-18.11 affected chainguard gitlab-runner-18.11
gitlab-runner-18.11 affected wolfi gitlab-runner-18.11
gitlab-runner-19.0 affected chainguard gitlab-runner-19.0
gitlab-runner-19.0 affected wolfi gitlab-runner-19.0
gitlab-runner-19.1 affected chainguard gitlab-runner-19.1
gitlab-runner-19.1 affected wolfi gitlab-runner-19.1
gitlab-runner-fips-18.10 affected chainguard gitlab-runner-fips-18.10
gitlab-runner-fips-18.11 affected chainguard gitlab-runner-fips-18.11
gitlab-runner-fips-19.0 affected chainguard gitlab-runner-fips-19.0
gitlab-runner-fips-19.1 affected chainguard gitlab-runner-fips-19.1
gitness affected chainguard gitness
gitness affected wolfi gitness
gitsign affected chainguard gitsign
gitsign affected wolfi gitsign
go-getter-2 affected chainguard go-getter-2
go-getter-2.1 affected chainguard go-getter-2.1
go-getter-2.2 affected chainguard go-getter-2.2
go-getter-2-fips affected chainguard go-getter-2-fips
gomplate-4 affected chainguard gomplate-4
gomplate-5 affected wolfi gomplate-5
gomplate-5 affected chainguard gomplate-5
gomplate-fips-4 affected chainguard gomplate-fips-4
gomplate-fips-5 affected chainguard gomplate-fips-5
google-cloud-otel-ops-collector affected chainguard google-cloud-otel-ops-collector
gostatsd affected chainguard gostatsd
gostatsd affected wolfi gostatsd
grafana-11.6 affected chainguard grafana-11.6
grafana-12.0 affected chainguard grafana-12.0
grafana-12.1 affected chainguard grafana-12.1
grafana-12.2 affected chainguard grafana-12.2
grafana-12.3 affected chainguard grafana-12.3
grafana-12.3 affected wolfi grafana-12.3
grafana-12.4 affected chainguard grafana-12.4
grafana-12.4 affected wolfi grafana-12.4
grafana-13.0 affected chainguard grafana-13.0
grafana-13.0 affected wolfi grafana-13.0
grafana-13.1 affected chainguard grafana-13.1
grafana-agent-operator affected chainguard grafana-agent-operator
grafana-agent-operator affected wolfi grafana-agent-operator
grafana-fips-11.6 affected chainguard grafana-fips-11.6
grafana-fips-12.0 affected chainguard grafana-fips-12.0
grafana-fips-12.1 affected chainguard grafana-fips-12.1
grafana-fips-12.2 affected chainguard grafana-fips-12.2
grafana-fips-12.3 affected chainguard grafana-fips-12.3
grafana-fips-12.4 affected chainguard grafana-fips-12.4
grafana-fips-13.0 affected chainguard grafana-fips-13.0
grafana-fips-13.1 affected chainguard grafana-fips-13.1
grafana-mimir-2.17 affected chainguard grafana-mimir-2.17
grafana-mimir-3.0 affected wolfi grafana-mimir-3.0
grafana-mimir-3.0 affected chainguard grafana-mimir-3.0
grafana-mimir-fips-2.17 affected chainguard grafana-mimir-fips-2.17
grafana-mimir-fips-3.0 affected chainguard grafana-mimir-fips-3.0
grafana-pyroscope-1.12 affected chainguard grafana-pyroscope-1.12
grafana-pyroscope-1.13 affected chainguard grafana-pyroscope-1.13
grafana-pyroscope-1.14 affected chainguard grafana-pyroscope-1.14
grept affected chainguard grept
grept-fips affected chainguard grept-fips
guac affected chainguard guac
guac affected wolfi guac
harbor-2.12 affected chainguard harbor-2.12
harbor-2.13 affected chainguard harbor-2.13
harbor-2.14 affected wolfi harbor-2.14
harbor-2.14 affected chainguard harbor-2.14
harbor-2.15 affected chainguard harbor-2.15
harbor-fips-2.12 affected chainguard harbor-fips-2.12
harbor-fips-2.13 affected chainguard harbor-fips-2.13
harbor-fips-2.14 affected chainguard harbor-fips-2.14
harbor-fips-2.15 affected chainguard harbor-fips-2.15
harbor-registry affected wolfi harbor-registry
harbor-registry affected chainguard harbor-registry
harbor-registry-fips affected chainguard harbor-registry-fips
harvester affected chainguard harvester
harvester-fips affected chainguard harvester-fips
influxd-2.7 affected chainguard influxd-2.7
juicefs-1.2 affected chainguard juicefs-1.2
k3d affected chainguard k3d
k3d affected wolfi k3d
k8sgpt affected wolfi k8sgpt
k8sgpt affected chainguard k8sgpt
k8s-image-swapper affected chainguard k8s-image-swapper
k8s-image-swapper-fips affected chainguard k8s-image-swapper-fips
karpenter-0.33 affected chainguard karpenter-0.33
karpenter-0.34 affected chainguard karpenter-0.34
karpenter-0.35 affected chainguard karpenter-0.35
karpenter-0.36 affected chainguard karpenter-0.36
karpenter-0.37 affected chainguard karpenter-0.37
karpenter-fips-0.33 affected chainguard karpenter-fips-0.33
karpenter-fips-0.34 affected chainguard karpenter-fips-0.34
karpenter-fips-0.35 affected chainguard karpenter-fips-0.35
karpenter-fips-0.36 affected chainguard karpenter-fips-0.36
karpenter-fips-0.37 affected chainguard karpenter-fips-0.37
kiam affected chainguard kiam
kots affected wolfi kots
kots affected chainguard kots
kserve affected wolfi kserve
kserve affected chainguard kserve
kserve-fips affected chainguard kserve-fips
kserve-localmodelnode-agent affected chainguard kserve-localmodelnode-agent
kserve-localmodelnode-agent-fips affected chainguard kserve-localmodelnode-agent-fips
kserve-modelmesh-serving affected wolfi kserve-modelmesh-serving
kserve-modelmesh-serving affected chainguard kserve-modelmesh-serving
kube-arangodb-1.3 affected chainguard kube-arangodb-1.3
kube-arangodb-1.4 affected chainguard kube-arangodb-1.4
kube-arangodb-1.4 affected wolfi kube-arangodb-1.4
kube-arangodb-fips-1.3 affected chainguard kube-arangodb-fips-1.3
kube-arangodb-fips-1.4 affected chainguard kube-arangodb-fips-1.4
kubeflow affected wolfi kubeflow
kubeflow affected chainguard kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines-driver-fips affected chainguard kubeflow-pipelines-driver-fips
kubeflow-pipelines-fips affected chainguard kubeflow-pipelines-fips
kubernetes-event-exporter affected chainguard kubernetes-event-exporter
kubernetes-event-exporter affected wolfi kubernetes-event-exporter
kubernetes-event-exporter-fips affected chainguard kubernetes-event-exporter-fips
kubescape affected chainguard kubescape
kubescape affected wolfi kubescape
kubescape-operator affected chainguard kubescape-operator
kubescape-operator affected wolfi kubescape-operator
kubescape-operator-fips affected chainguard kubescape-operator-fips
kubescape-server affected chainguard kubescape-server
kubescape-server-fips affected chainguard kubescape-server-fips
kubevirt-cdi-uploadserver-1.5 affected chainguard kubevirt-cdi-uploadserver-1.5
kubevirt-cdi-uploadserver-1.6 affected chainguard kubevirt-cdi-uploadserver-1.6
kubevirt-cdi-uploadserver-fips-1.5 affected chainguard kubevirt-cdi-uploadserver-fips-1.5
kubevirt-cdi-uploadserver-fips-1.6 affected chainguard kubevirt-cdi-uploadserver-fips-1.6
loki-2.9 affected chainguard loki-2.9
loki-3.4 affected chainguard loki-3.4
loki-3.5 affected chainguard loki-3.5
loki-3.6 affected wolfi loki-3.6
loki-3.6 affected chainguard loki-3.6
loki-3.7 affected chainguard loki-3.7
loki-3.7 affected wolfi loki-3.7
loki-fips-2.9 affected chainguard loki-fips-2.9
loki-fips-3.4 affected chainguard loki-fips-3.4
loki-fips-3.5 affected chainguard loki-fips-3.5
loki-fips-3.6 affected chainguard loki-fips-3.6
loki-fips-3.7 affected chainguard loki-fips-3.7
longhorn-backing-image-manager-1.8 affected chainguard longhorn-backing-image-manager-1.8
longhorn-backing-image-manager-1.9 affected chainguard longhorn-backing-image-manager-1.9
longhorn-backing-image-manager-fips-1.8 affected chainguard longhorn-backing-image-manager-fips-1.8
longhorn-backing-image-manager-fips-1.9 affected chainguard longhorn-backing-image-manager-fips-1.9
longhorn-engine-1.8 affected chainguard longhorn-engine-1.8
longhorn-engine-1.9 affected chainguard longhorn-engine-1.9
longhorn-instance-manager-1.8 affected chainguard longhorn-instance-manager-1.8
longhorn-instance-manager-1.8-fips affected chainguard longhorn-instance-manager-1.8-fips
longhorn-instance-manager-1.9 affected chainguard longhorn-instance-manager-1.9
longhorn-instance-manager-1.9-fips affected chainguard longhorn-instance-manager-1.9-fips
mapotf affected chainguard mapotf
mapotf-fips affected chainguard mapotf-fips
mattermost-10.11 affected chainguard mattermost-10.11
mattermost-11.1 affected chainguard mattermost-11.1
mattermost-11.1 affected wolfi mattermost-11.1
mattermost-11.2 affected chainguard mattermost-11.2
mattermost-fips-10.11 affected chainguard mattermost-fips-10.11
mattermost-fips-11.1 affected chainguard mattermost-fips-11.1
mattermost-fips-11.2 affected chainguard mattermost-fips-11.2
metrics-agent affected wolfi metrics-agent
metrics-agent affected chainguard metrics-agent
metrics-agent-fips affected chainguard metrics-agent-fips
monstache affected chainguard monstache
neuvector affected chainguard neuvector
neuvector-fips affected chainguard neuvector-fips
neuvector-scanner affected wolfi neuvector-scanner
neuvector-scanner affected chainguard neuvector-scanner
neuvector-scanner-fips affected chainguard neuvector-scanner-fips
newrelic-nri-statsd affected chainguard newrelic-nri-statsd
newrelic-nri-statsd affected wolfi newrelic-nri-statsd
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
node-problem-detector-1.34 affected chainguard node-problem-detector-1.34
node-problem-detector-1.35 affected wolfi node-problem-detector-1.35
node-problem-detector-1.35 affected chainguard node-problem-detector-1.35
node-problem-detector-fips-0.8 affected chainguard node-problem-detector-fips-0.8
node-problem-detector-fips-1.34 affected chainguard node-problem-detector-fips-1.34
node-problem-detector-fips-1.35 affected chainguard node-problem-detector-fips-1.35
nrdot-collector affected chainguard nrdot-collector
nrdot-collector-fips affected chainguard nrdot-collector-fips
nrdot-collector-k8s affected chainguard nrdot-collector-k8s
nrdot-collector-k8s-fips affected chainguard nrdot-collector-k8s-fips
openbao affected chainguard openbao
openbao affected wolfi openbao
openbao-fips affected chainguard openbao-fips
opencost affected wolfi opencost
opencost affected chainguard opencost
opencost-fips affected chainguard opencost-fips
opentelemetry-collector affected wolfi opentelemetry-collector
opentelemetry-collector affected chainguard opentelemetry-collector
opentelemetry-collector-contrib affected chainguard opentelemetry-collector-contrib
opentelemetry-collector-contrib affected wolfi opentelemetry-collector-contrib
opentelemetry-collector-contrib-fips affected chainguard opentelemetry-collector-contrib-fips
opentelemetry-collector-fips affected chainguard opentelemetry-collector-fips
opentelemetry-collector-k8s affected chainguard opentelemetry-collector-k8s
opentelemetry-collector-k8s-fips affected chainguard opentelemetry-collector-k8s-fips
opentofu-1.9 affected wolfi opentofu-1.9
opentofu-1.9 affected chainguard opentofu-1.9
opentofu-fips-1.9 affected chainguard opentofu-fips-1.9
packer affected chainguard packer
packer-fips affected chainguard packer-fips
plutono affected chainguard plutono
plutono-fips affected chainguard plutono-fips
porch affected chainguard porch
porch-fips affected chainguard porch-fips
postgres-operator affected wolfi postgres-operator
postgres-operator affected chainguard postgres-operator
postgres-operator-fips affected chainguard postgres-operator-fips
prometheus-2.51 affected chainguard prometheus-2.51
prometheus-3.12 affected chainguard prometheus-3.12
prometheus-3.12 affected wolfi prometheus-3.12
prometheus-3.5 affected chainguard prometheus-3.5
prometheus-fips-3.12 affected chainguard prometheus-fips-3.12
prometheus-fips-3.5 affected chainguard prometheus-fips-3.5
promxy affected wolfi promxy
promxy affected chainguard promxy
promxy-fips affected chainguard promxy-fips
rancher-2.10 affected chainguard rancher-2.10
rancher-2.11 affected chainguard rancher-2.11
rancher-2.12 affected chainguard rancher-2.12
rancher-2.13 affected wolfi rancher-2.13
rancher-2.13 affected chainguard rancher-2.13
rancher-2.14 affected wolfi rancher-2.14
rancher-2.14 affected chainguard rancher-2.14
rancher-agent-2.10 affected chainguard rancher-agent-2.10
rancher-agent-2.11 affected chainguard rancher-agent-2.11
rancher-agent-2.12 affected chainguard rancher-agent-2.12
rancher-agent-2.13 affected wolfi rancher-agent-2.13
rancher-agent-2.13 affected chainguard rancher-agent-2.13
rancher-agent-2.14 affected wolfi rancher-agent-2.14
rancher-agent-2.14 affected chainguard rancher-agent-2.14
rancher-agent-2.9 affected chainguard rancher-agent-2.9
rancher-machine affected wolfi rancher-machine
rancher-machine affected chainguard rancher-machine
redpanda-25.1 affected chainguard redpanda-25.1
redpanda-25.2 affected chainguard redpanda-25.2
redpanda-25.3 affected chainguard redpanda-25.3
rook-1.18 affected chainguard rook-1.18
rook-1.19 affected wolfi rook-1.19
rook-1.19 affected chainguard rook-1.19
rook-fips-1.18 affected chainguard rook-fips-1.18
rook-fips-1.19 affected chainguard rook-fips-1.19
s5cmd affected wolfi s5cmd
s5cmd affected chainguard s5cmd
s5cmd-fips affected chainguard s5cmd-fips
seaweedfs affected wolfi seaweedfs
seaweedfs affected chainguard seaweedfs
seaweedfs-fips affected chainguard seaweedfs-fips
seaweedfs-operator affected chainguard seaweedfs-operator
seaweedfs-operator-fips affected chainguard seaweedfs-operator-fips
seaweedfs-rocksdb affected chainguard seaweedfs-rocksdb
seaweedfs-rocksdb-fips affected chainguard seaweedfs-rocksdb-fips
slsa-verifier affected chainguard slsa-verifier
slsa-verifier affected wolfi slsa-verifier
splunk-otel-collector affected wolfi splunk-otel-collector
splunk-otel-collector affected chainguard splunk-otel-collector
splunk-otel-collector-fips affected chainguard splunk-otel-collector-fips
steampipe affected wolfi steampipe
steampipe affected chainguard steampipe
step-ca affected wolfi step-ca
step-ca affected chainguard step-ca
step-ca-fips affected chainguard step-ca-fips
tekton-chains affected chainguard tekton-chains
tekton-chains affected wolfi tekton-chains
tekton-chains-fips affected chainguard tekton-chains-fips
teleport-17 affected chainguard teleport-17
teleport-operator-fips-16 affected chainguard teleport-operator-fips-16
teleport-operator-fips-17 affected chainguard teleport-operator-fips-17
tempo-2.8 affected chainguard tempo-2.8
tempo-2.9 affected chainguard tempo-2.9
tempo-fips-2.8 affected chainguard tempo-fips-2.8
tempo-fips-2.9 affected chainguard tempo-fips-2.9
terraform affected wolfi terraform
terraform affected chainguard terraform
terraform-1.10 affected chainguard terraform-1.10
terraform-1.11 affected chainguard terraform-1.11
terraform-1.12 affected chainguard terraform-1.12
terraform-1.9 affected chainguard terraform-1.9
terragrunt affected chainguard terragrunt
terragrunt affected wolfi terragrunt
terragrunt-fips affected chainguard terragrunt-fips
tigera-operator-1.28 affected chainguard tigera-operator-1.28
tigera-operator-1.29 affected chainguard tigera-operator-1.29
tigera-operator-1.34 affected chainguard tigera-operator-1.34
tigera-operator-1.36 affected chainguard tigera-operator-1.36
tigera-operator-1.37 affected chainguard tigera-operator-1.37
tigera-operator-1.38 affected chainguard tigera-operator-1.38
tigera-operator-1.40 affected wolfi tigera-operator-1.40
tigera-operator-1.40 affected chainguard tigera-operator-1.40
tigera-operator-1.41 affected chainguard tigera-operator-1.41
tigera-operator-1.41 affected wolfi tigera-operator-1.41
tigera-operator-fips-1.29 affected chainguard tigera-operator-fips-1.29
tigera-operator-fips-1.34 affected chainguard tigera-operator-fips-1.34
tigera-operator-fips-1.36 affected chainguard tigera-operator-fips-1.36
tigera-operator-fips-1.37 affected chainguard tigera-operator-fips-1.37
tigera-operator-fips-1.38 affected chainguard tigera-operator-fips-1.38
tigera-operator-fips-1.40 affected chainguard tigera-operator-fips-1.40
tigera-operator-fips-1.41 affected chainguard tigera-operator-fips-1.41
trillian affected wolfi trillian
trillian affected chainguard trillian
trillian-fips affected chainguard trillian-fips
vault-1.16 affected chainguard vault-1.16
vault-1.17 affected chainguard vault-1.17
vault-1.18 affected chainguard vault-1.18
vault-1.19 affected chainguard vault-1.19
vault-1.20 affected chainguard vault-1.20
vault-1.21 affected chainguard vault-1.21
vault-2.0 affected chainguard vault-2.0
vault-benchmark affected wolfi vault-benchmark
vault-benchmark affected chainguard vault-benchmark
vault-env affected wolfi vault-env
vault-env affected chainguard vault-env
vault-fips-1.21 affected chainguard vault-fips-1.21
vault-fips-2.0 affected chainguard vault-fips-2.0
vault-secrets-operator affected chainguard vault-secrets-operator
vault-secrets-operator-fips affected chainguard vault-secrets-operator-fips
vault-secrets-webhook affected wolfi vault-secrets-webhook
vault-secrets-webhook affected chainguard vault-secrets-webhook
verticadb-operator affected chainguard verticadb-operator
verticadb-operator affected wolfi verticadb-operator
verticadb-operator-fips affected chainguard verticadb-operator-fips
wal-g affected chainguard wal-g
wal-g affected wolfi wal-g
weaviate affected chainguard weaviate
weaviate affected wolfi weaviate
zot affected wolfi zot
zot affected chainguard zot
Upstream advisory

GHSA-7f33-f4f5-xwgw

GooglePoC exploitCRITICAL2022-02-11

In-band key negotiation issue in AWS S3 Crypto SDK for golang

Affected products

ProductStatusVendorPackageEcosystem
aws/aws-sdk-go affected github.com github.com/aws/aws-sdk-go
Upstream advisory

GHSA-7f33-f4f5-xwgw

Open SourcePoC exploitCRITICAL2022-02-11

In-band key negotiation issue in AWS S3 Crypto SDK for golang

Affected products

ProductStatusVendorPackageEcosystem
amazon-cloudwatch-agent affected wolfi amazon-cloudwatch-agent
amazon-cloudwatch-agent affected chainguard amazon-cloudwatch-agent
amazon-cloudwatch-agent-fips affected chainguard amazon-cloudwatch-agent-fips
amazon-ecs-agent affected chainguard amazon-ecs-agent
amazon-ecs-agent-fips affected chainguard amazon-ecs-agent-fips
apply-cve-bump affected chainguard apply-cve-bump
argo-cd-3.0 affected wolfi argo-cd-3.0
argo-cd-3.0 affected chainguard argo-cd-3.0
argo-cd-3.1 affected wolfi argo-cd-3.1
argo-cd-3.1 affected chainguard argo-cd-3.1
argo-cd-3.2 affected chainguard argo-cd-3.2
argo-cd-3.2 affected wolfi argo-cd-3.2
argo-cd-3.3 affected chainguard argo-cd-3.3
argo-cd-3.3 affected wolfi argo-cd-3.3
argo-cd-fips-3.0 affected chainguard argo-cd-fips-3.0
argo-cd-fips-3.1 affected chainguard argo-cd-fips-3.1
argo-cd-fips-3.2 affected chainguard argo-cd-fips-3.2
argo-cd-fips-3.3 affected chainguard argo-cd-fips-3.3
argo-events affected chainguard argo-events
argo-events affected wolfi argo-events
argo-events-fips affected chainguard argo-events-fips
argo-rollouts affected chainguard argo-rollouts
argo-rollouts affected wolfi argo-rollouts
argo-rollouts-fips affected chainguard argo-rollouts-fips
atlas-1.0 affected chainguard atlas-1.0
atlas-1.0-fips affected chainguard atlas-1.0-fips
atlas-1.1 affected chainguard atlas-1.1
atlas-1.1-fips affected chainguard atlas-1.1-fips
atlas-1.2 affected chainguard atlas-1.2
aws/aws-sdk-go affected github.com github.com/aws/aws-sdk-go
aws-flb-cloudwatch affected chainguard aws-flb-cloudwatch
aws-flb-cloudwatch affected wolfi aws-flb-cloudwatch
aws-flb-cloudwatch-fips affected chainguard aws-flb-cloudwatch-fips
aws-flb-firehose affected wolfi aws-flb-firehose
aws-flb-firehose affected chainguard aws-flb-firehose
aws-flb-firehose-fips affected chainguard aws-flb-firehose-fips
aws-flb-kinesis affected wolfi aws-flb-kinesis
aws-flb-kinesis affected chainguard aws-flb-kinesis
aws-flb-kinesis-fips affected chainguard aws-flb-kinesis-fips
aws-node-termination-handler affected wolfi aws-node-termination-handler
aws-node-termination-handler affected chainguard aws-node-termination-handler
aws-node-termination-handler-fips affected chainguard aws-node-termination-handler-fips
aws-nuke affected chainguard aws-nuke
aws-nuke affected wolfi aws-nuke
aws-nuke-fips affected chainguard aws-nuke-fips
aws-otel-collector affected chainguard aws-otel-collector
aws-otel-collector affected wolfi aws-otel-collector
aws-otel-collector-fips affected chainguard aws-otel-collector-fips
aws-s3-controller affected wolfi aws-s3-controller
aws-s3-controller affected chainguard aws-s3-controller
aws-sigv4-proxy affected wolfi aws-sigv4-proxy
aws-sigv4-proxy affected chainguard aws-sigv4-proxy
aws-sigv4-proxy-fips affected chainguard aws-sigv4-proxy-fips
bank-vaults affected chainguard bank-vaults
bank-vaults affected wolfi bank-vaults
bank-vaults-fips affected chainguard bank-vaults-fips
bank-vaults-vault-operator affected chainguard bank-vaults-vault-operator
bank-vaults-vault-operator-fips affected chainguard bank-vaults-vault-operator-fips
cadence affected chainguard cadence
cadence-fips affected chainguard cadence-fips
cephcsi affected chainguard cephcsi
cephcsi-fips affected chainguard cephcsi-fips
cert-exporter affected wolfi cert-exporter
cert-exporter affected chainguard cert-exporter
cert-exporter-fips affected chainguard cert-exporter-fips
certificate-transparency affected chainguard certificate-transparency
certificate-transparency affected wolfi certificate-transparency
certificate-transparency-fips affected chainguard certificate-transparency-fips
cg affected chainguard cg
chartmuseum affected chainguard chartmuseum
chartmuseum affected wolfi chartmuseum
chartmuseum-fips affected chainguard chartmuseum-fips
cloudbeat-9.0 affected chainguard cloudbeat-9.0
cloudbeat-fips-8.17 affected chainguard cloudbeat-fips-8.17
cloudbeat-fips-9.0 affected chainguard cloudbeat-fips-9.0
cloud-sql-proxy-2.16 affected wolfi cloud-sql-proxy-2.16
cloud-sql-proxy-2.16 affected chainguard cloud-sql-proxy-2.16
cloud-sql-proxy-2.17 affected chainguard cloud-sql-proxy-2.17
cloud-sql-proxy-2.17 affected wolfi cloud-sql-proxy-2.17
cloud-sql-proxy-2.18 affected chainguard cloud-sql-proxy-2.18
cloud-sql-proxy-2.18 affected wolfi cloud-sql-proxy-2.18
cloud-sql-proxy-2.21 affected chainguard cloud-sql-proxy-2.21
cloud-sql-proxy-2.21 affected wolfi cloud-sql-proxy-2.21
cloud-sql-proxy-2.22 affected wolfi cloud-sql-proxy-2.22
cloud-sql-proxy-2.22 affected chainguard cloud-sql-proxy-2.22
cloud-sql-proxy-fips affected chainguard cloud-sql-proxy-fips
cluster-autoscaler-1.32 affected wolfi cluster-autoscaler-1.32
cluster-autoscaler-1.32 affected chainguard cluster-autoscaler-1.32
cluster-autoscaler-1.33 affected wolfi cluster-autoscaler-1.33
cluster-autoscaler-1.33 affected chainguard cluster-autoscaler-1.33
cluster-autoscaler-1.34 affected chainguard cluster-autoscaler-1.34
cluster-autoscaler-1.34 affected wolfi cluster-autoscaler-1.34
cluster-autoscaler-fips-1.32 affected chainguard cluster-autoscaler-fips-1.32
cluster-autoscaler-fips-1.33 affected chainguard cluster-autoscaler-fips-1.33
cluster-autoscaler-fips-1.34 affected chainguard cluster-autoscaler-fips-1.34
commercial-grafana-11.6 affected chainguard commercial-grafana-11.6
commercial-grafana-12.1 affected chainguard commercial-grafana-12.1
commercial-grafana-12.2 affected chainguard commercial-grafana-12.2
commercial-grafana-12.3 affected chainguard commercial-grafana-12.3
commercial-grafana-12.4 affected chainguard commercial-grafana-12.4
commercial-grafana-13.0 affected chainguard commercial-grafana-13.0
consul-1.18 affected chainguard consul-1.18
consul-1.19 affected chainguard consul-1.19
consul-1.20 affected chainguard consul-1.20
consul-1.21 affected chainguard consul-1.21
consul-fips-1.20 affected chainguard consul-fips-1.20
consul-fips-1.21 affected chainguard consul-fips-1.21
consul-k8s-1.1 affected chainguard consul-k8s-1.1
consul-k8s-1.3 affected chainguard consul-k8s-1.3
consul-k8s-1.4 affected chainguard consul-k8s-1.4
consul-k8s-1.5 affected chainguard consul-k8s-1.5
consul-k8s-1.6 affected chainguard consul-k8s-1.6
consul-k8s-1.6 affected wolfi consul-k8s-1.6
consul-k8s-fips-1.1 affected chainguard consul-k8s-fips-1.1
consul-k8s-fips-1.3 affected chainguard consul-k8s-fips-1.3
consul-k8s-fips-1.4 affected chainguard consul-k8s-fips-1.4
consul-k8s-fips-1.5 affected chainguard consul-k8s-fips-1.5
consul-k8s-fips-1.6 affected chainguard consul-k8s-fips-1.6
crossplane-aws-provider affected chainguard crossplane-aws-provider
crossplane-aws-provider-fips affected chainguard crossplane-aws-provider-fips
dapr-1.14 affected chainguard dapr-1.14
dapr-1.15 affected wolfi dapr-1.15
dapr-1.15 affected chainguard dapr-1.15
dapr-1.16 affected wolfi dapr-1.16
dapr-1.16 affected chainguard dapr-1.16
dapr-fips-1.14 affected chainguard dapr-fips-1.14
dapr-fips-1.15 affected chainguard dapr-fips-1.15
dapr-fips-1.16 affected chainguard dapr-fips-1.16
datadog-agent-7.71 affected chainguard datadog-agent-7.71
datadog-agent-7.77 affected wolfi datadog-agent-7.77
datadog-agent-7.77 affected chainguard datadog-agent-7.77
datadog-agent-7.78 affected chainguard datadog-agent-7.78
datadog-agent-7.78 affected wolfi datadog-agent-7.78
datadog-agent-7.79 affected chainguard datadog-agent-7.79
datadog-agent-7.79 affected wolfi datadog-agent-7.79
datadog-agent-fips-7.71 affected chainguard datadog-agent-fips-7.71
datadog-agent-fips-7.77 affected chainguard datadog-agent-fips-7.77
datadog-agent-fips-7.78 affected chainguard datadog-agent-fips-7.78
datadog-agent-fips-7.79 affected chainguard datadog-agent-fips-7.79
distribution affected wolfi distribution
distribution affected chainguard distribution
distribution-fips affected chainguard distribution-fips
drone affected chainguard drone
drone-fips affected chainguard drone-fips
elastic-agent-8.19 affected chainguard elastic-agent-8.19
elastic-agent-9.1 affected chainguard elastic-agent-9.1
elastic-agent-9.2 affected chainguard elastic-agent-9.2
elastic-agent-9.3 affected chainguard elastic-agent-9.3
elastic-agent-9.4 affected chainguard elastic-agent-9.4
elastic-agent-fips-8.19 affected chainguard elastic-agent-fips-8.19
elastic-agent-fips-9.1 affected chainguard elastic-agent-fips-9.1
elastic-agent-fips-9.2 affected chainguard elastic-agent-fips-9.2
elastic-agent-fips-9.3 affected chainguard elastic-agent-fips-9.3
elastic-agent-fips-9.4 affected chainguard elastic-agent-fips-9.4
external-secrets-fips affected chainguard external-secrets-fips
external-secrets-operator-1.2 affected wolfi external-secrets-operator-1.2
external-secrets-operator-1.2 affected chainguard external-secrets-operator-1.2
external-secrets-operator-1.3 affected chainguard external-secrets-operator-1.3
external-secrets-operator-1.3 affected wolfi external-secrets-operator-1.3
external-secrets-operator-2.0 affected wolfi external-secrets-operator-2.0
external-secrets-operator-2.0 affected chainguard external-secrets-operator-2.0
external-secrets-operator-2.1 affected wolfi external-secrets-operator-2.1
external-secrets-operator-2.1 affected chainguard external-secrets-operator-2.1
external-secrets-operator-2.2 affected wolfi external-secrets-operator-2.2
external-secrets-operator-2.2 affected chainguard external-secrets-operator-2.2
external-secrets-operator-2.3 affected chainguard external-secrets-operator-2.3
external-secrets-operator-2.3 affected wolfi external-secrets-operator-2.3
external-secrets-operator-2.4 affected wolfi external-secrets-operator-2.4
external-secrets-operator-2.4 affected chainguard external-secrets-operator-2.4
external-secrets-operator-2.5 affected chainguard external-secrets-operator-2.5
external-secrets-operator-2.5 affected wolfi external-secrets-operator-2.5
external-secrets-operator-2.6 affected wolfi external-secrets-operator-2.6
external-secrets-operator-2.6 affected chainguard external-secrets-operator-2.6
external-secrets-operator-2.7 affected chainguard external-secrets-operator-2.7
external-secrets-operator-fips-1.2 affected chainguard external-secrets-operator-fips-1.2
external-secrets-operator-fips-1.3 affected chainguard external-secrets-operator-fips-1.3
external-secrets-operator-fips-2.0 affected chainguard external-secrets-operator-fips-2.0
external-secrets-operator-fips-2.1 affected chainguard external-secrets-operator-fips-2.1
external-secrets-operator-fips-2.2 affected chainguard external-secrets-operator-fips-2.2
external-secrets-operator-fips-2.3 affected chainguard external-secrets-operator-fips-2.3
external-secrets-operator-fips-2.4 affected chainguard external-secrets-operator-fips-2.4
external-secrets-operator-fips-2.5 affected chainguard external-secrets-operator-fips-2.5
external-secrets-operator-fips-2.6 affected chainguard external-secrets-operator-fips-2.6
external-secrets-operator-fips-2.7 affected chainguard external-secrets-operator-fips-2.7
flagger affected chainguard flagger
flagger-fips affected chainguard flagger-fips
flyte affected chainguard flyte
flyte affected wolfi flyte
gatekeeper-3.20 affected chainguard gatekeeper-3.20
gatekeeper-3.20 affected wolfi gatekeeper-3.20
gatekeeper-3.21 affected chainguard gatekeeper-3.21
gatekeeper-3.21 affected wolfi gatekeeper-3.21
gatekeeper-3.22 affected chainguard gatekeeper-3.22
gatekeeper-3.22 affected wolfi gatekeeper-3.22
gatekeeper-fips-3.20 affected chainguard gatekeeper-fips-3.20
gatekeeper-fips-3.21 affected chainguard gatekeeper-fips-3.21
gatekeeper-fips-3.22 affected chainguard gatekeeper-fips-3.22
gitlab-cng-18.10 affected chainguard gitlab-cng-18.10
gitlab-cng-18.11 affected chainguard gitlab-cng-18.11
gitlab-cng-19.0 affected chainguard gitlab-cng-19.0
gitlab-cng-19.1 affected chainguard gitlab-cng-19.1
gitlab-cng-fips-18.10 affected chainguard gitlab-cng-fips-18.10
gitlab-cng-fips-18.11 affected chainguard gitlab-cng-fips-18.11
gitlab-cng-fips-19.0 affected chainguard gitlab-cng-fips-19.0
gitlab-cng-fips-19.1 affected chainguard gitlab-cng-fips-19.1
gitlab-runner-18.10 affected chainguard gitlab-runner-18.10
gitlab-runner-18.10 affected wolfi gitlab-runner-18.10
gitlab-runner-18.11 affected chainguard gitlab-runner-18.11
gitlab-runner-18.11 affected wolfi gitlab-runner-18.11
gitlab-runner-19.0 affected wolfi gitlab-runner-19.0
gitlab-runner-19.0 affected chainguard gitlab-runner-19.0
gitlab-runner-19.1 affected wolfi gitlab-runner-19.1
gitlab-runner-19.1 affected chainguard gitlab-runner-19.1
gitlab-runner-fips-18.10 affected chainguard gitlab-runner-fips-18.10
gitlab-runner-fips-18.11 affected chainguard gitlab-runner-fips-18.11
gitlab-runner-fips-19.0 affected chainguard gitlab-runner-fips-19.0
gitlab-runner-fips-19.1 affected chainguard gitlab-runner-fips-19.1
gitness affected chainguard gitness
gitness affected wolfi gitness
gitsign affected wolfi gitsign
gitsign affected chainguard gitsign
go-getter-2 affected chainguard go-getter-2
go-getter-2.1 affected chainguard go-getter-2.1
go-getter-2.2 affected chainguard go-getter-2.2
go-getter-2-fips affected chainguard go-getter-2-fips
gomplate-4 affected chainguard gomplate-4
gomplate-5 affected chainguard gomplate-5
gomplate-5 affected wolfi gomplate-5
gomplate-fips-4 affected chainguard gomplate-fips-4
gomplate-fips-5 affected chainguard gomplate-fips-5
google-cloud-otel-ops-collector affected chainguard google-cloud-otel-ops-collector
gostatsd affected chainguard gostatsd
gostatsd affected wolfi gostatsd
grafana-11.6 affected chainguard grafana-11.6
grafana-12.0 affected chainguard grafana-12.0
grafana-12.0 affected wolfi grafana-12.0
grafana-12.1 affected wolfi grafana-12.1
grafana-12.1 affected chainguard grafana-12.1
grafana-12.2 affected wolfi grafana-12.2
grafana-12.2 affected chainguard grafana-12.2
grafana-12.3 affected wolfi grafana-12.3
grafana-12.3 affected chainguard grafana-12.3
grafana-12.4 affected chainguard grafana-12.4
grafana-12.4 affected wolfi grafana-12.4
grafana-13.0 affected wolfi grafana-13.0
grafana-13.0 affected chainguard grafana-13.0
grafana-13.1 affected chainguard grafana-13.1
grafana-agent-operator affected wolfi grafana-agent-operator
grafana-agent-operator affected chainguard grafana-agent-operator
grafana-fips-11.6 affected chainguard grafana-fips-11.6
grafana-fips-12.0 affected chainguard grafana-fips-12.0
grafana-fips-12.1 affected chainguard grafana-fips-12.1
grafana-fips-12.2 affected chainguard grafana-fips-12.2
grafana-fips-12.3 affected chainguard grafana-fips-12.3
grafana-fips-12.4 affected chainguard grafana-fips-12.4
grafana-fips-13.0 affected chainguard grafana-fips-13.0
grafana-fips-13.1 affected chainguard grafana-fips-13.1
grafana-mimir-2.17 affected chainguard grafana-mimir-2.17
grafana-mimir-3.0 affected chainguard grafana-mimir-3.0
grafana-mimir-3.0 affected wolfi grafana-mimir-3.0
grafana-mimir-fips-2.17 affected chainguard grafana-mimir-fips-2.17
grafana-mimir-fips-3.0 affected chainguard grafana-mimir-fips-3.0
grafana-pyroscope-1.12 affected chainguard grafana-pyroscope-1.12
grafana-pyroscope-1.13 affected wolfi grafana-pyroscope-1.13
grafana-pyroscope-1.13 affected chainguard grafana-pyroscope-1.13
grafana-pyroscope-1.14 affected chainguard grafana-pyroscope-1.14
grept affected chainguard grept
grept-fips affected chainguard grept-fips
guac affected chainguard guac
guac affected wolfi guac
harbor-2.12 affected chainguard harbor-2.12
harbor-2.13 affected wolfi harbor-2.13
harbor-2.13 affected chainguard harbor-2.13
harbor-2.14 affected chainguard harbor-2.14
harbor-2.14 affected wolfi harbor-2.14
harbor-2.15 affected chainguard harbor-2.15
harbor-fips-2.12 affected chainguard harbor-fips-2.12
harbor-fips-2.13 affected chainguard harbor-fips-2.13
harbor-fips-2.14 affected chainguard harbor-fips-2.14
harbor-fips-2.15 affected chainguard harbor-fips-2.15
harbor-registry affected chainguard harbor-registry
harbor-registry affected wolfi harbor-registry
harbor-registry-fips affected chainguard harbor-registry-fips
harvester affected chainguard harvester
harvester-fips affected chainguard harvester-fips
influxd-2.7 affected chainguard influxd-2.7
juicefs-1.2 affected chainguard juicefs-1.2
k3d affected chainguard k3d
k3d affected wolfi k3d
k8sgpt affected wolfi k8sgpt
k8sgpt affected chainguard k8sgpt
k8s-image-swapper affected chainguard k8s-image-swapper
k8s-image-swapper-fips affected chainguard k8s-image-swapper-fips
karpenter-0.33 affected chainguard karpenter-0.33
karpenter-0.34 affected chainguard karpenter-0.34
karpenter-0.35 affected chainguard karpenter-0.35
karpenter-0.36 affected chainguard karpenter-0.36
karpenter-0.37 affected chainguard karpenter-0.37
karpenter-fips-0.33 affected chainguard karpenter-fips-0.33
karpenter-fips-0.34 affected chainguard karpenter-fips-0.34
karpenter-fips-0.35 affected chainguard karpenter-fips-0.35
karpenter-fips-0.36 affected chainguard karpenter-fips-0.36
karpenter-fips-0.37 affected chainguard karpenter-fips-0.37
kiam affected chainguard kiam
kots affected chainguard kots
kots affected wolfi kots
kserve affected wolfi kserve
kserve affected chainguard kserve
kserve-fips affected chainguard kserve-fips
kserve-localmodelnode-agent affected chainguard kserve-localmodelnode-agent
kserve-localmodelnode-agent-fips affected chainguard kserve-localmodelnode-agent-fips
kserve-modelmesh-serving affected chainguard kserve-modelmesh-serving
kserve-modelmesh-serving affected wolfi kserve-modelmesh-serving
kube-arangodb-1.3 affected wolfi kube-arangodb-1.3
kube-arangodb-1.3 affected chainguard kube-arangodb-1.3
kube-arangodb-1.4 affected wolfi kube-arangodb-1.4
kube-arangodb-1.4 affected chainguard kube-arangodb-1.4
kube-arangodb-fips-1.3 affected chainguard kube-arangodb-fips-1.3
kube-arangodb-fips-1.4 affected chainguard kube-arangodb-fips-1.4
kubeflow affected wolfi kubeflow
kubeflow affected chainguard kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines-driver-fips affected chainguard kubeflow-pipelines-driver-fips
kubeflow-pipelines-fips affected chainguard kubeflow-pipelines-fips
kubernetes-event-exporter affected chainguard kubernetes-event-exporter
kubernetes-event-exporter affected wolfi kubernetes-event-exporter
kubernetes-event-exporter-fips affected chainguard kubernetes-event-exporter-fips
kubescape affected chainguard kubescape
kubescape affected wolfi kubescape
kubescape-operator affected wolfi kubescape-operator
kubescape-operator affected chainguard kubescape-operator
kubescape-operator-fips affected chainguard kubescape-operator-fips
kubescape-server affected chainguard kubescape-server
kubescape-server-fips affected chainguard kubescape-server-fips
kubevirt-cdi-uploadserver-1.5 affected chainguard kubevirt-cdi-uploadserver-1.5
kubevirt-cdi-uploadserver-1.59 affected chainguard kubevirt-cdi-uploadserver-1.59
kubevirt-cdi-uploadserver-1.6 affected chainguard kubevirt-cdi-uploadserver-1.6
kubevirt-cdi-uploadserver-fips-1.5 affected chainguard kubevirt-cdi-uploadserver-fips-1.5
kubevirt-cdi-uploadserver-fips-1.59 affected chainguard kubevirt-cdi-uploadserver-fips-1.59
kubevirt-cdi-uploadserver-fips-1.6 affected chainguard kubevirt-cdi-uploadserver-fips-1.6
loki-2.9 affected chainguard loki-2.9
loki-3.4 affected chainguard loki-3.4
loki-3.5 affected wolfi loki-3.5
loki-3.5 affected chainguard loki-3.5
loki-3.6 affected wolfi loki-3.6
loki-3.6 affected chainguard loki-3.6
loki-3.7 affected wolfi loki-3.7
loki-3.7 affected chainguard loki-3.7
loki-fips-2.9 affected chainguard loki-fips-2.9
loki-fips-3.4 affected chainguard loki-fips-3.4
loki-fips-3.5 affected chainguard loki-fips-3.5
loki-fips-3.6 affected chainguard loki-fips-3.6
loki-fips-3.7 affected chainguard loki-fips-3.7
longhorn-backing-image-manager-1.8 affected chainguard longhorn-backing-image-manager-1.8
longhorn-backing-image-manager-1.9 affected chainguard longhorn-backing-image-manager-1.9
longhorn-backing-image-manager-fips-1.8 affected chainguard longhorn-backing-image-manager-fips-1.8
longhorn-backing-image-manager-fips-1.9 affected chainguard longhorn-backing-image-manager-fips-1.9
longhorn-engine-1.8 affected chainguard longhorn-engine-1.8
longhorn-engine-1.9 affected chainguard longhorn-engine-1.9
longhorn-instance-manager-1.8 affected chainguard longhorn-instance-manager-1.8
longhorn-instance-manager-1.8-fips affected chainguard longhorn-instance-manager-1.8-fips
longhorn-instance-manager-1.9 affected chainguard longhorn-instance-manager-1.9
longhorn-instance-manager-1.9-fips affected chainguard longhorn-instance-manager-1.9-fips
mapotf affected chainguard mapotf
mapotf-fips affected chainguard mapotf-fips
mattermost-10.11 affected chainguard mattermost-10.11
mattermost-11.1 affected wolfi mattermost-11.1
mattermost-11.1 affected chainguard mattermost-11.1
mattermost-11.2 affected chainguard mattermost-11.2
mattermost-11.2 affected wolfi mattermost-11.2
mattermost-fips-10.11 affected chainguard mattermost-fips-10.11
mattermost-fips-11.1 affected chainguard mattermost-fips-11.1
mattermost-fips-11.2 affected chainguard mattermost-fips-11.2
metrics-agent affected chainguard metrics-agent
metrics-agent affected wolfi metrics-agent
metrics-agent-fips affected chainguard metrics-agent-fips
monstache affected chainguard monstache
neuvector affected chainguard neuvector
neuvector-fips affected chainguard neuvector-fips
neuvector-scanner affected chainguard neuvector-scanner
neuvector-scanner affected wolfi neuvector-scanner
neuvector-scanner-fips affected chainguard neuvector-scanner-fips
newrelic-nri-statsd affected chainguard newrelic-nri-statsd
newrelic-nri-statsd affected wolfi newrelic-nri-statsd
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
node-problem-detector-1.34 affected chainguard node-problem-detector-1.34
node-problem-detector-1.35 affected chainguard node-problem-detector-1.35
node-problem-detector-1.35 affected wolfi node-problem-detector-1.35
node-problem-detector-fips-0.8 affected chainguard node-problem-detector-fips-0.8
node-problem-detector-fips-1.34 affected chainguard node-problem-detector-fips-1.34
node-problem-detector-fips-1.35 affected chainguard node-problem-detector-fips-1.35
nrdot-collector affected chainguard nrdot-collector
nrdot-collector-fips affected chainguard nrdot-collector-fips
nrdot-collector-k8s affected chainguard nrdot-collector-k8s
nrdot-collector-k8s-fips affected chainguard nrdot-collector-k8s-fips
openbao affected chainguard openbao
openbao affected wolfi openbao
openbao-fips affected chainguard openbao-fips
opencost affected wolfi opencost
opencost affected chainguard opencost
opencost-fips affected chainguard opencost-fips
opentelemetry-collector affected chainguard opentelemetry-collector
opentelemetry-collector affected wolfi opentelemetry-collector
opentelemetry-collector-contrib affected wolfi opentelemetry-collector-contrib
opentelemetry-collector-contrib affected chainguard opentelemetry-collector-contrib
opentelemetry-collector-contrib-fips affected chainguard opentelemetry-collector-contrib-fips
opentelemetry-collector-fips affected chainguard opentelemetry-collector-fips
opentelemetry-collector-k8s affected chainguard opentelemetry-collector-k8s
opentelemetry-collector-k8s-fips affected chainguard opentelemetry-collector-k8s-fips
opentofu-1.9 affected wolfi opentofu-1.9
opentofu-1.9 affected chainguard opentofu-1.9
opentofu-fips-1.9 affected chainguard opentofu-fips-1.9
packer affected chainguard packer
packer-fips affected chainguard packer-fips
plutono affected chainguard plutono
plutono-fips affected chainguard plutono-fips
porch affected chainguard porch
porch-fips affected chainguard porch-fips
postgres-operator affected wolfi postgres-operator
postgres-operator affected chainguard postgres-operator
postgres-operator-fips affected chainguard postgres-operator-fips
prometheus-2.51 affected chainguard prometheus-2.51
prometheus-3.12 affected chainguard prometheus-3.12
prometheus-3.12 affected wolfi prometheus-3.12
prometheus-3.5 affected chainguard prometheus-3.5
prometheus-fips-3.12 affected chainguard prometheus-fips-3.12
prometheus-fips-3.5 affected chainguard prometheus-fips-3.5
promxy affected wolfi promxy
promxy affected chainguard promxy
promxy-fips affected chainguard promxy-fips
rancher-2.10 affected chainguard rancher-2.10
rancher-2.11 affected chainguard rancher-2.11
rancher-2.12 affected chainguard rancher-2.12
rancher-2.13 affected chainguard rancher-2.13
rancher-2.13 affected wolfi rancher-2.13
rancher-2.14 affected chainguard rancher-2.14
rancher-2.14 affected wolfi rancher-2.14
rancher-agent-2.10 affected chainguard rancher-agent-2.10
rancher-agent-2.11 affected chainguard rancher-agent-2.11
rancher-agent-2.12 affected chainguard rancher-agent-2.12
rancher-agent-2.13 affected chainguard rancher-agent-2.13
rancher-agent-2.13 affected wolfi rancher-agent-2.13
rancher-agent-2.14 affected chainguard rancher-agent-2.14
rancher-agent-2.14 affected wolfi rancher-agent-2.14
rancher-agent-2.9 affected chainguard rancher-agent-2.9
rancher-machine affected chainguard rancher-machine
rancher-machine affected wolfi rancher-machine
redpanda-25.1 affected chainguard redpanda-25.1
redpanda-25.2 affected chainguard redpanda-25.2
redpanda-25.3 affected chainguard redpanda-25.3
rook-1.18 affected chainguard rook-1.18
rook-1.19 affected wolfi rook-1.19
rook-1.19 affected chainguard rook-1.19
rook-fips-1.18 affected chainguard rook-fips-1.18
rook-fips-1.19 affected chainguard rook-fips-1.19
s5cmd affected wolfi s5cmd
s5cmd affected chainguard s5cmd
s5cmd-fips affected chainguard s5cmd-fips
seaweedfs affected chainguard seaweedfs
seaweedfs affected wolfi seaweedfs
seaweedfs-fips affected chainguard seaweedfs-fips
seaweedfs-operator affected chainguard seaweedfs-operator
seaweedfs-operator-fips affected chainguard seaweedfs-operator-fips
seaweedfs-rocksdb affected chainguard seaweedfs-rocksdb
seaweedfs-rocksdb-fips affected chainguard seaweedfs-rocksdb-fips
slsa-verifier affected wolfi slsa-verifier
slsa-verifier affected chainguard slsa-verifier
splunk-otel-collector affected chainguard splunk-otel-collector
splunk-otel-collector affected wolfi splunk-otel-collector
splunk-otel-collector-fips affected chainguard splunk-otel-collector-fips
steampipe affected wolfi steampipe
steampipe affected chainguard steampipe
step-ca affected wolfi step-ca
step-ca affected chainguard step-ca
step-ca-fips affected chainguard step-ca-fips
tekton-chains affected wolfi tekton-chains
tekton-chains affected chainguard tekton-chains
tekton-chains-fips affected chainguard tekton-chains-fips
teleport-17 affected chainguard teleport-17
teleport-operator-fips-16 affected chainguard teleport-operator-fips-16
teleport-operator-fips-17 affected chainguard teleport-operator-fips-17
tempo-2.8 affected chainguard tempo-2.8
tempo-2.9 affected chainguard tempo-2.9
tempo-fips-2.8 affected chainguard tempo-fips-2.8
tempo-fips-2.9 affected chainguard tempo-fips-2.9
terraform affected chainguard terraform
terraform affected wolfi terraform
terraform-1.10 affected chainguard terraform-1.10
terraform-1.11 affected chainguard terraform-1.11
terraform-1.12 affected chainguard terraform-1.12
terraform-1.9 affected chainguard terraform-1.9
terragrunt affected chainguard terragrunt
terragrunt affected wolfi terragrunt
terragrunt-fips affected chainguard terragrunt-fips
tigera-operator-1.28 affected chainguard tigera-operator-1.28
tigera-operator-1.29 affected chainguard tigera-operator-1.29
tigera-operator-1.34 affected chainguard tigera-operator-1.34
tigera-operator-1.36 affected chainguard tigera-operator-1.36
tigera-operator-1.37 affected chainguard tigera-operator-1.37
tigera-operator-1.38 affected chainguard tigera-operator-1.38
tigera-operator-1.40 affected chainguard tigera-operator-1.40
tigera-operator-1.40 affected wolfi tigera-operator-1.40
tigera-operator-1.41 affected wolfi tigera-operator-1.41
tigera-operator-1.41 affected chainguard tigera-operator-1.41
tigera-operator-fips-1.29 affected chainguard tigera-operator-fips-1.29
tigera-operator-fips-1.34 affected chainguard tigera-operator-fips-1.34
tigera-operator-fips-1.36 affected chainguard tigera-operator-fips-1.36
tigera-operator-fips-1.37 affected chainguard tigera-operator-fips-1.37
tigera-operator-fips-1.38 affected chainguard tigera-operator-fips-1.38
tigera-operator-fips-1.40 affected chainguard tigera-operator-fips-1.40
tigera-operator-fips-1.41 affected chainguard tigera-operator-fips-1.41
trillian affected chainguard trillian
trillian affected wolfi trillian
trillian-fips affected chainguard trillian-fips
vault-1.16 affected chainguard vault-1.16
vault-1.17 affected chainguard vault-1.17
vault-1.18 affected chainguard vault-1.18
vault-1.19 affected chainguard vault-1.19
vault-1.20 affected chainguard vault-1.20
vault-1.21 affected chainguard vault-1.21
vault-2.0 affected chainguard vault-2.0
vault-benchmark affected chainguard vault-benchmark
vault-benchmark affected wolfi vault-benchmark
vault-env affected wolfi vault-env
vault-env affected chainguard vault-env
vault-fips-1.21 affected chainguard vault-fips-1.21
vault-fips-2.0 affected chainguard vault-fips-2.0
vault-secrets-operator affected chainguard vault-secrets-operator
vault-secrets-operator-fips affected chainguard vault-secrets-operator-fips
vault-secrets-webhook affected wolfi vault-secrets-webhook
vault-secrets-webhook affected chainguard vault-secrets-webhook
verticadb-operator affected chainguard verticadb-operator
verticadb-operator affected wolfi verticadb-operator
verticadb-operator-fips affected chainguard verticadb-operator-fips
wal-g affected wolfi wal-g
wal-g affected chainguard wal-g
weaviate affected wolfi weaviate
weaviate affected chainguard weaviate
zot affected chainguard zot
zot affected wolfi zot
Upstream advisory

DEBIAN-CVE-2022-0306

Open SourceEPSS > 79%CRITICAL2022-02-12

DEBIAN-CVE-2022-0306

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0289

Open SourceCoalition ESS < 30%CRITICAL2022-02-12

DEBIAN-CVE-2022-0289

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-39675

Open SourceCoalition ESS < 30%HIGH2022-02-08

In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2021-39675

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GO-2021-0242

Open SourceCoalition ESS < 30%2022-02-17

Panic on inputs with large exponents in math/big

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

GO-2021-0224

Open SourceCoalition ESS < 30%HIGH2022-02-17

Data race and crash in net/http

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

GO-2021-0234

Open SourceCoalition ESS < 30%HIGH2022-02-17

Infinite loop when decoding inputs in encoding/xml

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

DEBIAN-CVE-2022-0290

Open SourceCoalition ESS < 30%CRITICAL2022-02-12

DEBIAN-CVE-2022-0290

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GO-2021-0223

Open SourceCoalition ESS < 30%2022-02-17

Certificate verification error on Windows in crypto/x509

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

GHSA-856q-xv3c-7f2f

Open SourceCoalition ESS < 30%HIGH2022-02-23

Unauthenticated control plane denial of service attack in Istio

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio.io istio.io/istio
Upstream advisory

GHSA-856q-xv3c-7f2f

Open SourceCoalition ESS < 30%HIGH2022-02-23

Unauthenticated control plane denial of service attack in Istio

Affected products

ProductStatusVendorPackageEcosystem
cert-manager-istio-csr affected chainguard cert-manager-istio-csr
cert-manager-istio-csr affected wolfi cert-manager-istio-csr
cert-manager-istio-csr-fips affected chainguard cert-manager-istio-csr-fips
istio affected istio.io istio.io/istio
istio-cni-1.21 affected wolfi istio-cni-1.21
istio-cni-1.21 affected chainguard istio-cni-1.21
istio-cni-1.22 affected chainguard istio-cni-1.22
istio-cni-1.22 affected wolfi istio-cni-1.22
istio-fips-1.21 affected chainguard istio-fips-1.21
istio-operator-1.20 affected wolfi istio-operator-1.20
istio-operator-1.20 affected chainguard istio-operator-1.20
istio-operator-1.21 affected chainguard istio-operator-1.21
istio-operator-1.21 affected wolfi istio-operator-1.21
istio-operator-1.22 affected wolfi istio-operator-1.22
istio-operator-1.22 affected chainguard istio-operator-1.22
istio-pilot-agent-1.21 affected chainguard istio-pilot-agent-1.21
istio-pilot-agent-1.21 affected wolfi istio-pilot-agent-1.21
istio-pilot-agent-1.22 affected wolfi istio-pilot-agent-1.22
istio-pilot-agent-1.22 affected chainguard istio-pilot-agent-1.22
istio-pilot-discovery-1.21 affected chainguard istio-pilot-discovery-1.21
istio-pilot-discovery-1.21 affected wolfi istio-pilot-discovery-1.21
istio-pilot-discovery-1.22 affected wolfi istio-pilot-discovery-1.22
istio-pilot-discovery-1.22 affected chainguard istio-pilot-discovery-1.22
kgateway-2.3 affected chainguard kgateway-2.3
kgateway-2.4 affected chainguard kgateway-2.4
kgateway-fips-2.3 affected chainguard kgateway-fips-2.3
kgateway-fips-2.4 affected chainguard kgateway-fips-2.4
Upstream advisory

CVE-2022-23635

Open SourceCoalition ESS < 30%HIGH2022-02-22

Unauthenticated control plane denial of service attack in Istio

CVEs:CVE-2022-23635

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio.io istio.io/istio
Upstream advisory

CVE-2022-23635

Open SourceCoalition ESS < 30%HIGH2022-02-22

Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which resu...

CVEs:CVE-2022-23635

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio
Upstream advisory

CVE-2022-23261

Open SourceCoalition ESS < 30%MEDIUM2022-02-04

Microsoft Edge (Chromium-based) Tampering Vulnerability

CVEs:CVE-2022-23261

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2022-0100

Open SourceCoalition ESS < 30%CRITICAL2022-02-12

DEBIAN-CVE-2022-0100

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0115

Open SourceCoalition ESS < 30%HIGH2022-02-12

DEBIAN-CVE-2022-0115

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0117

Open SourceCoalition ESS < 30%MEDIUM2022-02-12

DEBIAN-CVE-2022-0117

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-vfp4-xx6m-7vf6

Open SourceCoalition ESS < 30%CRITICAL2022-02-15

Cryptographic Issues in ECK

Affected products

ProductStatusVendorPackageEcosystem
elastic/cloud-on-k8s affected github.com github.com/elastic/cloud-on-k8s
Upstream advisory

GHSA-vfp4-xx6m-7vf6

Open SourceCoalition ESS < 30%CRITICAL2022-02-15

Cryptographic Issues in ECK

Affected products

ProductStatusVendorPackageEcosystem
elastic/cloud-on-k8s affected github.com github.com/elastic/cloud-on-k8s
Upstream advisory

DEBIAN-CVE-2022-0101

Open SourceCoalition ESS < 30%CRITICAL2022-02-12

DEBIAN-CVE-2022-0101

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0104

Open SourceCoalition ESS < 30%CRITICAL2022-02-12

DEBIAN-CVE-2022-0104

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0096

Open SourceCoalition ESS < 30%CRITICAL2022-02-12

DEBIAN-CVE-2022-0096

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0109

Open SourceCoalition ESS < 30%HIGH2022-02-12

DEBIAN-CVE-2022-0109

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-5cgx-vhfp-6cf9

Open SourceCoalition ESS < 30%CRITICAL2022-02-15

Directory traversal in Kubernetes Secrets Store CSI Driver

Affected products

ProductStatusVendorPackageEcosystem
secrets-store-csi-driver affected sigs.k8s.io sigs.k8s.io/secrets-store-csi-driver
Upstream advisory

GHSA-5cgx-vhfp-6cf9

Open SourceCoalition ESS < 30%CRITICAL2022-02-15

Directory traversal in Kubernetes Secrets Store CSI Driver

Affected products

ProductStatusVendorPackageEcosystem
secrets-store-csi-driver affected sigs.k8s.io sigs.k8s.io/secrets-store-csi-driver
Upstream advisory

GO-2022-0629

Open SourceCoalition ESS < 30%CRITICAL2022-02-15

Directory traversal in sigs.k8s.io/secrets-store-csi-driver

Affected products

ProductStatusVendorPackageEcosystem
secrets-store-csi-driver affected sigs.k8s.io sigs.k8s.io/secrets-store-csi-driver
Upstream advisory

DEBIAN-CVE-2022-0102

Open SourceCoalition ESS < 30%HIGH2022-02-12

DEBIAN-CVE-2022-0102

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0114

Open SourceCoalition ESS < 30%HIGH2022-02-12

DEBIAN-CVE-2022-0114

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0106

Open SourceCoalition ESS < 30%CRITICAL2022-02-12

DEBIAN-CVE-2022-0106

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0105

Open SourceCoalition ESS < 30%CRITICAL2022-02-12

DEBIAN-CVE-2022-0105

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0103

Open SourceCoalition ESS < 30%CRITICAL2022-02-12

DEBIAN-CVE-2022-0103

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-23262

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-23262

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2022-0099

Open SourceCoalition ESS < 30%CRITICAL2022-02-12

DEBIAN-CVE-2022-0099

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-98p5-x8x4-c9m5

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Integer overflow in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-98p5-x8x4-c9m5

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Integer overflow in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-123

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-123

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-68

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-68

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23559

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-68

CVEs:CVE-2022-23559

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23559

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in embedding lookup operations. Both `embedding_size` and `lookup_size` are products of values provided by the user. Henc...

CVEs:CVE-2022-23559

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23559

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Integer overflow in TFLite

CVEs:CVE-2022-23559

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6g5f-f5pm-mjrg

Open SourceCoalition ESS < 30%CRITICAL2022-02-15

Istio may not check inbound TCP connections against istio-policy

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio.io istio.io/istio
Upstream advisory

GHSA-6g5f-f5pm-mjrg

Open SourceCoalition ESS < 30%CRITICAL2022-02-15

Istio may not check inbound TCP connections against istio-policy

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio.io istio.io/istio
Upstream advisory

DEBIAN-CVE-2022-0116

Open SourceCoalition ESS < 30%MEDIUM2022-02-12

DEBIAN-CVE-2022-0116

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-fq86-3f29-px2c

Open SourceCoalition ESS < 30%HIGH2022-02-07

`CHECK`-failures during Grappler's `IsSimplifiableReshape` in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fq86-3f29-px2c

Open SourceCoalition ESS < 30%HIGH2022-02-07

`CHECK`-failures during Grappler's `IsSimplifiableReshape` in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-145

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-145

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-90

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-90

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23581

Open SourceCoalition ESS < 30%MEDIUM2022-02-04

PYSEC-2022-90

CVEs:CVE-2022-23581

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23581

Open SourceCoalition ESS < 30%HIGH2022-02-04

`CHECK`-failures during Grappler's `IsSimplifiableReshape` in Tensorflow

CVEs:CVE-2022-23581

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23581

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. The Grappler optimizer in TensorFlow can be used to cause a denial of service by altering a `SavedModel` such that `IsSimplifiableReshape` would trigger `CHECK` failures. The fix will be included...

CVEs:CVE-2022-23581

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

DEBIAN-CVE-2022-0118

Open SourceCoalition ESS < 30%MEDIUM2022-02-12

DEBIAN-CVE-2022-0118

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-0608

GoogleCoalition ESS < 30%CRITICAL2022-02-15

Integer overflow in Mojo in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0608

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-0112

Open SourceCoalition ESS < 30%MEDIUM2022-02-12

DEBIAN-CVE-2022-0112

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-rrx2-r989-2c43

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Integer overflows in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rrx2-r989-2c43

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Integer overflows in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9px9-73fg-3fqp

Open SourceCoalition ESS < 30%MEDIUM2022-02-09

Null pointer dereference in Grappler's `IsConstant`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9px9-73fg-3fqp

Open SourceCoalition ESS < 30%MEDIUM2022-02-09

Null pointer dereference in Grappler's `IsConstant`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-153

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-153

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-98

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-98

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23589

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, Grappler component of TensorFlow can trigger a null pointer dereference. There are 2 places where this can occur, for the same malicious alteration of a `SavedModel` file...

CVEs:CVE-2022-23589

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23589

Open SourceCoalition ESS < 30%MEDIUM2022-02-04

Null pointer dereference in Grappler's `IsConstant`

CVEs:CVE-2022-23589

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23589

Open SourceCoalition ESS < 30%MEDIUM2022-02-04

PYSEC-2022-98

CVEs:CVE-2022-23589

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-131

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-131

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-76

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-76

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23567

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Integer overflows in Tensorflow

CVEs:CVE-2022-23567

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23567

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. The implementations of `Sparse*Cwise*` ops are vulnerable to integer overflows. These can be used to trigger large allocations (so, OOM based denial of service) or `CHECK`-fails when building new...

CVEs:CVE-2022-23567

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23567

Open SourceCoalition ESS < 30%HIGH2022-02-03

PYSEC-2022-76

CVEs:CVE-2022-23567

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

DEBIAN-CVE-2022-0110

Open SourceCoalition ESS < 30%MEDIUM2022-02-12

DEBIAN-CVE-2022-0110

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-4101

Open SourceCoalition ESS < 30%CRITICAL2022-02-11

DEBIAN-CVE-2021-4101

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-9p77-mmrw-69c7

Open SourceCoalition ESS < 30%HIGH2022-02-09

Null-dereference in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9p77-mmrw-69c7

Open SourceCoalition ESS < 30%HIGH2022-02-09

Null-dereference in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rww7-2gpw-fv6j

Open SourceCoalition ESS < 30%HIGH2022-02-09

Crash when type cannot be specialized in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rww7-2gpw-fv6j

Open SourceCoalition ESS < 30%HIGH2022-02-09

Crash when type cannot be specialized in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fq6p-6334-8gr4

Open SourceCoalition ESS < 30%MEDIUM2022-02-09

Memory leak in decoding PNG images

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fq6p-6334-8gr4

Open SourceCoalition ESS < 30%MEDIUM2022-02-09

Memory leak in decoding PNG images

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-134

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-134

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-136

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-136

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-149

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-149

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-79

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-79

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2022-81

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-81

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2022-94

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-94

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23570

Open SourceCoalition ESS < 30%HIGH2022-02-04

Null-dereference in Tensorflow

CVEs:CVE-2022-23570

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23570

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, TensorFlow might do a null-dereference if attributes of some mutable arguments to some operations are missing from the proto. This is guarded by a `DCHECK`. ...

CVEs:CVE-2022-23570

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23570

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-79

CVEs:CVE-2022-23570

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23572

Open SourceCoalition ESS < 30%HIGH2022-02-04

Crash when type cannot be specialized in Tensorflow

CVEs:CVE-2022-23572

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23572

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, TensorFlow can fail to specialize a type during shape inference. This case is covered by the `DCHECK` function however, `DCHECK` is a no-op in production builds and an as...

CVEs:CVE-2022-23572

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23572

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-81

CVEs:CVE-2022-23572

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23585

Open SourceCoalition ESS < 30%MEDIUM2022-02-04

Memory leak in decoding PNG images

CVEs:CVE-2022-23585

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23585

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. When decoding PNG images TensorFlow can produce a memory leak if the image is invalid. After calling `png::CommonInitDecode(..., &decode)`, the `decode` value contains allocated buffers which can...

CVEs:CVE-2022-23585

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23585

Open SourceCoalition ESS < 30%MEDIUM2022-02-04

PYSEC-2022-94

CVEs:CVE-2022-23585

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-0451

Open SourceCoalition ESS < 30%HIGH2022-02-18

Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensitive information. By default, HttpClient handles redirection logic. If a...

CVEs:CVE-2022-0451

Affected products

ProductStatusVendorPackageEcosystem
dart_software_development_kit affected dart
Upstream advisory

GHSA-pqrv-8r2f-7278

Open SourceCoalition ESS < 30%HIGH2022-02-09

Crash due to erroneous `StatusOr` in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-pqrv-8r2f-7278

Open SourceCoalition ESS < 30%HIGH2022-02-09

Crash due to erroneous `StatusOr` in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-154

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-154

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-99

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-99

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23590

Open SourceCoalition ESS < 30%HIGH2022-02-04

Crash due to erroneous `StatusOr` in TensorFlow

CVEs:CVE-2022-23590

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23590

Open SourceCoalition ESS < 30%MEDIUM2022-02-04

PYSEC-2022-99

CVEs:CVE-2022-23590

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23590

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. A `GraphDef` from a TensorFlow `SavedModel` can be maliciously altered to cause a TensorFlow process to crash due to encountering a `StatusOr` value that is an error and forcibly extracting the v...

CVEs:CVE-2022-23590

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-0470

GoogleCoalition ESS < 30%HIGH2022-02-02

Out of bounds memory access in V8 in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0470

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0467

GoogleCoalition ESS < 30%HIGH2022-02-02

Inappropriate implementation in Pointer Lock in Google Chrome on Windows prior to 98.0.4758.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2022-0467

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-0107

Open SourceCoalition ESS < 30%CRITICAL2022-02-12

DEBIAN-CVE-2022-0107

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0098

Open SourceCoalition ESS < 30%CRITICAL2022-02-12

DEBIAN-CVE-2022-0098

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-5qw5-89mw-wcg2

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Out of bounds write in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-5qw5-89mw-wcg2

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Out of bounds write in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-130

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-130

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-75

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-75

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23566

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-75

CVEs:CVE-2022-23566

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23566

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. TensorFlow is vulnerable to a heap OOB write in `Grappler`. The `set_output` function writes to an array at the specified index. Hence, this gives a malicious user a write primitive. The fix will...

CVEs:CVE-2022-23566

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23566

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Out of bounds write in Tensorflow

CVEs:CVE-2022-23566

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-0454

GoogleCoalition ESS < 30%CRITICAL2022-02-02

Heap buffer overflow in ANGLE in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0454

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-8jj7-5vxc-pg2q

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Integer overflow in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8jj7-5vxc-pg2q

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Integer overflow in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-151

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-151

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-96

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-96

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23587

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-96

CVEs:CVE-2022-23587

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23587

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, Grappler component of TensorFlow is vulnerable to an integer overflow during cost estimation for crop and resize. Since the cropping parameters are user controlled, a mal...

CVEs:CVE-2022-23587

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23587

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Integer overflow in TensorFlow

CVEs:CVE-2022-23587

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

DEBIAN-CVE-2022-0097

Open SourceCoalition ESS < 30%CRITICAL2022-02-12

DEBIAN-CVE-2022-0097

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-gjqc-q9g6-q2j3

Open SourceCoalition ESS < 30%HIGH2022-02-10

`CHECK`-failures in binary ops in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gjqc-q9g6-q2j3

Open SourceCoalition ESS < 30%HIGH2022-02-10

`CHECK`-failures in binary ops in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-147

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-147

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-92

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-92

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23583

Open SourceCoalition ESS < 30%HIGH2022-02-04

`CHECK`-failures in binary ops in Tensorflow

CVEs:CVE-2022-23583

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23583

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that any binary op would trigger `CHECK` failures. This occurs when the protobuf part corresponding to the tensor ar...

CVEs:CVE-2022-23583

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23583

Open SourceCoalition ESS < 30%MEDIUM2022-02-04

PYSEC-2022-92

CVEs:CVE-2022-23583

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

DEBIAN-CVE-2022-0311

Open SourceCoalition ESS < 30%HIGH2022-02-12

DEBIAN-CVE-2022-0311

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-0462

GoogleCoalition ESS < 30%MEDIUM2022-02-02

Inappropriate implementation in Scroll in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2022-0462

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-fx5c-h9f6-rv7c

Open SourceCoalition ESS < 30%HIGH2022-02-09

`CHECK`-fails due to attempting to build a reference tensor

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fx5c-h9f6-rv7c

Open SourceCoalition ESS < 30%HIGH2022-02-09

`CHECK`-fails due to attempting to build a reference tensor

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-152

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-152

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-97

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-97

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23588

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that Grappler optimizer would attempt to build a tensor using a reference `dtype`. This would result in a crash due ...

CVEs:CVE-2022-23588

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23588

Open SourceCoalition ESS < 30%MEDIUM2022-02-04

PYSEC-2022-97

CVEs:CVE-2022-23588

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23588

Open SourceCoalition ESS < 30%HIGH2022-02-04

`CHECK`-fails due to attempting to build a reference tensor

CVEs:CVE-2022-23588

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gwcx-jrx4-92w2

Open SourceCoalition ESS < 30%HIGH2022-02-09

Segfault in `simplifyBroadcast` in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gwcx-jrx4-92w2

Open SourceCoalition ESS < 30%HIGH2022-02-09

Segfault in `simplifyBroadcast` in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-102

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-102

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2022-157

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-157

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23593

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-157

CVEs:CVE-2022-23593

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23593

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. The `simplifyBroadcast` function in the MLIR-TFRT infrastructure in TensorFlow is vulnerable to a segfault (hence, denial of service), if called with scalar shapes. If all shapes are scalar, then...

CVEs:CVE-2022-23593

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23593

Open SourceCoalition ESS < 30%HIGH2022-02-04

Segfault in `simplifyBroadcast` in Tensorflow

CVEs:CVE-2022-23593

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-0461

GoogleCoalition ESS < 30%MEDIUM2022-02-02

Policy bypass in COOP in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to bypass iframe sandbox via a crafted HTML page.

CVEs:CVE-2022-0461

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-vq36-27g6-p492

Open SourceCoalition ESS < 30%HIGH2022-02-09

Out of bounds read in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vq36-27g6-p492

Open SourceCoalition ESS < 30%HIGH2022-02-09

Out of bounds read in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-101

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-101

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2022-156

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-156

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23592

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. TensorFlow's type inference can cause a heap out of bounds read as the bounds checking is done in a `DCHECK` (which is a no-op during production). An attacker can control the `input_idx` variable...

CVEs:CVE-2022-23592

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23592

Open SourceCoalition ESS < 30%HIGH2022-02-04

Out of bounds read in Tensorflow

CVEs:CVE-2022-23592

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23592

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-156

CVEs:CVE-2022-23592

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

DEBIAN-CVE-2022-0113

Open SourceCoalition ESS < 30%MEDIUM2022-02-12

DEBIAN-CVE-2022-0113

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-4070

Open SourceCoalition ESS < 30%CRITICAL2022-02-23

DEBIAN-CVE-2021-4070

Affected products

ProductStatusVendorPackageEcosystem
golang-v2ray-core affected Debian:11 golang-v2ray-core
golang-v2ray-core affected Debian:12 golang-v2ray-core
golang-v2ray-core affected Debian:13 golang-v2ray-core
golang-v2ray-core affected Debian:14 golang-v2ray-core
Upstream advisory

GHSA-m4hf-j54p-p353

Open SourceCoalition ESS < 30%HIGH2022-02-10

Type confusion leading to segfault in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-m4hf-j54p-p353

Open SourceCoalition ESS < 30%HIGH2022-02-10

Type confusion leading to segfault in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-110

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-110

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-55

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-55

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-21731

Open SourceCoalition ESS < 30%HIGH2022-02-03

PYSEC-2022-55

CVEs:CVE-2022-21731

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21731

Open SourceCoalition ESS < 30%HIGH2022-02-03

Type confusion leading to segfault in Tensorflow

CVEs:CVE-2022-21731

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21731

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `ConcatV2` can be used to trigger a denial of service attack via a segfault caused by a type confusion. The `axis` argument is translated into `concat_di...

CVEs:CVE-2022-21731

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-77gp-3h4r-6428

Open SourceCoalition ESS < 30%HIGH2022-02-09

Out of bounds read and write in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-77gp-3h4r-6428

Open SourceCoalition ESS < 30%HIGH2022-02-09

Out of bounds read and write in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-138

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-138

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-83

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-83

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23574

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. There is a typo in TensorFlow's `SpecializeType` which results in heap OOB read/write. Due to a typo, `arg` is initialized to the `i`th mutable argument in a loop where the loop index is `j`. Hen...

CVEs:CVE-2022-23574

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23574

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-83

CVEs:CVE-2022-23574

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23574

Open SourceCoalition ESS < 30%HIGH2022-02-04

Out of bounds read and write in Tensorflow

CVEs:CVE-2022-23574

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-0464

GoogleCoalition ESS < 30%HIGH2022-02-02

Use after free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.

CVEs:CVE-2022-0464

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0603

GoogleCoalition ESS < 30%CRITICAL2022-02-15

Use after free in File Manager in Google Chrome on Chrome OS prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0603

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0606

GoogleCoalition ESS < 30%CRITICAL2022-02-15

Use after free in ANGLE in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0606

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0607

GoogleCoalition ESS < 30%CRITICAL2022-02-15

Use after free in GPU in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0607

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-5f2r-qp73-37mr

Open SourceCoalition ESS < 30%HIGH2022-02-10

`CHECK`-failures during Grappler's `SafeToRemoveIdentity` in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-5f2r-qp73-37mr

Open SourceCoalition ESS < 30%HIGH2022-02-10

`CHECK`-failures during Grappler's `SafeToRemoveIdentity` in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-98j8-c9q4-r38g

Open SourceCoalition ESS < 30%CRITICAL2022-02-10

Memory exhaustion in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-98j8-c9q4-r38g

Open SourceCoalition ESS < 30%CRITICAL2022-02-10

Memory exhaustion in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-428x-9xc2-m8mj

Open SourceCoalition ESS < 30%HIGH2022-02-09

Division by zero in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-428x-9xc2-m8mj

Open SourceCoalition ESS < 30%HIGH2022-02-09

Division by zero in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-627q-g293-49q7

Open SourceCoalition ESS < 30%MEDIUM2022-02-07

Abort caused by allocating a vector that is too large in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-627q-g293-49q7

Open SourceCoalition ESS < 30%MEDIUM2022-02-07

Abort caused by allocating a vector that is too large in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-143

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-143

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-144

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-144

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-88

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-88

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2022-89

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-89

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23579

Open SourceCoalition ESS < 30%HIGH2022-02-04

`CHECK`-failures during Grappler's `SafeToRemoveIdentity` in Tensorflow

CVEs:CVE-2022-23579

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23579

Open SourceCoalition ESS < 30%MEDIUM2022-02-04

PYSEC-2022-88

CVEs:CVE-2022-23579

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23579

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. The Grappler optimizer in TensorFlow can be used to cause a denial of service by altering a `SavedModel` such that `SafeToRemoveIdentity` would trigger `CHECK` failures. The fix will be included ...

CVEs:CVE-2022-23579

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23580

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. During shape inference, TensorFlow can allocate a large vector based on a value from a tensor controlled by the user. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this co...

CVEs:CVE-2022-23580

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23580

Open SourceCoalition ESS < 30%MEDIUM2022-02-04

PYSEC-2022-89

CVEs:CVE-2022-23580

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23580

Open SourceCoalition ESS < 30%MEDIUM2022-02-04

Abort caused by allocating a vector that is too large in Tensorflow

CVEs:CVE-2022-23580

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-120

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-120

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-65

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-65

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-21741

Open SourceCoalition ESS < 30%HIGH2022-02-03

Division by zero in TFLite

CVEs:CVE-2022-21741

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21741

Open SourceCoalition ESS < 30%HIGH2022-02-03

PYSEC-2022-65

CVEs:CVE-2022-21741

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21741

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. ### Impact An attacker can craft a TFLite model that would trigger a division by zero in the implementation of depthwise convolutions. The parameters of the convolution can be user controlled and...

CVEs:CVE-2022-21741

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

PYSEC-2022-112

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-112

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-57

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-57

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-21733

Open SourceCoalition ESS < 30%MEDIUM2022-02-03

PYSEC-2022-57

CVEs:CVE-2022-21733

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21733

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. The implementation of `StringNGrams` can be used to trigger a denial of service attack by causing an out of memory condition after an integer overflow. We are missing a validation on `pad_witdh` ...

CVEs:CVE-2022-21733

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-21733

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Memory exhaustion in Tensorflow

CVEs:CVE-2022-21733

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-23hm-7w47-xw72

Open SourceCoalition ESS < 30%HIGH2022-02-09

Out of bounds read in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-23hm-7w47-xw72

Open SourceCoalition ESS < 30%HIGH2022-02-09

Out of bounds read in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-105

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-105

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-50

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-50

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-21726

Open SourceCoalition ESS < 30%HIGH2022-02-03

Out of bounds read in Tensorflow

CVEs:CVE-2022-21726

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21726

Open SourceCoalition ESS < 30%HIGH2022-02-03

PYSEC-2022-50

CVEs:CVE-2022-21726

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21726

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. The implementation of `Dequantize` does not fully validate the value of `axis` and can result in heap OOB accesses. The `axis` argument can be `-1` (the default value for the optional argument) o...

CVEs:CVE-2022-21726

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-vjg4-v33c-ggc4

Open SourceCoalition ESS < 30%HIGH2022-02-09

Out of bounds read in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-vjg4-v33c-ggc4

Open SourceCoalition ESS < 30%HIGH2022-02-09

Out of bounds read in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-109

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-109

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-54

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-54

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-21730

Open SourceCoalition ESS < 30%HIGH2022-02-03

Out of bounds read in Tensorflow

CVEs:CVE-2022-21730

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21730

Open SourceCoalition ESS < 30%HIGH2022-02-03

PYSEC-2022-54

CVEs:CVE-2022-21730

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21730

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. The implementation of `FractionalAvgPoolGrad` does not consider cases where the input tensors are invalid allowing an attacker to read from outside of bounds of heap. The fix will be included in ...

CVEs:CVE-2022-21730

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-9gwq-6cwj-47h3

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Integer overflow in TFLite array creation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9gwq-6cwj-47h3

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Integer overflow in TFLite array creation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-122

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-122

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-67

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-67

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23558

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in `TfLiteIntArrayCreate`. The `TfLiteIntArrayGetSizeInBytes` returns an `int` instead of a `size_t. An attacker can cont...

CVEs:CVE-2022-23558

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23558

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-67

CVEs:CVE-2022-23558

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23558

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Integer overflow in TFLite array creation

CVEs:CVE-2022-23558

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

DEBIAN-CVE-2022-0310

Open SourceCoalition ESS < 30%HIGH2022-02-12

DEBIAN-CVE-2022-0310

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-6445-fm66-fvq2

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Integer overflows in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6445-fm66-fvq2

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Integer overflows in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-43jf-985q-588j

Open SourceCoalition ESS < 30%HIGH2022-02-09

Multiple `CHECK`-fails in `function.cc` in TensowFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-43jf-985q-588j

Open SourceCoalition ESS < 30%HIGH2022-02-09

Multiple `CHECK`-fails in `function.cc` in TensowFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-150

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-150

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-95

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-95

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23586

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that assertions in `function.cc` would be falsified and crash the Python interpreter. The fix will be included in Te...

CVEs:CVE-2022-23586

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23586

Open SourceCoalition ESS < 30%MEDIUM2022-02-04

PYSEC-2022-95

CVEs:CVE-2022-23586

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23586

Open SourceCoalition ESS < 30%HIGH2022-02-04

Multiple `CHECK`-fails in `function.cc` in TensowFlow

CVEs:CVE-2022-23586

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-132

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-132

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-77

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-77

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23568

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Integer overflows in Tensorflow

CVEs:CVE-2022-23568

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23568

Open SourceCoalition ESS < 30%HIGH2022-02-03

PYSEC-2022-77

CVEs:CVE-2022-23568

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23568

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. The implementation of `AddManySparseToTensorsMap` is vulnerable to an integer overflow which results in a `CHECK`-fail when building new `TensorShape` objects (so, an assert failure based denial ...

CVEs:CVE-2022-23568

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-247x-2f9f-5wp7

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Stack overflow in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-247x-2f9f-5wp7

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Stack overflow in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-100

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-100

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2022-155

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-155

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23591

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Stack overflow in TensorFlow

CVEs:CVE-2022-23591

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23591

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. The `GraphDef` format in TensorFlow does not allow self recursive functions. The runtime assumes that this invariant is satisfied. However, a `GraphDef` containing a fragment such as the followin...

CVEs:CVE-2022-23591

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23591

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-155

CVEs:CVE-2022-23591

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-44qp-9wwf-734r

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Heap overflow in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-44qp-9wwf-734r

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Heap overflow in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-119

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-119

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-64

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-64

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-21740

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Heap overflow in Tensorflow

CVEs:CVE-2022-21740

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21740

Open SourceCoalition ESS < 30%HIGH2022-02-03

PYSEC-2022-64

CVEs:CVE-2022-21740

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21740

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseCountSparseOutput` is vulnerable to a heap overflow. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow...

CVEs:CVE-2022-21740

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

DEBIAN-CVE-2022-0111

Open SourceCoalition ESS < 30%MEDIUM2022-02-12

DEBIAN-CVE-2022-0111

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-0459

GoogleCoalition ESS < 30%HIGH2022-02-02

Use after free in Screen Capture in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who had compromised the renderer process and convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted ...

CVEs:CVE-2022-0459

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-23263

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-23263

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

GHSA-4j82-5ccr-4r8v

Open SourceCoalition ESS < 30%HIGH2022-02-10

`CHECK`-failures in `TensorByteSize` in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4j82-5ccr-4r8v

Open SourceCoalition ESS < 30%HIGH2022-02-10

`CHECK`-failures in `TensorByteSize` in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-c94w-c95p-phf8

Open SourceCoalition ESS < 30%CRITICAL2022-02-10

Integer overflow in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-c94w-c95p-phf8

Open SourceCoalition ESS < 30%CRITICAL2022-02-10

Integer overflow in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8cxv-76p7-jxwr

Open SourceCoalition ESS < 30%HIGH2022-02-10

Null-dereference in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8cxv-76p7-jxwr

Open SourceCoalition ESS < 30%HIGH2022-02-10

Null-dereference in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-87v6-crgm-2gfj

Open SourceCoalition ESS < 30%HIGH2022-02-10

Division by zero in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-87v6-crgm-2gfj

Open SourceCoalition ESS < 30%HIGH2022-02-10

Division by zero in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gcvh-66ff-4mwm

Open SourceCoalition ESS < 30%HIGH2022-02-10

`CHECK`-failures in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gcvh-66ff-4mwm

Open SourceCoalition ESS < 30%HIGH2022-02-10

`CHECK`-failures in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-34f9-hjfq-rr8j

Open SourceCoalition ESS < 30%CRITICAL2022-02-10

Overflow and uncaught divide by zero in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-34f9-hjfq-rr8j

Open SourceCoalition ESS < 30%CRITICAL2022-02-10

Overflow and uncaught divide by zero in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-v3f7-j968-4h5f

Open SourceCoalition ESS < 30%MEDIUM2022-02-10

Division by zero in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-v3f7-j968-4h5f

Open SourceCoalition ESS < 30%MEDIUM2022-02-10

Division by zero in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-3mw4-6rj6-74g5

Open SourceCoalition ESS < 30%HIGH2022-02-09

Null pointer dereference in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-3mw4-6rj6-74g5

Open SourceCoalition ESS < 30%HIGH2022-02-09

Null pointer dereference in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-x4qx-4fjv-hmw6

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Integer overflow leading to crash in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-x4qx-4fjv-hmw6

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Integer overflow leading to crash in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f2vv-v9cg-qhh7

Open SourceCoalition ESS < 30%HIGH2022-02-09

Assertion failure based denial of service in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f2vv-v9cg-qhh7

Open SourceCoalition ESS < 30%HIGH2022-02-09

Assertion failure based denial of service in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-139

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-139

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-141

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-141

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-146

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-146

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-84

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-84

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2022-86

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-86

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2022-91

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-91

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23577

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-86

CVEs:CVE-2022-23577

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23577

Open SourceCoalition ESS < 30%HIGH2022-02-04

Null-dereference in Tensorflow

CVEs:CVE-2022-23577

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23577

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. The implementation of `GetInitOp` is vulnerable to a crash caused by dereferencing a null pointer. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow ...

CVEs:CVE-2022-23577

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23575

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-84

CVEs:CVE-2022-23575

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23575

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Integer overflow in Tensorflow

CVEs:CVE-2022-23575

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23575

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. The implementation of `OpLevelCostEstimator::CalculateTensorSize` is vulnerable to an integer overflow if an attacker can create an operation which would involve a tensor with large enough number...

CVEs:CVE-2022-23575

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23582

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that `TensorByteSize` would trigger `CHECK` failures. `TensorShape` constructor throws a `CHECK`-fail if shape is pa...

CVEs:CVE-2022-23582

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23582

Open SourceCoalition ESS < 30%MEDIUM2022-02-04

PYSEC-2022-91

CVEs:CVE-2022-23582

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23582

Open SourceCoalition ESS < 30%HIGH2022-02-04

`CHECK`-failures in `TensorByteSize` in Tensorflow

CVEs:CVE-2022-23582

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-116

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-116

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-117

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-117

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-118

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-118

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-61

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-61

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2022-62

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-62

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2022-63

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-63

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-21737

Open SourceCoalition ESS < 30%HIGH2022-02-03

Assertion failure based denial of service in Tensorflow

CVEs:CVE-2022-21737

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21737

Open SourceCoalition ESS < 30%HIGH2022-02-03

PYSEC-2022-61

CVEs:CVE-2022-21737

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21737

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. The implementation of `*Bincount` operations allows malicious users to cause denial of service by passing in arguments which would trigger a `CHECK`-fail. There are several conditions that the in...

CVEs:CVE-2022-21737

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-21738

Open SourceCoalition ESS < 30%HIGH2022-02-03

PYSEC-2022-62

CVEs:CVE-2022-21738

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21738

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Integer overflow leading to crash in Tensorflow

CVEs:CVE-2022-21738

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21738

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseCountSparseOutput` can be made to crash a TensorFlow process by an integer overflow whose result is then used in a memory allocation. The fix will be included in Tens...

CVEs:CVE-2022-21738

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

PYSEC-2022-104

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-104

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-108

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-108

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-113

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-113

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-114

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-114

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-49

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-49

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2022-53

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-53

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2022-58

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-58

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2022-59

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-59

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-21739

Open SourceCoalition ESS < 30%HIGH2022-02-03

PYSEC-2022-63

CVEs:CVE-2022-21739

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21739

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. The implementation of `QuantizedMaxPool` has an undefined behavior where user controlled inputs can trigger a reference binding to null pointer. The fix will be included in TensorFlow 2.8.0. We w...

CVEs:CVE-2022-21739

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-21739

Open SourceCoalition ESS < 30%HIGH2022-02-03

Null pointer dereference in TensorFlow

CVEs:CVE-2022-21739

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21734

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. The implementation of `MapStage` is vulnerable a `CHECK`-fail if the key tensor is not a scalar. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2....

CVEs:CVE-2022-21734

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-21734

Open SourceCoalition ESS < 30%HIGH2022-02-03

`CHECK`-failures in Tensorflow

CVEs:CVE-2022-21734

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21734

Open SourceCoalition ESS < 30%HIGH2022-02-03

PYSEC-2022-58

CVEs:CVE-2022-21734

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21735

Open SourceCoalition ESS < 30%HIGH2022-02-03

Division by zero in Tensorflow

CVEs:CVE-2022-21735

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21735

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. The implementation of `FractionalMaxPool` can be made to crash a TensorFlow process via a division by 0. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on Tenso...

CVEs:CVE-2022-21735

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-21735

Open SourceCoalition ESS < 30%HIGH2022-02-03

PYSEC-2022-59

CVEs:CVE-2022-21735

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21729

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Overflow and uncaught divide by zero in Tensorflow

CVEs:CVE-2022-21729

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21729

Open SourceCoalition ESS < 30%HIGH2022-02-03

PYSEC-2022-53

CVEs:CVE-2022-21729

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21729

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. The implementation of `UnravelIndex` is vulnerable to a division by zero caused by an integer overflow bug. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on Te...

CVEs:CVE-2022-21729

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-21725

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. The estimator for the cost of some convolution operations can be made to execute a division by 0. The function fails to check that the stride argument is strictly positive. Hence, the fix is to a...

CVEs:CVE-2022-21725

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-21725

Open SourceCoalition ESS < 30%MEDIUM2022-02-03

Division by zero in Tensorflow

CVEs:CVE-2022-21725

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21725

Open SourceCoalition ESS < 30%MEDIUM2022-02-03

PYSEC-2022-49

CVEs:CVE-2022-21725

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-wm93-f238-7v37

Open SourceCoalition ESS < 30%CRITICAL2022-02-10

Integer overflow in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-wm93-f238-7v37

Open SourceCoalition ESS < 30%CRITICAL2022-02-10

Integer overflow in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-140

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-140

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-85

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-85

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23576

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-85

CVEs:CVE-2022-23576

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23576

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Integer overflow in Tensorflow

CVEs:CVE-2022-23576

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23576

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. The implementation of `OpLevelCostEstimator::CalculateOutputSize` is vulnerable to an integer overflow if an attacker can create an operation which would involve tensors with large enough number ...

CVEs:CVE-2022-23576

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-fpcp-9h7m-ffpx

Open SourceCoalition ESS < 30%MEDIUM2022-02-09

Null pointer dereference in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fpcp-9h7m-ffpx

Open SourceCoalition ESS < 30%MEDIUM2022-02-09

Null pointer dereference in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-103

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-103

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2022-158

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-158

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23595

Open SourceCoalition ESS < 30%MEDIUM2022-02-04

Null pointer dereference in TensorFlow

CVEs:CVE-2022-23595

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23595

Open SourceCoalition ESS < 30%MEDIUM2022-02-04

PYSEC-2022-158

CVEs:CVE-2022-23595

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23595

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. When building an XLA compilation cache, if default settings are used, TensorFlow triggers a null pointer dereference. In the default scenario, all devices are allowed, so `flr->config_proto` is `...

CVEs:CVE-2022-23595

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-0610

GoogleCoalition ESS < 30%HIGH2022-02-15

Inappropriate implementation in Gamepad API in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0610

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0452

GoogleCoalition ESS < 30%CRITICAL2022-02-02

Use after free in Safe Browsing in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2022-0452

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0453

GoogleCoalition ESS < 30%CRITICAL2022-02-02

Use after free in Reader Mode in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0453

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0457

GoogleCoalition ESS < 30%HIGH2022-02-02

Type confusion in V8 in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0457

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0460

GoogleCoalition ESS < 30%CRITICAL2022-02-02

Use after free in Window Dialogue in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0460

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0532

GoogleCoalition ESS < 30%MEDIUM2022-02-09

Incorrect Permission Assignment for Critical Resource in CRI-O

CVEs:CVE-2022-0532

Affected products

ProductStatusVendorPackageEcosystem
cri-o/cri-o affected github.com github.com/cri-o/cri-o
Upstream advisory

CVE-2022-0532

GoogleCoalition ESS < 30%MEDIUM2022-02-09

An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork k...

CVEs:CVE-2022-0532

Affected products

ProductStatusVendorPackageEcosystem
cri-o affected kubernetes
openshift_container_platform affected redhat
Upstream advisory

GHSA-c582-c96p-r5cq

Open SourceCoalition ESS < 30%HIGH2022-02-10

Memory exhaustion in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-c582-c96p-r5cq

Open SourceCoalition ESS < 30%HIGH2022-02-10

Memory exhaustion in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-111

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-111

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-56

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-56

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-21732

Open SourceCoalition ESS < 30%HIGH2022-02-03

Memory exhaustion in Tensorflow

CVEs:CVE-2022-21732

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21732

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. The implementation of `ThreadPoolHandle` can be used to trigger a denial of service attack by allocating too much memory. This is because the `num_threads` argument is only checked to not be nega...

CVEs:CVE-2022-21732

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-21732

Open SourceCoalition ESS < 30%MEDIUM2022-02-03

PYSEC-2022-56

CVEs:CVE-2022-21732

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gf2j-f278-xh4v

Open SourceCoalition ESS < 30%HIGH2022-02-09

Division by zero in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gf2j-f278-xh4v

Open SourceCoalition ESS < 30%HIGH2022-02-09

Division by zero in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-121

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-121

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-66

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-66

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23557

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would trigger a division by zero in `BiasAndClamp` implementation. There is no check that the `bias_size` is non zero. The fix will be included in Tensor...

CVEs:CVE-2022-23557

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23557

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-66

CVEs:CVE-2022-23557

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23557

Open SourceCoalition ESS < 30%HIGH2022-02-04

Division by zero in TFLite

CVEs:CVE-2022-23557

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-q85f-69q7-55h2

Open SourceCoalition ESS < 30%HIGH2022-02-09

Uninitialized variable access in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-q85f-69q7-55h2

Open SourceCoalition ESS < 30%HIGH2022-02-09

Uninitialized variable access in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-137

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-137

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-82

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-82

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23573

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. The implementation of `AssignOp` can result in copying uninitialized data to a new tensor. This later results in undefined behavior. The implementation has a check that the left hand side of the ...

CVEs:CVE-2022-23573

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23573

Open SourceCoalition ESS < 30%HIGH2022-02-04

Uninitialized variable access in Tensorflow

CVEs:CVE-2022-23573

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23573

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-82

CVEs:CVE-2022-23573

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-0465

GoogleCoalition ESS < 30%HIGH2022-02-02

Use after free in Extensions in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via user interaction.

CVEs:CVE-2022-0465

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-pfjj-m3jj-9jc9

Open SourceCoalition ESS < 30%HIGH2022-02-09

Undefined behavior in `SparseTensorSliceDataset`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-pfjj-m3jj-9jc9

Open SourceCoalition ESS < 30%HIGH2022-02-09

Undefined behavior in `SparseTensorSliceDataset`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-115

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-115

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-60

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-60

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-21736

Open SourceCoalition ESS < 30%HIGH2022-02-03

PYSEC-2022-60

CVEs:CVE-2022-21736

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21736

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseTensorSliceDataset` has an undefined behavior: under certain condition it can be made to dereference a `nullptr` value. The 3 input arguments to `SparseTensorSliceDat...

CVEs:CVE-2022-21736

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-21736

Open SourceCoalition ESS < 30%HIGH2022-02-03

Undefined behavior in `SparseTensorSliceDataset`

CVEs:CVE-2022-21736

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

DEBIAN-CVE-2022-0300

Open SourceCoalition ESS < 30%HIGH2022-02-12

DEBIAN-CVE-2022-0300

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

DEBIAN-CVE-2022-0304

Open SourceCoalition ESS < 30%HIGH2022-02-12

DEBIAN-CVE-2022-0304

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0120

Open SourceCoalition ESS < 30%MEDIUM2022-02-12

DEBIAN-CVE-2022-0120

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-4099

Open SourceCoalition ESS < 30%CRITICAL2022-02-11

DEBIAN-CVE-2021-4099

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-4100

Open SourceCoalition ESS < 30%HIGH2022-02-11

DEBIAN-CVE-2021-4100

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-0458

GoogleCoalition ESS < 30%CRITICAL2022-02-02

Use after free in Thumbnail Tab Strip in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0458

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-24x4-6qmh-88qg

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Use after free in `DecodePng` kernel

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-24x4-6qmh-88qg

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Use after free in `DecodePng` kernel

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-148

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-148

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-93

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-93

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23584

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-93

CVEs:CVE-2022-23584

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23584

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a use after free behavior when decoding PNG images. After `png::CommonFreeDecode(&decode)` gets called, the values of `decode.width` and `decode.height` are in an unspe...

CVEs:CVE-2022-23584

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23584

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Use after free in `DecodePng` kernel

CVEs:CVE-2022-23584

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-0468

GoogleCoalition ESS < 30%CRITICAL2022-02-02

Use after free in Payments in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0468

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0469

GoogleCoalition ESS < 30%CRITICAL2022-02-02

Use after free in Cast in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific interactions to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0469

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-8r7c-3cm2-3h8f

Open SourceCoalition ESS < 30%MEDIUM2022-02-10

Memory leak in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8r7c-3cm2-3h8f

Open SourceCoalition ESS < 30%MEDIUM2022-02-10

Memory leak in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-142

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-142

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-87

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-87

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23578

Open SourceCoalition ESS < 30%MEDIUM2022-02-04

Memory leak in Tensorflow

CVEs:CVE-2022-23578

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23578

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. If a graph node is invalid, TensorFlow can leak memory in the implementation of `ImmutableExecutorState::Initialize`. Here, we set `item->kernel` to `nullptr` but it is a simple `OpKernel*` point...

CVEs:CVE-2022-23578

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23578

Open SourceCoalition ESS < 30%MEDIUM2022-02-04

PYSEC-2022-87

CVEs:CVE-2022-23578

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-0463

GoogleCoalition ESS < 30%HIGH2022-02-02

Use after free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.

CVEs:CVE-2022-0463

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2021-39665

Open SourceCoalition ESS < 30%HIGH2022-02-08

In checkSpsUpdated of AAVCAssembler.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation....

CVEs:CVE-2021-39665

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-23264

Open SourceCoalition ESS < 30%MEDIUM2022-02-08

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVEs:CVE-2022-23264

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

GHSA-c6fh-56w7-fvjw

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Integer overflow in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-c6fh-56w7-fvjw

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Integer overflow in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-106

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-106

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-51

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-51

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-21727

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `Dequantize` is vulnerable to an integer overflow weakness. The `axis` argument can be `-1` (the default value for the optional argument) or any other po...

CVEs:CVE-2022-21727

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-21727

Open SourceCoalition ESS < 30%HIGH2022-02-03

PYSEC-2022-51

CVEs:CVE-2022-21727

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-21727

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Integer overflow in Tensorflow

CVEs:CVE-2022-21727

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-0455

GoogleCoalition ESS < 30%MEDIUM2022-02-02

Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 98.0.4758.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2022-0455

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0604

GoogleCoalition ESS < 30%HIGH2022-02-15

Heap buffer overflow in Tab Groups in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0604

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2021-4098

Open SourceCoalition ESS < 30%HIGH2022-02-11

DEBIAN-CVE-2021-4098

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0292

Open SourceCoalition ESS < 30%MEDIUM2022-02-12

DEBIAN-CVE-2022-0292

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-0466

GoogleCoalition ESS < 30%CRITICAL2022-02-02

Inappropriate implementation in Extensions Platform in Google Chrome prior to 98.0.4758.80 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2022-0466

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-qx3f-p745-w4hr

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Integer overflow in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qx3f-p745-w4hr

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Integer overflow in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-39616

Open SourceCoalition ESS < 30%HIGH2022-02-08

Summary:Product: AndroidVersions: Android SoCAndroid ID: A-204686438

CVEs:CVE-2021-39616

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PYSEC-2022-126

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-126

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-71

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-71

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23562

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. The implementation of `Range` suffers from integer overflows. These can trigger undefined behavior or, in some scenarios, extremely large allocations. The fix will be included in TensorFlow 2.8.0...

CVEs:CVE-2022-23562

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23562

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Integer overflow in Tensorflow

CVEs:CVE-2022-23562

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23562

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-71

CVEs:CVE-2022-23562

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

ASB-A-204686438

GoogleCoalition ESS < 30%2022-02-01

ASB-A-204686438

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

DEBIAN-CVE-2022-0309

Open SourceCoalition ESS < 30%MEDIUM2022-02-12

DEBIAN-CVE-2022-0309

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-0605

GoogleCoalition ESS < 30%HIGH2022-02-15

Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and convinced a user to enage in specific user interaction to potentially exploit heap corruption via a cra...

CVEs:CVE-2022-0605

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2021-25081

GoogleCoalition ESS < 30%MEDIUM2022-02-28

The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack

CVEs:CVE-2021-25081

Affected products

ProductStatusVendorPackageEcosystem
wp_google_map affected wpgooglemap
Upstream advisory

CVE-2021-39658

Open SourceCoalition ESS < 30%HIGH2022-02-08

ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions of the caller,resulting in permission leaks。Third-party apps can use this service to arbitrarily m...

CVEs:CVE-2021-39658

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-207479207

GoogleCoalition ESS < 30%2022-02-01

ASB-A-207479207

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-9c78-vcq7-7vxq

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Out of bounds write in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9c78-vcq7-7vxq

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Out of bounds write in TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-125

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-125

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-70

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-70

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23561

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Out of bounds write in TFLite

CVEs:CVE-2022-23561

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23561

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause a write outside of bounds of an array in TFLite. In fact, the attacker can override the linked list used by the memory allocator. This can be...

CVEs:CVE-2022-23561

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23561

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-70

CVEs:CVE-2022-23561

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

DEBIAN-CVE-2022-0302

Open SourceCoalition ESS < 30%HIGH2022-02-12

DEBIAN-CVE-2022-0302

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-39671

Open SourceCoalition ESS < 30%MEDIUM2022-02-08

In code generated by aidl_const_expressions.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation...

CVEs:CVE-2021-39671

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-4v5p-v5h9-6xjx

Open SourceCoalition ESS < 30%HIGH2022-02-09

`CHECK`-failures in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-4v5p-v5h9-6xjx

Open SourceCoalition ESS < 30%HIGH2022-02-09

`CHECK`-failures in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-j3mj-fhpq-qqjj

Open SourceCoalition ESS < 30%HIGH2022-02-09

Reachable Assertion in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-j3mj-fhpq-qqjj

Open SourceCoalition ESS < 30%HIGH2022-02-09

Reachable Assertion in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-129

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-129

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-135

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-135

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-74

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-74

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

PYSEC-2022-80

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-80

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23565

Open SourceCoalition ESS < 30%HIGH2022-02-04

`CHECK`-failures in Tensorflow

CVEs:CVE-2022-23565

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23565

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-74

CVEs:CVE-2022-23565

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23565

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. An attacker can trigger denial of service via assertion failure by altering a `SavedModel` on disk such that `AttrDef`s of some operation are duplicated. The fix will be included in TensorFlow 2....

CVEs:CVE-2022-23565

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23571

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, a TensorFlow process can encounter cases where a `CHECK` assertion is invalidated based on user controlled arguments, if the tensors have an invalid `dtype` ...

CVEs:CVE-2022-23571

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23571

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-80

CVEs:CVE-2022-23571

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23571

Open SourceCoalition ESS < 30%HIGH2022-02-04

Reachable Assertion in Tensorflow

CVEs:CVE-2022-23571

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8rcj-c8pj-v3m3

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Reachable Assertion in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8rcj-c8pj-v3m3

Open SourceCoalition ESS < 30%CRITICAL2022-02-09

Reachable Assertion in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-128

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-128

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-73

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-73

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23564

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Reachable Assertion in Tensorflow

CVEs:CVE-2022-23564

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23564

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. When decoding a resource handle tensor from protobuf, a TensorFlow process can encounter cases where a `CHECK` assertion is invalidated based on user controlled arguments. This allows attackers t...

CVEs:CVE-2022-23564

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23564

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-73

CVEs:CVE-2022-23564

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qj5r-f9mv-rffh

Open SourceCoalition ESS < 30%HIGH2022-02-09

`CHECK`-fails when building invalid tensor shapes in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qj5r-f9mv-rffh

Open SourceCoalition ESS < 30%HIGH2022-02-09

`CHECK`-fails when building invalid tensor shapes in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-133

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-133

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-78

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

PYSEC-2022-78

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23569

Open SourceCoalition ESS < 30%HIGH2022-02-03

`CHECK`-fails when building invalid tensor shapes in Tensorflow

CVEs:CVE-2022-23569

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23569

Open SourceCoalition ESS < 30%CRITICAL2022-02-03

Tensorflow is an Open Source Machine Learning Framework. Multiple operations in TensorFlow can be used to trigger a denial of service via `CHECK`-fails (i.e., assertion failures). This is similar to TFSA-2021-198 and has similar fixes. We have patched ...

CVEs:CVE-2022-23569

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23569

Open SourceCoalition ESS < 30%HIGH2022-02-03

PYSEC-2022-78

CVEs:CVE-2022-23569

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

DEBIAN-CVE-2022-0301

Open SourceCoalition ESS < 30%CRITICAL2022-02-12

DEBIAN-CVE-2022-0301

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-23425

Open SourceCoalition ESS < 30%CRITICAL2022-02-11

Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base station.

CVEs:CVE-2022-23425

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39677

Open SourceCoalition ESS < 30%HIGH2022-02-11

In startVideoStream() there is a possibility of an OOB Read in the heap, when the camera buffer is ‘zero’ in size.Product: AndroidVersions: Android-11Android ID: A-205097028

CVEs:CVE-2021-39677

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-24925

Open SourceCoalition ESS < 30%MEDIUM2022-02-11

Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigger a permanent denial of service attack on a victim's devices.

CVEs:CVE-2022-24925

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-204904989

GoogleCoalition ESS < 30%2022-02-01

ASB-A-204904989

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-204905255

GoogleCoalition ESS < 30%2022-02-01

ASB-A-204905255

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-204905325

GoogleCoalition ESS < 30%2022-02-01

ASB-A-204905325

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

GHSA-5x29-3hr9-6wpw

GoogleCoalition ESS < 30%CRITICAL2022-02-11

TPM 1.2 key authorization values vulnerable to TPM transport eavesdropper in go-tpm

Affected products

ProductStatusVendorPackageEcosystem
google/go-tpm affected github.com github.com/google/go-tpm
Upstream advisory

GHSA-5x29-3hr9-6wpw

GoogleCoalition ESS < 30%CRITICAL2022-02-11

TPM 1.2 key authorization values vulnerable to TPM transport eavesdropper in go-tpm

Affected products

ProductStatusVendorPackageEcosystem
google/go-tpm affected github.com github.com/google/go-tpm
Upstream advisory

CVE-2022-23428

Open SourceCoalition ESS < 30%CRITICAL2022-02-11

An improper boundary check in eden_runtime hal service prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.

CVEs:CVE-2022-23428

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39663

Open SourceCoalition ESS < 30%HIGH2022-02-08

In openFileAndEnforcePathPermissionsHelper of MediaProvider.java, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is no...

CVEs:CVE-2021-39663

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39674

Open SourceCoalition ESS < 30%HIGH2022-02-08

In btm_sec_connected and btm_sec_disconnected of btm_sec.cc file , there is a possible use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: Andr...

CVEs:CVE-2021-39674

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20044

Open SourceCoalition ESS < 30%HIGH2022-02-09

In Bluetooth, there is a possible service crash due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126814; Issue ID:...

CVEs:CVE-2022-20044

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20045

Open SourceCoalition ESS < 30%HIGH2022-02-09

In Bluetooth, there is a possible service crash due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126820; Issue ID:...

CVEs:CVE-2022-20045

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20025

Open SourceCoalition ESS < 30%HIGH2022-02-08

In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0612683...

CVEs:CVE-2022-20025

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20026

Open SourceCoalition ESS < 30%HIGH2022-02-08

In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0612682...

CVEs:CVE-2022-20026

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20027

Open SourceCoalition ESS < 30%HIGH2022-02-08

In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0612682...

CVEs:CVE-2022-20027

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20028

Open SourceCoalition ESS < 30%HIGH2022-02-08

In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0619866...

CVEs:CVE-2022-20028

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-209700749

GoogleCoalition ESS < 30%HIGH2022-02-01

ASB-A-209700749

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-209702508

GoogleCoalition ESS < 30%HIGH2022-02-01

ASB-A-209702508

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-209702509

GoogleCoalition ESS < 30%HIGH2022-02-01

ASB-A-209702509

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-209705229

GoogleCoalition ESS < 30%HIGH2022-02-01

ASB-A-209705229

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-195752523

GoogleCoalition ESS < 30%2022-02-01

PUB-A-195752523

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

PUB-A-195752651

GoogleCoalition ESS < 30%2022-02-01

PUB-A-195752651

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

GHSA-9x52-887g-fhc2

Open SourceCoalition ESS < 30%HIGH2022-02-09

Out of bounds read in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9x52-887g-fhc2

Open SourceCoalition ESS < 30%HIGH2022-02-09

Out of bounds read in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23594

Open SourceCoalition ESS < 30%HIGH2022-02-04

Out of bounds read in Tensorflow

CVEs:CVE-2022-23594

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23594

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. The TFG dialect of TensorFlow (MLIR) makes several assumptions about the incoming `GraphDef` before converting it to the MLIR-based dialect. If an attacker changes the `SavedModel` format on disk...

CVEs:CVE-2022-23594

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23594

Open SourceCoalition ESS < 30%HIGH2022-02-04

Out of bounds read in Tensorflow

CVEs:CVE-2022-23594

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-20041

Open SourceCoalition ESS < 30%HIGH2022-02-09

In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALP...

CVEs:CVE-2022-20041

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20043

Open SourceCoalition ESS < 30%HIGH2022-02-09

In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALP...

CVEs:CVE-2022-20043

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20030

Open SourceCoalition ESS < 30%HIGH2022-02-09

In vow driver, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS058377...

CVEs:CVE-2022-20030

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39619

Open SourceCoalition ESS < 30%HIGH2022-02-08

In updatePackageMappingsData of UsageStatsService.java, there is a possible way to bypass security and privacy settings of app usage due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges ...

CVEs:CVE-2021-39619

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39672

Open SourceCoalition ESS < 30%HIGH2022-02-08

In fastboot, there is a possible secure boot bypass due to a configuration error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Version...

CVEs:CVE-2021-39672

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-202018701

GoogleCoalition ESS < 30%NONE2022-02-01

ASB-A-202018701

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-39668

Open SourceCoalition ESS < 30%HIGH2022-02-08

In onActivityViewReady of DetailDialog.kt, there is a possible Intent Redirect due to a confused deputy. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution privileges needed. Us...

CVEs:CVE-2021-39668

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-mpq4-rjj8-fjph

GoogleCoalition ESS < 30%HIGH2022-02-26

Uncontrolled Resource Consumption in github.com/google/fscrypt

Affected products

ProductStatusVendorPackageEcosystem
google/fscrypt affected github.com github.com/google/fscrypt
Upstream advisory

GHSA-mpq4-rjj8-fjph

GoogleCoalition ESS < 30%HIGH2022-02-26

Uncontrolled Resource Consumption in github.com/google/fscrypt

Affected products

ProductStatusVendorPackageEcosystem
google/fscrypt affected github.com github.com/google/fscrypt
Upstream advisory

CVE-2022-25326

GoogleCoalition ESS < 30%MEDIUM2022-02-25

Uncontrolled Resource Consumption in github.com/google/fscrypt

CVEs:CVE-2022-25326

Affected products

ProductStatusVendorPackageEcosystem
google/fscrypt affected github.com github.com/google/fscrypt
Upstream advisory

CVE-2022-25326

GoogleCoalition ESS < 30%MEDIUM2022-02-25

fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting the permissions on existing fscry...

CVEs:CVE-2022-25326

Affected products

ProductStatusVendorPackageEcosystem
fscrypt affected google
Upstream advisory

CVE-2022-22292

Open SourceCoalition ESS < 30%HIGH2022-02-11

Unprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted applications to launch arbitrary activity.

CVEs:CVE-2022-22292

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20040

Open SourceCoalition ESS < 30%HIGH2022-02-09

In power_hal_manager_service, there is a possible permission bypass due to a stack-based buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. ...

CVEs:CVE-2022-20040

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39664

Open SourceCoalition ESS < 30%MEDIUM2022-02-08

In LoadedPackage::Load of LoadedArsc.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure when parsing an APK file with no additional execution privileges needed. User interaction is...

CVEs:CVE-2021-39664

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20029

Open SourceCoalition ESS < 30%MEDIUM2022-02-09

In cmdq driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05747150; I...

CVEs:CVE-2022-20029

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20033

Open SourceCoalition ESS < 30%MEDIUM2022-02-09

In camera driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862973;...

CVEs:CVE-2022-20033

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20035

Open SourceCoalition ESS < 30%HIGH2022-02-09

In vcu driver, there is a possible information disclosure due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171675; Issue ...

CVEs:CVE-2022-20035

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39676

Open SourceCoalition ESS < 30%HIGH2022-02-08

In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...

CVEs:CVE-2021-39676

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20042

Open SourceCoalition ESS < 30%MEDIUM2022-02-09

In Bluetooth, there is a possible information disclosure due to incorrect error handling. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS061...

CVEs:CVE-2022-20042

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20038

Open SourceCoalition ESS < 30%HIGH2022-02-09

In ccu driver, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06183335; Is...

CVEs:CVE-2022-20038

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20039

Open SourceCoalition ESS < 30%HIGH2022-02-09

In ccu driver, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06183345; Issue ID...

CVEs:CVE-2022-20039

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20031

Open SourceCoalition ESS < 30%HIGH2022-02-09

In fb driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05850708; Issue...

CVEs:CVE-2022-20031

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20036

Open SourceCoalition ESS < 30%MEDIUM2022-02-09

In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0...

CVEs:CVE-2022-20036

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20037

Open SourceCoalition ESS < 30%MEDIUM2022-02-09

In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0...

CVEs:CVE-2022-20037

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20017

Open SourceCoalition ESS < 30%MEDIUM2022-02-09

In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0...

CVEs:CVE-2022-20017

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-23431

Open SourceCoalition ESS < 30%CRITICAL2022-02-11

An improper boundary check in RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.

CVEs:CVE-2022-23431

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-23432

Open SourceCoalition ESS < 30%CRITICAL2022-02-11

An improper input validation in SMC_SRPMB_WSM handler of RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.

CVEs:CVE-2022-23432

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39687

Open SourceCoalition ESS < 30%HIGH2022-02-11

In HandleTransactionIoEvent of actuator_driver.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2021-39687

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-204421047

GoogleCoalition ESS < 30%HIGH2022-02-01

PUB-A-204421047

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-23999

Open SourceCoalition ESS < 30%LOW2022-02-11

PendingIntent hijacking vulnerability in CpaReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.

CVEs:CVE-2022-23999

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-24000

Open SourceCoalition ESS < 30%LOW2022-02-11

PendingIntent hijacking vulnerability in DataUsageReminderReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.

CVEs:CVE-2022-24000

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20046

Open SourceCoalition ESS < 30%HIGH2022-02-09

In Bluetooth, there is a possible memory corruption due to a logic error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06142410; Issue ID: ALPS...

CVEs:CVE-2022-20046

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39662

Open SourceCoalition ESS < 30%HIGH2022-02-08

In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content of media provider collections due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed....

CVEs:CVE-2021-39662

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-8vwm-8vj8-rqjf

GoogleCoalition ESS < 30%MEDIUM2022-02-26

User login denial of service in github.com/google/fscrypt

Affected products

ProductStatusVendorPackageEcosystem
google/fscrypt affected github.com github.com/google/fscrypt
Upstream advisory

GHSA-8vwm-8vj8-rqjf

GoogleCoalition ESS < 30%MEDIUM2022-02-26

User login denial of service in github.com/google/fscrypt

Affected products

ProductStatusVendorPackageEcosystem
google/fscrypt affected github.com github.com/google/fscrypt
Upstream advisory

CVE-2022-25327

GoogleCoalition ESS < 30%MEDIUM2022-02-25

User login denial of service in github.com/google/fscrypt

CVEs:CVE-2022-25327

Affected products

ProductStatusVendorPackageEcosystem
google/fscrypt affected github.com github.com/google/fscrypt
Upstream advisory

CVE-2022-25327

GoogleCoalition ESS < 30%MEDIUM2022-02-25

The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file th...

CVEs:CVE-2022-25327

Affected products

ProductStatusVendorPackageEcosystem
fscrypt affected google
Upstream advisory

CVE-2021-39688

Open SourceCoalition ESS < 30%MEDIUM2022-02-11

In TBD of TBD, there is a possible out of bounds read due to TBD. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAn...

CVEs:CVE-2021-39688

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0524

Open SourceCoalition ESS < 30%MEDIUM2022-02-11

In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure of installed packages due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges ...

CVEs:CVE-2021-0524

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39631

Open SourceCoalition ESS < 30%MEDIUM2022-02-08

In clear_data_dlg_text of strings.xml, there is a possible situation when "Clear storage" functionality sets up the wrong security/privacy expectations due to a misleading message. This could lead to local information disclosure with no additional exec...

CVEs:CVE-2021-39631

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39666

Open SourceCoalition ESS < 30%MEDIUM2022-02-08

In extract of MediaMetricsItem.h, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2021-39666

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20024

Open SourceCoalition ESS < 30%HIGH2022-02-08

In system service, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS...

CVEs:CVE-2022-20024

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-209705228

GoogleCoalition ESS < 30%NONE2022-02-01

ASB-A-209705228

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-206039140

GoogleCoalition ESS < 30%MEDIUM2022-02-01

PUB-A-206039140

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-wc4g-r73w-x8mm

Open SourceCoalition ESS < 30%HIGH2022-02-09

Insecure temporary file in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-wc4g-r73w-x8mm

Open SourceCoalition ESS < 30%HIGH2022-02-09

Insecure temporary file in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-127

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-127

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

PYSEC-2022-72

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

PYSEC-2022-72

Affected products

ProductStatusVendorPackageEcosystem
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2022-23563

Open SourceCoalition ESS < 30%HIGH2022-02-04

PYSEC-2022-72

CVEs:CVE-2022-23563

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-23563

Open SourceCoalition ESS < 30%CRITICAL2022-02-04

Tensorflow is an Open Source Machine Learning Framework. In multiple places, TensorFlow uses `tempfile.mktemp` to create temporary files. While this is acceptable in testing, in utilities and libraries it is dangerous as a different process can create ...

CVEs:CVE-2022-23563

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-23563

Open SourceCoalition ESS < 30%HIGH2022-02-04

Insecure temporary file in Tensorflow

CVEs:CVE-2022-23563

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-22291

Open SourceCoalition ESS < 30%MEDIUM2022-02-11

Logging of excessive data vulnerability in telephony prior to SMR Feb-2022 Release 1 allows privileged attackers to get Cell Location Information through log of user device.

CVEs:CVE-2022-22291

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-23426

Open SourceCoalition ESS < 30%MEDIUM2022-02-11

A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allows attackers to access files with system privilege.

CVEs:CVE-2022-23426

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-23427

Open SourceCoalition ESS < 30%HIGH2022-02-11

PendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission via implicit Intent.

CVEs:CVE-2022-23427

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-23429

Open SourceCoalition ESS < 30%HIGH2022-02-11

An improper boundary check in audio hal service prior to SMR Feb-2022 Release 1 allows attackers to read invalid memory and it leads to application crash.

CVEs:CVE-2022-23429

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20032

Open SourceCoalition ESS < 30%HIGH2022-02-09

In vow driver, there is a possible memory corruption due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05852822; Issue ID: AL...

CVEs:CVE-2022-20032

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-24001

Open SourceCoalition ESS < 30%HIGH2022-02-11

Information disclosure vulnerability in Edge Panel prior to Android S(12) allows physical attackers to access screenshot in clipboard via Edge Panel.

CVEs:CVE-2022-24001

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-99cg-575x-774p

GoogleCoalition ESS < 30%MEDIUM2022-02-01

Go-Attestation Improper Input Validation with attacker-controlled TPM Quote

Affected products

ProductStatusVendorPackageEcosystem
google/go-attestation affected github.com github.com/google/go-attestation
Upstream advisory

GHSA-99cg-575x-774p

GoogleCoalition ESS < 30%MEDIUM2022-02-01

Go-Attestation Improper Input Validation with attacker-controlled TPM Quote

Affected products

ProductStatusVendorPackageEcosystem
google/go-attestation affected github.com github.com/google/go-attestation
Upstream advisory

CVE-2022-0317

GoogleCoalition ESS < 30%MEDIUM2022-02-01

Go-Attestation Improper Input Validation with attacker-controlled TPM Quote

CVEs:CVE-2022-0317

Affected products

ProductStatusVendorPackageEcosystem
google/go-attestation affected github.com github.com/google/go-attestation
Upstream advisory

CVE-2022-0317

GoogleCoalition ESS < 30%MEDIUM2022-02-01

An improper input validation vulnerability in go-attestation before 0.3.3 allows local users to provide a maliciously-formed Quote over no/some PCRs, causing AKPublic.Verify to succeed despite the inconsistency. Subsequent use of the same set of PCR va...

CVEs:CVE-2022-0317

Affected products

ProductStatusVendorPackageEcosystem
go-attestation affected google
Upstream advisory

CVE-2022-20034

Open SourceCoalition ESS < 30%MEDIUM2022-02-09

In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges n...

CVEs:CVE-2022-20034

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39669

Open SourceCoalition ESS < 30%HIGH2022-02-08

In onCreate of InstallCaCertificateWarning.java, there is a possible way to mislead an user about CA installation circumstances due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges...

CVEs:CVE-2021-39669

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-0247

GoogleCoalition ESS < 30%HIGH2022-02-25

An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO that they do not have permission to. We recommend upgrading past commit d97c05d2301799ed585620a9c5c739...

CVEs:CVE-2022-0247

Affected products

ProductStatusVendorPackageEcosystem
fuchsia affected google
Upstream advisory

GHSA-wqwf-x5cj-rg56

Open SourceEPSS <= 49%CRITICAL2022-02-15

Kubernetes Arbitrary Command Injection

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-wqwf-x5cj-rg56

Open SourceEPSS <= 49%CRITICAL2022-02-15

Kubernetes Arbitrary Command Injection

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GO-2021-0172

Open SourceEPSS <= 49%MEDIUM2022-02-15

Denial of service when parsing large forms in mime/multipart

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

GHSA-jp32-vmm6-3vf5

Open SourceEPSS <= 49%HIGH2022-02-15

Directory Traversal in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

GHSA-jp32-vmm6-3vf5

Open SourceEPSS <= 49%HIGH2022-02-15

Directory Traversal in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

GO-2022-0701

Open SourceEPSS <= 49%CRITICAL2022-02-15

Directory traversal in k8s.io/kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2021-25011

GoogleEPSS <= 49%MEDIUM2022-02-28

The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's...

CVEs:CVE-2021-25011

Affected products

ProductStatusVendorPackageEcosystem
wp_google_map affected wpgooglemap
Upstream advisory

OSV-2021-1658

Open SourceAll remainingHIGH2022-02-18

Null-dereference READ in istio.io/istio/security/pkg/util.ExtractJwtAud

Affected products

ProductStatusVendorPackageEcosystem
istio affected Go istio
Upstream advisory

GHSA-h6gw-r52c-724r

Open SourceAll remainingCRITICAL2022-02-09

NULL Pointer Dereference and Access of Uninitialized Pointer in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h6gw-r52c-724r

Open SourceAll remainingCRITICAL2022-02-09

NULL Pointer Dereference and Access of Uninitialized Pointer in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-43q8-3fv7-pr5x

Open SourceAll remainingHIGH2022-02-09

Improper Validation of Integrity Check Value in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-43q8-3fv7-pr5x

Open SourceAll remainingHIGH2022-02-09

Improper Validation of Integrity Check Value in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-wcv5-vrvr-3rx2

Open SourceAll remainingCRITICAL2022-02-09

Integer Overflow or Wraparound in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-wcv5-vrvr-3rx2

Open SourceAll remainingCRITICAL2022-02-09

Integer Overflow or Wraparound in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

OSV-2022-125

Open SourceAll remainingHIGH2022-02-06

Invalid-free in NIOHTTP2.NIOHTTP2Handler.

Affected products

ProductStatusVendorPackageEcosystem
grpc-swift affected OSS-Fuzz grpc-swift
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.